ralph schwehr

Privacy

We take the protection of your personal data seriously. This privacy policy explains which data we process, for what purpose, on what legal basis, and what rights you have. This site is deliberately lean: no tracking, no advertising cookies, no analytics.

1. Data Controller

Controller within the meaning of the GDPR is: Ralph Schwehr Management. Innovation. Group. GmbH Seeholzenstraße 2 82166 Gräfelfing near Munich Germany Email: ralph@schwehr.ai Managing Director: Ralph Schwehr

2. Principles of Our Data Processing

We process personal data only insofar as necessary to provide this website, respond to your inquiries, and fulfil legal obligations. All processing takes place exclusively within the European Union. We do not use tracking cookies, advertising networks, or any web analytics tool such as Google Analytics, Matomo, or Plausible.

3. Hosting and Server Logs

This website is hosted by Vercel Inc. (440 N Barranca Avenue #4133, Covina, CA 91723, USA). Delivery takes place from the Edge network in the EU region (Frankfurt). When you visit, Vercel automatically processes technical data (server logs) such as IP address, browser, operating system, date/time, page requested, and referrer. This data is processed to ensure operation and defend against attacks (legal basis Art. 6 (1) (f) GDPR, legitimate interest). We have a Data Processing Agreement (DPA) with Vercel including EU Standard Contractual Clauses. Logs are typically deleted automatically after a short period (a few days).

4. Contact Form

You can send us a message via the contact form on /kontakt. Data processed: name, email address, optionally company, your message, language version (DE/EN), timestamp. Purpose: responding to your inquiry and communication. Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in communication). The data is stored in our database (see point 6) and simultaneously sent as a notification to ralph@schwehr.ai (see point 7). Retention period: until the inquiry has been finally processed and no statutory retention obligations remain, then deletion.

5. CV Download via Magic Link

On /downloads you can request a download link for the current CV. Data processed: name, email address, optionally company, language version, timestamp. Additionally, a random one-time token is generated and sent to you by email. When you click the link, the token is verified against the database and you receive access to the CV PDF. Purpose: authenticated delivery of the CV. Legal basis: Art. 6 (1) (b) GDPR. Tokens are valid for 24 hours. Lead data retention: 12 months from request, then automatic deletion unless a statutory retention obligation applies.

6. Database: Neon (EU)

Lead data (contact form, downloads) is stored in a PostgreSQL database operated by Neon Inc. (548 Market St, San Francisco, CA 94104, USA). Storage location is exclusively the EU region (Frankfurt, AWS). We have a Data Processing Agreement (DPA) with Neon including EU Standard Contractual Clauses. Neon processes data exclusively on our instructions. Legal basis: Art. 6 (1) (b) and (f) GDPR in conjunction with Art. 28 GDPR.

7. Email Delivery: Resend (EU)

Magic-link emails and contact notifications are sent via Resend Inc. (2261 Market Street #5039, San Francisco, CA 94114, USA). Email delivery takes place exclusively via the EU region (eu-west-1, Ireland). We have a Data Processing Agreement (DPA) with Resend including EU Standard Contractual Clauses. Resend processes data exclusively for email delivery. Emails are DKIM-signed and SPF-authenticated, sending occurs exclusively via the subdomain send.schwehr.ai. Legal basis: Art. 6 (1) (b) and (f) GDPR in conjunction with Art. 28 GDPR.

8. Fonts via Google Fonts

This website uses the Fraunces and Inter fonts. These are delivered locally with the website via next/font (self-hosted). No connection to Google servers is made, and no data is transmitted to Google.

9. Cookies

This website uses no tracking cookies and no advertising cookies. Only technically necessary storage mechanisms required for the operation of the website are used (e.g. session data during form submission). No consent is required for this type of processing under § 25 (2) (2) TTDSG.

10. External Services: Google Search Console

We have registered our website with Google Search Console (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Search Console only analyses data that Google already collects via its search engine (clicks, impressions, search queries). No tracking takes place on this website, no cookies are set, and no script is embedded in the website. Search Console is a pure backend tool for us as site operator. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the discoverability of the website).

11. Links to External Sites

This website contains links to external sites (e.g. LinkedIn, oakai.de). When you click an external link, you are redirected to the respective site and subject to its privacy regulations. We have no influence on the data processing at those sites.

12. Data Sharing with Third Parties

We do not share your data with third parties, except with the processors named in points 3, 6, and 7 for the technical provision of the service. Transfer to third countries outside the EU/EEA only occurs on the basis of appropriate safeguards (in particular EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR).

13. Automated Decision-Making

Automated decision-making within the meaning of Art. 22 GDPR, including profiling, does not take place.

14. Your Rights as a Data Subject

You have the following rights at any time: • Access to data stored about you (Art. 15 GDPR) • Rectification of incorrect data (Art. 16 GDPR) • Erasure of your data (Art. 17 GDPR) • Restriction of processing (Art. 18 GDPR) • Data portability (Art. 20 GDPR) • Objection to processing (Art. 21 GDPR) • Withdrawal of consent given with effect for the future (Art. 7 (3) GDPR) An informal message to ralph@schwehr.ai is sufficient to exercise your rights.

15. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for our location in Gräfelfing/Munich is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany. You may also contact the authority of your place of residence.

16. Data Security

This website is delivered exclusively via HTTPS with TLS encryption. The database is secured by authentication and encryption at rest. Backups are kept in the EU. We take appropriate technical and organisational measures to protect your data against loss and unauthorised access.

17. Updates to This Privacy Policy

This privacy policy may be updated from time to time, for example due to technical changes or new legal requirements. You can always find the current version on this page. Last updated: May 2026.
Notice. This privacy policy has been prepared with care but does not constitute individual legal advice. For specific legal questions, please consult a lawyer or data protection officer.