Skip to content

Legal

Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Mainframe IT Solutions – Travis Hull
Sole proprietorship
Zum Viadukt 15
64711 Erbach
Germany
Phone: +49 6062 2630045
Email: contact@mainframe-it.com

No data protection officer has been appointed because there is currently no statutory obligation to appoint one.

2. Current website setup

In the current implementation, no cookies are set. I use a cookieless analytics service for reach measurement (see section 6). Space Grotesk, Instrument Serif, and JetBrains Mono are served locally from this domain; no external font service is loaded.

If you switch between light and dark display mode, pause background motion, or mute or enable interaction sounds, your browser stores those preferences in Local Storage under the keys theme, mainframe.motion, and mainframe.sound. These settings remain in your browser and are not used by us for recognition or analytics.

If analytics, marketing tools, embedded media, or other third-party services are introduced later, this policy will be updated before or alongside that change. Consent controls will be added where legally required.

3. Server log data

When you access this website, the hosting provider automatically records information transmitted by your browser. This includes: IP address, date and time of access, transferred data volume, browser type and operating system, and referrer URL.

This data is processed to ensure operation, defend against attacks, and troubleshoot errors. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the stable and secure operation of the website). Retention depends on the log rotation actually configured and on operational security needs. Log data is deleted or anonymised once it is no longer required for these purposes; a specific security incident or legal obligation may require longer retention.

4. Hosting

The website is hosted by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The servers are located in Germany (Falkenstein). A data processing agreement (DPA) under Art. 28 GDPR is in place with Hetzner. The DPA is available at: https://accounts.hetzner.com/account/dpa

Hetzner's privacy policy: https://www.hetzner.com/de/legal/privacy-policy/

5. Contact form and email

If you contact me via the contact form or by email, I process the information you provide, in particular your name, email address, optional phone number, selected category, message content, and language. The contact form additionally processes date and time, IP address, and user agent so that abuse can be limited, errors can be traced, and the request can be assigned correctly.

For server-side rate limiting, an entry derived from the IP address is also held temporarily in the form service's volatile memory. No separate persistent database is created for this purpose.

The legal basis is Art. 6 (1) (b) GDPR where your enquiry concerns the initiation or performance of a contract. Otherwise, the legal basis is Art. 6 (1) (f) GDPR; my legitimate interest is responding to enquiries, operating the contact form securely, and preventing abuse.

Contact-form enquiries are transmitted by my form handler over an encrypted connection to contact@mainframe-it.com. Both these enquiries and direct emails to contact@mainframe-it.com, support@mainframe-it.com, or security@mainframe-it.com are processed through Google Workspace. The provider for customers based in Germany is Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. Google may engage group companies and subprocessors, including outside the European Economic Area. The data processing terms, including provisions governing international transfers, are available at: https://workspace.google.com/terms/dpa_terms/. The current subprocessor list is available at: https://workspace.google.com/terms/subprocessors/. I do not use messages for advertising or tracking purposes.

Enquiries are stored for as long as needed to process and reasonably follow up the request. Enquiries that are no longer needed are reviewed and deleted regularly. If an enquiry results in a contractual or business relationship, statutory retention periods may apply. Providing the data is neither a statutory nor contractual requirement; however, without the required minimum information I cannot process your enquiry.

6. Analytics (Umami)

I use Umami, a cookieless analytics tool, to evaluate the use of this website statistically. The provider is Umami Software, Inc., 28 Geary St, Suite 650 #243, San Francisco, CA, USA. The account is configured for Umami Cloud's EU data region. The tracker file and collection path are served under my own domain; requests are forwarded to Umami Cloud through my reverse proxy. This does not make Umami self-hosted.

In the current configuration, Umami sets no cookies and we do not use user-linked Distinct IDs. Depending on the URL visited and the provider configuration, the data processed can include hostname, page path and query parameters, page title, referrer, browser, operating system, device type, screen size, language, approximate region and city, and session and visit metrics. UTM parameters or advertising click identifiers contained in a URL may also be recorded. According to Umami, the IP address is used to derive location metrics but is not stored. Umami documents its defined metrics in its metric reference.

The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is the needs-based design and statistical evaluation of our website. Analytics is configured without cookies and without intentionally reading or writing browser storage for analytics purposes, so no consent banner is currently used for Umami. A data processing agreement under Art. 28 GDPR is in place with the provider; transfers involving the US-based provider are safeguarded through the EU Standard Contractual Clauses incorporated into that agreement (Art. 46 GDPR). The DPA is available at: https://umami.is/dpa.

7. Your rights as a data subject

You have the following rights vis-à-vis the controller in respect of personal data concerning you:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

To exercise your rights, you can contact me at any time by email at contact@mainframe-it.com.

8. Right to lodge a complaint with a supervisory authority

Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data-protection supervisory authority. The competent authority is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI) (Hessian Commissioner for Data Protection and Freedom of Information)
Wilhelmstraße 7
65185 Wiesbaden
Phone: 0611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de

9. Data security

This website uses TLS encryption. Fully secure data transmission over the internet is not possible by current standards; appropriate technical and organisational measures are nevertheless maintained on an ongoing basis.

10. Automated decision-making

Automated decision-making, including profiling, does not take place.

11. Transparency about AI-generated content

The film sequences on the home page, along with the images and film sequences in the web experiments in “Mainframe Lab”, were created using generative AI. I disclose this voluntarily. The labelling duty in Article 50(4) of Regulation (EU) 2024/1689 (AI Act) targets deep fakes — material depicting real persons, places, objects or events that could falsely appear authentic. The motifs used here are evidently artistic and fictional, and the web experiments explicitly show fictitious businesses rather than client projects.

This website uses no AI chatbot and no AI system that interacts with you or evaluates your data. Editorial content is reviewed by a human before publication and published under my editorial responsibility.

12. Changes to this privacy policy

This privacy policy will be updated whenever changes to the website or to processing operations require it. The current version is always available at this URL.

As of: September 2026