Privacy Policy
Data controller
Patrik Thomas Michalski Stockholmstraße 29 24109 Kiel, Germany
Email: contact [at] ptrkmchk [dot] com
Using the website and data transmission
Visiting this website involves processing technical access data. If you contact me, I also process the information you send. The following sections explain the purposes, recipients and retention periods. The public website at ptrkmchk.com uses HTTPS to encrypt data in transit.
Contact by email
Incoming emails, including sender details and attachments, are forwarded through mailbox.org (Heinlein Hosting GmbH, Germany) to my Outlook.com mailbox at Microsoft. No additional copy is kept in the mailbox.org inbox. The providers’ privacy notices are available at https://mailbox.org/en/data-protection/ and https://privacy.microsoft.com/en-us/privacystatement. Microsoft may also process data outside the European Economic Area; its privacy statement explains the safeguards used for these transfers.
When you contact me by email, I process your sender address, message and associated metadata to respond. Article 6(1)(b) GDPR applies to contractual and pre-contractual enquiries. Other enquiries are processed under Article 6(1)(f) GDPR, based on my legitimate interest in professional and academic communication. Messages in my mailbox are normally deleted within six months of the final reply. Legal retention duties or the establishment, exercise or defence of legal claims may require longer storage.
Contact form
The form processes your name, email address, optional subject and message. Providing these details is voluntary. The form cannot send a message without a name, valid email address and message text. The data is sent to my mailbox through Plus Five Five, Inc. (Resend). Once the delivery service has accepted the message, an automatic acknowledgement without your message text is requested. The same legal bases and mailbox retention periods apply as for contact by email.
Resend is operated by Plus Five Five, Inc., USA, and processes addressing data and message content as a processor. Its DPA governs international transfers through the Data Privacy Framework and EU Standard Contractual Clauses: https://resend.com/legal/dpa. Privacy information: https://resend.com/legal/privacy-policy.
Resend states a 30-day retention period for email and log data on its standard plans. This applies to data at the delivery service; messages in my mailbox follow the retention period described above. Source: https://resend.com/security/gdpr.
Submission limits and duplicate prevention
I use shared storage at Upstash, Inc. to protect the contact form from abuse. The selected database region is Frankfurt, Germany. A secret key is used to derive a pseudonymous identifier from the IP address. The identifier and request counters expire after ten minutes. A keyed hash of the submission and its delivery status expire after 24 hours and help identify repeated sending attempts. This database contains no plain-text IP addresses, names, email addresses or message content. Processing is based on Article 6(1)(f) GDPR and my legitimate interest in a reliable contact form protected against abuse.
Upstash acts as a processor under its DPA. Processing outside the EEA, including the USA, is possible despite the Frankfurt database region. The DPA provides for US transfers under the Data Privacy Framework and, where required, EU Standard Contractual Clauses: https://upstash.com/trust/dpa.pdf. Privacy information: https://upstash.com/trust/privacy.pdf.
Bot protection with Cloudflare Turnstile
The security check loads only when you interact with the form. Cloudflare Turnstile, provided by Cloudflare, Inc., USA, examines signals such as IP address, browser identification and TLS characteristics to detect automated submissions. Cloudflare processes these signals on my behalf for form protection and as an independent controller to improve bot detection. Details: https://www.cloudflare.com/turnstile-privacy-policy/.
I use Turnstile under Article 6(1)(f) GDPR, based on my legitimate interest in protecting the form and receiving mailbox from abuse. Where Turnstile accesses information on your device, this serves the necessary protection of the requested contact form (§ 25(2) no. 2 TDDDG). Processing in the USA is possible. International transfers are governed by Cloudflare’s DPA, which incorporates EU Standard Contractual Clauses: https://www.cloudflare.com/cloudflare-customer-dpa/.
Appearance and language
Your appearance preference is stored as “theme” in the browser’s local storage until you remove the setting or browser data. An explicitly selected language is stored for one year in the “locale” cookie. Both values retain your choices. Device access is based on § 25(2) no. 2 TDDDG. Where personal data is processed, Article 6(1)(f) GDPR applies, based on my legitimate interest in providing your chosen settings.
Hosting and logs
This website is hosted by Vercel Inc.. Requests generate technical data such as IP address, time, requested path and browser information. These are processed to deliver and secure the website. Processing is based on Article 6(1)(f) GDPR and my legitimate interest in a secure, accessible website. I do not combine these data with other datasets.
On the Vercel Hobby plan used here, runtime logs are available for one hour. This is not a universal deletion period for all of the provider’s infrastructure and security data. Vercel determines retention according to the purpose and legal requirements: https://vercel.com/docs/logs/runtime and https://vercel.com/legal/privacy-notice.
Vercel Inc. is based in the USA. Processing outside the EEA is possible. Vercel’s DPA governs processing on my behalf and international transfers, including EU Standard Contractual Clauses: https://vercel.com/legal/dpa.
Fonts, images and external links
The website uses system fonts available on your device. Images are served through this website. There is no advertising tracking or embedded social-media content. External profile, publication and project pages are contacted when you follow their links. Those websites are governed by their operators’ privacy policies.
Your rights
Subject to the legal conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). You may object to processing based on legitimate interests on grounds relating to your particular situation (Article 21). You may withdraw any consent at any time for future processing. To exercise your rights, use the contact details above. You may also complain to a data protection supervisory authority (Article 77).
There is no automated decision-making with legal or similarly significant effects within the meaning of Article 22 GDPR. The security check only assesses whether a form submission appears automated.
Competent supervisory authority
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD) Holstenstraße 98, 24103 Kiel, Germany https://www.datenschutzzentrum.de
Policy version
Last updated: 7 September 2026.