Privacy Policy

September 2026

This English version was adapted from the German original and should get a human legal review before it is relied on. German Impressum/Datenschutzerklärung requirements do not map one-to-one onto English legal phrasing.
Protecting your personal data and complying with the General Data Protection Regulation (GDPR) is a core concern for us. This privacy policy explains which personal data we collect when you visit this website, for which purposes we process it, and which rights you have.
Last updated: September 2026

Contents

1. Controller and contact

The controller within the meaning of the GDPR is:
beansandbytes GmbH
Bahnhofplatz 4f
85540 Haar
Germany
Email: kontakt@beansandbytes.de
For any questions or concerns regarding data protection, you can reach us at the email address above.
Imprint: https://fabianrittmeier.com/en/imprint

2. General information on data processing

We process personal data only to the extent necessary to provide a functional website and our content, or where you have given consent. Where we obtain the data subject's consent for processing operations, Art. 6 (1) (a) GDPR serves as the legal basis. For processing necessary to perform a contract, we rely on Art. 6 (1) (b) GDPR. Where processing is necessary to comply with a legal obligation, Art. 6 (1) (c) GDPR serves as the basis. Where processing is necessary to safeguard a legitimate interest, Art. 6 (1) (f) GDPR serves as the legal basis.
Personal data is deleted as soon as the purpose of storage no longer applies and no statutory retention obligations prevent deletion.

3. Data processing when visiting this website

3.1 Server log files

When you visit this website (fabianrittmeier.com), our web server temporarily records each access in a log file. The following data is collected and stored until it is automatically deleted:
  • IP address of the requesting device,
  • date and time of access,
  • name and URL of the retrieved file,
  • confirmation of successful retrieval,
  • identification data of the browser and operating system used.
This data is processed for the following purposes: enabling use of the website (establishing the connection), system security, technical administration of the network infrastructure, and optimization of our online offering. This data is not combined with other data sources without consent, and it is not attributed to specific individuals.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the purposes stated above.

3.2 Hosting and technical provision

To operate this website securely and efficiently, we use external service providers for hosting and content delivery (content delivery network). On our behalf, they process the data transmitted via the website (in particular technical access data such as server log files and your IP address) to enable the operation, security, and fast delivery of the website.
The legal basis is our legitimate interest in the secure, stable, and efficient provision of our online offering pursuant to Art. 6 (1) (f) GDPR. We have concluded data processing agreements with the service providers we use.
Since data may be transferred to the USA in this context, please note the section "Data sharing and third-country transfers".

3.3 Fonts

For consistent font rendering we use Google Fonts. These fonts are stored locally on our server or with our hosting provider and are delivered from there. No connection to Google servers is established, and in particular no data is transmitted to Google.

4. Cookies and web analytics

We use Vercel Web Analytics, provided by Vercel Inc., USA, to understand visits to our website and the use of our contact options. Analytics runs without a consent prompt and does not use analytics cookies. The Google Calendar integration is described separately below.
Vercel processes technical request data, including the IP address needed for the connection. Analytics statistics include page paths, referrers, time, approximate location, browser, operating system and device type. We remove query parameters and fragments from the page URL before sending analytics events. Email and booking link clicks contain only the language and placement of the link as additional properties; we do not send email contents, form entries or booking details. Clicks do not confirm that an email was sent or a booking completed.
According to Vercel, visitor identification uses a hash derived from the request; visitor sessions are discarded after 24 hours. This does not mean that aggregate statistics are deleted after 24 hours. We use the statistics to improve our content and contact options, without tracking visitors across websites or using the data for personalized advertising.
We rely on our legitimate interest in measuring and improving this website under Art. 6 (1) (f) GDPR. You may object to processing on grounds relating to your particular situation using the contact details above; see also the section on the right to object. Data may be processed in the USA; the section on third-country transfers applies. Further information: Vercel Web Analytics privacy information.

5. Appointment booking via Google Calendar

On the "Book a call" page we embed the appointment booking widget of Google Calendar. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you open that page, a connection to Google servers is established, and data (including your IP address) may be transmitted to Google. If you book an appointment via the widget, Google also processes the data you enter (such as your name and email address) to carry out the appointment booking.
The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures taken at your request) as well as our legitimate interest in simple and efficient appointment scheduling pursuant to Art. 6 (1) (f) GDPR. For more information on data processing by Google, see https://policies.google.com/privacy. Since data may be transferred to the USA in this context, please note the section "Data sharing and third-country transfers".

6. Contact by email

If you contact us by email, we process the data you provide (in particular your email address, name, and the content of your message) to handle your inquiry. The legal basis is Art. 6 (1) (b) GDPR where your inquiry relates to concluding or performing a contract, and otherwise our legitimate interest in responding to your inquiry pursuant to Art. 6 (1) (f) GDPR.

7. Social media profiles

We maintain profiles on LinkedIn and GitHub to communicate with users registered there and to provide information about our work. When you interact with our profiles, the respective platform operators process your data under their own responsibility in accordance with their privacy policies.
The providers are:
  • LinkedIn: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
  • GitHub: GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA.
The legal basis for processing in connection with our social media profiles is Art. 6 (1) (f) GDPR (legitimate interest in public presentation and communication). We have only limited influence on data processing by the platform operators; for details, please refer to the privacy notices of the respective providers.

8. Data sharing and third-country transfers

We share your personal data with third parties only where this is legally permitted or where you have given consent. Data is shared in particular with the categories of service providers named in this policy (e.g. for hosting and technical provision) or with the providers named individually (e.g. for appointment booking). They act as our processors on the basis of corresponding agreements, or as independent controllers.
Where we process data in countries outside the European Union (EU) or the European Economic Area (EEA), or where this occurs through the use of third-party services, this only takes place if the special requirements of Art. 44 et seq. GDPR are met. This means the processing takes place on the basis of appropriate safeguards ensuring a level of data protection comparable to that of the EU.
These safeguards include:
  • Transfers to countries for which the EU Commission has determined an adequate level of data protection (adequacy decision). For the USA, this applies to companies certified under the EU-US Data Privacy Framework (DPF).
  • The use of Standard Contractual Clauses (SCCs) approved by the EU Commission.
We ensure that our service providers in third countries can demonstrate one of these safeguards to protect your data.

9. Storage duration

Personal data is stored only for as long as necessary to fulfill the purposes stated above, unless statutory retention obligations require longer storage.

10. Your rights as a data subject

Under the GDPR, provided the respective requirements are met, you have the following rights:
  • the right of access to the data stored about you pursuant to Art. 15 GDPR,
  • the right to rectification of inaccurate data pursuant to Art. 16 GDPR,
  • the right to erasure of the data stored about you pursuant to Art. 17 GDPR,
  • the right to restriction of processing pursuant to Art. 18 GDPR,
  • the right to data portability pursuant to Art. 20 GDPR,
  • the right to withdraw consent at any time pursuant to Art. 7 (3) GDPR, with the effect that we may no longer continue the data processing based on that consent in the future,
  • the right to lodge a complaint with a competent supervisory authority pursuant to Art. 77 GDPR if you believe that the processing of your personal data violates the GDPR.

11. Right to object (Art. 21 GDPR)

Where we process your data on the basis of legitimate interests pursuant to Art. 6 (1) (f) GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation.

12. Security measures

We use technical and organizational security measures to protect your personal data, in particular encryption, access controls, and secure data storage.

13. Changes to this privacy policy

We may update this privacy policy from time to time. The current version is always available on this website.

14. Contact and complaints

If you have questions or complaints about this privacy policy, you can contact us at kontakt@beansandbytes.de. You also have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.