Legal

Privacy policy

Last updated September 18, 2026

Who this is

This website is run by Hamann Sites, operated by Malte Hamann, in Madison, South Dakota, USA. I am the person who decides what happens to any information you send through this site, and I am the person who answers when you ask about it.

Email malte@hamannsites.com or call (605) 291-5949.

What I collect

Only what you type into the contact form, and only when you choose to send it. The form has five fields:

  • Name and email — required, because I need to know who you are and how to reply.
  • Business and phone — optional. Leave them blank and the form still sends.
  • Message — required. Whatever you want to tell me about the project.

That is the whole list of what you actively send me. There is no account to create, no newsletter sign-up, no profile built about you, and nothing that follows you around the site as you read it.

Two things do happen automatically at the network level, and both involve your IP address: the server that delivers this page records the request, and your browser fetches the typefaces from Google. The first is inherent to how the web works. The second is a choice I made and can reverse. Both are set out in full under Hosting, fonts and server logs below, because “I collect nothing” would be the easy claim to make and not quite a true one.

Sending the form is the consent. Nothing is transmitted until you press Send inquiry. If you would rather not use the form at all, call or email me instead — the phone number and address are above.

Why I collect it

To read your inquiry, reply to it, and if we go ahead, to do the work and send you an invoice. That is the only reason. I do not use your details for marketing, I do not add you to a mailing list, and I do not sell, rent or share them for anyone else’s advertising.

The legal basis, if you are in the EU or UK

For anything you send through the contact form, the basis is your request — you are asking me about work, and handling that request is what the data is for (GDPR Article 6(1)(b), steps taken at your request before entering a contract).

For the server logs described below, the basis is legitimate interest (Article 6(1)(f)): delivering the page you asked for and keeping the site secure. It cannot be consent, because your request reaches the server before there is any opportunity to ask you anything.

Who else sees it

Three companies are involved in getting this site to you and your message to me. None of them uses either for anything of their own — all three act on my instructions, as processors:

Cloudflare
Cloudflare hosts this site and serves it from whichever of their locations is nearest you. Every page request therefore passes through them, which means they process your IP address and the connection details listed below. Your form submission does not pass through Cloudflare — the form posts from your browser straight to Web3Forms — so Cloudflare never sees your name, your message or your contact details. Cloudflare, Inc. is based in San Francisco, USA, and acts under its published Data Processing Addendum, which incorporates the EU Standard Contractual Clauses.
Web3Forms
The contact form posts to Web3Forms, which takes the submission and emails it to me. Your name, business, email, phone and message pass through their servers. They act on my behalf as a processor.
My email provider
Once delivered, your message sits in my inbox like any other email.

Beyond that, I share your information only if the law actually requires it — a court order or a legal obligation. Not because someone asked.

How long I keep it

If we work together, I keep the correspondence and the invoice for as long as I need to for tax and accounting records — in practice several years, because that is what the tax rules expect.

If we do not work together, there is no reason for me to keep your inquiry, and you can ask me to delete it at any time. Email me and I will.

Server logs are a separate matter, and the honest answer is that I do not hold them at all. See below.

Cookies

This site sets no cookies. Not one — not for analytics, not for advertising, not for preferences, and not the “strictly necessary” kind either. It also stores nothing in your browser by any other means: no local storage, no session storage, no tracking pixels, no fingerprinting.

That is why there is no cookie banner. A consent banner exists to ask permission to put something on your device or read something already there. Since this site does neither, there is nothing to ask you about, and a banner would be decoration rather than a choice.

If that ever changes — if I add analytics, for instance — this section changes first, and a real consent request comes with it.

Hosting, fonts and server logs

Two things happen at the network level that are worth being straight about, because they involve your IP address even though no cookie is set.

Google Fonts

The page loads its two typefaces, Sora and JetBrains Mono, from Google’s font servers. To deliver a font, Google receives your IP address and basic request information. Google states it does not set cookies for font requests and does not use them to build advertising profiles, but the IP transfer does happen, and if you are in the EU or UK that transfer is the kind of thing GDPR cares about.

I can remove this entirely by serving the font files from the same server as the site. If you would rather I did, say so — it is a small change and I am happy to make it.

Hosting and server logs

This site is hosted on Cloudflare. Loading a page means your browser makes a request to their network, and that request necessarily carries:

  • your IP address;
  • the date and time;
  • which page or file you asked for;
  • the page you arrived from, if you followed a link;
  • your browser and operating system, as the user-agent string reports them;
  • whether the request succeeded, and how much data was sent.

None of this is something I switched on. It is what an HTTP request is — a server cannot send you a page without being told where to send it.

Cloudflare uses this to deliver the page, keep the site available, and block attacks and abusive traffic. Storing raw request logs is a separate, paid, opt-in feature on their platform. I have not turned it on. There is therefore no log archive of visitors that I can search, export, or connect to anything you send through the contact form — not as a matter of restraint, but because it does not exist. What Cloudflare retains for running its own network is governed by its privacy policy and by my Data Processing Addendum with them, not by me.

Because Cloudflare is a US company, this involves your data being handled outside the EU and UK. Their addendum covers that with the EU Standard Contractual Clauses, and applies the UK Addendum to UK-protected data.

If I ever switch log retention on, or add any analytics product, this section is where it gets written down, and the date at the top of the page changes.

Your choices

South Dakota does not currently have a comprehensive consumer privacy law, and this is a one-person business well under the thresholds that trigger the California, Colorado, Virginia and similar state acts. So strictly, most of those statutory rights do not apply here.

I would rather not hide behind that. Whoever and wherever you are, you can ask me to:

  • tell you what I hold about you;
  • send you a copy of it;
  • correct anything wrong;
  • delete it, unless I am legally required to keep it for tax records.

Email me and I will do it. I will not ask you to fill out a form to make a request about a form.

One limit worth stating plainly: a request about server logs is one I cannot usefully answer, because I hold none to look in.

Children

This site sells web design to businesses. It is not aimed at children, and I do not knowingly collect anything from anyone under 13. If you believe a child has sent me something through the form, tell me and I will delete it.

Security, and what happens if it goes wrong

The site is served over HTTPS, with the certificate and encryption handled by Cloudflare, so what you type into the form is encrypted in transit. I keep the number of places your details can sit deliberately small — that is the main reason there is no database behind this site, no analytics on it, and no stored logs.

No system is perfectly secure, and I am not going to claim otherwise. If there is a breach that compromises personal information, South Dakota law (SDCL § 22-40-20) requires notification within 60 days of discovery, and I will notify affected people within that window.

Changes to this policy

If what the site does changes, this page changes with it, and the “last updated” date at the top changes too. There is no archive of old versions — ask me if you need one.

Contact

Questions about any of this go to malte@hamannsites.com, or call (605) 291-5949. A real person reads it.