AI agents that actually shipFintech with real marginsCustom software, not off-the-shelfResearch that reaches productionBacking people first, slides secondReal estate with a tech lensFairways over pitch decksSkin in the game — alwaysSignal over noiseBerlin-rooted. Worldwide reach.
André Beyer

Data Protection

Privacy Policy

How I collect, process, and protect your personal data in accordance with the General Data Protection Regulation (GDPR).

1. Controller and Contact

The controller responsible for the processing of personal data within the meaning of Art. 4(7) GDPR is:

André Beyer c/o Online-Impressum.de #4691 Europaring 90 53757 Sankt Augustin GERMANY

For privacy-related enquiries you can reach me at privacy@andrebeyer.com or by using the contact details above. I have not appointed a Data Protection Officer because the statutory thresholds of § 38 BDSG are not met; the person named above is the responsible point of contact for data protection matters.

Version: August 2026

2. Legal Bases

Personal data is only processed insofar as this is necessary for the provision of the website with its functionalities and its contents as well as for the processing of the respective contractual relationship or the user's requests. The processing of personal data by me is based on the following legal bases:

Art. 6(1)(a) GDPR: For processing operations of personal data where I obtain the consent of the data subject (e.g. analytics, newsletter subscription).

Art. 6(1)(b) GDPR: The processing is necessary for the performance of a contract to which the data subject is party or for the implementation of pre-contractual measures taken at the request of the data subject (e.g. handling an enquiry about working together).

Art. 6(1)(f) GDPR: Processing is necessary for the purposes of the legitimate interests of the controller or of a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject (e.g. ensuring IT security, preventing spam and abuse of the forms, answering general enquiries).

§ 25(1) and (2) TDDDG: for the storage of, and access to, information on your end-device (cookies, local storage and similar technologies).

Where I rely on legitimate interests, you have the right to object under Art. 21 GDPR (see section 13).

3. Data I Process and from Whom

Depending on how you interact with this website, I process different categories of personal data:

Website visitors — the technical access data described in section 4, plus any data you voluntarily submit through the contact form, the work-with-me note form, or the Out of Band subscription form (see section 5).

Enquirers and contacts — the data you provide in your enquiry (name, email address, contact details, the content of your message) and any follow-up correspondence.

Subscribers — the email address you provide when subscribing to the Out of Band newsletter, plus the date and time of registration.

Chat users — the messages you send via the chat widget, a client-side session identifier, and the technical access data described in section 4 (see section 5(d).

4. Server Log Files and Technical Access Data

When you access this website, my hosting infrastructure and application logs may automatically record the following technical data:

– the IP address (or, behind a trusted reverse proxy, the client-facing IP forwarded via standard headers), – date and time of the request, – the URL requested, HTTP method, status code, and response size, – the referring URL, – browser type and version, operating system, and language settings (user-agent), – rate-limit counters keyed against the IP address (in-memory, short-lived).

Purpose: ensuring the stable and secure delivery of the website, detecting and preventing attacks and abuse (e.g. brute-force, denial-of-service, spam submissions), enforcing per-IP and global rate limits, diagnosing technical errors, and improving performance.

Legal basis: Art. 6(1)(f) GDPR — my legitimate interest in operating a secure and functional website. Where IP addresses are processed for security I balance this interest against your interests in accordance with Recital 49 GDPR.

Retention: log files are deleted within a maximum of 30 days unless an incident requires longer retention for security investigation purposes. Rate-limit counters are kept in memory only and reset automatically at the end of the rate-limit window.

5. Contact Form, Work-with-Me Note and Out of Band Subscription

a) Contact form (/contact): When you submit the contact form, I process the data you provide: full name, email address, and (optionally) company, employee count, and the content of your message. If the enquiry relates to my services, the legal basis is Art. 6(1)(b) GDPR (pre-contractual measures); otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries directed at me), together with your consent given by ticking the privacy acknowledgement.

b) Work-with-me note (/work-with-me): The note form processes your name, email address, what you are building or where we overlap, how we connected, and (optionally) a link to a product, deck, or GitHub. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) where the note relates to working together, and Art. 6(1)(f) GDPR otherwise, together with your consent given by ticking the privacy acknowledgement.

c) Out of Band subscription: For the newsletter subscription, the specification of the email address is required. The data collected is used exclusively for the newsletter dispatch and its technical administration. The legal basis is Art. 6(1)(a) GDPR. The user can revoke the consent to the storage of the data and use for the newsletter dispatch at any time; each newsletter contains a corresponding link, or you can use the other communication channels for this purpose. When registering, I store the date and time of registration in order to be able to track possible misuse.

d) Chat assistant: This website features a chat widget (bottom-right of each page). When you start a conversation, the messages you type, a client-side session identifier, and the technical access data described in section 4 are transmitted to my self-hosted workflow backend, which runs on my own servers within the European Union. To generate a response, the message content may be forwarded to one or more third-party large language model (LLM) providers acting as my processors under Art. 28 GDPR — currently OpenRouter AI Inc., which is established in the United States (see sections 9 and 10 for further details). Conversations may be reviewed for quality assurance and abuse prevention. The chat is not subject to bot mitigation; instead, it is protected by per-IP and global rate limits and an origin check.

The forms described above — with the exception of the chat widget, which is protected by per-IP and global rate limits and an origin check — are protected against automated abuse by bot mitigation (see section 8). Your submission is transmitted to my self-hosted workflow backend, which runs on my own servers within the European Union, where it triggers an internal email notification to me. No personal data from these forms is transferred to third parties. For the chat assistant, see paragraph (d).

Purpose: handling and responding to your enquiry; pre-contractual communication if you are interested in working together; sending the newsletter; answering visitor questions via the chat assistant. Retention: until your enquiry is fully resolved, plus the period required to comply with statutory retention obligations (in particular §§ 147 AO, 257 HGB — up to 6 or 10 years for tax-relevant correspondence). Subscriber data is deleted when you unsubscribe. Chat conversation logs are deleted within 90 days, unless a specific enquiry requires longer processing or statutory retention obligations apply.

6. Cookies, Local Storage and Consent Management

I use cookies and similar technologies (e.g. browser local storage) only to the extent strictly necessary for the operation of the website, or with your consent. Where consent is required, I collect it via my consent manager before activating the corresponding technology. The consent manager itself stores your choices locally on your device so that the banner does not reappear on every visit.

The technologies I use fall into two categories:

Strictly necessary (always active; § 25(2) no. 2 TDDDG): the consent record itself, origin/CSRF enforcement on the form endpoints, and the chat widget's session state, which is stored locally in your browser to resume your conversation on subsequent visits.

Analytics (only with consent; § 25(1) TDDDG and Art. 6(1)(a) GDPR): Matomo Analytics in pseudonymised mode (see section 7).

You can review and change your choices at any time via the “Privacy settings” link in the footer, by reopening the consent manager, or via your browser settings.

7. Matomo Analytics (self-hosted, consent-based)

Subject to your consent I use Matomo, a self-hosted web analytics software. Matomo runs on my own server in Germany; no usage data is transmitted to any third party.

When you visit the website, Matomo stores: the website from which you visited me, the parts of the website you visit, the date and duration of your visit, your anonymized IP address, information about the device (device type, operating system, screen resolution, language, country you are in, and web browser type) you used during your visit, and more. I process this usage data for statistical purposes, to improve the website, and to detect and stop abuse.

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG (your consent), revocable at any time in the consent manager (see section 6). Retention: aggregated reports are kept for up to 26 months.

8. Bot Mitigation (anti-abuse)

My forms are protected by open-source bot mitigation based on proof-of-work. It works entirely within your browser: your browser solves a short computational puzzle whose solution is verified against my own server. No data is transmitted to any third party, and it does not use tracking, cookies, or behavioural profiling.

Legal basis: Art. 6(1)(f) GDPR — my legitimate interest in preventing spam, scraping, and automated abuse of my forms. The puzzle is started only when you interact with the form.

9. Hosting and Third-Party Services

This website, its workflow automation backend, and transactional email dispatch all run on my own virtual private server located in a German data centre. I do not use US cloud platforms, third-party serverless platforms, or third-party managed CDNs to deliver dynamic content.

No third-party recipient receives personal data from this website except the workflow backend mentioned above, which I operate myself within the European Union, and — for the chat assistant only — the LLM providers named below.

AI model providers: To generate chat responses, my workflow backend may forward message content to third-party large language model (LLM) providers acting as my processors under Art. 28 GDPR. I currently use OpenRouter AI Inc., which is established in the United States. This provider has contractually agreed not to use customer inputs to train its foundation models. Transfers to this provider are safeguarded as described in section 10.

Web fonts and icons used on the website are self-hosted; I do not load resources from Google Fonts or comparable third-party font services. Where I link to external websites (e.g. social media profiles or partner sites), the linked operator's privacy notice applies as soon as you follow the link.

10. Transfers to Third Countries

All systems involved in operating this website run on my own infrastructure within the European Union: the website itself, the workflow automation backend, and the transactional email dispatch. I do not use US cloud platforms, third-party serverless platforms, or third-party managed CDNs to deliver dynamic content.

The only categories of recipients that may receive personal data outside the European Economic Area (EEA) are the third-party LLM provider named in section 9, which is established in the United States.

Transfers to these providers rely on the EU-US Data Privacy Framework (adequacy decision of 10 July 2023) insofar as the respective provider is self-certified, and/or on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supplemented, where appropriate, by additional technical and organisational measures.

On request I will provide further information about the specific safeguards in place for an individual transfer.

11. Storage and Erasure

I store personal data only for as long as necessary to achieve the purpose for which it was processed, or as required by law. Specific retention periods are set out in the relevant sections above. Data are deleted or anonymised:

– when the original purpose of processing has been fulfilled, – when statutory retention obligations expire, – when consent is withdrawn and no other legal basis applies, – when an objection under Art. 21 GDPR is upheld, – or when erasure is otherwise required by law.

Where erasure is not possible because of statutory retention obligations (e.g. § 147 AO, § 257 HGB), processing will be restricted accordingly and the data will be erased once those obligations have expired.

12. Data Security

I implement appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access. These measures include in particular:

– transport encryption (HTTPS/TLS) for all traffic to and from the website, – role-based access controls and the principle of least privilege, – CSRF/origin checks on state-changing endpoints, per-IP and global rate-limiting, and bot mitigation via proof-of-work, – regular patching of operating systems and dependencies, vulnerability scanning, and security reviews, – contractual security requirements imposed on any processors.

You can responsibly disclose suspected vulnerabilities to security@andrebeyer.com.

13. Your Rights as a Data Subject

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis me as the controller:

a) Right to information: You may request confirmation as to whether personal data concerning you is being processed by me. If such processing is taking place, you may request information about the purposes, the categories of data, the recipients, the planned duration of storage, the existence of a right to rectification or erasure, the existence of a right of appeal to a supervisory authority, any available information on the origin of the data, and the existence of automated decision-making, including profiling. You also have the right to be informed about appropriate safeguards pursuant to Art. 46 GDPR in connection with transfers to a third country or an international organization.

b) Right to rectification: You have a right to rectification and/or completion vis-à-vis me, insofar as the processed personal data concerning you is inaccurate or incomplete. I shall carry out the rectification without undue delay.

c) Right to restriction of processing: You may request the restriction of the processing of personal data concerning you if you contest the accuracy of the data, if the processing is unlawful and you object to erasure, if I no longer need the data but you need it for the establishment, exercise or defense of legal claims, or if you have objected to the processing pursuant to Article 21(1) GDPR and it is not yet clear whether my legitimate grounds override your grounds.

d) Right to deletion: You may request me to erase the personal data concerning you without undue delay if the data is no longer necessary, you revoke your consent, you object to the processing and there are no overriding legitimate grounds, the data has been processed unlawfully, erasure is necessary for compliance with a legal obligation, or the data was collected in relation to information society services. The right to erasure does not exist insofar as the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the assertion, exercise or defense of legal claims.

e) Right of notification: If you have asserted the right to rectification, erasure or restriction of processing, I am obliged to notify all recipients to whom the personal data has been disclosed. You have the right to be informed about these recipients.

f) Right to data portability: You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transfer this data to another controller without hindrance, provided that the processing is based on consent or on a contract and is carried out with the help of automated procedures.

g) Right of objection: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) GDPR. If the personal data is processed for the purposes of direct marketing, you have the right to object at any time; the personal data will then no longer be processed for these purposes.

h) Right to revoke the declaration of consent under data protection law: You have the right to revoke your declaration of consent at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

i) Automated decision in individual cases including profiling: You have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you, unless the decision is necessary for the conclusion or performance of a contract, is permitted by legal provisions, or is made with your express consent.

j) Right to complain to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, workplace or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

To exercise any of these rights, please contact me using the details in section 1 or write to privacy@andrebeyer.com. I will respond without undue delay and at the latest within one month of your request (Art. 12(3) GDPR).

14. No Automated Decision-Making with Legal Effect

I do not use the data collected via this website for automated individual decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22(1) GDPR.

15. Obligation to Provide Data

You are under no statutory or contractual obligation to provide personal data via this website. However, certain functions (e.g. the contact form, the chat widget, or the newsletter subscription) require at least the data marked as mandatory in the relevant form; without that data I cannot process your request.

16. Children

This website is directed at adults and professional users; it is not intended for children under the age of 16. I do not knowingly collect personal data from children. If you become aware that a child has provided me with personal data without verifiable parental consent, please contact me so that I can delete that data.

17. Changes to this Privacy Policy

I may update this Privacy Policy from time to time to reflect changes in my processing activities, technology, or applicable law. The current version is the version published on this page and is identified by the version date shown in section 1. For material changes I will provide reasonable advance notice through the website.