1. Controller
PrimeVision Webstudio, owner Pierre Tichy, Forstbergstraße 5, 64354 Reinheim, Deutschland. E-mail: info@primevision-webstudio.com.
2. Hosting and server logs
When this website is accessed, technically necessary connection data such as IP address, time, requested resource, referrer and browser/device information may be processed by the web server and hosting provider. Processing serves delivery, stability, troubleshooting and security (Art. 6(1)(f) GDPR). Logs are retained only for as long as required for operation, security or legal obligations.
3. Contact form and e-mail
We process information submitted through the contact form or by e-mail to answer enquiries and prepare or perform contracts (Art. 6(1)(b) GDPR). Anti-abuse measures such as form tokens, rate limits, duplicate detection and shortened/hash-based technical identifiers are used on the basis of Art. 6(1)(f) GDPR.
4. Orders, onboarding and portals
For orders and project delivery we process account and contact data, selected services, order and payment status, project briefings, messages, files, approvals, support requests and security/activity logs. The legal basis is primarily Art. 6(1)(b) GDPR; security logging is additionally based on Art. 6(1)(f) GDPR.
5. Shopping cart, sessions and technically necessary storage
The shopping cart may use local browser storage so selected services remain available during checkout. Authentication uses technically necessary session cookies. These mechanisms are necessary to provide functions expressly requested by the user. PrimeVision Webstudio does not set its own advertising, tracking or analytics cookies.
6. Payments with Stripe
Online payments are processed through Stripe. When checkout is started, order data such as name, e-mail address, selected services, prices and transaction references are transmitted to Stripe. Payment-card data is entered directly in Stripe Checkout and is not stored on the PrimeVision server. Processing is based on Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(c) GDPR. Stripe may process data outside the European Economic Area as part of its payment infrastructure and describes the relevant transfer safeguards in its privacy and data-processing terms. More information: Stripe Privacy Policy.
7. Recipients and technical service providers
To provide, secure and internally process our services, we may use carefully selected hosting, payment, e-mail, internal communication and notification service providers. Only data required for the respective purpose is processed. Where providers process data in third countries, this takes place only in accordance with the applicable legal requirements for international data transfers. Depending on the processing, the legal basis is in particular Art. 6(1)(b), (c) or (f) GDPR.
8. E-mail delivery
Transactional, contact and support e-mails are sent using the server-side configured mail provider. Recipient, sender, subject and message content are processed only as required for communication and contract handling.
9. Retention
Personal data is retained only for as long as necessary for its purpose. Contract, invoice and accounting records are stored for the applicable statutory retention periods. Account and project data is deleted or anonymised when no longer required and no legal retention obligation applies.
10. Your rights
Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, data portability and objection. You may also lodge a complaint with a competent data-protection supervisory authority.
11. Supervisory authority in Hesse
The Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Wilhelmstraße 7, 65185 Wiesbaden, Germany. Website: datenschutz.hessen.de.
12. Security
We use access controls, password hashing, CSRF protection, rate limiting, protected uploads, restrictive session settings and server-side secrets. No internet service can guarantee absolute security.
Last updated: August 2026.