Privacy policy
Last updated: August 2026
1. Controller
The controller responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:
Fedir Shtanko
FISHERDESIGN
Paulusstraße 27
76694 Forst
Germany
Phone: 015159077580
Email: kontakt@fisherdesign.de
Personal data means any information relating to an identified or identifiable natural person.
2. Purpose of this policy
This privacy policy explains what personal data we process when you visit and use this website, for what purposes, on what legal basis, and what rights you have.
3. Hosting
Our website is hosted by:
TOV „NETH“ (S-HOST)
vul. Pidvoiskoho 10, Office 36
04060 Kyiv
Ukraine
Website: https://s-host.com.ua/
Email: support@s-host.com.ua
The website is served from the provider's servers. According to our technical information, the server location is in the Netherlands (EU). When you access the site, the necessary technical data are processed on the hosting provider's systems, including IP address, date and time of access, files retrieved, data volume transferred, referrer URL, and browser and operating system information (server log files).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable, and accessible website operation). Where required, we conclude a data processing agreement with the provider pursuant to Art. 28 GDPR.
The hosting provider is based in Ukraine. If personal data are transferred to Ukraine in connection with hosting services, we rely on appropriate safeguards under Art. 44 ff. GDPR (e.g. standard contractual clauses) where no adequacy decision applies.
4. Server log files
Even if you use our website for information only, we process the technical access data your browser automatically transmits, in particular:
- page / URL accessed
- date and time of access
- data volume transferred
- referrer (previous page, if transmitted)
- browser type and version
- operating system
- IP address (possibly truncated/anonymized)
Processing serves website delivery, system security, and investigation of abusive or unlawful access. Legal basis: Art. 6(1)(f) GDPR. Log data are deleted when no longer needed for these purposes, unless longer retention is required by law.
5. SSL/TLS encryption
This website uses SSL/TLS encryption to protect data in transit. You can recognize an encrypted connection by "https://" and the lock icon in your browser's address bar.
6. Cookies and similar technologies
We use cookies and similar technologies (including localStorage). Cookies are small text files stored on your device; localStorage is browser storage for website settings.
Cookies and localStorage remain in your browser and are not transmitted to our hosting provider as cookie files. Normal page requests still generate server log files on the provider's systems (see section 4) — these are request access data, not the contents of your cookie or localStorage settings.
We currently use only technically necessary and functional storage. Analytics or marketing services (e.g. Google Analytics, Meta Pixel) are not used.
Technically necessary
- Cookie consent: cookie
bootstrap_site_consentand localStoragebootstrap_site_cookie_consent(365 days) — stores your choice in the cookie banner. - Language preference: cookie
bootstrap_site_lang(365 days) — stores your selected site language (German, English, Ukrainian, or Russian) when you use the language switcher or visit a localized URL. - WordPress: cookie
wordpress_test_cookie(session) — checks whether cookies are enabled in your browser.
Functional
- Display preference: localStorage
bootstrap-site-theme— stores your light/dark theme choice. - Accessibility tool: localStorage
bootstrap_site_accessibility— stores your settings (e.g. font size, contrast). Open via "Accessibility adjustments" in the burger menu.
Legal basis for technically necessary storage: Art. 6(1)(f) GDPR and, where applicable, Section 25(2) TDDDG. For functional comfort settings: Art. 6(1)(f) GDPR (legitimate interest in a user-friendly website).
You can reject, delete, or manage cookies and localStorage in your browser. Some website features may then be limited.
7. Cookie consent tool
When you visit the website, a cookie consent tool is displayed. It informs you transparently about storage technologies used and, where optional services are added in future, lets you choose which to allow.
To store your choice, the tool uses technically necessary cookies or local storage (bootstrap_site_consent, bootstrap_site_cookie_consent). Where personal data are processed in this context (e.g. IP address for consent logging), legal basis is Art. 6(1)(c) GDPR (legal obligation to obtain and document consent) and Art. 6(1)(f) GDPR (legitimate interest in compliant consent management).
8. Contact
When you contact us via the "Request a quote" form, email, or phone, we process the data you provide as needed to handle your inquiry.
The form may collect: first name and last name (required), email address (required), phone number (optional), desired service, preferred call time (optional), budget indication (optional), and your project description. We also store the time of submission.
Form submissions are delivered by email via our hosting provider's SMTP service (S-HOST / TOV „NETH“) to kontakt@fisherdesign.de. We remain the controller; the hosting provider processes transmission on our behalf (Art. 28 GDPR) where a processing agreement exists.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries). If contact aims at entering or performing a contract, Art. 6(1)(b) GDPR also applies. Where you expressly consent via the form checkbox, Art. 6(1)(a) GDPR applies as well.
We retain data only as long as needed for processing or as required by law, then delete or restrict it.
To protect against spam and automated submissions, we use Cloudflare Turnstile in the contact form only (not as a CDN/proxy for the entire site). This may connect to Cloudflare, Inc. (USA) servers and process technical data (e.g. IP address, browser information, verification token). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse-free contact). Transfers to the USA rely, where applicable, on the EU-US Data Privacy Framework (Art. 45 GDPR) or appropriate safeguards under Art. 46 GDPR.
9. Accessibility tool (Fisher Design)
We provide a custom accessibility tool to improve usability. It allows settings such as font size, line height, contrast, reading aids, or disabling animations.
Find it in the burger menu under "Accessibility adjustments". When used, settings are stored locally in your browser (localStorage key: bootstrap_site_accessibility). No tracking cookies for advertising or analytics are set. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in accessible website use).
10. Display preferences (light/dark)
You can choose light or dark color scheme on this website. Your choice is stored locally (localStorage key: bootstrap-site-theme) so it persists on return visits. No personal profiles are created and no data are sent to third parties. Legal basis: Art. 6(1)(f) GDPR.
11. Recipients and third-country transfers
We remain responsible for data processing on this website. Recipients/processors may include:
- Hosting and email delivery: TOV „NETH“ (S-HOST), based in Ukraine; server location per our information: Netherlands (EU). Transfers to Ukraine rely on appropriate safeguards under Art. 44 ff. GDPR where no adequacy decision applies.
- Form inquiries: delivery via hosting provider SMTP to kontakt@fisherdesign.de.
- Spam protection: Cloudflare Turnstile (Cloudflare, Inc., USA) when submitting the contact form.
- Further recipients only where necessary for contract performance, legal obligations, or consent (e.g. IT or security providers).
12. Retention
We store personal data only as long as necessary for the respective purpose, until consent is withdrawn, or as required by statutory retention periods, then delete or restrict processing.
13. Your rights
Where legal requirements are met, you have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), withdrawal of consent (Art. 7(3)), and to lodge a complaint with a supervisory authority (Art. 77 GDPR).
To exercise your rights, contact us using the details above.
14. Right to object
Where we process data on legitimate interests (Art. 6(1)(f) GDPR), you may object at any time for reasons arising from your particular situation (Art. 21(1) GDPR). We will cease processing unless we demonstrate compelling legitimate grounds or processing is needed for legal claims.
If data are processed for direct marketing, you may object at any time (Art. 21(2) GDPR).
15. Obligation to provide data
Providing personal data is neither legally nor contractually mandatory. Without certain technical data, however, use of the website may be impossible or limited. Without details in contact requests, we may be unable to handle your enquiry.
16. No automated decision-making
No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place that produces legal effects or similarly significantly affects you.
17. Updates
We may update this privacy policy when legal requirements, our services, or technologies change. The current version is always published on this page.