FIDDLERCRAB / LEGAL INFORMATION
Privacy policy
Updated 15 September 2026 · Document version 2026-09-16-marketing-v1
How we handle personal data when you visit this marketing and portfolio website or contact us. This website has no accounts, checkout, advertising cookies or third-party analytics.
1. Controller and privacy contact
FiddlerCrab UG (haftungsbeschränkt), Balbronner Straße 4, 14195 Berlin, Germany. Email: hello@fiddlercrab.com. Telephone: +49 30 69204740. Represented by Dr. Clemens Dorian Chaskel.
Use these contact details for privacy questions or to exercise your rights. This site is a marketing and portfolio page only: it has no account area, shop, checkout, payment processing or contact form. Other websites we link to have their own privacy notices.
2. Website delivery and server logs
Our hosting provider receives IP addresses, requested URLs, access times, browser and device information, response status and, where transmitted, the referring page. This is technically necessary to deliver the website, diagnose faults and defend against abuse. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in a reliable and secure website.
These technical records are kept for the hosting service’s operational logging period and, where a security incident requires investigation, until that investigation and any necessary legal follow-up are complete. They are not used to build advertising profiles and are not combined with other data to identify you.
3. Cookies and browser storage
This website sets no cookies. We use no tracking pixels, advertising networks, analytics, social plug-ins or other non-essential storage. Because the site has no non-essential cookies or similar technologies, it does not display a consent banner or set a consent cookie.
If you switch the colour theme, your choice is stored in your browser under the key fiddlercrab-theme using localStorage. It stays on your device, is never transmitted to us, and exists only to remember the appearance you selected. This is a function you request within the meaning of § 25(2)(2) TDDDG. You can delete it at any time by clearing site data in your browser; the website works normally without it.
All fonts, stylesheets, scripts and images are served from our own domain. No external service loads content or receives your IP address while you view these pages. If we later add analytics, advertising, embeds or other non-essential technologies, we will update this notice and obtain any consent required before loading them.
4. No tracking or profiling
We run no web analytics, no heat mapping, no session recording and no A/B testing on this website. We do not know which individual pages you visited, and we cannot recognise you across visits or across sites.
There is no automated decision-making producing legal or similarly significant effects, and no profiling for such decisions.
5. Contacting us by email
Email links on this site open your own mail program; no contact form data is processed on the website itself. When you write to us, we process your email address, your name if you give it, the content of your message and the technical delivery information that comes with it.
We use this to handle your enquiry. The legal basis is Article 6(1)(b) GDPR where your message concerns a contract or pre-contractual steps, and otherwise Article 6(1)(f) GDPR: our legitimate interest in answering enquiries addressed to us. Please do not send special-category data (for example health information) unless it is genuinely necessary for your request.
Routine correspondence is deleted once the matter is resolved and no further purpose or retention duty applies. Business correspondence is generally retained for six years, invoices and accounting vouchers for eight years, and accounting books and annual accounts for ten years, usually from the end of the relevant calendar year (§ 257 HGB, § 147 AO). Statutory extensions and necessary legal holds may apply (Article 6(1)(c) and (f) GDPR).
6. Recipients and international processing
Only people within our company who need the information, and the service providers listed below, process personal data for us:
Vercel Inc. — website hosting. Serves this website through global infrastructure and processes the technical request data described in section 2; processing and support can take place in the United States and other countries.
Microsoft 365 / Microsoft Ireland Operations Limited — business email. Hosts our correspondence and processes message contents, addresses, attachments and technical and security information; service and support can involve other countries.
Where data leaves the EEA, the provider terms provide safeguards such as EU standard contractual clauses under Article 46 GDPR or an applicable adequacy decision under Article 45 GDPR. Contact us for information about the applicable safeguards, subject to the protection of confidential information.
Advisers, authorities or courts may receive information where this is necessary for legal obligations or legal claims (Article 6(1)(c) or (f) GDPR). Provider logs, mailboxes and backups are separate from each other; deleting a message does not immediately erase every backup copy, and residual backups are restricted to recovery and rotate under the relevant service arrangements.
7. Your rights
Subject to the statutory conditions you have the rights of access (Article 15 GDPR), rectification (16), erasure (17), restriction of processing (18) and data portability (20). You may withdraw any consent you have given at any time with effect for the future (Article 7(3) GDPR). We normally respond within one month and will explain any permitted extension.
You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR (Article 21 GDPR). We then stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin. You do not need to contact us first.
8. External links, required information and changes
You can read this website without providing any personal data. The project links do not load third-party content on this site. If you click one, your browser connects to the selected provider, which may process your IP address, device data and the request details under that provider’s own privacy notice. We use rel="noopener noreferrer" on external project links so this site does not pass a referrer URL.
If you contact us, we need the information required to answer you — usually a reply address and your actual question. We update this notice when our purposes, services or providers change, and obtain consent where the law requires it. An updated notice does not retrospectively create or broaden consent. This version is dated below.