header-image

Privacy Policy

Personal data (usually referred to just as "data" below) will only be processed by me to the extent necessary and for the purpose of providing a functional, secure, and user-friendly website, including its contents and the interactive portfolio services offered here.

Per Art. 4 No. 1 of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as the "GDPR"), "processing" refers to any operation or set of operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction performed on personal data, whether by automated means or not.

The following privacy policy is intended to inform you in particular about the type, scope, purpose, duration, and legal basis for the processing of such data either under my own control or in conjunction with my server hosting provider. I also inform you below about the self-contained components and system features I use to optimize my website and improve your user experience, which may result in external third parties also processing data they collect and control when you exit my domain boundaries.

My privacy policy is structured as follows:

I. Information about me as the controller of your data
II. The rights of users and data subjects
III. Information about the data processing

I. Information about me as the controller of your data

The party responsible for this website (the "controller") for purposes of data protection law is:

Kathrin Markworth
Süderlücke 3
24944 Flensburg
Germany

Telephone: 004915732745789
Email: sunnyandkate@icloud.com

II. The rights of users and data subjects

With regard to the data processing to be described in more detail below, users and data subjects have the right:

In addition, I am obliged to inform all recipients to whom I disclose data of any such corrections, deletions, or restrictions placed on processing the same per Art. 16, 17 Para. 1, 18 GDPR. However, this obligation does not apply if such notification is impossible or involves a disproportionate effort. Nevertheless, users have a right to information about these recipients.

Likewise, under Art. 21 GDPR, users and data subjects have the right to object to the future processing of their data pursuant to Art. 6 Para. 1 lit. f) GDPR. In particular, an objection to data processing for the purpose of direct advertising is permissible.

III. Information about the data processing

Your data processed when using my website will be deleted or blocked as soon as the purpose for its storage ceases to apply, provided the deletion of the same is not in breach of any statutory storage obligations or unless otherwise stipulated below.

Content Management System (CMS) Security Cookies

When accessing my live PHP application demo environments, the server drops a single, strictly necessary security session cookie (named PHPSESSID). This cookie is entirely technical and is required to manage administrator or guest authentication states. It does not track your browsing habits, contains no marketing telemetry, and automatically self-destructs the moment you close your web browser tab.

Disabling Cookies

You can refuse the use of cookies by changing the settings on your browser. Likewise, you can use the browser to delete cookies that have already been stored. However, the steps and measures required vary depending on the browser you use. If you have any questions, please use the help function or consult the documentation for your browser or contact its maker for support.

If you prevent or restrict the installation of cookies, please note that some of the dynamic database features on my portfolio site may not function correctly.

Contact Details

If you contact me via email, the data you provide will be used strictly for the purpose of processing your request. I must have this data in order to process and answer your inquiry; otherwise I will not be able to answer it in full or at all. The legal basis for this data processing is Art. 6 Para. 1 lit. b) GDPR. Your data will be deleted once I have fully answered your inquiry and there is no further legal obligation to store your data.

User Posts, Comments, and Ratings

I offer you the opportunity to post questions, answers, opinions, and ratings on my website, hereinafter referred to jointly as "posts." If you make use of this opportunity, I will process and publish your post, the date and time you submitted it, and any pseudonym you may have used.

The legal basis for this is Art. 6 Para. 1 lit. a) GDPR. You may revoke your prior consent under Art. 7 Para. 3 GDPR with future effect. All you have to do is inform me that you are revoking your consent.

In addition, I will also process your IP address and email address. The IP address is processed because I might have a legitimate interest in taking or supporting further action if your post infringes the rights of third parties and/or is otherwise unlawful. In this case, the legal basis is Art. 6 Para. 1 lit. f) GDPR. My legitimate interest lies in any legal defense I may have to mount.

Server Data and Log Files (Hosting Infrastructure)

For technical reasons, the following data sent by your internet browser to me or to my cloud infrastructure server providers will be collected, especially to ensure a secure, stable, and functional website. These server log files record the type and version of your browser, operating system, the website from which you came (referrer URL), the webpages on my site visited, the date and time of your visit, as well as the IP address from which you visited my site.

The data thus collected will be temporarily stored, but not in association with any other of your data. The basis for this storage is Art. 6 Para. 1 lit. f) GDPR. My legitimate interest lies in the improvement, stability, functionality, and security of my website. The data will be deleted automatically within a window of 7 to 14 days, unless continued storage is required for evidentiary purposes.

Hosting & Database Infrastructure Provider Disclosures:
  1. GitHub Pages: This website uses static content hosting nodes provided by GitHub, Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA. To review how GitHub handles metadata, you can read the GitHub General Privacy Statement. GitHub secures data processing alignment through standard contractual frameworks.
  2. Vercel Infrastructure: Application routing and rendering environments are hosted via Vercel Inc., 440 Bond Street, Suite 260, Austin, TX 78704, USA. To inspect their regulatory parameters, look at the Vercel Privacy Notice and the Vercel Data Processing Addendum. Vercel is fully certified under the EU-U.S. Data Privacy Framework to ensure data safety.
  3. Render Web Services: Backend application rendering environments are hosted via Render Services, Inc., 525 Brannan St, Suite 300, San Francisco, CA 94107, USA. Render handles runtime computational metadata and server transaction logs required to execute our code. Render is certified under the EU-U.S. Data Privacy Framework to align cross-border data delivery with European transparency standards. You can inspect their parameters in the official Render Privacy Policy.
  4. Aiven Cloud Databases: Application data layers, database storage management systems, and memory cache environments are provisioned through Aiven Oy, Antinkatu 1, 00100 Helsinki, Finland. Aiven handles secure database persistence, operational profiling logs, and structured account vectors. As a provider established within the European Union, Aiven satisfies strict data confinement safeguards under standard European data protection rules. You can review their full security profiles via the official Aiven Privacy Policy.
  5. ByetHost Web Hosting Infrastructure: Web server hosting, domain routing networks, and file storage environments are provisioned via ByetHost, a service operated by iFastNet Ltd., Unit 11, Newcastle Enterprise Centres, Newcastle upon Tyne, NE6 1LF, United Kingdom. ByetHost automatically processes technical server log variables necessary to securely deliver backend content and protect server nodes from resource exploitation. Because the United Kingdom operates under an official EU Adequacy Decision, data transfers to their servers satisfy strict European legal confinement and data safety criteria. You can review their full data logging parameters via the official ByetHost Privacy Policy.

Unity Engine

This site features embedded games and projects built using the Unity Engine. When you launch and interact with these builds, Unity Technologies automatically gathers technical device metrics required to initialize, render, and execute the game smoothly. This telemetry collection includes your unique hardware identifiers (such as IP addresses and device IDs), operating system profile, graphics vendor specifications, and real-world execution performance logs.

For explicit insights regarding how they independently isolate, manage, or retain player profiling records, please refer directly to the official Unity Game Player and App User Privacy Policy.

External Retail Redirection (Online Shop Links)

My interactive wishlist system features optional outbound links to third-party digital marketplaces and physical online storefronts. Once you click these store buttons, you leave my project domain. I maintain absolutely no control, oversight, or legal liability over the tracking pixels, cookies, or data compilation methods deployed by those external merchants.

Portfolio Project Sandbox Disclaimer & Tech Stack Confinement

This entire web application is an educational software development portfolio piece highlighting my cozy pastel animal designs and game asset integration. The interactive user database environment (including the simulated code_reviewer login matrix) functions exclusively as a read-only testing sandbox to show my backend CRUD programming capabilities. No real-world commercial retail sales or financial transactions take place on this server.

Please note that certain linked repositories across this domain—such as the Loot Ecosystem Project—function strictly as open educational sandboxes and testing vaults. These systems are engineered to demonstrate multi-platform full-stack integrations (including React frontends, Java Spring Boot REST APIs, and Unity game engines connected to a relational MySQL database cluster managed via our infrastructure providers).

Data Boundaries: These sandbox configurations do not collect, process, or store any Personally Identifiable Information (PII), tracking cookies, real names, or email records. All data records, blueprints, entries, and transaction logs generated inside the system panels use completely anonymous, structural gameplay variables (e.g., item names, numeric primary key IDs, and state properties) and can be cleared or deleted during administrative data purges at any time.




Model Data Protection Statement for Anwaltskanzlei Weiß & Partner