Legal information · Updated 9 September 2026
Privacy.
This notice explains how personal data is processed when you visit no-notes.studio and contact NO NOTES. The redirect domain no-notes.de also uses Cloudflare.
1. Controller
NN No Notes UG (haftungsbeschränkt), represented by managing director Josia Brezing
Theodor-Storm-Str. 17, 71642 Ludwigsburg, Germany
Email: mail@no-notes.studio
Phone: +49 176 32415704
You can also use these contact details to exercise your data protection rights.
2. Website, hosting and security
The website is delivered via Cloudflare Pages and the content delivery network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare processes, in particular, your IP address, the time and destination of a request, browser and protocol information, data volumes transferred, response status and, where transmitted, the referring page. This data is needed to deliver content, analyse errors and prevent abusive access.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to provide a reliable, fast and secure company website. Delivery is not possible without the technically necessary connection data.
Through Network Error Logging headers, Cloudflare may ask supporting browsers to report failed network requests to a.nel.cloudflare.com. The configuration reviewed does not sample successful requests. These technical error reports help identify delivery problems and may contain connection and error details; they form part of the operational and error analysis described here.
Cloudflare provides server-side operational, security and aggregated usage information. We do not operate our own application server for this static website or export access logs separately through Cloudflare Logpush. No client-side service for general visitor measurement, including Cloudflare Web Analytics, is enabled on this website. We do not use marketing pixels or session replays.
Technical data is retained according to what is needed for delivery, operational and security checks, and, where applicable, legal obligations and the investigation of specific security incidents. The website does not set its own blanket deletion period for logs managed by Cloudflare. Cloudflare describes its retention criteria in Section 11 of its privacy policy.
3. Fonts, images and header trailer
Fonts, preview images and the silent header trailer are loaded as files under our own domain through the hosting described above. They do not call Google Fonts, Instagram embeds or external Stream players. The header uses an MP4 file, not R2 or an embedded third-party player.
Where your browser permits it, the trailer starts in the visible area after the initial page render. It stays silent, can be stopped using “Pause trailer” and pauses outside the visible area. A still image remains when reduced motion is enabled or autoplay is blocked. These functions present our portfolio and support accessible delivery; the legal basis is Article 6(1)(f) GDPR. Technical media buffers and browser caches serve content delivery, not recognition for advertising.
4. Project films using Cloudflare Stream
The six project films are embedded using direct Cloudflare Stream players only after you give permission. Clicking “Play film” does not itself constitute consent. Unless permission already exists, it first opens information and the choices “Allow videos” or “Not now”.
If you agree, Cloudflare receives, in particular, your IP address, browser and device information, the requested video ID and technical playback information. The player subsequently loads video and, where applicable, audio data, as well as its own scripts. Technical diagnostics may involve requests to platform.dash.cloudflare.com/sentry/envelope. Delivery also allows Cloudflare to provide server-side statistics on video minutes requested and countries. Normal project links and credits remain visible without permission.
Processing for these optional players, including their technical diagnostics, is based on your consent under Article 6(1)(a) GDPR. Where information is stored on or accessed from your device and this is not strictly technically necessary, permission also covers Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Processing without cookies may still involve personal data and access to your device.
Consent is voluntary and applies to the six project players in this browser tab until the session ends. Declining does not affect the rest of the website. When you withdraw permission, embedded players are removed and our page does not initiate further player requests. Data already sent to Cloudflare is not retrospectively retrieved; the lawfulness of processing before withdrawal is unaffected. Operational and diagnostic data already transferred is subject to the provider’s purpose-specific retention criteria, particularly operational security, error investigation and legal obligations. No additional fixed deletion period is promised here.
5. Privacy settings and device storage
External project players are blocked on your first visit. No cookie banner opens automatically. You can allow, decline or withdraw video permission at any time through a project film or here.
External project videos are blocked by default.
We store only your explicitly chosen video preference (“allowed” or “denied”) under the versioned key nn-video-consent-v1 in this tab’s Session Storage. No visitor identifier is created and no consent log is sent to a server. The choice survives navigation within the tab, generally ends when the session closes, and is overwritten when changed or withdrawn. A browser’s session restore may restore this storage; you can withdraw the choice again at any time. If storage is blocked, your choice applies only to the currently open page.
Storing and reading your choice is necessary to implement your privacy decision (Section 25(2), point 2, TDDDG). Where personal data is concerned, processing fulfils data protection obligations under Article 6(1)(c) in conjunction with Article 7 GDPR. The header’s pause state is held only in the memory of the open page.
After video permission is given, the Cloudflare Stream player stores the key stream.estimatedBandwidth in Local Storage on its own origin, separate from the website’s storage. The value describes estimated bandwidth and supports playback quality selection. Local Storage has no automatic browser-defined expiry; the value may remain until the provider deletes or overwrites it, or until you or your browser remove the website data. Withdrawal on our website stops further embedded players but does not retrospectively delete storage on the external player origin. You can remove it through your browser’s website data settings. During the playback reviewed, no cookies or additional player Session Storage entries were observed; provider changes and security checks may differ.
The normal website does not set its own tracking cookies. Cloudflare may use technically necessary security information or cookies when a security check is needed, for example to demonstrate that a check was passed. The purpose is protection against automated abuse, not advertising. The applicable bases are Section 25(2) TDDDG for necessary device access and Article 6(1)(f) GDPR for the associated security processing. Further information is available in Cloudflare’s security cookie documentation.
6. Contact
If you contact us by email or phone, we process your contact details, the content of your enquiry and any attachments you provide to respond to your message and prepare or carry out our collaboration. Please do not send particularly sensitive information unless it is necessary for your enquiry.
For enquiries concerning a contract with you, the legal basis is Article 6(1)(b) GDPR. For general enquiries and communication with business contacts, it is Article 6(1)(f) GDPR; our interest is the appropriate handling of business correspondence.
Our email service is Namecheap Private Email, provided by Namecheap, Inc., USA. It processes messages, including sender, recipient, timestamps, content and attachments, for receipt, storage and sending. There is no automatic forwarding to another email provider. The website has no contact form; the email link opens your own email application. It does not call a sending service such as Resend from the website.
We retain enquiries as long as necessary to handle them, perform a subsequent contract or establish or defend legal claims. They are then deleted unless statutory retention duties apply. Article 6(1)(c) GDPR also applies to business and tax records subject to mandatory retention. Retention and deletion depend on the document type and the relevant legal duty; not every message is kept for the same length of time.
7. Recipients, agreements and international transfers
Recipients include, in particular, the hosting, video and email providers named above and the subprocessors they use to operate their services. Processing may take place outside the EU and EEA, particularly in the USA. Exclusively European storage is not promised.
Cloudflare publishes a Data Processing Addendum and a list of subprocessors. According to these provider documents, Cloudflare is certified under the EU–US Data Privacy Framework. For transfers covered by that certification, Cloudflare identifies the corresponding adequacy framework (Article 45 GDPR); for other covered third-country transfers, the addendum provides for EU standard contractual clauses under Article 46 GDPR.
Namecheap also publishes a Data Processing Addendum with standard contractual clauses for covered processing and transfers, and a privacy policy. The published documents describe the contractual safeguards provided by each supplier; they do not guarantee EU-only processing. You can also request information about the safeguards relevant to your data, and a copy, using our contact details above.
Further disclosure takes place where required by law, for example to competent authorities. This website does not make automated decisions with legal or similarly significant effects within the meaning of Article 22 GDPR.
8. External links
Instagram, the filmmakers’ personal websites and other linked information pages are normal external links. Their content is not embedded merely by displaying our links. Only when you follow a link do you go to the relevant provider, whose privacy notice then applies. A Cloudflare film opened separately operates outside our consent controls and can be stopped by closing its tab.
9. Your rights
Subject to the GDPR, you have, in particular, rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). You can withdraw consent at any time with effect for the future (Article 7(3)).
Objection: Where we process data under Article 6(1)(f) GDPR, you can object on grounds relating to your particular situation (Article 21 GDPR). For direct marketing, you may object at any time without giving such grounds. We do not conduct direct-marketing tracking through this website.
You can also lodge a complaint with a data protection supervisory authority, particularly where you live, work or believe an infringement occurred (Article 77 GDPR). For our registered office, the relevant authority is the Baden-Württemberg State Commissioner for Data Protection and Freedom of Information: Heilbronner Straße 35, 70191 Stuttgart; information and complaints.