Privacy policy

What happens to your data on takeo.cx.

As of

In short

This website sets no cookies of its own and uses no tracking, no analytics and no advertising. It loads nothing from other servers. Personal data is processed in only two situations:

  • when the website is delivered to your browser by the hosting provider Cloudflare
  • when you send me a request via the form or by email

The details follow below.

Controller

The controller within the meaning of Art. 4(7) GDPR is:

Takeo Scharkin Konrad-Adenauer-Straße 20 42651 Solingen Germany

Email: hello@takeo.cx

For questions about your data, write to this address. Further details are in the imprint.

Hosting and delivery

This website is hosted by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare also runs the name servers of the domain takeo.cx. Every visit to this website therefore passes through Cloudflare’s network. The connection is encrypted (HTTPS).

Data
Your IP address, date and time of the request, the page or file requested, the website you came from (if your browser sends it), browser and operating system (user agent), the approximate location derived from the IP address (country), and technical data such as status code and amount of data transferred.
Purpose
Delivering the website and keeping it stable and secure, for example by detecting and fending off attacks and misuse.
Legal basis
Art. 6(1)(f) GDPR. My legitimate interest is delivering the website reliably and securely. Without this data the website cannot be displayed.
Processor
Cloudflare processes this data on my behalf under a data processing agreement (Art. 28 GDPR).
Transfer to third countries

Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework. For certified companies, the European Commission has decided that the USA ensures an adequate level of data protection (adequacy decision of 10 July 2023, Art. 45 GDPR).

Cloudflare usually answers a request from a data centre close to you. Depending on the route, this can also be a data centre outside the EU. For such transfers, Cloudflare’s data processing agreement provides for the EU standard contractual clauses (Art. 46(2)(c) GDPR).

Storage

In my Cloudflare account I can see statistics and, for security analysis, samples of individual requests (including IP address, page requested, browser and country). Cloudflare keeps this data for up to 31 days. I only look at it to fix errors or fend off attacks.

When you send the contact form, the request is handled by a small program of mine that runs on Cloudflare (a Worker). It does not keep a log of your request. Only if something goes wrong does it write a short technical error note to my Cloudflare account, without your form data, email address or IP address. Cloudflare deletes these notes after 3 days.

Beyond that, Cloudflare keeps technical data only as long as it needs it for operation and security. Details are in Cloudflare’s privacy policy.

Contact form

On the start page you can send me a request. The following data is processed:

  • name, email address, subject and message, as you enter them
  • the time of sending
  • your IP address: my program uses it for one minute as a counter so that no more than five requests per minute can be sent from the same address (for IPv6 addresses only the network part, the first half of the address). This protects the form against mass submissions. It is not stored beyond that.

A hidden field that people do not see catches automated spam. If it is filled in, nothing is sent.

Your browser sends the data over an encrypted connection to my program on Cloudflare (the Worker described under Hosting), which turns your request into an email and sends it via Cloudflare’s email service from anfrage@takeo.cx to my mailbox at Proton AG in Switzerland. Your email address is set as the reply address, so I can answer you directly. The form data is not stored in a database on this website.

Purpose
Processing and answering your request.
Legal basis
Art. 6(1)(b) GDPR if your request concerns a possible project or contract (steps taken at your request before entering into a contract). Otherwise Art. 6(1)(f) GDPR: my legitimate interest is to answer messages sent to me. For the IP-based limit: Art. 6(1)(f) GDPR, my legitimate interest is protecting the form against misuse.
Required data
Name, email address, subject and message are required so that I can assign and answer your request. Using the form is voluntary; you can also write an email instead.
Recipients

Cloudflare (see Hosting). For each email sent, Cloudflare keeps delivery data in my account for up to 31 days: sender and recipient address, subject line, message ID, time and delivery status.

Proton AG, Switzerland, which hosts my mailbox. For Switzerland, the European Commission has decided that it ensures an adequate level of data protection (Decision 2000/518/EC of 26 July 2000).

Storage
I delete your request and our correspondence once it has been dealt with, no later than six months after our last contact. If a contract results from it, I keep the correspondence for as long as German tax law requires (generally six years for business correspondence, § 147 AO).

Email

You can also write to hello@takeo.cx. Emails to this address are received by Cloudflare (Email Routing) and forwarded to my mailbox at Proton AG in Switzerland. For each email, Cloudflare keeps delivery data in my account for up to 31 days: sender and recipient address, subject line, message ID, time and delivery status.

Purpose, legal basis, recipients and storage period are the same as for the contact form.

Cookies, tracking, external content

This website sets no cookies and uses no tracking, analytics or advertising tools. Cloudflare Web Analytics is not used either.

The fonts (Funnel Display and Funnel Sans) are served from this website itself. No content is loaded from other providers: no external fonts, maps, videos or social media plugins. Links to other websites only take effect when you click them.

One exception can come from Cloudflare: if it has to show you a security check, for example during an attack on the website, Cloudflare may store cookies needed for this check (such as cf_clearance, which records that you passed it). Legal basis: § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. My legitimate interest is protecting the website against attacks.

Automated decisions

I do not use automated decision-making, including profiling (Art. 22 GDPR).

Your rights

Regarding your personal data, you have the right to

  • access (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object (Art. 21 GDPR, see below).

An informal email to hello@takeo.cx is enough.

Right to object (Art. 21 GDPR)

Where I process your data on the basis of Art. 6(1)(f) GDPR (legitimate interests), you have the right to object at any time, on grounds relating to your particular situation. I will then stop processing your data, unless I can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. An informal email to hello@takeo.cx is enough.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for me is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

Changes

I update this privacy policy when the website or the legal situation changes. The current version is always on this page.

As of October 2026