Controller
Martin Hübner, Kremper Straße 8, 20251 Hamburg, Deutschland. Email: contact@martinhuebner.me. I am the controller for the processing described here, within the meaning of Art. 4(7) GDPR. The full provider information is in the legal notice.
Visiting this website
This is a static site. It sets no cookies, runs no analytics and embeds no tracking pixels. There are no forms and no newsletter, so there is nothing here to submit, and the only contact route is a mailto: link, which opens your own mail program with an empty message — nothing reaches me until you write it and send it. Loading a page makes no request to any third party: the typefaces are served from this domain rather than from a font provider, so no other company learns that you were here.
Hosting and server logs
The site is hosted by Netlify, Inc., San Francisco, California, USA, acting as a processor on my instructions under a data processing agreement (Art. 28 GDPR). Delivering a page necessarily produces server-log data: your IP address, the time of the request, the URL requested, and the user-agent string your browser sends. That data is processed to deliver the site, keep it available and defend it against attacks, on the basis of Art. 6(1)(f) GDPR; I do not combine it with anything else and do not use it to identify visitors. Netlify is a US provider, so that log data is transferred to the United States. Two mechanisms carry that transfer, in this order. First, adequacy: Netlify states that it complies with the EU-U.S. Data Privacy Framework and has certified adherence to its principles to the U.S. Department of Commerce, and the Framework rests on the Commission's own adequacy decision, Implementing Decision (EU) 2023/1795 — a transfer covered by it needs no separate safeguard. Second, the fallback: if the Framework is invalidated or Netlify does not re-certify, § 14.3 of its data processing agreement puts the EU Standard Contractual Clauses in its place (Implementing Decision (EU) 2021/914, Module Two, controller to processor), while § 14.2 of the same agreement makes the Framework the primary route. That document is also how you obtain a copy of the safeguards, which is what Art. 13(1)(f) GDPR asks for beyond naming them. One limit, stated plainly: what I checked is Netlify's own agreement and privacy policy (both read 21 August 2026), not the official participant list — so the corroboration here is the provider's own published statement, and a certification is held per company and can lapse. That is exactly why the fallback is named too — the paragraph stays true even if the Framework does not.
How I contact people about my work
I approach a small number of organisations directly. For that I collect business contact data about people in their professional capacity — the person responsible for a topic my work touches — from publicly accessible company pages such as team, management, imprint, press and career pages, and from publicly readable professional profiles. The purpose is direct marketing: an individually written approach about the services this site describes, and the message says so plainly. Naming it that way is deliberate, because direct marketing is the processing that carries the unconditional right to object set out below. The approach is a bounded sequence rather than a campaign: at most three messages over roughly three weeks, and then no further contact, whether or not you reply. There is no mailing list, no bulk sending and no automated dispatch. Drafting is AI-assisted; every message is read, edited and sent by me, one at a time. Any assessment behind it is a professional judgement about business fit — whether the topic plausibly sits with this person, whether writing at all makes sense — and I am the one who decides whether to make contact. No decision about you is taken solely by automated means, and none produces legal effects for you or similarly significantly affects you.
Legal basis
Both activities rest on legitimate interests, Art. 6(1)(f) GDPR. For the website, that interest is delivering a working, secure page to you. For outreach, it is offering professional services to organisations that plausibly need them, and I weighed it against your interest in not being contacted. The balance holds because of the limits that come with it: I write to people only in a professional capacity and only at business addresses, never to a private address or a private number; each person receives a short, bounded sequence rather than an open-ended campaign; and an objection ends the contact immediately and permanently. If you tell me the balance came out wrong in your case, that settles it — see the section on objection below.
Where your data came from
Art. 14(2)(f) GDPR requires me to tell you the source of data I did not get from you, and whether it came from publicly accessible sources. It did, and the categories are the ones named in the outreach section above: public company pages, and publicly readable professional profiles. Above that requirement there is a working habit worth stating, because it is what makes a question answerable in practice: a contact record carries its own provenance, with the public URL a data point was read from and the date it was read stored alongside it. So if you ask which page names you as responsible for a given topic, that page and that date are what I can give you — and where a source has since moved or vanished, I can tell you that too. Nothing in a contact record comes from a data broker, a purchased list or a lead-generation provider.
What data I hold
For a business contact: name, professional role or function, employer, business contact details (a work email address, and a work phone number where the company publishes one), and professional statements the person has published themselves — a talk, an article, a job posting they are named in. What is deliberately absent: no private postal addresses, no private phone numbers, nothing from personal social media accounts, nothing from behind a login or a paywall, no special categories of data under Art. 9 GDPR, and no inferences about your private life, your health, your beliefs or anything else outside your professional role. Every sourced fact carries the URL it was read from and the date it was read. Where a record holds a professional judgement rather than a quotation — that a role plausibly owns a particular decision, that someone probably does business in German — it is written down as an inference and marked as one, not presented as fact. That marking is what lets you have an inference corrected as easily as a fact.
Who receives the data
Nobody buys this data and nobody rents it: I do not sell contact data and do not share it for advertising or for anyone else's marketing. There is no CRM, no sales-automation platform and no mailing list anywhere in the chain, and records are kept as ordinary files rather than in a vendor's database. Data does reach service providers, though, and these are the categories: the hosting provider for this website, described above; my email provider, which necessarily processes any message I send or receive; the professional network through which a first contact is made, because sending you a message there discloses your name and the text of that message to the platform, which acts as an independent controller under its own terms and its own privacy notice; and the AI service I use to research and to draft, which processes the content of a contact record — name, role, employer, published professional statements — on my instructions. Some of these providers are established outside the EEA or process data there. For the hosting provider that question has its own section above; the two on the outreach side have two different answers, and running them together would make one of them false. My email provider is established in the United States and certified under the EU-U.S. Data Privacy Framework, so that transfer rests on the Commission's adequacy decision for the Framework, Implementing Decision (EU) 2023/1795, and needs no further safeguard. The AI service rests on a different basis: it is used on commercial terms that incorporate a data processing addendum, and the addendum carries the transfer on the EU Standard Contractual Clauses, Implementing Decision (EU) 2021/914. Adequacy for the one, contractual safeguards for the other. Those same commercial terms exclude the content I send from being used to train models, which is probably the sentence a person in a contact record cares about most: it is a contractual exclusion, not a reassurance. Both positions were taken from the providers' own published terms on 21 August 2026, and since certification is held per company and can lapse, a change on that side changes this paragraph with it. This notice discloses categories of recipient rather than vendor names, so what is named here is the instrument and not the supplier. Beyond these, data goes to a third party only where I am legally obliged to disclose it.
How long I keep it
Contact data is kept while there is a live business interest in the contact, and deleted three months after the last contact — the last message I sent, or the last reply you sent me. That period is short rather than generous, and the reason is the shape of the approach itself: at most three messages over roughly three weeks, and I treat silence at the end of that sequence as a decline, so no second approach follows. That is my own standard rather than one the law imposes, and because nothing further follows, holding the record past that point would serve no purpose — and under storage limitation, Art. 5(1)(e) GDPR, no purpose is the whole of the answer. Server-log data is a different case, because I never hold it: the hosting provider holds it for as long as it needs to deliver the site and defend it against attacks, and not beyond that purpose, and I keep no copy and have no access to a log archive. Its documentation publishes a retention period for function logs but none for the access logs an ordinary page request produces, and its privacy policy commits only to determining retention by the amount, nature and sensitivity of the data (both read 21 August 2026). So what I can honestly give you for the logs is the criteria rather than a duration — delivery and security of this site, and nothing beyond that — which is the alternative Art. 13(2)(a) GDPR provides where a period cannot be stated. If the provider publishes a period, or gives me one on request, it will be named here instead. One thing is deliberately kept when you object: a minimal suppression record, enough to recognise you and not write again. The dossier goes and that one entry stays, and it is the entry rather than the dossier that protects you, so it is retained for as long as that purpose lasts.
Your rights
You have the right of access to the data I hold about you (Art. 15 GDPR), to have it corrected (Art. 16), to have it erased (Art. 17), to have its processing restricted (Art. 18), and, where the conditions apply, to receive it in a portable form (Art. 20). The right to object has its own section below, because here it is the one that matters most. To exercise any of them, send one email to contact@martinhuebner.me. There is no form to fill in, no account to create and no charge, and I will not ask you to prove more than that you are the person the data is about.
Your right to object
Under Art. 21(2) GDPR you may object at any time to the processing of your data for direct marketing. That objection needs no reason and no justification, and once you make it, the processing for that purpose stops. A single line of reply is enough — “no thanks”, “stop writing” — in any form and any wording; it does not have to reach me as a formal request. I honour it immediately, permanently, and across every channel rather than only the one you replied on, and no later message asks you to reconsider. Independently of direct marketing, you may object under Art. 21(1) GDPR to processing based on legitimate interests on grounds relating to your particular situation.
Complaints to a supervisory authority
Under Art. 77 GDPR you may lodge a complaint with a data protection supervisory authority about how your data is handled here, and you do not have to contact me first. The authority competent for me is Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg, telephone (040) 428 54-4040, mailbox@datenschutz.hamburg.de. It asks that complaints and reports be submitted through its own form rather than by email, at the path /service-information/beschwerde-oder-hinweis-einreichen on datenschutz-hamburg.de (read 21 August 2026) — worth knowing before you write, because it saves you the detour. Naming Hamburg is a convenience for you, not a restriction: Art. 77 GDPR leaves you the authority of your habitual residence, the one for your place of work, and the one for the place of the alleged infringement, and any of the three can take your complaint.
Getting in touch
For anything in this notice — access, correction, erasure, an objection, or the question of where one particular detail came from — write to contact@martinhuebner.me. One address, one person, the same route for all of it.