Legal

Privacy Policy

Data protection notice pursuant to Art. 13/14 GDPR (EU Regulation 2016/679) and the German Federal Data Protection Act (BDSG)

Standard template — legal review required before this page is merged/published. This is a standard GDPR-compliant privacy-policy template. No bespoke clauses have been drafted or invented; entity details are filled in from Westover Labs UG's public record.

Our pledge

We don’t track you. We never have.

No analytics, no tracking pixels, no advertising cookies, no third-party marketing scripts, no fingerprinting. We don’t A/B test you, and we don’t build a profile of your visit. We set no cookies of our own.

For the whole life of this site, plain server request logs have told us everything we need to keep it fast and secure — so that’s all we use. Privacy-by-default isn’t a setting here; it’s the architecture. The precise, honest detail is below.

1. Controller

The controller responsible for data processing on this website within the meaning of the GDPR is:

Westover Labs UG (haftungsbeschränkt)
Lützowstraße 111
10785 Berlin, Germany

Represented by the managing director: James Wesley Westover
Commercial Register: Amtsgericht Charlottenburg, HRB 284781 B
Email: james@westover.dev

2. Overview of processing

This is a static marketing website. It does not use analytics, tracking pixels, advertising cookies, or third-party marketing scripts. No account creation, checkout, or user-generated content is collected through this site. The only processing that occurs is (a) hosting/delivery via our content-delivery provider, and (b) the personal data you volunteer if you contact us directly (e.g. by email).

3. Hosting

This website is hosted and delivered via Cloudflare Pages / Cloudflare's global content-delivery network (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, with EU data-processing arrangements). Cloudflare processes standard connection metadata (e.g. IP address, request timestamp, user agent) as a data processor, to the extent technically necessary to deliver the site and protect it against abuse, on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in operating a secure and reliable website. Cloudflare's own privacy policy governs this processing to the extent it acts as an independent controller for security/network purposes.

4. Server log files

Our hosting infrastructure automatically collects and stores information in server log files that your browser transmits automatically, including:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing device
  • Time of the server request
  • IP address (truncated/anonymized where technically supported)

This data is not combined with other data sources. Legal basis is Art. 6(1)(f) GDPR — our legitimate interest in the technically error-free presentation and security of our website. This data is retained only as long as necessary for these purposes and is then deleted or anonymized.

5. Contact by email

If you contact us by email, the personal data you provide (name, email address, message content) is stored by us for the purpose of processing your inquiry and in case of follow-up questions. Legal basis is Art. 6(1)(b) GDPR (pre-contractual measures / performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries), depending on the context of your message. We do not share this data with third parties without your consent, except where required by law.

6. Cookies and tracking

Cookies we set

None. This website sets no cookies of its own — not for analytics, advertising, personalization, or tracking. We do not load Google Analytics, Google Tag Manager, Plausible, Fathom, Matomo, Hotjar, Segment, Mixpanel, Meta Pixel, or any comparable analytics or advertising tag. Our fonts are the standard system fonts already on your device, so no third-party font service (e.g. Google Fonts) is contacted either.

Strictly-necessary security cookie (our CDN)

Because the site is delivered through Cloudflare’s global network, Cloudflare may set a single strictly-necessary security cookie (typically __cf_bm) to tell humans from bots and protect the site against abuse. This is a technically necessary cookie under §25(2) TTDSG and Art. 6(1)(f) GDPR (legitimate interest in secure operation); it requires no consent banner, it is not used to track you across sites, and we do not read it or use it for analytics.

Booking (Cal.com)

Our booking page (book.westoverlabs.eu) simply links to scheduling hosted on Cal.com. We do not embed Cal.com on our pages, so no third-party booking cookies are set while you are on our site. If you click through to book a call, you leave our site for Cal.com’s own domain, where Cal.com acts as an independent controller under its own privacy policy.

Gated area

A small non-public area (e.g. shared private presentations) is protected by Cloudflare Access, which sets an authentication cookie for signed-in visitors only. This does not apply to the public marketing pages covered by the pledge above.

7. Your rights as a data subject

Under the GDPR, you have the right to:

  • Request access to the personal data we hold about you (Art. 15 GDPR)
  • Request rectification of inaccurate data (Art. 16 GDPR)
  • Request erasure of your data (Art. 17 GDPR)
  • Request restriction of processing (Art. 18 GDPR)
  • Object to processing (Art. 21 GDPR)
  • Request data portability (Art. 20 GDPR)
  • Withdraw consent at any time, where processing is based on consent (Art. 7(3) GDPR)
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, contact us at james@westover.dev. The supervisory authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, BlnBDI).

8. International data transfers

Where our hosting provider processes data outside the European Economic Area, such transfers are governed by an adequacy decision or appropriate safeguards (e.g. Standard Contractual Clauses under Art. 46 GDPR), as provided in our hosting provider's data processing terms.

9. Changes to this policy

We may update this privacy policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons. The current version is always available at this URL.

10. Contact

Questions about this privacy policy or our data processing can be directed to james@westover.dev. See also our Imprint for full entity details.