Privacy Policy
Last updated: 5 October 2026
1. Controller
The controller responsible for personal data processing on this website is:
Frank Yukio Nedwed, sole proprietorFYNTech Frank Yukio Nedwed Technology Consulting
Ruhestraße 12
55127 Mainz
Germany
Email: info@fyntech.de
2. Website delivery and security
We use Cloudflare Workers and Cloudflare's content delivery network, provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, to deliver this website and process form submissions. Technical request data is processed, including IP address, requested URL, time, browser information and technical status or error data. This supports delivery, troubleshooting and protection against abusive access. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is operating a secure and reliable website.
The application code does not log enquiry content, passwords or session cookies. This is separate from the hosting provider's technical operational and security data. Retention depends on the processing purpose, including the period needed for operation, troubleshooting and abuse prevention, and legal obligations. Cloudflare describes these criteria in its Privacy Policy.
Cloudflare also processes data outside the European Economic Area, particularly in the United States. Processing on our behalf is governed by Cloudflare's Data Processing Addendum, incorporated into its Self-Serve terms. It provides EU Standard Contractual Clauses for transfers requiring these safeguards. A copy of those safeguards is available through that link.
3. Consent and browser preferences
We use self-hosted CookieConsent software to manage your choices for optional services. Your choice is saved in the fyntech_consent cookie for 180 days. Consent management itself does not contact an external CookieConsent service.
When you use the corresponding features, we store your display preference under fyntech-theme and home-page card order under fyntech.subbrandOrder.v1 in your browser's local storage. These values contain no contact information and remain until you delete them through your browser.
Storage or access necessary for features you explicitly request is based on Section 25(2)(2) of the German TDDDG. Where personal data is processed, the legal basis is Article 6(1)(f) GDPR and our interest in respecting your choices and providing requested features.
Optional external services are initially disabled and load only after consent. The legal bases are Section 25(1) TDDDG for the corresponding storage or access on your device and Article 6(1)(a) GDPR for personal data processing. You can change or withdraw your choice at any time through Cookie Settings in the footer. Withdrawal does not affect the lawfulness of earlier processing. We currently have no dedicated analytics or marketing trackers on this website.
4. Password-protected Arthur Takeshi area
When you sign in, the Worker checks the password you enter. After successful sign-in, the website sets the signed arthur_takeshi_session cookie to verify access on subsequent requests. It contains an expiry time and no name or email address. It is protected with Secure, HttpOnly and SameSite=Lax, lasts at most 30 days and is deleted when you sign out.
The cookie is used only for the requested access protection. Necessary storage is based on Section 25(2)(2) TDDDG; the legal basis for personal data processing is Article 6(1)(f) GDPR and our interest in protecting this area.
5. TradingView
The market ticker from TradingView.com, Inc., New York, USA, loads only after consent to External media & functionality. IP address, browser details and technical usage data may then be transmitted to TradingView, which may use cookies or browser storage. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. TradingView describes processing outside the EEA, particularly in the USA. Information on recipients, transfer safeguards and retention: TradingView Privacy Policy and Cookies Policy. Without consent the ticker stays disabled; the rest of the website remains available.
6. Contact and enquiries
When you contact us by form or email, we process the contact details you provide and your enquiry to respond and, where appropriate, prepare or perform a contract. This includes name, email address, subject, message and optional information about your objective, constraints or requested service. Providing information is voluntary; without required fields we cannot submit or answer a form enquiry.
General contact, Life Performance and IRL forms send data over HTTPS to the FYNTech Worker, which validates it and delivers it through STRATO SMTP to info@fyntech.de. Email delivery and mailboxes use STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. Your email address is used as the reply address. We do not maintain a separate website enquiry database. Provider information: STRATO privacy information and Data Processing Agreement.
The AI Acuity enquiry feature prepares an email draft in your email application. Your request is transmitted through your email provider only when you send it yourself. Copying and downloading happen locally on your device and do not submit a request to us. This also applies to the IRL text download. Website code does not persist form entries in browser storage; your browser may offer its own recovery or autofill features. These enquiry features do not send your entries to an AI model provider.
The legal basis is Article 6(1)(b) GDPR for enquiries concerning entering into or performing a contract, and otherwise Article 6(1)(f) GDPR with our interest in handling your message. Legally required retention is based on Article 6(1)(c) GDPR. Contact details are not used for marketing merely because you submitted an enquiry.
7. Retention and deletion
We delete simple completed enquiries without an order or statutory retention requirement when they are no longer needed for processing or follow-up, and at the latest twelve months after completion. At the annual deletion date, all completed simple enquiries are deleted, including those younger than twelve months. Necessary earlier deletion and erasure requests are handled independently of that date.
Documents subject to statutory retention follow the applicable archive periods: in particular six years for business correspondence subject to retention and eight years for invoices or accounting records, generally starting at the end of the relevant calendar year. Longer statutory periods apply where required for other records. Pending disputes or legal requirements may justify longer necessary retention. Data is deleted once its purpose and retention requirements have ended.
8. Your rights
Subject to the GDPR, you have rights including access, rectification, erasure, restriction and data portability. Consent may be withdrawn at any time for the future. You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation; you may object to processing for direct marketing at any time. Contact info@fyntech.de to exercise your rights.
You may complain to a data protection authority, particularly the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, Hintere Bleiche 34, 55116 Mainz, Germany. We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR.
