kernprinzip.
Plan your route

Privacy · Updated 28 August 2026

Privacy notice

This notice describes how personal data is processed when you visit kernprinzip.de or contact us.
KERNBER / DE
01

Controller

The controller is Balázs Borka, KERNPRINZIP, Emmentaler Str. 95, 13409 Berlin, Germany.

02

Hosting and server logs

This website is delivered through Vercel Inc., United States. When a page is requested, technically necessary information such as the IP address, time, requested page, referrer, browser and device information may be processed. This supports secure, stable and efficient delivery of the website on the basis of Article 6(1)(f) GDPR. Vercel may process data in the United States and states that it relies on appropriate safeguards, including the EU-US Data Privacy Framework and Standard Contractual Clauses.

03

Enquiries and first conversations

If you use the enquiry form or another contact channel, we process the information you provide, particularly your name, contact method, language, country, objective, timeframe and message, together with any voluntary project details. Processing is necessary to answer your enquiry and take pre-contractual steps under Article 6(1)(b) GDPR and, where applicable, for our legitimate interest in orderly communication under Article 6(1)(f) GDPR. Information is shared with specialist partners only when this is necessary for your request and has been agreed with you, or another legal basis applies.

04

Email delivery through Resend

Form enquiries are transmitted to KERNPRINZIP as transactional email through Resend, Inc., United States. This involves processing sender and recipient addresses, message content and technical delivery metadata. Delivery is necessary to answer your enquiry and take pre-contractual steps under Article 6(1)(b) GDPR and supports our legitimate interest in reliable communication under Article 6(1)(f) GDPR. The configured sending region is Ireland. Resend describes appropriate safeguards for necessary international transfers, including Standard Contractual Clauses.

05

Abuse prevention through Upstash

We use Upstash Redis in the Frankfurt region to protect the form against automated or excessively frequent requests. The server converts the requesting IP address into a non-reversible hash; only that key, counters and an expiry value are stored for rate limiting. Processing is based on our legitimate interest in the security and availability of the service under Article 6(1)(f) GDPR. Upstash identifies the EU-US Data Privacy Framework and Standard Contractual Clauses as safeguards for international transfers where required.

06

Retention

We retain personal data only for as long as necessary to answer an enquiry, perform an engagement or comply with statutory record-keeping and evidence obligations. Data is deleted when the purpose no longer applies and no retention obligation remains.

07

Cookies and audience measurement

We currently use no optional analytics, marketing or profiling services. If consent-based technologies are introduced later, they will be activated only after consent and this notice will be updated accordingly.

08

Your rights

Subject to the GDPR, you may request access, correction, deletion, restriction and portability of your personal data and object to processing. You may also complain to a data protection authority; the competent authority in Berlin is the Berlin Commissioner for Data Protection and Freedom of Information.