Data protection
Privacy Notice
This privacy notice provides information under Article 13 of the General Data Protection Regulation (GDPR) about how personal data is processed when the FeatureRocket website and project-inquiry form are used. Last updated: 14 July 2026.
1. Controller
FeatureRocket Web Design & Applications Thomas WieseSteinhoffweg 9
29328 Faßberg, Germany
Email: info@featurerocket.com
Phone: +49 8000 117 113
2. Website delivery and server logs
This website runs on a server administered by FeatureRocket and provided by Server4You GmbH, Hessen-Homburg-Platz 1, 63452 Hanau, Germany. The server is located in a data centre in Strasbourg, France.
The web server processes technical connection and access data required for operation. This may include IP address, access time, requested resource, referrer, browser and operating-system information, HTTP status code, and transferred data volume.
Processing is based on Article 6(1)(f) GDPR. The legitimate interest is secure, stable, and technically reliable website delivery and the detection and prevention of attacks.
Server logs are rotated weekly and four rotated generations are retained. Entries are normally deleted after no more than approximately 35 days unless a specific security incident or legal duty requires longer retention.
3. Technically necessary session and external services
The project-inquiry form uses a technically necessary, short-lived session solely for CSRF protection, the local anti-abuse challenge, and orderly form processing. It is not used for tracking or advertising.
The website uses no analytics or advertising technology, loads no externally hosted fonts, and uses neither Google reCAPTCHA nor another third-party CAPTCHA. This statement must be reviewed whenever the implementation changes.
4. Project inquiries
When the inquiry form is used, the name, email address, optional company, area of interest, subject, message, language, version of the privacy information presented, and relevant timestamps are stored to review and process the inquiry. No automatic email is initially sent.
Article 6(1)(b) GDPR is the legal basis for inquiries aimed at entering into a contract. Other business inquiries are processed under Article 6(1)(f) GDPR; the legitimate interest is the orderly receipt, review, and response to business communication.
Name, email address, area of interest, subject, and message are required for processing. Without this information, the inquiry cannot be reviewed or answered through the form. Company information is voluntary.
Spam is generally deleted after 30 days. Rejected or non-qualified inquiries are generally deleted after six months unless a documented business or legal reason requires longer retention. Qualified inquiries are converted into business contacts only through a deliberate internal decision.
5. Abuse prevention
The form is protected by server-side validation, CSRF protection, a local challenge, a honeypot, minimum completion time, short-lived rate limiting, and duplicate detection. Where an origin signal is required, the IP address is processed only briefly as a cryptographically pseudonymized, non-reversible value stored separately from the inquiry. The raw IP address and full user agent are not stored permanently with the inquiry.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is protecting the website and maintaining the availability of the inquiry channel.
6. Recipients and international transfers
Personal data is disclosed to technical service providers only where necessary for hosting, maintenance, or communication. Hosting-related processing takes place within the European Union. No third-country transfer of form data is currently intended.
7. Your rights
Subject to the applicable legal conditions, you have rights of access, rectification, erasure, restriction of processing, and data portability. Where processing is based on Article 6(1)(f) GDPR, you also have a right to object under Article 21 GDPR. The project-inquiry processing described in this notice is not based on consent.
8. Right to lodge a complaint
You may lodge a complaint with a data-protection supervisory authority. The authority responsible for FeatureRocket’s registered location is in particular the State Commissioner for Data Protection of Lower Saxony.
9. No automated decision-making
No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place in connection with the website or project-inquiry form.
10. Changes
This notice is reviewed when the website, providers, processing purposes, or legal requirements change.