Legal

Privacy policy

1. Controller

Maximilian Blücher
Ahornring 54
38553 Wasbüttel
Deutschland
max@bluecherlab.com

Privacy enquiries may be sent directly to the address above.

2. Scope and principles

This notice applies to bluecherlab.com, including its German and English marketing pages, documentation, and public Outlays demo. The website is statically generated and has no user account, form backend, or proprietary visitor database.

No advertising, audience-measurement, or analytics profiles are created; no external fonts are loaded; and no third-party content is embedded automatically. Personal data is limited to what is necessary for delivery, security, and communication.

3. Technical delivery through Cloudflare Pages

The website is delivered through Cloudflare Pages. The recipient and processor is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. On each request, Cloudflare processes data including the IP address, time, requested URL and file, HTTP information, status code, transferred volume, referrer, user agent, and routing and security information.

The purposes are delivery of requested content, TLS encryption, stability, fault analysis, and detection and prevention of abuse and attacks. The legal basis is Article 6(1)(f) GDPR. The legitimate interests are a secure, available, and economically operable website. The site cannot be delivered without processing technical connection data.

Cloudflare processes data in the European Union and in third countries, particularly the United States. Under the Cloudflare Data Processing Addendum, Cloudflare acts as processor. Transfers to the United States rely on the EU-U.S. Data Privacy Framework; where it is not applicable, the EU Standard Contractual Clauses and the supplementary safeguards described in the DPA apply. A copy of the relevant safeguards may be requested through the contact address above. The Cloudflare privacy policy also applies.

BluecherLab does not enable optional Cloudflare Web Analytics or Zaraz features and does not export person-level visitor logs. Cloudflare retains technical metadata only as long as required under the contract and DPA for the relevant delivery and security purposes. The specific period depends on data type, Cloudflare service, and security event; data is then deleted or anonymised under the contractual deletion rules. Statutory preservation and retention duties remain unaffected.

4. Cookies, device storage, and demo preferences

The website sets no cookies and uses neither local storage nor session storage. There is no consent-requiring audience measurement, advertising, or cross-device recognition, so no consent banner is used. Technical browser and HTTP caches may temporarily retain requested files according to browser and server cache headers solely to deliver the service explicitly requested.

German and English use separate URLs; no language preference is stored. The public Outlays demo keeps language, appearance, and filters only in the active document and, for shareable views, after the “#” in the URL fragment. URL fragments are not transmitted to Cloudflare or BluecherLab in HTTP requests. The demo contains synthetic data; nevertheless, please do not enter personal information into its search field.

The clipboard is written only after the user deliberately activates “copy email”, “share view”, or “copy section link”. The website never reads clipboard contents.

5. Contact by email

The website uses a link to open the email application on your device for contact. The website itself neither stores nor transmits a message. Only when you send an email will the sender and recipient addresses, timestamp, technical email metadata, and content you entered be processed by the participating email providers and then by BluecherLab.

Project or contract-related enquiries are processed to take pre-contractual steps or perform a contract under Article 6(1)(b) GDPR. General messages are processed under Article 6(1)(f) GDPR; the legitimate interest is proper response, documentation, and IT security of communications. Where statutory retention duties apply, Article 6(1)(c) GDPR provides an additional legal basis.

Recipients are limited to email and IT providers required to handle the message and, where legally necessary, professional advisers or public authorities. Providers are engaged as processors where required. Transfers to third countries take place only on the basis of an adequacy decision or appropriate safeguards under Article 46 GDPR.

Unsuccessful general and project enquiries are deleted no later than twelve months after the last substantive contact. If a contract is formed, contract and accounting records are retained for its duration and then only for applicable commercial and tax periods: generally six years for business correspondence, eight years for accounting vouchers, and up to ten years for certain books and financial statements. Data needed to establish or defend legal claims may be retained with restricted access until statutory limitation periods expire.

6. External links

Links to GitHub, SleepTrack Audio, app stores, Cloudflare, and other providers open only after a deliberate action. This website’s referrer policy prevents a referrer from being sent. Once opened, the destination provider processes data independently under its own privacy information.

7. Products presented

Product descriptions and static previews on this website do not cause BluecherLab to process app, health, household, retailer, or home-network data. The Outlays web demo uses synthetic data only and offers no upload. Actual use of an app is governed by the product-specific privacy notice presented before data is collected; this website notice does not replace it. A dedicated Wake From Far privacy policy is available for the iOS and Android apps.

8. Your data protection rights

Where the statutory conditions are met, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), and objection (Article 21). Consent may be withdrawn at any time for the future; this website currently relies on no consent-based processing. To exercise a right, email max@bluecherlab.com.

10. Right to complain

You may lodge a complaint with a data protection supervisory authority. The authority responsible for the controller’s location is in particular the State Commissioner for Data Protection of Lower Saxony: lfd.niedersachsen.de. You may also contact the authority for your place of residence or work.

11. Provision, sources, and automated decisions

Technical connection data comes directly from your browser and is required to retrieve the website; there is no statutory or contractual obligation to use the site. Information in an email is voluntary, although an enquiry may not be answerable without a reachable sender address and sufficient content. No further personal data is enriched from public or third-party sources. There is no automated decision-making or profiling within the meaning of Article 22 GDPR.