Legal
Privacy Policy
Last updated: 17 August 2026
1. Controller
The controller responsible for data processing on this website is:
Moritz Laube — Dots & Dashes StudioEberhard-Roters-Platz 14
10965 Berlin, Germany
Email: hello@dotsanddashes.studio
2. Scope
This policy explains what personal data we process when you visit dotsanddashes.studio, on what legal basis, and what rights you have. We process personal data only in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
3. Your rights
You have the following rights regarding your personal data at any time:
- Access to the data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future, where processing is based on consent
To exercise any of these, email hello@dotsanddashes.studio. You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
4. Hosting and server log files
This website is hosted on servers of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany), located in Germany. Content and video assets are delivered through Cloudflare, Inc. (101 Townsend St, San Francisco, CA, USA), which also provides DNS, a reverse proxy, and our media storage (Cloudflare R2).
When you access the site, the server and Cloudflare automatically collect and store technical information in log files: your IP address, date and time of the request, the requested resource, the referring URL, and your browser and operating system. This data is required for the secure, stable delivery of the site and is not merged with other data. The legal basis is our legitimate interest in operating the site securely (Art. 6 (1)(f) GDPR). Because Cloudflare is a US provider, data may be transferred to the USA; this transfer is safeguarded by the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses.
5. Cookies and consent
By default we set only what is technically necessary. Anything that is not strictly necessary — in particular analytics and advertising measurement — is loaded only after you actively consent through our cookie banner (legal basis: Art. 6 (1)(a) GDPR). Your choice is stored locally in your browser so we can respect it on future visits. You can review or withdraw your consent at any time using the “Cookie settings” control in the bottom corner of the site; if you withdraw it, we actively delete the corresponding cookies. We use Google Consent Mode v2, so analytics and advertising storage stay denied until you opt in.
6. Contact form and email
When you use the contact form, we process the data you enter — your name, email address, an optional website URL, your answer to one short multiple-choice question (depending on the page, either a budget range or the size of your team), and your message — in order to respond to your enquiry. Submissions are delivered to us by email; we do not store them in a separate database. The legal basis is the initiation or performance of a contract (Art. 6 (1)(b) GDPR) and our legitimate interest in answering enquiries (Art. 6 (1)(f) GDPR).
Email delivery is handled by our processor Resend (Resend, Inc., USA) on our behalf; the data you submit is transmitted to Resend for this purpose, safeguarded by the EU–US Data Privacy Framework and/or Standard Contractual Clauses. To protect the form against automated abuse we use a hidden honeypot field and a short-term, in-memory rate limit based on your IP address; this information is not stored permanently. We retain enquiry data for as long as needed to handle your request and thereafter only for the duration of statutory retention obligations.
7. Appointment booking (Cal.com)
We embed the scheduling tool Cal.com (Cal.com, Inc., USA) so you can book a discovery call. The embed loads only when you open the booking. If you book, the name, email address, and appointment details you provide are processed by Cal.com on our behalf to arrange the meeting (legal basis: Art. 6 (1)(b) GDPR). Data may be transferred to the USA under the EU–US Data Privacy Framework and/or Standard Contractual Clauses. See Cal.com’s privacy notice at cal.com/privacy.
8. Web analytics (Google Analytics 4)
Only if you consent, we use Google Analytics 4, a service of Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). It helps us understand how visitors use the site so we can improve it. Google Analytics sets cookies and processes usage data such as pages viewed, an abbreviated IP address, approximate location, and device information. The legal basis is your consent (Art. 6 (1)(a) GDPR), which you can withdraw at any time via the “Cookie settings” control with effect for the future.
Data may be transferred to Google LLC in the USA, safeguarded by the EU–US Data Privacy Framework and the EU Standard Contractual Clauses. We track two conversion events — a contact-form submission and a completed booking — to measure whether the site is doing its job. For more information, see Google’s privacy policy at policies.google.com/privacy.
9. Advertising measurement (Google Ads)
Only if you consent to the “Advertising” category, we additionally load Google Ads,
a service of Google Ireland Ltd. We use it to measure whether an advertisement actually led to
an enquiry or a booking. For this, Google sets cookies (in particular _gcl_au) and
processes usage and device information; your consent releases the Consent Mode v2 signals ad_storage, ad_user_data, and ad_personalization. The
legal basis is your consent (Art. 6 (1)(a) GDPR). If you withdraw it via the “Cookie
settings” control, we delete the _gcl* cookies that were set. Without your consent,
no Google Ads script is loaded and no event is transmitted.
10. Campaign attribution
If you reach the site by clicking an advertisement or campaign link, the URL may contain
attribution parameters (such as gclid or utm_*). We store these
locally in your browser and, if you then contact us or book a call, attach them to that enquiry
so we can understand which campaign brought you here. The legal basis is our legitimate interest
in measuring the effectiveness of our marketing (Art. 6 (1)(f) GDPR).
11. Fonts
Our fonts are self-hosted and served directly from our own servers. No connection to a third-party font provider (such as Google Fonts) is established, and no data is transmitted to such providers.
12. Encryption
This site uses TLS/SSL encryption for all connections, recognisable by the “https” prefix and the lock icon in your browser, to protect the data transmitted between you and us.
13. Transfers to third countries
Some of the services above (Cloudflare, Resend, Cal.com, Google) are provided by companies in the USA, so certain processing takes place there. In each case the transfer is safeguarded by an adequacy decision (the EU–US Data Privacy Framework, where the provider is certified) and/or the EU Standard Contractual Clauses under Art. 46 GDPR.
14. Changes to this policy
We may update this policy to reflect changes to the site or to legal requirements. The current version always applies, and the date at the top of this page shows when it was last revised.