Privacy notice
In short: no cookies, nothing stored on or read from your device, no third-party services. We log which pages and sections are used, without your IP address — and you can switch that off.
1. Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
Paulo Aloisio Priess
sole trader (Empresário Individual, MEI)
Trading as PRIESS Creative Studio
Rua Pastor Oswald Hesse, 909
89015-100 Blumenau – SC
Brazil
E-mail: paulo@paulopriess.net
Phone: +55 47 99720 8831
Privacy contact: Paulo Priess, paulo@paulopriess.net.
2. Hosting and server logs
This website runs on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (location: Nuremberg, Germany). Hetzner processes data on our behalf (Art. 28 GDPR).
For every page request our front web server processes technically necessary data: IP address, date and time, requested address, referrer, browser identifier (user agent), status code and bytes transferred. The purpose is secure and stable operation; the legal basis is Art. 6(1)(f) GDPR. These access logs are rotated weekly and deleted after at most 35 days.
The application itself uses the IP address only briefly in memory to limit abuse (requests per minute) and never writes it to storage.
3. Navigation log
To understand which content is useful, we log how this website is used, on our own server. No third-party analytics service is involved. We store:
- a random visit identifier, delivered by our server with the page, which expires when you close the tab
- time, page viewed and language
- actions on the page: profile chosen, sections reached, buttons clicked, report code entered (valid/invalid), report groups opened
- the domain of the referring website (not the full address) and the device class (phone, tablet, desktop), derived from request data your browser sends anyway
We do not store: IP addresses, cookies, device identifiers or fingerprints. Nothing is stored on or read from your device, so § 25 TDDDG does not apply. Your answers to the two questions on the home page live only in the page address.
The legal basis is our legitimate interest in improving what we offer (Art. 6(1)(f) GDPR). Logs are deleted automatically after 180 days.
Objection: if your browser sends Global Privacy Control or Do Not Track, nothing is logged. The button below switches logging off for the rest of this visit. You can also object at any time by e-mail (Art. 21 GDPR).
4. Guitar Summit reports
I personally handed exhibitors at Guitar Summit 2026 a code that opens a report about their website. The report contains the results of automated checks of the company’s publicly accessible homepage and legal pages.
When a report is opened, we log that together with the visit identifier, so the conversation from the fair can continue in a useful way. The legal basis is Art. 6(1)(f) GDPR. Report data is deleted at the latest twelve months after the fair.
5. Contact by e-mail, phone or WhatsApp
When you contact us, we process your details to answer your enquiry — to take steps towards a contract (Art. 6(1)(b) GDPR) or in our legitimate interest in business correspondence (Art. 6(1)(f) GDPR). E-mail is processed by our e-mail hosting provider in Brazil.
The WhatsApp link opens the WhatsApp app (Meta). This website loads nothing from WhatsApp; WhatsApp’s privacy terms apply only once you use the link.
We delete enquiries once they are settled, unless statutory retention obligations apply.
6. Transfers outside the EU
The controller is established in Brazil and accesses e-mail and logs from there. This is based on Art. 49(1)(b) GDPR (carrying out the communication you requested) or, where an adequacy decision for Brazil applies, Art. 45 GDPR. The website data itself stays on the server in Germany.
As the processing is occasional, involves no special categories of personal data and is unlikely to result in a risk to your rights, no representative in the EU has been designated (Art. 27(2)(a) GDPR).
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
You can lodge a complaint with any data protection supervisory authority, in particular in the member state where you live, work or where the alleged infringement took place (Art. 77 GDPR). In Brazil, the Autoridade Nacional de Proteção de Dados (ANPD) is responsible.
8. No automated decisions; security
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.
Transfers are encrypted with TLS (HTTPS with HSTS); a strict Content Security Policy prevents loading content from elsewhere.