Privacy Policy (Datenschutzerklärung)
This page explains what personal data GridGraph processes, why, and what rights you have — describing the implementation as it actually works, not a general template.
1. Controller
The controller responsible for data processing on this website (Art. 4(7) GDPR) is:
Email: labs@luchianenco.dev
Full details are in the Impressum.
2. Hosting and server logs
The GridGraph web application is hosted on Vercel, deployed to run in the Frankfurt, Germany (fra1) region. Like most web hosts, Vercel's infrastructure processes standard server log data for every request — for example IP address, requested URL, timestamp, referrer and user agent — for operating and securing the service (Art. 6(1)(f) GDPR, legitimate interest in a reliable and secure service). GridGraph itself does not read or store these logs; they are handled by Vercel as our hosting processor under its own data processing terms. The lead database described in Section 4 runs separately, on a PostgreSQL server the controller operates on a self-managed OVH VPS (Virtual Private Server) — it is not part of Vercel's infrastructure.
3. Cookies and analytics
GridGraph uses Vercel Web Analytics to understand which pages and features are actually used — for example page views, and specific interactions such as opening the weekly-brief lead form, applying a filter, exporting a CSV, opening the score explanation, or following an official MaStR link. Per Vercel's own documentation, Web Analytics does not use cookies or any persistent identifier to track individual visitors across sessions or sites; it reports aggregated usage. GridGraph's tracked events never include your submitted work email, company name, or any other personal data — only which feature was used and, where relevant, a non-personal category (for example a Bundesland or technology name). Because no consent-requiring cookie or comparable tracking technology is used, this site does not show a cookie consent banner. If that changes, this section and the site's consent mechanism will be updated first.
4. Weekly-brief lead form
When you submit the “Receive a filtered weekly brief for your market” form, GridGraph collects:
- your work email address (required);
- your company name (required);
- the Bundesländer you select as relevant (optional);
- the technologies/asset categories you select as relevant (optional);
- which page the form was opened from, and the submission timestamp.
Purpose and legal basis. This data is used to respond to your request for a filtered weekly brief and, where a business relationship results, to prepare and send that brief — processing necessary to take steps at your request prior to a contract, or to perform one (Art. 6(1)(b) GDPR). GridGraph does not currently operate an automated subscription or mailing system: a person on our side reviews and follows up on submissions manually.
Storage. Submissions are stored in GridGraph's PostgreSQL database (hosted with OVH (self-managed VPS)). They are not published, sold, or added to any advertising or analytics product.
Recipients. Submissions are visible to GridGraph personnel who review and act on leads. No real-time notification integration is currently configured.
Retention and deletion. GridGraph retains lead submissions for as long as needed to respond to your request and, if a business relationship follows, to operate it. There is no automated deletion schedule: instead, deletion or correction requests are handled manually by the controller, who runs an internal, credential-gated database operation identifying your record by the work email you submitted. This is not a public or self-service function — it requires direct database access and is available only to the controller. To request deletion or correction, contact the email in Section 1 (see also Section 6).
5. International data transfers
The lead database itself runs on an OVH VPS the controller operates directly, and the web application is deployed to Vercel's Frankfurt, Germany (fra1) region, so lead-form data is processed within the European Economic Area as a matter of GridGraph's own infrastructure choices. Vercel Inc. is nonetheless a US-headquartered company: parts of its global network (for example edge routing, DDoS protection, or static-asset delivery) may still involve its wider infrastructure outside the EEA. Where that happens, it relies on Vercel's own applicable safeguards (such as EU Standard Contractual Clauses) as our hosting processor. GridGraph does not itself transfer lead-form data outside the EEA beyond what operating the service in this way requires.
6. Your rights
Under the GDPR, you have the right to:
- access the personal data GridGraph holds about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data deleted (Art. 17);
- restrict processing in certain circumstances (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent or object to further contact at any time, with effect for the future, without affecting the lawfulness of processing before the withdrawal;
- lodge a complaint with a data protection supervisory authority.
To exercise any of these rights, contact labs@luchianenco.dev.
Last updated: 2026-09-14