Datenschutzerklärung
Privacy policy
Last updated: September 2026
This is a courtesy translation. Only the German version is legally binding.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Camilo Cepeda Danies
Thadenstraße 22
22767 Hamburg
Germany
Email: hi@camilocepedadanies.com
2. General information
This privacy policy explains which personal data is processed when you visit this website and for what purposes.
Personal data is any information relating to an identified or identifiable natural person.
Personal data is only processed insofar as this is necessary for the technical operation of the website, communication with visitors or the functions expressly offered.
There is no automated decision-making and no profiling.
3. Hosting and server log files
This website runs on my own server at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (data centre in Nuremberg). A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
When you visit this website, technically necessary information is processed. This may include in particular:
- IP address
- date and time of access
- page or file requested
- browser and user agent information
- referrer information, if transmitted by the browser
The processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, stable and technically error-free operation of this website and in detecting and preventing misuse and attacks.
The server logs have a fixed size limit and are then automatically overwritten. Longer storage only takes place if this is necessary in an individual case for security reasons or for the establishment, exercise or defence of legal claims.
4. Contact form
If you use the contact form, the data you enter is processed:
- name
- email address
- subject
- content of your message
- technically necessary connection data, in particular the IP address
The data is used solely to handle and answer your request. All fields are mandatory, as I cannot answer your request otherwise. Alternatively, you can always write to me directly by email.
Your message is not stored on my server; it is delivered directly by email via the sending service Resend (Plus Five Five, Inc., USA; see section 11) to my mailbox at Google Ireland Limited.
To protect against misuse and mass automated sending, my server only stores an irreversible check value (HMAC) of your IP address together with the time of the request. This information is deleted automatically after 24 hours.
If your request relates to the preparation or performance of a contract, the processing is based on Art. 6(1)(b) GDPR. In all other cases it is based on Art. 6(1)(f) GDPR. The legitimate interest lies in handling incoming requests, communicating professionally with visitors to this website and protecting against misuse.
Messages sent via the contact form are deleted as soon as they are no longer needed to handle the request, unless statutory retention obligations or other legitimate reasons require longer storage.
5. Contact by email
If you contact me directly by email, the data you send is processed solely to handle your request (Art. 6(1)(b) or (f) GDPR).
Emails to hi@camilocepedadanies.com are forwarded to my mailbox at Google Ireland Limited by the forwarding service of my domain provider Namecheap, Inc. Personal data may be processed outside the European Economic Area in this context (see section 11).
Emails are deleted as soon as they are no longer needed to handle the request, unless statutory retention obligations apply.
6. Cookies, local storage and tracking
This website sets no cookies and uses no analytics or advertising tracking services.
If you choose a display setting (light or dark mode) or a language, this choice is stored locally in your browser's storage (local storage). This serves solely to provide the function you requested and is strictly necessary for it (§ 25(2) no. 2 TDDDG).
This information does not leave your browser, is not used for advertising or analytics and is not passed on to third parties. You can delete it at any time in your browser settings.
7. Fonts, images, videos and external content
Fonts, images and videos on this website are served from my own server. No third-party content is loaded automatically.
External websites or services (e.g. YouTube or client websites) are only accessed when you actively click a corresponding link. From that point on, the privacy policy of the respective provider applies.
8. Web applications under danies.trade
The “Software” section presents web applications that run under the domain danies.trade or its subdomains.
A separate privacy policy (in German) applies to these applications; it is also linked within each application.
9. Local chat demo
The chat demo on this website works entirely locally in your browser. What you enter there is transmitted neither to my server nor to third parties.
The content is not stored permanently and is lost at the latest when you reload or close the page.
10. Security demo and one-time sign-in codes
In the security demo (“Secure by default”) you can enter your email address to receive a one-time six-digit sign-in code. The email address is processed solely to provide this function.
In addition, the IP address is processed to prevent misuse, automated access and mass sending.
The processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in providing the demo securely and protecting the technical infrastructure.
The sign-in codes are sent via Resend (Plus Five Five, Inc., USA; see section 11). In particular, the recipient's email address and technical sending information are processed.
My server stores neither the email address, the IP address nor the code in plain text, only irreversible check values (HMAC). A code is valid for ten minutes; all check values are deleted automatically after 24 hours. No user account is created.
Files you select in the demo do not leave your browser and are not uploaded.
11. Recipients and transfers to third countries
Personal data is only passed on to service providers insofar as this is necessary for the purposes described in this privacy policy:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – hosting and server operation (data processing pursuant to Art. 28 GDPR)
- Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA – sending messages from the contact form and the demo's sign-in codes
- Namecheap, Inc., 4600 East Washington Street, Suite 300, Phoenix, AZ 85034, USA – domain services and email forwarding
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland – mailbox
Resend, Namecheap and Google may process data in the USA. Resend and Google LLC are certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission); standard contractual clauses are additionally in place with Resend. Otherwise, transfers are based on appropriate safeguards pursuant to Art. 46 GDPR, in particular standard contractual clauses.
Data is only passed on beyond this if there is a legal obligation, if it is necessary for the performance of a contract or if you have expressly consented.
12. Storage period
Personal data is generally only stored for as long as necessary for the respective purpose. Overview:
- server logs: fixed size limit, then automatically overwritten
- check values for abuse protection (contact form and demo): deleted automatically after 24 hours
- emails and messages from the contact form: until the request has been fully handled
Longer storage may take place if statutory retention obligations apply or if data is needed for the establishment, exercise or defence of legal claims.
13. Your rights
Subject to the legal requirements, you have in particular the following rights:
- right of access (Art. 15 GDPR)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object (Art. 21 GDPR)
To exercise your rights, a message to hi@camilocepedadanies.com is sufficient.
14. Right to lodge a complaint
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law. The competent authority is in particular:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22
20459 Hamburg
15. Changes to this privacy policy
This privacy policy is updated when the technical functions of this website, the service providers used or the legal requirements change. The current version published on this website applies.