Privacy Policy
How I collect, use and protect personal data on this website and in the applications I operate.
Last updated: 19 September 2026
Controller
Marin Benke - Web & IT, Bosstraat 28, 6291CK Vaals, Netherlands (KvK 99906341) is the controller for the personal data described here. You can reach me at [email protected] with any privacy question or request.
What I collect and why
Contact form
When you submit the contact form I process your name, email address, subject and message in order to answer you. The message is delivered to me by email through Resend, and you receive an automatic confirmation email at the address you entered. Legal basis: steps taken at your request prior to a contract (Art. 6(1)(b) GDPR) and my legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). I keep the correspondence for as long as needed to handle your request, and where it leads to an invoice for the seven-year period required by Dutch tax law.
Appointment booking
If you book a call with me, the booking is handled by Cal.com, which processes your name, email address and the details you enter for the appointment. The appointment is then written to my own calendar. Legal basis: Art. 6(1)(b) GDPR.
Website analytics
This site uses OpenPanel, which I host myself at analytics.marinbenke.dev. It records page views, referrer, approximate country, browser and device type, and clicks on outgoing links. It sets no advertising cookies, does not store raw IP addresses in the analytics database, and does not follow you across other websites. Legal basis: my legitimate interest in understanding how the site is used (Art. 6(1)(f) GDPR).
Spam protection
The contact form is protected by Cloudflare Turnstile. To verify that a submission is not automated, Cloudflare processes your IP address and technical signals from your browser. Legal basis: my legitimate interest in protecting the form against abuse (Art. 6(1)(f) GDPR).
Hosting and server logs
The site runs on Cloudflare Pages. Cloudflare processes connection data such as IP address, requested URL, timestamp and user agent in order to deliver the site and protect it from attacks. Legal basis: Art. 6(1)(f) GDPR.
Fonts
Typefaces are loaded from Google Fonts. When a page loads, your browser connects to Google servers and your IP address is transmitted to Google. Legal basis: my legitimate interest in consistent typography (Art. 6(1)(f) GDPR).
Google API Services
I operate private applications registered in Google Cloud that connect to Google APIs. They are internal tools for running my own business and are used only by me as the sole person working in it. They are not offered to clients or to the public, and no third party signs in to them.
Where such an application is authorised with a Google account, it may request access to Google Calendar (reading and creating events) and to Google Home and smart device data. Access is only ever granted through the Google OAuth consent screen and only for the scopes shown there.
Limited Use: my use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide the features requested. It is never sold, never used for advertising or profiling, never used to train generalised artificial intelligence or machine learning models, and never disclosed to any third party except where you direct it, where it is necessary for security purposes, or where the law requires it.
OAuth tokens are stored encrypted and only for as long as the connection is in use. Calendar and device data is processed to carry out the requested action and is not retained beyond what that action requires. Access can be withdrawn at any time at myaccount.google.com/permissions; revoking access deletes the stored tokens, and you can ask me by email to delete anything that remains.
Service providers
I use the following providers, each under a data processing agreement where one applies: Cloudflare (hosting, CDN and Turnstile), Resend (transactional email), Cal.com (appointment booking) and Google (fonts and, for the applications described above, Google APIs). Some of them process data in the United States; those transfers are covered by the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
Cookies and local storage
This site sets no advertising or cross-site tracking cookies. Your light or dark theme preference is stored in your browser local storage and never leaves your device. Cloudflare may set strictly necessary cookies for security and bot protection.
Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. Where processing rests on consent, you can withdraw that consent at any time with effect for the future. Send any request to [email protected] and I will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens:
https://www.autoriteitpersoonsgegevens.nl/Changes to this policy
I may update this policy when the site or the services behind it change. The date at the top always reflects the current version.