Joel A. A. Bredaprivacy policy
Privacy Policy
1. Controller
The controller responsible for data processing on this website (Art. 4 No. 7 GDPR) is:
Melanie Breuer c/o Block Services Stuttgarter Str., 106 70736, Fellbach, Germany Email: hi@jbreda.dev Legal notice: https://docs.jbreda.dev/imprint.php
2. General Information on Data Processing
This website is a personal portfolio. The scope of personal data processing is deliberately kept minimal. Below you will find a transparent overview of which data is processed, and in what context.
Personal data is only collected where technically necessary or where consent has been given. Data is not shared with third parties beyond what is described here.
3. Hosting and Server Log Files
This website is operated by the following hosting provider:
Hostinger International Ltd.
61 Lordou Vironos Street, 6023 Larnaca, Cyprus
The servers hosting this website are located in the data center in Frankfurt am Main, Germany.
The hosting provider processes data on our behalf (data processing agreement, Art. 28 GDPR) that arises from the use of this website.
Every time this website is accessed, the server automatically collects so-called server log files, which your browser transmits automatically. This includes:
- IP address (typically shortened/anonymized or deleted after a short period)
- Date and time of the request
- File/URL requested
- Referrer URL
- Browser and operating system used
Important note: This site hosts JavaScript files that may also be embedded by third-party websites via <script src="...">. If a visitor loads such a third-party site that embeds this script, their browser will load the script file directly from this server. In that case, their IP address is technically processed in the server log files as well — regardless of whether they have ever visited this portfolio website directly.
Log file processing serves to ensure stable operation, deliver requested content, and maintain IT security (e.g. detection of attacks or abuse).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and functional website operation).
Retention period: Log files are typically deleted or anonymized after 7 days, unless further retention is required to investigate a security incident.
4. Contact Form
If you use the contact form on this website, the following data is processed:
- The data you enter (e.g. name, email address, message text)
- Your IP address
Purpose of IP storage: The IP address is processed exclusively for rate-limiting purposes — i.e. to prevent abuse (such as automated spam or mass submissions) and to ensure the form functions reliably.
Legal basis:
- Processing your inquiry: Art. 6(1)(b) GDPR (pre-contractual/inquiry-related communication) or Art. 6(1)(f) GDPR (legitimate interest in communicating with inquirers)
- IP storage for rate-limiting: Art. 6(1)(f) GDPR (legitimate interest in abuse prevention)
Retention period: The IP address is automatically deleted after 12 hours. Form data (name, message) is deleted once the purpose of the inquiry has been fulfilled and no legal retention obligations apply.
5. Global Rate-Limiting and Bot Protection
To protect this website against automated abuse (e.g. scraping, mass automated requests, or bot traffic), a rate-limiting mechanism applies across the entire site. If more than 10 requests are made from the same IP address within a 60-second window, further access is temporarily blocked and the visitor is redirected to a verification page, where they must complete a CAPTCHA to confirm they are a human visitor before continuing.
Rate-limit counting
To determine whether this threshold has been reached, your IP address is processed as follows:
- Your IP address is not stored in plain text. Instead, it is immediately converted into a one-way SHA-256 hash, which is used as a counter identifier.
- For each request, a timestamp is added to this counter. Timestamps older than 60 seconds are automatically discarded whenever the counter is next updated.
- Once the number of recent timestamps exceeds the limit, the visitor is redirected to the CAPTCHA page.
Purpose: Protecting the website's availability and integrity by distinguishing human visitors from automated bots.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and ensuring stable, secure operation of the website).
Retention period: Because the counter only ever looks at the last 60 seconds, timestamps older than 60 seconds no longer have any effect and are removed the next time the counter is written to. The underlying hash is not reversible back into your IP address.
CAPTCHA verification (hCaptcha)
If you are redirected to the verification page, the CAPTCHA challenge shown there is provided by the third-party service hCaptcha, operated by:
Intuition Machines, Inc. (hCaptcha) 2100 Geng Road, Suite 210 Palo Alto, CA 94303, USA
While completing the CAPTCHA, hCaptcha may process the following data:
- Your IP address
- Browser and device information (e.g. user agent, screen resolution)
- Interaction data used to distinguish humans from bots (e.g. mouse movement, timing)
This may involve a transfer of personal data to hCaptcha's infrastructure, which can include processing outside the European Economic Area (e.g. in the United States). Where such a transfer occurs, it is based on Standard Contractual Clauses (Art. 46 GDPR) or another appropriate safeguard provided by hCaptcha.
Purpose: Verifying that a rate-limited visitor is a human, not an automated bot.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse prevention). The CAPTCHA is only shown to visitors who have exceeded the rate limit; it is not loaded during ordinary browsing.
Retention period: Data processed by hCaptcha itself is subject to hCaptcha's own retention practices; further information is available in hCaptcha's Privacy Policy.
Verification cookie
Once you successfully complete the CAPTCHA, a cookie is set on your device so you do not have to repeat the CAPTCHA on every page for a short period afterwards. This cookie contains a cryptographic signature and a hash of your IP address, but not your IP address itself, and no other personal or tracking data.
Purpose: Avoiding repeated CAPTCHA challenges for visitors who have already been verified.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing a functional website without unnecessary friction for verified visitors).
Retention period: This cookie automatically expires 15 minutes after it is issued and is not renewed automatically; after expiry, you may be asked to complete the CAPTCHA again if the rate limit is triggered.
6. Personalized Greeting ("Terminal") and Cookies
This website includes an interactive terminal element on the landing page. After you give explicit consent via the cookie consent banner, your approximate city is determined based on your IP address (IP-based geolocation) and displayed in the terminal as "Hello, {City}!".
A cookie is used for this feature to store your consent decision and, where applicable, the result for the duration of your session.
| Cookie purpose | Necessary? | Legal basis |
|---|---|---|
| Storing your consent decision | Yes | Art. 6(1)(c) GDPR in conjunction with applicable ePrivacy / cookie consent law |
| Displaying "Hello {City}!" (IP-based geolocation) | No, personalization only | Art. 6(1)(a) GDPR (consent) |
Withdrawal: You may withdraw your consent at any time with future effect by clearing your cookies or resetting your browser's site settings for this website. Processing carried out prior to withdrawal remains lawful.
Without consent: If consent is not given, the website functions fully and only the personalized greeting is omitted.
7. No Disclosure to Third Parties
Your personal data is not shared with third parties for advertising, marketing, or other purposes. The only exception is the hosting provider named in Section 3 and CAPTCHA service provider named in Section 5, acting as a data processor.
8. Your Rights as a Data Subject
Under applicable law, you have the right at any time to:
- Access the personal data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Withdraw consent previously given, with future effect (Art. 7(3) GDPR)
To exercise these rights, contact us using the details provided in Section 1.
9. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data e.g. the authority responsible for your place of residence, or the authority responsible for us:
The State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, LDI NRW) Kavalleriestraße 2-4, 40213 Düsseldorf, Germany https://www.ldi.nrw.de
10. SSL/TLS Encryption
For security reasons, we use SSL/TLS encryption which can be recognized by the "https://" prefix in the URL.
11. Changes to this Privacy Policy
This privacy policy is updated as needed to remain compliant with current legal requirements or to reflect changes to the website (e.g. new features). The version published on this page at any given time applies.
Last updated: 09.09.2026