iarcBack to the site

Privacy

Privacy policy.

Last updated

We ask for as little as we can. This site sets no cookies, runs no analytics and carries no advertising trackers. The only personal data we receive is what you choose to send us.

Who is responsible

iarc is the freelance practice of Alessio Jorge Arrigone, who is the controller of your personal data under the EU General Data Protection Regulation (GDPR):

Alessio Jorge ArrigoneJagdstraße 280639 MünchenGermany[email protected]

As a one-person practice we are not required to appoint a data protection officer (§ 38 BDSG). For anything to do with your data, write to the address above. Full business details are in our Impressum.

What we process, and why

Visiting the site. Our hosting and network providers’ servers record each request: your IP address, the date and time, the page requested, your browser and operating system, and the referring page. This is needed to deliver the site and keep it secure, which is our legitimate interest (Art. 6(1)(f) GDPR). The logs are not combined with other data or used to identify anyone.

Sending an enquiry. Our contact form asks for your name, email address and a description of what you need. We use them to read and answer your enquiry, and to send you one email confirming it arrived, with a copy of what you wrote. Where you are asking about working with us, this is a step towards a contract (Art. 6(1)(b) GDPR); otherwise it is our legitimate interest in replying to the people who write to us (Art. 6(1)(f) GDPR). The same applies when you email us directly.

Giving us your details is voluntary, but without an email address we cannot reply. We don’t collect special categories of data, and we make no automated decisions or profiles about you.

Cookies and tracking

We set no cookies and use no analytics, advertising or social media tools. Nothing is stored on or read from your device beyond what is strictly necessary to show you the page, so no consent is required under § 25 TDDDG and there is no cookie banner. Our typefaces are served from our own domain, so loading a page does not contact Google or any other font service.

Our network provider Cloudflare may set a strictly necessary security cookie to tell people from automated attacks. It holds no personal profile and needs no consent (§ 25(2) no. 2 TDDDG).

If that ever changes, we will update this policy and ask for your consent first.

Who else receives it

We never sell your data. These providers process it on our behalf:

  • Railway Corporation (USA) hosts this website and keeps its request logs.
  • Cloudflare, Inc. (USA) delivers the site through its network, protecting it from attacks, and forwards email sent to our domain to our mailbox.
  • Resend, Inc. (USA) delivers messages from our contact form to our inbox and sends you a confirmation copy.
  • Google (Gmail) (Ireland and USA) hosts the mailbox where enquiries and correspondence are kept.

Where a provider processes data outside the EU, including in the USA, the transfer rests on an adequacy decision such as the EU–US Data Privacy Framework (Art. 45 GDPR) where the provider is certified, and otherwise on the EU standard contractual clauses (Art. 46(2)(c) GDPR).

We disclose data to authorities only where the law obliges us to.

How long we keep it

Enquiries that don’t lead to work are deleted 24 months after our last exchange. If we work together, we keep project correspondence while the work continues, and records we must keep under German commercial and tax law (§ 147 AO), such as invoices and business letters, for the periods it sets, currently up to eight years. Server logs are deleted by our providers after a short period.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have your data erased (Art. 17) or its processing restricted (Art. 18);
  • receive the data you gave us in a portable format (Art. 20).

Right to object (Art. 21 GDPR). Where we rely on legitimate interests, you may object at any time on grounds relating to your particular situation. We will then stop, unless we have compelling legitimate grounds that override your interests, or need the data to establish or defend legal claims.

To use any of these rights, write to [email protected]. We will respond within one month, free of charge.

You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State where you live or work. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach (lda.bayern.de).

Keeping it safe

The site is served only over an encrypted (TLS) connection, enquiries reach us over encrypted connections, and only we have access to our inbox.

Changes to this policy

When our practices change, we update this page and the date at the top. If a change affects data we already hold, we will tell you directly.