Legal
Privacy Policy
This is a convenience translation of our German privacy policy; the German version is the legally binding text.
This website deliberately works without cookies, without tracking, and without analytics services. Below, we explain which data is nevertheless processed for technical reasons when you use the site, and what rights you have.
1. Controller
The controller within the meaning of the GDPR is:
Alhomam Chalabi
routinefrei (sole proprietorship)
Ahrensburger Str. 46b
22041 Hamburg
Email: moin@routinefrei.de
2. Hosting (Cloudflare)
This website is delivered via Cloudflare Pages, a service provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you access the website, Cloudflare processes technically necessary connection data (in particular your IP address, the date and time of access, the volume of data transferred, and your browser type and version) in order to deliver the website and protect it against attacks.
The legal basis is our legitimate interest in providing the website securely and reliably (Art. 6(1)(f) GDPR). A data processing agreement in accordance with Art. 28 GDPR is in place with Cloudflare. Any transfer to the USA takes place on the basis of the EU-US Data Privacy Framework, under which Cloudflare is certified, together with supplementary standard contractual clauses. For more information, see the Cloudflare privacy policy.
3. No cookies, no tracking
This website sets no cookies, uses no analytics or marketing tools, and embeds no content from third-party servers. Even the fonts we use are served locally from our own hosting, so there is no connection to Google Fonts or comparable services. For this reason, this website does not require a cookie banner.
4. Contact by email
If you contact us by email, we process the data you provide (name, email address, content of your message) in order to respond to your inquiry. The legal basis is Art. 6(1)(b) GDPR (initiation or performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding to your inquiry).
Your data is deleted as soon as it is no longer required to handle your inquiry and no statutory retention obligations (for example, under commercial or tax law) apply.
5. AI chat assistant
On this website, we offer an AI-powered chat assistant and already label it clearly as AI on a voluntary basis. The relevant transparency obligations under Art. 50 EU AI Act apply from 2 August 2026. The chat only starts once you actively open it and send a message. No cookies are set in the process; your conversation history is held only temporarily in your browser and is discarded when you close the page.
To generate responses, your message is transmitted to and processed by Cloudflare's Workers AI service. Cloudflare processes the input solely to provide the response and, according to its own statements, does not use it to train the models. The legal basis is our legitimate interest in providing simple initial information (Art. 6(1)(f) GDPR). Please do not enter any sensitive personal data in the chat.
On the "Live Demo" page (routinefrei.de/demo), you can enter sample text to try things out. This text is transmitted to Cloudflare's Workers AI for analysis and is not stored permanently. Here too, please do not enter any real personal or sensitive data.
On the "Integrations" page (routinefrei.de/integrationen), you can try an AI assistant that demonstrates how the AI would connect to typical applications (such as calendars, shops, or invoices). Your input is transmitted to Cloudflare's Workers AI for this purpose. The applications shown are only simulated in this demo (sample data); there is no connection to real accounts or systems, and your input is not stored permanently. Here too, please do not enter any real personal or sensitive data.
If you leave your name and contact details through a contact form on this website, including the form in the chat, we store this information (name, email address or phone number, message) in order to handle your inquiry and get in touch with you. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures); for other general inquiries, it is our legitimate interest in responding under Art. 6(1)(f) GDPR. The required checkbox only confirms that you have read this privacy notice; it is not consent.
Along with the inquiry, we store the time and version of the confirmed privacy notice. The lead record, including any generated category and internal suggested response, is held in a Cloudflare D1 database. Once the record is more than 180 days old, it is automatically removed from the active database by the next daily deletion run. Depending on the plan, Cloudflare may retain earlier database states for recovery through D1 Time Travel for 7 days or up to 30 days. Those recovery states are not used for ongoing handling and expire automatically; after a restore, the deletion run is repeated before the database is used again. No separate email copy of the form data is created and the data is not forwarded to an external lead-alert service. Statutory retention obligations may apply independently to business records arising from a later contractual relationship.
To speed up handling, your message is automatically categorized once after submission by Cloudflare's Workers AI (for example, as an inquiry) and given an internal suggested response. This categorization runs automatically in the background and may take a few seconds; your inquiry itself is already stored the moment you submit it. The suggestion serves solely to make our work easier. No automated decision with legal effect for you within the meaning of Art. 22 GDPR takes place; your inquiry is always decided by a person.
To protect against misuse (such as automated bulk inquiries), your IP address is transformed only inside the Worker, together with the purpose and the relevant 60-second window, using SHA-256 into a pseudonymous, window-bound check value when you use the chat, Live Demo, or contact form. Only that value, the counter, and the expiry time are stored in D1; the raw IP address is not stored there. Expired entries are deleted during subsequent API requests. The legal basis is our legitimate interest in secure operation free from misuse (Art. 6(1)(f) GDPR).
Advertising management (Meta, Google, TikTok): If you engage us to create and manage your advertising campaigns, we receive access to your advertising accounts on the respective platforms (for example, Meta, Google, TikTok) to the extent required for this purpose. In doing so, we process the data needed for the campaigns, such as campaign, account, and reporting data, solely on your behalf and in accordance with your instructions. This is based on a separate data processing agreement in accordance with Art. 28 GDPR. The privacy policies of the respective providers additionally apply to the processing within the advertising platforms themselves and to any transfers to third countries.
6. Your rights
You have the following rights regarding your personal data in relation to us:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Right to withdraw any consent granted separately at any time with effect for the future (Art. 7(3) GDPR)
To exercise your rights, a simple email to moin@routinefrei.de is sufficient.
7. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Straße 22, 7th floor
20459 Hamburg
datenschutz-hamburg.de
Last updated: July 2026