Privacy
Privacy Policy
1. Controller
Paul Harbig, trading as Paularyo
Lohrstraße 32, 09113 Chemnitz, Germany
Email: hello@paularyo.com
2. Purposes and legal bases
Paularyo processes personal data only where necessary to provide the website, handle enquiries, take pre-contractual steps, perform contracts, process payments, maintain security, evidence legal declarations or comply with legal obligations.
The principal legal bases are Art. 6(1)(b) GDPR for contracts and pre-contractual steps, Art. 6(1)(c) for legal obligations, Art. 6(1)(f) for secure operation, abuse prevention, organisation and improvement, and Art. 6(1)(a) where consent is expressly requested.
3. Hosting, delivery and server logs
The website is delivered through Vercel. Technically necessary data such as IP address, date and time, requested URL, referrer, browser, operating system and status codes may be processed.
Processing serves secure, stable and performant delivery, troubleshooting and attack prevention under Art. 6(1)(f) GDPR.
4. Vercel Web Analytics and Speed Insights
Paularyo uses Vercel Web Analytics and Speed Insights for aggregated usage and performance information. Under the current configuration, no marketing profiles are created and no first-party marketing cookies are set.
Technical and aggregated data may include page views, referrer, device type, approximate region and performance metrics. The legal basis is Art. 6(1)(f) GDPR. Technologies requiring consent are loaded only after consent.
5. Supabase, authentication and customer portals
Supabase is used for database functions, secure server processing, authentication and private customer and project portals.
Depending on use, data may include name, email, website, project, audit and report data, statuses, customer requests, payment references, contract and cancellation data. Processing is based on Art. 6(1)(b) and (f) GDPR.
6. Forms, Website Audit and public website analysis
Data entered in contact, fit-check, onboarding, work, upgrade, withdrawal or cancellation forms is processed. This may include name, email, company, website, budget, platform, scope, content, functionality, access method, messages and contract references.
For the Quick Check and Website Audit, Paularyo processes the supplied website address, contact details, public HTML, metadata, technical signals and screenshots of the public homepage. Protected areas are not reviewed without separate access.
Access credentials and recovery information must not be submitted and may be technically rejected. Abuse and rate-limit data is handled in a data-minimising manner without storing raw IP or email values for those limits.
7. Stripe: payments and subscriptions
Stripe processes payments and subscriptions, including payment, billing, contact, transaction, technical and fraud-prevention data.
Paularyo does not receive full card details and receives only information needed for Checkout, allocation, payment status, refunds and subscription management. Processing is based on Art. 6(1)(b) GDPR. Stripe may act independently for its own legal duties and fraud prevention.
8. Resend and contract communications
Resend is used for contact confirmations, audit, project and retainer email, contract confirmations and receipts for withdrawal and cancellation.
Processed data includes email, name, subject, message, contract or project information and delivery status under Art. 6(1)(b), (c) and (f) GDPR.
9. Checkout declarations, withdrawal and cancellation
Paularyo stores the confirmed versions and timestamps of the Terms, Privacy Policy and Withdrawal Policy, requests for early performance, acknowledged withdrawal consequences, contract reference, Stripe Session and a contract summary.
The public withdrawal and cancellation functions process name, email, contract reference, product, declaration, date, time and, where applicable, reason and requested end date.
The purpose is contract performance, receipt and confirmation of declarations and evidence of legal duties and claims. No raw IP address is stored. Legal bases are Art. 6(1)(b), (c) and (f) GDPR.
10. Cookies and local storage
Paularyo currently sets no first-party marketing cookies. Strictly necessary cookies or storage may be used for authentication, security, language, Checkout and private portal states.
Non-essential analytics, marketing or advertising technologies are used only after required consent.
11. Recipients and international transfers
Recipients may include hosting, database, payment, email, security and technical providers where necessary.
Where data is processed outside the EEA, transfers rely on an adequacy decision, EU Standard Contractual Clauses or another lawful basis.
12. Retention
Data is retained only as long as required for its purpose, contract administration, statutory retention duties or the establishment and defence of legal claims.
Enquiry data is reviewed and deleted after completion where no further legal basis exists. Contract, payment, invoice and project data is retained for the contract and applicable statutory periods. Security and rate-limit records are retained for substantially shorter, purpose-limited periods.
13. Rights, complaints and automated decisions
Subject to legal requirements, individuals have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn for the future. Requests may be sent to hello@paularyo.com.
Individuals may complain to a data protection supervisory authority, particularly at their habitual residence, place of work or place of the alleged infringement.
No solely automated decision with legal or similarly significant effects under Art. 22 GDPR is made. Automated audit analysis supports recommendations; larger project approvals are not made solely by automation.
14. Security and version
Paularyo uses appropriate technical and organisational measures to protect data.
This policy is updated when services, processes or legal requirements change.
Last updated: 19 July 2026.