Privacy Policy
In accordance with GDPR (EU) 2016/679 — Datenschutzerklärung gemäß DSGVO. Last updated: March 2026.
1. Who is responsible for this website?
The person responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Juan Garizabalo BadilloEmdenerStrasse 42
10551 Berlin, Germany
Email: see Impressum
This is a personal portfolio website operated by an individual, not a company. No Data Protection Officer (DPO) is required under Art. 37 GDPR.
2. Hosting & server logs
This website is hosted by Vercel Inc. (340 Pine Street, Suite 701, San Francisco, CA 94104, USA). When you visit any page, Vercel's servers automatically log the following data for security and technical operation:
- IP address (anonymised after processing)
- Date and time of the request
- URL and HTTP status code
- Browser type and operating system
- Referrer URL (page you came from)
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in ensuring the technical stability and security of the website. This data is not used to identify individuals and is deleted within a short retention period.
Vercel processes data under Standard Contractual Clauses (SCCs) in compliance with Art. 46 GDPR. For more information, see Vercel's Privacy Policy .
3. Web analytics (Vercel Analytics)
This website uses Vercel Analytics, a privacy-first analytics tool provided by Vercel Inc. It collects aggregated, non-personal usage data, specifically:
- Page views and navigation paths
- Country and region (derived from IP — IP is not stored)
- Device type, operating system, and browser
- Referrer URL
Vercel Analytics does not:
- Use cookies or local storage to track you
- Build personal profiles or cross-site user profiles
- Track individual users across sessions
- Share data with advertising networks
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding aggregate website usage to improve content. Because no personal data is stored and no cookies are placed, prior consent is not required.
4. Web fonts (served locally)
This website uses the typeface Hanken Grotesk, which is served directly from this server. No request is made to Google Fonts, Adobe Fonts, or any other external font provider.
This means your browser never connects to a third-party server to load fonts, and no data (such as your IP address) is transmitted to font providers. This approach is specifically recommended by German data protection authorities (see LG München I, Az. 3 O 17493/20).
5. Cookies & tracking
This website does not use:
- Tracking or advertising cookies
- Session or persistent cookies of any kind
- Third-party tools such as Google Analytics, Meta Pixel, or Hotjar
- Retargeting or behavioural advertising technologies
No cookie banner is displayed because no consent-requiring cookies are used. The only data processing that takes place is described in sections 2 and 3 above, both of which are based on legitimate interest and require no consent under GDPR.
6. Contact by email
If you contact me by email, the information you provide (name, email address, and the content of your message) will be stored and used solely to respond to your enquiry. This data is not shared with third parties, not used for marketing, and is deleted once the communication is no longer necessary.
Legal basis: Art. 6(1)(b) GDPR (processing necessary for the performance of a contract or pre-contractual steps) or Art. 6(1)(f) GDPR (legitimate interest in responding to your message).
7. Links to external websites
This website contains links to external sites (e.g. LinkedIn, Instagram, the EU ODR platform). When you follow these links, their respective privacy policies apply. I have no control over and accept no responsibility for the content or data practices of third-party websites.
8. Your rights under GDPR
As a data subject under the GDPR, you have the following rights:
Right of access (Art. 15)
You have the right to obtain confirmation of whether personal data concerning you is being processed, and if so, to receive a copy of that data.
Right to rectification (Art. 16)
You have the right to request correction of inaccurate personal data concerning you without undue delay.
Right to erasure — "Right to be forgotten" (Art. 17)
You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent on which processing is based.
Right to restriction of processing (Art. 18)
You have the right to request that processing of your data be restricted under certain circumstances (e.g. while contesting the accuracy of the data).
Right to data portability (Art. 20)
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your data in a structured, commonly used, machine-readable format.
Right to object (Art. 21)
Where processing is based on legitimate interest (Art. 6(1)(f)), you have the right to object at any time. Processing will cease unless compelling legitimate grounds that override your interests can be demonstrated.
To exercise any of these rights, please contact me at the address listed in the Impressum. I will respond within 30 days as required by Art. 12 GDPR.
9. Right to lodge a complaint
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR. The competent supervisory authority for this website (based in Berlin) is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)Friedrichstr. 219
10969 Berlin, Germany
www.datenschutz-berlin.de
This does not affect your right to take legal action in the courts.
10. Changes to this privacy policy
I may update this privacy policy from time to time to reflect changes in technology, law, or the services offered on this website. The date at the top of this page indicates when the policy was last revised. I encourage you to review this page periodically.