Privacy Policy for LugLab
Last updated: December 8, 2025
LugLab ("we", "us", or "our") is operated by Jakob Ziller. We are committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, and safeguard information when you use our website or contact us.
If you have any questions, you can reach us at: info@lug-lab.com.
1. Data We Collect
1.1 Contact Form Data
When you send us a message through our contact form, we collect:
- Name
- Email address
- Phone number
- Message content
Purpose: To respond to your inquiry and communicate with you.
Legal basis (GDPR): Art. 6(1)(b) — performance of a contract or pre-contractual steps.
How this data is processed
- Submitted form data is first sent to our backend (hosted on Hetzner).
- From there, the message is forwarded to us via email (Gmail).
- The data is not stored in any database.
Storage duration
- We only store your message in our Gmail inbox for as long as necessary to handle your inquiry.
- No temporary or long-term storage happens on our servers.
We do not share this information with third parties except our email provider (Google/Gmail).
2. Analytics Data
2.1 Google Analytics (GA4)
We use Google Analytics 4 (GA4) to understand how visitors use our website.
Data collected by Google Analytics
- Device information
- Browser version
- Approximate general location
- Pages visited
- Time spent on pages
- Interactions (for example, clicks)
Privacy features enabled
- IP anonymization is enabled.
- Advertising features such as Google Signals, Remarketing, or Demographics are not enabled.
Legal basis: Art. 6(1)(a) GDPR — your consent (through the cookie/analytics consent mechanism).
You can opt out of analytics at any time through your browser settings or via Google's opt-out tools.
3. Hosting and Infrastructure
3.1 Cloudflare
Our frontend is delivered via Cloudflare Workers and the Cloudflare CDN.
Cloudflare may process:
- IP addresses
- Request metadata
- Security-related information
Purpose:
- To deliver the website efficiently
- To protect against attacks and abuse
- To ensure operational stability
Cloudflare acts as a data processor under GDPR.
3.2 Hetzner (Backend Hosting)
Our backend is hosted on servers provided by Hetzner (Germany/EU).
Hetzner may process technical information required for server operation. Our backend:
- Hosts the backend Java application.
- May store general technical logs, but we do not store IP addresses or user-specific data in these logs.
We do not store IP addresses or personal data in backend logs.
4. No User Accounts
We do not offer any login system. We do not create or store user accounts. We do not store passwords or authentication data.
5. Cookies
We only use cookies related to:
- Cloudflare (for security and performance)
- Google Analytics (if you consent)
No tracking cookies are set without your consent (GDPR compliant).
6. Sharing of Personal Data
We do not sell personal data. We only share limited data with:
- Google (Gmail) — to receive your contact form messages
- Cloudflare — for hosting and delivery
- Google Analytics — if you consent to analytics
These providers act as processors or independent controllers under GDPR, depending on the service.
7. International Data Transfers
Because Google (Analytics and Gmail) is based in the U.S., some data may be transferred outside the EU.
Transfers rely on Google's adherence to the EU–US Data Privacy Framework or on Standard Contractual Clauses (SCCs).
8. Your Rights Under GDPR
As an EU/EEA user, you have the right to:
- Access your personal data
- Request correction
- Request deletion ("right to be forgotten")
- Restrict processing
- Object to processing
- Withdraw consent at any time
- Data portability (receive your data in machine-readable form)
To exercise these rights, contact us at info@lug-lab.com.
9. CCPA/CPRA Notice (California Residents)
If you are a California resident, you have the right to:
- Know what personal information is collected
- Request deletion of your data
- Know whether your data is sold or shared (we do not sell data)
- Opt out of data sharing for advertising (we do not use advertising features)
- Be free from discrimination for exercising your privacy rights
Requests can be sent to info@lug-lab.com.
10. Security Measures
We implement technical and organizational measures to protect your data, including:
- HTTPS encryption
- Secure hosting environments (Cloudflare & Hetzner)
- Limited access to our email inbox
- No unnecessary data storage
Despite these measures, no online service can be fully secure.
11. Changes to This Privacy Policy
We may update this policy as needed. The latest version will always be available on our website.
12. Contact
If you have questions, requests, or concerns, contact:
Jakob Ziller
Email: info@lug-lab.com