Skip to content

§Legal

Privacy policy

What data this website processes, for what purpose, on what legal basis, who is involved and how long we keep it. This is a translation for convenience; the German version is legally binding.

As of: 25 September 2026

Controller

The controller responsible for data processing on this website is:

headon
Owner: Onur Cirakoglu
Am Vogelsberg 8
97922 Lauda-Königshofen
Germany

Email: hallo@headon.pro
Phone: +49 176 63040241

You can reach us at these details for any questions about data protection and to exercise your rights.

Summary

  • We do not use cookies for analytics or advertising and do not store data in your browser.
  • Analytics run with Umami on our own server – without cookies and without recognising you across other websites.
  • Our server is in Nuremberg, our database in Frankfurt am Main. The website is delivered via the Cloudflare network.
  • Enquiries are deleted automatically after one year.
  • The AI assistant “Ask headon” uses the language model Claude by Anthropic. What you enter there is transmitted to Anthropic for this purpose.

Hosting and delivery

Server

The website and our analytics instance run on a server operated by Hetzner Online GmbH in its Nuremberg data centre. Hetzner processes the data on our behalf. Transmission between your browser and the website is encrypted via TLS.

Purpose
Providing the website, operation and security
Data
All data arising from use: IP address, requested address, time, browser and device information, form input
Legal basis
Art. 6(1)(f) GDPR – legitimate interest in secure and reliable operation
Recipient
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, as processor (Art. 28 GDPR)
Third country
No transfer

Logs

Our web server does not write access logs for this website. The application logs technical error messages so that we can fix faults; IP addresses are not recorded.

Retention: error logs are overwritten continuously once they reach 15 MB (three files of 5 MB each) and are deleted completely with every website update.

Delivery via Cloudflare

All requests to this website and our analytics instance pass through the Cloudflare network. Cloudflare accepts your browser’s encrypted connection, defends against attacks such as overload attacks and forwards the request to our server, technically processing the transmitted content in the process.

If Cloudflare classifies a request as suspicious, a security check may appear. After passing it, Cloudflare stores a technically necessary cookie that records the passed check (§ 25(2) no. 2 TDDDG).

Purpose
Fast delivery, protection against attacks and abuse
Data
IP address, time, requested address, transmitted content including form input, browser and device information
Legal basis
Art. 6(1)(f) GDPR – legitimate interest in security, availability and short load times
Recipient
Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, as processor
Third country
USA. Cloudflare is certified under the EU-US Data Privacy Framework; the transfer is based on the European Commission’s adequacy decision (Art. 45 GDPR).
Retention
We do not store this data ourselves. Cloudflare keeps connection data only as long as necessary for operation and security, in line with its privacy policy.

Abuse protection

To protect forms and the AI assistant against automated abuse, we count requests per IP address – at most five form submissions and 20 chat messages per hour. The IP address is kept only in the server’s memory for this purpose, is not linked to other data and is deleted automatically after the 60-minute window. Forms also contain a field invisible to humans that helps us recognise automated input.

The legal basis is Art. 6(1)(f) GDPR – our legitimate interest in keeping services available and preventing abuse.

Analytics with Umami

To understand which content is used and where the website falls short, we use the open-source software Umami, which we run ourselves on our Hetzner server (analytics.headon.pro); the data is not passed to any other provider.

Umami sets no cookies, stores nothing in your browser and does not recognise you across other websites. We load the analytics script only after you have been on the page for at least three seconds and interacted with it. If your browser sends the “Global Privacy Control” signal, we do not load it at all.

Purpose
Statistical analysis of use, improvement of content and technology
Data
Pages viewed, referrer, browser, operating system, device type, screen size, language, approximate location (country, region, city), time of day and weekday, clicks on buttons and external links (domain and path only), scroll depth, time on page, load-time metrics and technical error messages
IP address
Processed only briefly to derive the approximate location and a pseudonymous, regularly changing session identifier; not stored.
Legal basis
Art. 6(1)(f) GDPR – legitimate interest in audience measurement and improving our offering
Recipient
None beyond Hetzner and Cloudflare, which are technically involved (see above)
Retention
12 months; older analytics data is deleted by a monthly automatic run.

You can object to analytics at any time by enabling “Global Privacy Control” in your browser or by emailing us.

Fonts, images and videos

We serve fonts, images and videos from our own server. Fonts are embedded locally; no connection to Google Fonts or other font providers is made. Videos play without embedding services such as YouTube.

The load-time display at the bottom of each page is calculated in your browser only and is not transmitted.

Contact by email or phone

If you contact us by email or phone, we process your details to handle your request. Our mailbox is operated by Google (Google Workspace) on our behalf.

Purpose
Handling your request and communicating with you
Data
Name, contact details, content and time of your message
Legal basis
Art. 6(1)(b) GDPR if your request relates to a contract; otherwise Art. 6(1)(f) GDPR – legitimate interest in answering enquiries
Recipient
Google (Google Workspace) as processor
Third country
Processing by Google LLC in the USA is possible. Google LLC is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).
Retention
Until your request has been fully handled. Statutory retention obligations, in particular under commercial and tax law, remain unaffected.

Contact form and enquiries

You can send us an enquiry via the contact form. We process enquiries arising from the AI assistant or the free website checks in the same way (see below).

Purpose
Handling your enquiry, preparing a quote
Data
Name, email address, company (optional), topic and message; for enquiries via the AI assistant or the calculator possibly also phone number, project type, budget and timeframe; time and origin of the enquiry
Legal basis
Art. 6(1)(b) GDPR – pre-contractual measures at your request; Art. 6(1)(f) GDPR for internal organisation
Recipient
Supabase (storage), Resend (email notification), Google Workspace (our mailbox) – details below
Retention
Automatic deletion after one year (daily deletion run), earlier on request. If a contract results, statutory retention periods apply.

Prioritisation

From details on project type, budget and timeframe we calculate an internal score that only determines the order of processing. There is no automated decision within the meaning of Art. 22 GDPR; a person reads every enquiry.

Storage with Supabase

We store enquiries in a database operated by Supabase in the Frankfurt am Main data centre. Supabase processes the data as a processor. If Supabase accesses the data from outside the EU in individual cases, for example for support, this is based on standard contractual clauses (Art. 46(2)(c) GDPR).

Email notification (Resend)

We also receive your enquiry as an email via the delivery service Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). Resend is certified under the EU-US Data Privacy Framework (Art. 45 GDPR) and keeps delivery data for 30 days.

Short notice via Telegram

So that we can respond quickly, we receive a short notice in our Telegram chat for each new enquiry. It only states that an enquiry has arrived and through which channel (such as the contact form) and contains no personal data. We read the enquiry itself in our mailbox and database.

AI assistant “Ask headon”

Via “Ask headon” in the page header or the shortcut ⌘K / Ctrl+K you can ask questions about our services.

You are talking to an AI system, not a person. The answers are generated automatically by the language model Claude by Anthropic. They may contain errors and are not binding; only our quotes are binding (notice under Art. 50(1) of the AI Act, Regulation (EU) 2024/1689).

Please do not enter sensitive data – such as health information, login credentials, bank details, trade secrets or personal data of third parties.

The conversation exists only in your open browser window and is gone after reloading. For each answer our server sends the conversation so far to Anthropic; we do not store it ourselves. If you give your name, email address and request in the conversation, the assistant creates an enquiry from it (name, email, short description and, where applicable, project type, budget and timeframe), which we treat like an enquiry via the contact form.

Purpose
Answering questions about our services; on request, creating an enquiry
Data
Your messages and the history of the current conversation
Legal basis
Art. 6(1)(f) GDPR – legitimate interest in answering questions quickly; Art. 6(1)(b) GDPR once you submit an enquiry via the assistant
Recipient
Anthropic Ireland, Limited, Dublin, Ireland, as processor; processing also takes place at Anthropic, PBC in the USA. According to Anthropic, content from the API is not used to train its models.
Third country
USA, based on standard contractual clauses (Art. 46(2)(c) GDPR)
Retention
We do not store the chat history. According to Anthropic, inputs and outputs are deleted within 30 days; in case of suspected policy violations Anthropic may keep them longer.

You do not have to use the assistant: you can reach us just as well by email or via the contact form.

Cost calculator

On some guide pages you can use a calculator to create a cost estimate and have it sent to you by email.

Purpose
Creating and sending the cost estimate, handling your enquiry
Data
Name, email address, phone number, company and message (optional), your input in the calculator, the calculated estimate and an internal prioritisation score
Legal basis
Art. 6(1)(b) GDPR – pre-contractual measures at your request
Recipient
Supabase (storage), Resend (sending the estimate to you and the notification to us), Google Workspace (our mailbox) – see above
Retention
Automatic deletion after one year, earlier on request

Free website checks

For the AI visibility check and the SEO check you provide your website address, your email address and optionally your name and industry. This creates an enquiry like the contact form; we send you the results by email.

For the accessibility check our server retrieves the public source code of the given address and analyses it automatically; you see the result immediately. Data is stored only if you voluntarily provide your email address – we then create an enquiry with the address and the result.

Purpose
Carrying out and sending the analysis, follow-up questions if needed
Data
Website address, email address, name and industry (optional), analysis result
Legal basis
Art. 6(1)(b) GDPR – pre-contractual measures at your request
Recipient
As for the contact form (Supabase, Resend, Google Workspace)
Retention
Automatic deletion after one year, earlier on request

Service providers at a glance

These service providers process personal data on our behalf or receive it from us:

ProviderTaskThird country
Hetzner Online GmbHServerNone (Germany)
Cloudflare, Inc.Delivery, protectionUSA – Data Privacy Framework
SupabaseDatabase (Frankfurt am Main)Only for access from outside the EU – standard contractual clauses
Plus Five Five, Inc. (Resend)Email deliveryUSA – Data Privacy Framework
Google (Google Workspace)MailboxUSA – Data Privacy Framework
AnthropicAI assistantUSA – standard contractual clauses

Providing your data is neither legally nor contractually required. Without the fields marked as mandatory, however, we cannot process an enquiry.

Client projects

Data that we process on behalf of our clients in client projects – for example in AI sprints or geodata analyses – is not covered by this policy; for this we conclude a data processing agreement with the respective client under Art. 28 GDPR.

Your rights

You have the right to

  • access the data stored about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR).

Right to object: Where processing is based on Art. 6(1)(f) GDPR, you may object to it at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests.

An informal message to hallo@headon.pro is sufficient.

Complaint to the supervisory authority

You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Heilbronner Straße 35, 70191 Stuttgart, Germany
Phone: +49 711 615541-0 · Email: poststelle@lfdi.bwl.de
www.baden-wuerttemberg.datenschutz.de

Changes

We update this policy when our services or the services we use change. The version published here applies.

As of: 25 September 2026

Provider details can be found in our legal notice.