DE EN

Privacy

00

In two sentences

What this is about

I take the protection of your data seriously. This page explains which data I process when you visit roman-thomas.de, for what purpose, on which legal basis, and how you can exercise your rights.
01

Controller

Who is responsible for this site

Name
Roman Thomas
Address
Wittinger Straße 38B
29223 Celle
Deutschland
Phone
0175 9390007
Email
kontakt@roman-thomas.de
A data protection officer is not required by law and has not been appointed.
02

Hosting

Where this site runs

This site is delivered via Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When you visit, Cloudflare processes technically necessary data in server log files (IP address, date and time of access, page requested, amount of data transferred, browser type, operating system, referrer URL). This data is needed to deliver the site reliably and securely and to protect it against attacks. The legal basis is Art. 6 Abs. 1 lit. f DSGVO (GDPR).
A data processing agreement under Art. 28 DSGVO is in place with Cloudflare (Cloudflare Data Processing Addendum, version 6.4 of April 3, 2026). Since Cloudflare is headquartered in the USA and data may be transferred there, the transfer is based on the Standard Contractual Clauses of the EU Commission (Implementing Decision 2021/914) and the EU-U.S. Data Privacy Framework. Cloudflare is certified under ISO/IEC 27001 and 27701.
You can find Cloudflare’s privacy policy at https://www.cloudflare.com/privacypolicy/.
03

Fonts

How the typefaces are loaded

The display typeface N27 is loaded locally from my own server. No connection to third parties is established.
The reading typeface Inter is also served locally from my own server. No Google Fonts or comparable third-party CDNs are embedded.
04

Contact

When you write to me

If you write to me by email, I process the data you provide (at least your name and email address, and where applicable your phone number and the content of your inquiry) in order to answer your inquiry.
The legal basis is Art. 6 Abs. 1 lit. b DSGVO insofar as your inquiry is aimed at concluding a contract, and otherwise Art. 6 Abs. 1 lit. f DSGVO, my legitimate interest in handling inquiries.
I delete the data once your inquiry has been dealt with and no statutory retention obligations stand in the way.
05

Analytics

Audience measurement

For audience measurement I use Cloudflare Web Analytics, a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare Web Analytics works without cookies and without cross-device tracking. It collects anonymous usage data: pages visited, time on page, referrer source, browser and device type, approximate geographic region.
IP addresses are processed solely for bot and spam detection and are not stored. These data do not make it possible to identify individual persons. The legal basis is Art. 6 Abs. 1 lit. f DSGVO, my legitimate interest in privacy-friendly audience measurement. No cookie banner is required for this.
For data transfers to the USA, the same safeguards apply as under section 02 (Standard Contractual Clauses, Data Privacy Framework). You can find Cloudflare’s privacy policy at https://www.cloudflare.com/privacypolicy/.
06

Cookies

What is stored

This site itself does not set any cookies, neither technically necessary ones nor analytics or marketing cookies. Only if you load a virtual tour by clicking on it can the provider set its own cookies (see section 08). Since that embed only loads on your click, no cookie banner is required.
One exception is the protected client area at portal.roman-thomas.de: after signing in, a technically necessary session cookie is set there. What it does and why no consent is needed for it is explained in section 07.
Should anything change beyond this, for instance because an interactive feature needs a cookie that requires consent, this section will be updated and, if necessary, a consent banner will be added.
07

Client portal

The protected project space (portal.roman-thomas.de)

For ongoing client projects I run a protected project space at portal.roman-thomas.de. There, clients can view drafts, read presentations, and give feedback. Access works without a password: you enter your email address and receive a personal sign-in link that is valid for 15 minutes and can be used only once. Access is open exclusively to people whose email address I have previously registered for a joint project.
Data processed
In the portal I process the data needed for our collaboration: name, email address, form of address, project content (drafts, images, texts), and your feedback with its timestamp. So that the greeting in the project space feels personal, I also store the time of your current and your previous visit as well as a simple visit counter. These details are overwritten on each visit, are not combined into a movement profile, and are not evaluated for advertising purposes. The legal basis is Art. 6 Abs. 1 lit. b DSGVO, that is, the performance of the contract or pre-contractual measures.
Session cookie
After signing in, the portal sets exactly one cookie (rt_sess). It maintains your session so you stay signed in, and it is strictly necessary for that purpose. It contains only a random identifier, no tracking, no advertising, no analytics. Under § 25 Abs. 2 Nr. 2 TDDDG, no consent is required for strictly necessary cookies, which is why there is no cookie banner. The cookie is deleted when you sign out; otherwise it expires automatically.
Protection against automated sign-ins
To keep the sign-in field from being abused by bots, Cloudflare Turnstile checks at login whether the request comes from a human. In the process, technical details of your browser and your IP address are processed. Turnstile is designed for data minimization, usually works invisibly, and does not serve advertising or cross-site tracking. The provider is Cloudflare (see section 02, the same data processing agreement). The legal basis is my legitimate interest in a secure sign-in procedure protected against abuse (Art. 6 Abs. 1 lit. f DSGVO).
Service providers
Like this site, the portal runs on Cloudflare (see section 02, the same data processing agreement); the project data is stored there as well. The sign-in and notification emails are sent on my behalf by the service Resend (Resend, Inc., USA); your email address is processed in the process. The Standard Contractual Clauses of the EU Commission apply to the transfer to the USA.
Retention period
I delete project data and feedback as soon as they are no longer needed for our collaboration and no statutory retention obligations stand in the way.
08

Virtual tours

Embedded 360-degree walkthroughs

On the photography page I offer virtual 360-degree tours via the service mpskin (my.mpskin.com). The tours do not load automatically. At first you only see a preview, and the tour is loaded only once you start it by clicking. Before that, no connection to mpskin exists.
As soon as you load a tour by clicking, your browser establishes a direct connection to the provider’s servers. Your IP address is transmitted in the process, and the provider may set its own cookies or comparable technologies, over which I have no influence. The legal basis is your consent, which you give with the click (Art. 6 Abs. 1 lit. a DSGVO).
Which data the provider processes in detail can be found in mpskin’s privacy policy. If you do not load a tour, no connection is established and no data is transmitted to mpskin.
09

Audio content

Where the sounds come from

Some of the audio content used on this website comes from Pixabay and Mixkit and is used under the respective platform license. The files were downloaded, technically adapted, and embedded locally on this website.
No connection to Pixabay or Mixkit is established during playback.
10

Security

Encryption

For security reasons and to protect the transmission of confidential content, this site uses TLS encryption. You can recognize an encrypted connection by the address bar of your browser showing https instead of http and displaying the lock symbol.
11

Your rights

What you can request

You have the following rights toward me as the controller, at any time:
Access to the data stored about you and to how it is processed (Art. 15 DSGVO)
Rectification of inaccurate data (Art. 16 DSGVO)
Erasure of your data (Art. 17 DSGVO)
Restriction of processing (Art. 18 DSGVO)
Data portability in a structured, commonly used format (Art. 20 DSGVO)
Objection to processing based on legitimate interest (Art. 21 DSGVO)
Withdrawal of consent once given, with effect for the future (Art. 7 Abs. 3 DSGVO)
A short email to kontakt@roman-thomas.de is all it takes.
12

Complaints

Supervisory authority

If you believe that the processing of your data violates the GDPR, you can lodge a complaint with a supervisory authority. The authority responsible for me is:
Authority
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
Phone
0511 120-4500
Web
lfd.niedersachsen.de
13

Changes

Version of this policy

This privacy policy is dated 2026. Technical changes to the site or changes in legal requirements may make an update necessary. You will always find the current version here on this page.
Roman Thomas · Wittinger Straße 38B · 29223 Celle Legal Notice