Legal
Privacy notice
Last updated: 27 July 2026
1. Controller
The controller responsible for processing personal data on this website is:
plusquam.studioLangenfelder Str. 35
22769 Hamburg
Germany
Email: hallo@wp-zero.com
2. Cookies and tracking
This website does not use cookies, analytics, advertising services, tracking pixels, or comparable browser identifiers. It does not store information in Local Storage or Session Storage. Fonts and other assets needed to display the site are loaded from our own domain.
We therefore do not show a consent banner. If we introduce technology that requires consent, we will update this notice first and activate that technology only after valid consent.
3. Hosting and server logs
When you open this website, our hosting provider processes connection data required to deliver it. This may include your IP address, date and time, requested URL, amount of data transferred, referrer, browser identifier, and operating system. We use this information to serve the site, investigate errors, and defend against attacks.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of this website. Technical logs are kept only for as long as they are required for operation and security or by law.
4. Contact form and initial assessment
When you submit the form, we process:
- the website URL you provide,
- your email address and/or telephone number,
- your selected contact method,
- the selected symptom and an optional description,
- language, submission time, and the generated reference number,
- delivery status and the number of delivery attempts,
- a shortened IP identifier.
The full IP address is used temporarily while the form request is processed. To prevent automated or repeated submissions, the server creates a hash from the IP address and domain using a secret key. The limit is five requests within ten minutes. The lead record itself stores only a shortened IP identifier.
Before storage, free text is checked for common credential patterns. Recognised passwords, API keys, and long tokens are redacted. Please do not send passwords, SSH keys, hosting, FTP, or database credentials through the form, ordinary email, or WhatsApp.
We process your request to take steps at your request before entering into a contract under Article 6(1)(b) GDPR. Measures against abuse and attacks are based on Article 6(1)(f) GDPR. Our legitimate interest is protecting the form and our systems.
5. Storage and internal delivery
An accepted request is first stored in an Upstash Redis database. The record is deleted automatically after no more than 30 days unless a contract is formed or the law requires a longer retention period.
The request is then sent through an encrypted SMTP connection to an internal administrator mailbox. Form users cannot select the recipient. The email address you enter is used only as the reply address. If delivery fails, the request remains stored with a pending status. Once all delivery attempts have been exhausted, it is marked as undeliverable for internal follow-up.
If a contract is formed, contract and billing records may be retained for longer under applicable commercial and tax laws. The legal bases are Article 6(1)(b) and (c) GDPR.
6. Recipients and service providers
Personal data is available only to parties that need it for the purposes described above:
- authorised people handling the request,
- Vercel Inc. for hosting, delivery, and server functions,
- Upstash Inc. for Redis storage and distributed rate limiting,
- the email service used for internal SMTP delivery.
We do not sell personal data or disclose it for advertising. Technical service providers process data only as required to provide and secure their respective services.
7. Processing outside the EU or EEA
Vercel and Upstash are based in the United States. The Redis database used for this website operates in an EU region. Regardless of the storage location, access by affiliates or subprocessors outside the EU or EEA cannot be ruled out completely.
Where personal data is transferred to a third country, the transfer is based on an adequacy decision by the European Commission or appropriate safeguards under Article 46 GDPR, particularly standard contractual clauses. See the privacy notices ofVercelandUpstashfor further information.
8. Contact by email or telephone
If you contact us by email or telephone, we process your contact details and message to respond to your request. Article 6(1)(b) GDPR applies to contractual or pre-contractual enquiries. In other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is responding appropriately to your message.
9. WhatsApp
The website does not embed WhatsApp content and does not transfer data to WhatsApp merely because you open a page. Only when you click the WhatsApp link do you leave our website and communicate through Meta's service. Meta then processes data such as your telephone number, connection data, and message content under its own terms. WhatsApp is optional. You can use the form, email, or telephone instead. Do not send passwords or credentials through WhatsApp.
10. No automated decisions
We do not use your data for profiling or decisions based solely on automated processing that produce legal or similarly significant effects.
11. Your rights
Subject to the applicable legal requirements, you have the right to:
- access under Article 15 GDPR,
- rectification under Article 16 GDPR,
- erasure under Article 17 GDPR,
- restriction of processing under Article 18 GDPR,
- data portability under Article 20 GDPR,
- object to processing under Article 21 GDPR.
To exercise your rights, email hallo@wp-zero.com. You may also lodge a complaint with a data protection authority. The authority responsible in Hamburg is theHamburg Commissioner for Data Protection and Freedom of Information.
12. Security and updates
We use technical and organisational measures to protect personal data against loss, unauthorised access, and alteration. The website and form are transmitted over encrypted HTTPS connections. We update this notice when processing activities, service providers, or legal requirements change.