Legal
Privacy notice
Last updated: 2 October 2026
Controller and scope
The controller is Maximilian Bossow, trading as Vonaxe, Bonnaskenplatz 6, 03044 Cottbus, Germany. Privacy enquiries: info@vonaxe.com.
This notice covers vonaxe.com and the redirected vonaxai.com domains, including enquiries and bookings made through this website. Our services are business-only. Business contact details relating to individuals are also personal data.
Website access, hosting and security
Requests involve processing IP address, time, requested URL, browser and connection information and, where supplied, the referring page. This supports delivery, troubleshooting and abuse prevention. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in a secure, available website.
Vercel Inc., USA, and its infrastructure providers host and deliver the website. Processing may take place outside the EEA; we do not promise EU-only processing. Application error logs do not contain form contents as long as sending succeeds. If an enquiry cannot be sent, it is saved once in the hosting error log so that it is not lost. Hosting and security logs may also include connection data.
Technical logs are needed only for operations, troubleshooting and security investigation. Actual retention depends on log type and hosting settings. Evidence needed for an incident may be retained until it is resolved. We do not claim automatic deletion after an unverified fixed number of days.
No tracking, no cookies, no consent banner
The website does not use Meta Pixel, Meta CAPI, Google Analytics or individual visitor measurement. Advertising parameters in links do not activate such services.
Language is determined by the URL. The website sets no cookies and stores no data in your browser storage. Font files, images and videos are served through this website’s hosting, not loaded from third-party servers.
Form entries exist only in the open page’s memory until you submit them. Because no information is stored on or read from your device beyond what is technically required for the page you requested, no consent banner is needed.
Contact and concept enquiries
We process the name, contact and project details you submit to answer your enquiry or provide the service you expressly request. Phone numbers, website, timing and budget details and additional business details are optional unless needed for a reply channel you choose. Please do not submit patient data, health information or confidential third-party documents.
The legal basis is Article 6(1)(b) GDPR for pre-contractual requests made by the data subject; for corporate representatives and other business enquiries it is Article 6(1)(f) GDPR, our interest in handling the communication requested. Blanket consent to this privacy notice is not required.
We use Resend (Plus Five Five, Inc., USA) to send messages. Enquiries are delivered as email to info@vonaxe.com; the mailbox is operated by IONOS SE, Germany. Recipients also include the authorised people handling your request. Name, email address, message content and delivery data are processed for the requested communication. An enquiry or booking does not subscribe you to a newsletter.
Unsuccessful enquiries are generally scheduled for deletion 90 days after closure. If a contract follows, contractual and statutory retention purposes apply. Evidence needed for specific legal claims is excepted. This is an operational retention rule, not a claim that automatic deletion has already been configured at every recipient.
Enquiries do not trigger automatic marketing sequences. Marketing email is subject to section 7 UWG as well as data protection law. Legitimate interests alone do not replace consent required under that provision.
Appointments and internal handling
Bookings involve name, email address, requested appointment, language and time zone, plus optional phone, company and message. The purposes are scheduling, preventing duplicate bookings, confirmation and service-related reminders. The legal bases are Article 6(1)(b) or (f) GDPR as explained for enquiries.
Bookings are forwarded server-side to our internal booking system. Notion Labs, Inc., USA, may be used for internal customer management; email and hosting use the providers described above. If a direct booking is not confirmed, an email appointment request is attempted. The interface distinguishes a confirmed booking from a request awaiting personal confirmation.
Appointment and contact data follow the retention rules for enquiries after closure or, if a contract follows, those for business records. Any later manual entry into customer management supports handling the request, not visitor attribution.
Applications and collaboration
If you apply or introduce yourself by email, we process contact details, qualifications, work samples and correspondence only to assess the specific opportunity. Recipients are the proprietor and authorised people handling it, plus email and, where applicable, administration providers.
Employment applications are processed under section 26(1) BDSG in conjunction with Article 88 GDPR; independent collaboration under Article 6(1)(b) GDPR. If no hire follows, deletion is generally scheduled six months after closure. Interim retention to defend potential claims relies on Article 6(1)(f) GDPR. Specific pending proceedings may justify longer retention. A longer-term talent pool requires separate voluntary consent; submitting an application does not provide it.
External links and WhatsApp
The website contains ordinary links, for example to reference clients’ websites and to the privacy notices of the providers named here. No embedded third-party content is loaded. A connection to another site starts only when you open the link; its operator is responsible for processing there.
WhatsApp is included as an ordinary external link, not as an automatically loaded widget. A connection to the provider (WhatsApp Ireland Limited, Ireland, with Meta Platforms, Inc., USA) starts only when you open the link. WhatsApp may process phone, profile and message information. Email and the contact form remain alternatives that do not require this service.
Subsequent processing by the platform follows its privacy notice and may include international transfers. Our handling of a message you choose to send there follows the legal bases and retention rules for enquiries.
Recipients, international transfers and retention
The hosting, communication and administration providers named above may process personal data outside the EEA. Transfers must meet Articles 44 et seq. GDPR, including an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. The published data processing terms of Vercel, Resend and Notion describe relevant transfer mechanisms. We do not claim processing takes place only in Germany or Europe. You may request information and a copy of the safeguards relevant to a specific operation at info@vonaxe.com.
Statutory retention duties, for example for accounting records and business correspondence, may require longer retention of particular documents. These are handled separately from the operational enquiry record. Unneeded copies in mailboxes, customer management and providers’ systems must be considered; backups follow their recovery and overwrite cycles. Deletions must be reapplied if data is restored from backup.
Business contacts from public sources (Article 14 GDPR)
Where business contacts are obtained from public company websites or professional directories rather than provided by the individuals themselves, the data may include name, professional role, company, business address and professional contact details. The specific source must be identified on request and within the statutory information deadlines.
Processing to prepare business communication requires an assessment of necessity and a balancing of interests under Article 6(1)(f) GDPR. Public availability alone permits neither unlimited retention nor unsolicited marketing email or automated marketing calls. The additional requirements of section 7 UWG must be assessed separately.
Recipients are authorised internal personnel and the administration providers described above. Unneeded contact records must be deleted; unsuccessful, closed approaches generally follow the 90-day rule. Objections are respected; a minimal suppression record may be retained to avoid recontacting the person. In particular, you can object to direct marketing at any time.
Your rights
Subject to the legal requirements, you have rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18) and portability (Article 20 GDPR). Consent may be withdrawn at any time for the future; earlier lawful processing remains unaffected.
You may object to processing under Article 6(1)(f) GDPR on grounds relating to your particular situation (Article 21 GDPR). You can object to processing for direct marketing at any time without giving reasons.
You may complain to a data protection supervisory authority, particularly where you live or work or where the alleged infringement occurred. For the controller’s location in Cottbus, the Brandenburg Commissioner for Data Protection and Access to Information is one contact point.
There is no legal obligation to complete public forms. Without the contact details necessary for your enquiry, we cannot answer it. This website does not make solely automated decisions producing legal or similarly significant effects within Article 22 GDPR.