Data Protection
Privacy Notice (GDPR)
This notice explains how econworks GmbH processes personal data on econ.works / econworks.de, in line with the EU GDPR.
Last updated: September 4, 2026
Controller
econworks GmbH
Schleiermacherstraße 10, 64283 Darmstadt, Germany
Contact: hello@econ.works
Data protection inquiries: Please contact us using the details above.
No DPO is required under Sec. 38 BDSG at present.
1. Hosting & Server Logs
Our Website is hosted by Vercel Inc. As our processor, Vercel processes server log data (e.g., IP address, user-agent, URL, timestamp) to deliver and secure the service.
Legal basis: Art. 6(1)(f) GDPR (legitimate interests in secure, error-free operation)
Recipients: Vercel Inc. (processor) incl. listed sub-processors
International transfers: US – covered by the EU-US Data Privacy Framework (where certified) or Standard Contractual Clauses
Retention: We only use log data for troubleshooting and security; hoster-side retention may apply
We run no reach measurement and no performance telemetry. No analytics script loads, and no request leaves this website's own domain when you view a page.
2. Contact form
When you send us a message using the contact form on this website, we process the data you provide — your name, your email address, your company (optional) and the content of your message — in order to respond to your enquiry.
Legal basis: Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract) and Art. 6(1)(f) GDPR (our legitimate interest in responding to business enquiries)
Recipients of your message: see 2.1 below, the delivery path and the mail path. The rate limit in 2.2 involves no other provider and never receives your message.
Retention: Your message stays in our team mailbox for as long as we need it to handle your enquiry and any business relationship arising from it — under our ordinary business-correspondence practice. Statutory retention periods remain unaffected.
2.1 Email delivery via Resend
The form does not open your own email program. When you submit it, our server sends your name, email address, company (if given) and message as one email to our team mailbox, hello@econ.works, through Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA), with your address as the reply-to. Resend stores message content and delivery logs for 30 days on its servers in the USA, regardless of the sending region.
The form also carries two signals used only to recognise automated submissions: a hidden field that a person never fills, and the time the form was open. If either signal indicates an automated submission, the message is still delivered, with a warning in the subject line, so that a genuine enquiry is never lost. Neither signal is shown to you or stored.
Mail path: the domain econ.works receives mail through Cloudflare Email Routing (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA), which forwards it to our mailboxes on Microsoft 365 (Microsoft Ireland Operations Ltd., One Microsoft Place, Dublin 18, Ireland). Both act as processors; nothing is stored by the website itself.
Legal basis: Art. 6(1)(b) GDPR (your enquiry); Art. 6(1)(f) GDPR for the abuse signals
Recipients: Plus Five Five, Inc. (Resend), Cloudflare, Inc. and Microsoft Ireland Operations Ltd. (processors)
International transfers: US – Standard Contractual Clauses in Resend's data processing agreement, and the EU-US Data Privacy Framework where Resend is certified; Cloudflare and Microsoft via DPF or SCCs, Microsoft 365 within the EU Data Boundary where available
2.2 Abuse prevention: submission rate limit
Our server counts submissions per IP address, in memory, for 60 seconds, and refuses more than five in that window. The counter lives on our server only, is not sent to any other provider, and is discarded after the window.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the website)
3. Scheduling via Microsoft Bookings (only if used)
If you book a meeting, you are redirected in a new browser tab to our Microsoft Bookings page. Microsoft processes the data you enter there (e.g., name, email, appointment preferences) to schedule the appointment. Because the page opens on Microsoft's own domain, no Bookings cookies are set on this website.
Legal basis: Art. 6(1)(b) GDPR
Recipients: Microsoft Ireland Operations Ltd. / Microsoft Corporation (processor)
International transfers: US – via DPF (if certified) or SCCs; the Microsoft 365 EU Data Boundary applies where available
4. Cookies, Local Storage & Consent
We set no cookies and use no browser storage. We run no analytics. Should we ever embed a third-party service that stores or accesses information on your device beyond what is strictly necessary, we will ask for your consent first.
Sec. 25 TDDDG (formerly TTDSG): not engaged, because this website neither stores information on your device nor reads any. The server log data described in section 1 rests on Art. 6(1)(f) GDPR.
Consent: We ask for none, because no storage or access takes place. Should that change, you will be able to withdraw a consent you have given at any time with effect for the future, and we will explain how here.
5. Third-party Resources
This website loads no resource from any third party: no fonts from a content-delivery network, no analytics, no embedded videos or maps, no chat widget. Every script, style, font and image is served from our own domain, and our Content-Security-Policy prevents the browser from loading anything else. This website has no consent banner, because there is nothing to consent to.
The only ways your browser contacts another provider are links you click: the appointment page on Microsoft Bookings (section 3), our product site maxcelerate.ai, LinkedIn, and the supervisory authority's site. Each opens in a new tab and receives only our domain as the referrer. Our link to LinkedIn is an ordinary hyperlink, not a social-media plug-in: nothing is transmitted to LinkedIn until you click it and leave this website.
6. Your Rights
You have the rights under Art. 15–22 GDPR:
- Access to your personal data
- Rectification of incorrect data
- Erasure of your data
- Restriction of processing
- Data portability
- Objection to processing
You may lodge a complaint with your supervisory authority. For Hesse, Germany: Hessian Commissioner for Data Protection and Freedom of Information –https://datenschutz.hessen.de
7. Security Measures
We implement appropriate technical and organisational measures (Art. 32 GDPR), including TLS encryption, access controls, logging, and deletion routines.
8. Changes to this Notice
We update this privacy notice as soon as technical or legal changes make it necessary.