Privacy Information

Privacy Policy

A straightforward explanation of the information involved in visiting this website or contacting me.

1. Controller

The person responsible for processing personal data for BrimFrame is:

Daniel Schmid
Hiltenspergerstr. 78
80796 München
Germany
dcschmid@murena.io

You can use this contact address for questions or requests about your personal data.

2. Hosting

This website is hosted by Render Services, Inc., United States. It is a static site delivered through Render’s global infrastructure and content delivery network (CDN), rather than a server located exclusively in Germany or the European Union.

Render provides a Data Processing Addendum. Render may use subprocessors to provide its hosting infrastructure. The current list is maintained on Render’s security and subprocessors page. Further information is available in Render’s Privacy Policy.

3. Technical website access

Delivering pages securely and reliably requires processing technical connection information. This may include your IP address, the date and time of a request, the requested resource, browser and device information, and other technical request information transmitted by your browser.

The legal basis is Art. 6(1)(f) GDPR. My legitimate interest is the secure, reliable and efficient provision of this website. Render may process technical information as required for operation, security and delivery; BrimFrame does not operate application analytics or behavioural tracking.

4. Contact by email

If you send me an email, I process your email address, your name if provided, message content, attachments and technical email metadata to respond to your enquiry and communicate with you. Email links open your own email application; this website has no contact form backend.

The legal basis for contract-related or pre-contractual enquiries is Art. 6(1)(b) GDPR. For general enquiries, it is Art. 6(1)(f) GDPR: my legitimate interest in responding to people who contact BrimFrame and maintaining normal business communication. Where legal retention obligations apply, processing is based on Art. 6(1)(c) GDPR.

The current email service is Murena Workspace / murena.io. According to Murena’s published provider information, its email and cloud infrastructure is hosted in the European Union, including Finland.

5. Cookies and tracking

This website does not use analytics, advertising trackers, fingerprinting, behavioural profiling or third-party marketing scripts. It sets no cookies and uses no local or session browser storage. Fonts and images are served with the website; there are no external Google Fonts requests or third-party embeds.

There is no newsletter service or optional tracking to consent to, so no cookie consent banner is used. If additional services are introduced, their privacy requirements will be reviewed before use.

6. Data retention

Under BrimFrame’s internal policy, general email enquiries are normally deleted no later than 12 months after the matter has been concluded. Longer retention may be necessary for an ongoing business relationship, legal obligations or the establishment, exercise or defence of legal claims. This is my correspondence policy, not a retention period imposed by Murena.

Technical information processed by the hosting provider is retained according to its applicable operational and security retention policies. There is no separate BrimFrame analytics database or visitor profiling log.

7. International data transfers

Render’s global delivery infrastructure means that technical information may be processed outside the European Economic Area, including in the United States. Its published transfer arrangements provide for the EU-U.S. Data Privacy Framework where applicable, and European Commission Standard Contractual Clauses where that framework does not apply or is no longer available.

Details of these safeguards are available in Render’s Data Processing Addendum. You can also contact me for information about safeguards relevant to your personal data. Murena’s published email infrastructure information is linked in the email section above.

8. Your rights

Depending on the circumstances and applicable GDPR conditions, you can:

  • Request access to your personal data and information about its use.
  • Ask for inaccurate or incomplete data to be corrected.
  • Request erasure or restriction of processing.
  • Receive eligible data in a portable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with a competent data protection supervisory authority.

Please contact me using the controller details above to exercise your rights.

9. Right to object

Under Art. 21 GDPR, you may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. I will stop that processing unless compelling legitimate grounds override your interests, rights and freedoms, or the data is needed to establish, exercise or defend legal claims.

10. Supervisory authority

You may lodge a complaint with a competent data protection supervisory authority, including one in the EU country where you live or work or where the alleged infringement occurred. This right is not limited to the authority listed here.

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
poststelle@lda.bayern.de

BayLDA contact information and complaint options

11. Changes to this policy

I will update this policy when the website’s services or data processing change. The current version is available on this page.

Last updated: .