Privacy Policy
The short version
This website stores nothing on your device until you agree to it. The one cookie we set without asking is the one that records your answer to the cookie question — without it we would have to put that question to you on every page. If you accept analytics we load Google Analytics, and you can take that back at any time. If you decline, your browser never contacts Google at all.
Every page is served from our own domain, with one further exception that you have to ask for: the booking calendar on the contact page, which is fetched only if you choose to book a call. The only data that reaches us automatically is what our host records to deliver the page, and whatever you choose to tell us when you get in touch.
The sections below set that out in the detail the GDPR requires, including your rights and how to exercise them.
Who is responsible
The controller for data processing on this website is:
Schmezko & Gottselich GbRIm Gesenk 2231275 LehrteGermany- hello@polluxdev.com
- Phone
- +49 176 53200526
We are a two-person business and have not appointed a data protection officer, as we are not required to under Art. 37 GDPR and § 38 BDSG.
Visiting this website
When you open a page, your browser sends technical information that our hosting provider records in order to deliver the page and keep the service secure. This is:
- your IP address
- the date and time of the request
- the page or file requested
- the HTTP status and amount of data transferred
- the referring page, where your browser sends one
- your browser type, version and operating system
We do not combine this data with anything else, and we do not use it to identify individual visitors. The legal basis is Art. 6(1)(f) GDPR: we have a legitimate interest in a website that is reachable, stable and protected against attack.
Hosting
This site is hosted on Cloudflare Workers, a service of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, and its European entity Cloudflare Germany GmbH. Cloudflare processes the request data described above on our behalf as a processor under Art. 28 GDPR, on the basis of a data processing agreement. Cloudflare also filters traffic to protect the site against denial-of-service attacks and other abuse.
Data may be processed on servers outside the European Union. The transfer is covered by the standard contractual clauses adopted by the European Commission and Cloudflare's certification under the EU-U.S. Data Privacy Framework.
Fonts, content and assets
Apart from Google Analytics and the booking calendar — both described below, both loaded only once you have decided — this site loads nothing from a third-party server. The typefaces come from Google Fonts, but they are downloaded when we build the site and served from our own domain afterwards — your browser never contacts Google, and no connection data reaches it.
The same applies to everything else on the page. Text, images and any content we manage in an external editing system are fetched when the site is built, not when you visit it. There are no embedded videos, maps, social widgets or advertising scripts anywhere on the site. The Google Analytics script is the only thing loaded from a third-party server, and it is loaded only after you consent to it.
Cookies
Cookies are small text files a website stores on your device. We keep them to a minimum. On your first visit a banner asks whether you consent to analytics. Until you answer, nothing is written to or read from your device apart from the cookie that records the answer itself.
This website may set the following cookies:
- cc_cookie (necessary) — Stores which cookies you agreed to, so you are not asked again on every page. Lifetime: 6 months. Set by us (first-party).
- _ga (analytics) — Assigns a randomly generated number so repeat visits can be told apart without identifying you. Lifetime: 2 years. Set by Google (first-party).
- _ga_VSN6LC5KVS (analytics) — Keeps the state of the current session for this property. Lifetime: 2 years. Set by Google (first-party).
The consent cookie is strictly necessary and exempt from consent under § 25(2)(2) TTDSG: it is required to provide the service you asked for — a website that respects your privacy choice. It holds your selection and nothing else: no identifier for you, and no record of your behaviour.
The analytics cookies do not exist until you have agreed, and are deleted the moment you withdraw. We use no heatmaps, no session recording, no A/B testing, and no advertising or conversion tracking.
The booking calendar on the contact page stands apart from all of this: if you open it, Cal.com stores what it needs inside its own frame in order to run the booking. It is never loaded unless you ask for it.
Google Analytics
If you consent to the analytics category, we load Google Analytics 4. It is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acting as our processor under Art. 28 GDPR on the basis of the Google Ads Data Processing Terms, with Google LLC (United States) engaged as a sub-processor. We use it to see which pages actually get read and how visitors find us.
The legal basis is your consent alone, under Art. 6(1)(a) GDPR and § 25(1) TTDSG. We do not fall back on a legitimate interest for this. Without your consent the script is not loaded: your browser makes no connection to googletagmanager.com, no cookies are set, and no data is sent to Google — not even cookieless measurement signals.
Once you have consented, the following is processed:
- a randomly generated, pseudonymous identifier (client ID) held in the cookies listed above
- the pages you open, and the time and duration of the visit
- the referring page or search term that brought you here
- device type, screen size, browser, operating system and language setting
- an approximate location at country and region level, derived from your IP address
Google shortens the IP address before storing it. We never receive it, and we see aggregated reports only; we cannot identify an individual from them.
What we deliberately do not do: we do not enable Google Signals, we use no advertising, remarketing or audience features, we do not link the data across devices or with other Google services, and we send Google no customer data of our own. The advertising consent signals stay permanently denied in our code.
Data may be processed on Google LLC servers in the United States. That transfer is covered by the standard contractual clauses adopted by the European Commission and Google's certification under the EU-U.S. Data Privacy Framework. Despite those safeguards, access by US authorities cannot be entirely ruled out.
Google stores the underlying user- and event-level data for two months, the shortest period Google offers. After that only aggregated reports remain, with no link to an individual identifier.
You can withdraw your consent at any time with effect for the future: open your . The analytics cookies are deleted and the script stops loading. Independently of that, you can prevent collection by Google Analytics with the browser add-on Google provides. How Google handles the data is set out in its privacy policy.
Contacting us
If you email or call us, we process the contact details and the content of your message in order to answer it. Where you contact us about a possible project, the legal basis is Art. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract. For every other enquiry it is Art. 6(1)(f) GDPR, our legitimate interest in responding to the people who approach us.
The form on our contact page collects your work email, your store address, an optional storefront preview password, which of our services the project is closest to, and your description of what you need. We process all of it in order to answer you; the legal basis is Art. 6(1)(b) GDPR. The form posts to our own server, which sends the result to us as an email — nothing is stored in a database on the way.
The storefront preview password is optional and is only ever the password Shopify puts in front of an unpublished storefront. We never ask for an admin or staff login, and you should never send us one. Where you do give us a preview password, we delete it as soon as your enquiry has been answered.
Email reaches us through our email provider, which processes the message on our behalf under a data processing agreement. Enquiries sent through the contact form are delivered into that same inbox by Resend, Inc. (United States), also acting as our processor under Art. 28 GDPR, with any transfer outside the European Union covered by the standard contractual clauses adopted by the European Commission. Email is not encrypted end to end in transit unless both sides support it; please do not send us anything highly confidential by email without agreeing a route with us first.
Booking a call
The calendar on our contact page is provided by Cal.com, Inc. (United States), acting as our processor under Art. 28 GDPR. It is loaded at one moment only: after you have submitted the form and asked to book a call. If you send your details without booking, or never get that far, your browser does not contact Cal.com at all.
Once the calendar loads, Cal.com receives your IP address and browser information in order to serve it, and — if you go on to book — the time you choose along with the email address and description already carried over from the form. Data may be processed on servers outside the European Union on the basis of the standard contractual clauses adopted by the European Commission. The legal basis is Art. 6(1)(b) GDPR: you are asking us to arrange an appointment.
Our Shopify apps
This policy covers polluxdev.com only. Our apps on the Shopify App Store run inside a merchant's own Shopify store and process store data under a separate agreement with that merchant, alongside the data protection terms of the App Store listing. If you are a merchant and need the details for your own records, write to us and we will send them.
Who receives your data
We do not sell data and we do not pass it on for advertising. Data is only shared with processors acting on our instructions — our hosting provider, our email provider, Resend for delivering contact-form enquiries, Google for audience measurement where you have consented to it, and Cal.com if you book a call — and with public authorities where we are legally obliged to do so. Where a project makes it necessary, we may involve tax advisors, accountants or lawyers, all of whom are bound by professional confidentiality.
How long we keep it
Server log data is deleted or anonymised by our host after a short retention period, normally measured in days, and is kept longer only where a specific incident is being investigated.
Cookies expire on the schedule set out in the table above, and you can delete them yourself in your browser at any time. The user- and event-level data in Google Analytics is deleted after two months. If you withdraw your consent, the analytics cookies are removed immediately.
Correspondence is kept as long as it takes to deal with your enquiry and for as long afterwards as we may need it to answer follow-up questions. A storefront preview password sent with an enquiry is the exception: it is deleted as soon as the enquiry is answered. Where commercial or tax law requires it, business letters and invoices are retained for the statutory period of six or ten years under § 257 HGB and § 147 AO.
Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have data erased (Art. 17)
- have processing restricted (Art. 18)
- receive your data in a portable format (Art. 20)
- object to processing based on legitimate interests (Art. 21)
- withdraw consent at any time, with effect for the future, where you have given it— for the analytics cookies that takes one click on
To exercise any of these, write to hello@polluxdev.com. Exercising them costs you nothing and we will not treat you differently for it.
Right to object
Where we process data on the basis of a legitimate interest under Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. If you do, we will stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Complaints
You can complain to a data protection supervisory authority, in the member state where you live, where you work, or where you believe an infringement took place. The authority responsible for us is:
Die Landesbeauftragte für den Datenschutz NiedersachsenPrinzenstraße 530159 HannoverGermanyChanges to this policy
We update this policy when the site changes — a new tool, a new provider, a new way of getting in touch. The date at the top of this page always shows when it last changed. Please check it if you want to know whether anything has moved since you last read it.