Privacy policy
Effective date: 6 July 2026
This policy explains what personal data is processed when you visit this site or send United Development a business inquiry, and the rights the EU General Data Protection Regulation (GDPR) gives you over that data.
The short version: this is a static marketing site with no accounts, no cookies, and no trackers. The only personal data we receive is what you choose to type into the contact form, and it is used solely to answer you.
01Who is responsible
Kateryna Martynova — a freelance software developer based in Germany, working under the name United Development — is the “we” in this policy and the controller within the meaning of Art. 4(7) GDPR for all processing described here.
Full contact details, including the postal address, are published in the Impressum. For any privacy matter you can also simply use the contact form.
02Visiting the site
All pages are delivered over an encrypted HTTPS connection. The site is static: there is no login, no comment system, and no embedded third-party content — even the fonts are bundled and served with the site itself, so opening a page sends no request to anyone but our host.
Like every web server, the server delivering this site records technical access data with each request: the requesting IP address, date and time, the URL requested, and the browser and operating system identifiers your browser sends along. Processing this data is technically necessary to deliver pages and to keep the site stable and secure; the legal basis is our legitimate interest in operating it reliably (Art. 6(1)(f) GDPR). Log data is not combined with other data, is not used to identify visitors, and is routinely deleted after a short period.
04Contacting us
The contact form is the only place on this site where personal data is actively collected. It asks for your name, your email address, and the service you are interested in; company name, website, and a project description are optional and entirely up to you — share only what you consider useful.
- Purpose: handling and answering your business inquiry — nothing else. Your details are not added to mailing lists, not used for advertising, and not used for profiling.
- Legal basis: Art. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract — and, for general questions, our legitimate interest in answering correspondence (Art. 6(1)(f) GDPR). Replying to a message you sent us requires no consent under the GDPR, which is why the form has no consent checkbox.
- Who reads it: your message is received and processed on our behalf by the form-handling provider we use — Zink, operated by Binary Please UG — which stores it and forwards it onward by email, ultimately reaching a mailbox read only by the business owner. It is handled only by providers acting on our instructions, never used for advertising, and never sold.
05Service providers
Several providers technically handle data on our behalf, each acting only as a processor bound by a data processing agreement under Art. 28 GDPR and barred from using it for its own purposes. The hosting provider serves the site and processes the server logs described above.
Messages sent through the contact form are handled by Zink, a form-handling service operated by Binary Please UG (haftungsbeschränkt), c/o Factory Works GmbH, Rheinsberger Straße 76/77, 10115 Berlin. Zink receives each submission, stores it as a record, and dispatches the notification email to us; it acts as a processor bound by a data processing agreement under Art. 28 GDPR.
To send that notification email, Zink relies on Brevo (Brevo GmbH, Köpenicker Straße 126, 10179 Berlin) as a sub-processor; Brevo’s servers are located in the EU, and it too is bound by a data processing agreement under Art. 28 GDPR.
The email then reaches our email provider, Proton (Proton AG), which delivers and stores our inquiry messages. Proton is based in Geneva and keeps its core mail infrastructure in Switzerland, with additional data centres in Germany and Norway.
Beyond that, personal data leaves us only where the law requires disclosure — for example to authorities acting on a lawful order.
06International transfers
Apart from inquiry email, personal data from this site is processed in Germany and the wider European Economic Area. Handling of contact-form submissions by our form provider and dispatch of the notification email are carried out by providers established in Germany on servers within the EU, and so add no transfer to a third country. Inquiry messages are stored by our email provider, Proton, in Switzerland — a country outside the EEA. If you write to us from outside the EEA — for example from the Americas — our reply necessarily travels back to you there; that transfer occurs at your own request (Art. 49(1)(b) GDPR).
Switzerland is recognised by the European Commission as ensuring an adequate level of data protection (Art. 45 GDPR), so entrusting inquiry email to a Swiss provider rests on that adequacy decision. Where any provider processes data outside the EEA without such a decision, we rely on the EU Standard Contractual Clauses as the safeguard required by Chapter V of the GDPR.
07Security
Traffic between your browser and this site is encrypted in transit (HTTPS/TLS), as is the delivery of form submissions. Inquiry data sits in a single access-protected mailbox read by one person. No system can be guaranteed absolutely secure, but the attack surface here is kept deliberately small: there is no user database to breach in the first place.
08How long we keep data
Inquiry correspondence is kept while the matter is open and deleted once it is concluded. If an inquiry leads to a business relationship, German commercial and tax law (§ 257 HGB, § 147 AO) obliges us to retain the related business correspondence for six to ten years; it is deleted when those periods expire. Server logs are deleted by the hosting provider after a short period.
Separately, each contact-form submission is also stored by our form-handling provider, Zink, as a record of what was received. That copy is not on an automatic, time-based deletion schedule at present; stored submissions are cleared periodically instead.
09Your rights
The GDPR gives you the following rights over your personal data. Exercising them costs nothing — contact us through the form or the details in the Impressum, and we will respond without undue delay, at the latest within one month (Art. 12(3) GDPR):
- Access (Art. 15): ask whether we process data about you, and receive a copy of it.
- Rectification (Art. 16): have inaccurate or incomplete data corrected.
- Erasure (Art. 17): have your data deleted where no retention obligation stands against it.
- Restriction (Art. 18): have the processing of your data restricted.
- Portability (Art. 20): receive the data you provided in a structured, machine-readable format.
- Objection (Art. 21): object at any time to processing we base on legitimate interest.
- Complaint (Art. 77): lodge a complaint with a data protection supervisory authority — in Germany, the authority of the federal state where we are established, or any authority at your own place of residence.
10Changes to this policy
We revise this policy when our practices or the legal requirements change — for example, if a new service provider is engaged — and update the effective date above. The version published on this page is always the one that applies.
11Questions
If anything in this policy is unclear, or you want to exercise any of your rights, write to us through the contact form or the contact details in the Impressum.