Legal
Privacy
- Controller
- Timo Weigelt
Königstr. 3
01097 Dresden
Germany
Email: hello@timoweigelt.com
Contact form
I am not required to appoint a data protection officer and have not appointed one. - Overview
- This website sets no cookies and uses no tracking, no analytics and no third-party content. Fonts, images and scripts come from my own server.
I only process personal data where it is technically necessary (the hosting server logs) or when you write to me (contact form or email), and only to run the website and to answer you. - Hosting and server log files
- The website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, in a data centre in Frankfurt am Main, Germany.
With every request, Hostinger's servers automatically record technical access data: your IP address, date and time, the page requested and the status code, possibly also information about your browser. This serves the secure and stable operation of the website and the defence against attacks. The legal basis is my legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).
Hostinger deletes these logs automatically after a period that Hostinger sets itself; I have no influence on that period. I can view the logs for up to 7 days back and only look at them when needed for security. Beyond that, I do not store them, combine them with other data or analyse them.
Hostinger processes the data on my behalf. The data processing agreement under Art. 28 GDPR is part of Hostinger's terms of service (Data Processing Agreement). Hostinger uses sub-processors, including providers in the USA; transfers there are based on the EU Standard Contractual Clauses.
The connection to the website is encrypted with TLS (https). - No cookies, local storage in your browser
- This website sets no cookies. So that some features behave the way you set them, your browser remembers a few small settings, but only once you do something yourself:
– Light or dark: when you switch the colour scheme, your choice (“light” or “dark”). It stays saved (localStorage) until you choose “System” again or clear the website data in your browser.
– Cookie notice: when you close the (joke) cookie notice on the home page, only the fact that you closed it (“cookie-notice-dismissed”), so that it does not appear again. This also stays saved (localStorage) until you clear the website data in your browser.
Everything else only lasts until you close the tab (sessionStorage):
– where you moved the portrait window on the home page and whether it is rolled up,
– the language you chose for the Grand Teleprompter privacy policy and terms,
– on a phone, that the tab bar of the app page has already shown once that it scrolls,
– which photos in the photo section have already “developed”,
– that the “private” album is hidden after three wrong passwords.
These entries never leave your browser; I cannot see them. They are strictly necessary for the feature you are using (§ 25(2) no. 2 TDDDG, the German Telecommunications Digital Services Data Protection Act), so no consent is needed. You can delete them at any time in your browser settings. - Contact form
- If you write to me through the contact form, I process the details you enter: topic, name, email address and message, plus the date and time you sent it and the page you wrote from. I use this data only to answer your enquiry.
The legal basis is Art. 6(1)(b) GDPR where your enquiry concerns a contract or steps prior to entering into one (for example a project or support for an app), otherwise my legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
The website does not store your message. It is forwarded straight to me as an email. To send it, I use the email service Brevo, operated by Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany, a subsidiary of Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France. Brevo processes the data on my behalf; the data processing agreement under Art. 28 GDPR is part of Brevo's terms of use. Brevo processes the data on servers in the European Union. For some services (for example network protection and support) Brevo uses sub-processors in the USA; transfers there are based on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses. Brevo keeps sending logs (for example recipient, subject, time and delivery status) for one month and then deletes them. Your IP address is not passed on to Brevo. The email is plain text without a tracking pixel; Brevo's sending statistics are set to anonymised tracking.
Spam protection: the form uses a hidden field, a minimum time to fill it in and a limit of five messages per hour and IP address. For this, the server keeps your IP address in its memory for at most one hour after you send the form and uses it only for this count. It is never stored and never logged. No third-party services (such as captchas) are used. The legal basis is my legitimate interest in protecting the website and my mailbox from abuse (Art. 6(1)(f) GDPR).
The email arrives in my Apple iCloud Mail mailbox (see “Contact by email”). I keep it there until your enquiry is dealt with and then delete it, unless I am legally required to keep it. - Contact by email
- If you write to me at hello@timoweigelt.com, I process your email address, your name and the content of your message to answer you. Legal basis and retention as for the contact form.
My mailbox is hosted by Apple iCloud Mail. For users in the EU the provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Apple also stores data with Apple Inc. in the USA; according to Apple, transfers there are based on the EU Standard Contractual Clauses. - Fonts, images and content
- All fonts and images are stored on my own server. When you visit the website, your browser makes no requests to Google or any other third party.
The photos in the photo section are published without metadata: no GPS data, no serial numbers. The page only shows the camera, lens, exposure settings and the day the photo was taken. - External links
- Links to other websites (for example to the App Store, later) are plain links. The other website only receives data from you once you click the link; its own privacy policy then applies.
- Apps
- Grand Teleprompter has its own privacy policy.
- Your rights
- You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Where you have given consent, you can withdraw it at any time with effect for the future. Just write to hello@timoweigelt.com.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for me is the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte), Maternistraße 17, 01067 Dresden, Germany (postal address: Postfach 11 01 32, 01330 Dresden), datenschutz.sachsen.de. You can also contact any other supervisory authority, for example where you live. - Last updated
- 9 October 2026. I update this privacy policy when the website changes.