1. Introduction
Protecting your personal data matters to me. This privacy notice explains which data I process on caze.eu, for which purposes, on which legal basis, and which rights you have.
Personal data means any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
Last updated: August 2026
2. Controller
The controller responsible for data processing on this website is:
Carolin Zeyher
STUDIO CAZE / FRAU CAZE
Dresdener Str. 20
10999 Berlin
Germany
Phone: +49 176 72977816
Email: mail@caze.eu
Website: https://caze.eu
A data protection officer has not been appointed, as this is not legally required.
3. Your rights
You have the following rights in relation to me:
- Access to the personal data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data or completion of incomplete data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
To exercise these rights, a short message to mail@caze.eu is sufficient.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for me is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Alt-Moabit 59–61
10555 Berlin
Germany
www.datenschutz-berlin.de
4. Hosting
This website is hosted by Alfahosting GmbH, Ankerstraße 3b, 06108 Halle (Saale), Germany. Alfahosting is part of the dogado group (dogado GmbH, Antonio-Segni-Straße 11, 44263 Dortmund, Germany). The servers are located in Germany.
Alfahosting processes personal data (in particular IP addresses and server log files) on my behalf. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure, available website) and, where a contract with you is being prepared or performed, Art. 6(1)(b) GDPR. A data processing agreement pursuant to Art. 28 GDPR is in place with the host.
Further information: Alfahosting privacy policy.
5. Server log files
When you visit the website, the hosting server automatically collects data transmitted by your browser. This may include:
- IP address
- date and time of the request
- requested URL
- referrer URL
- browser type and version
- operating system
- amount of data transferred
- HTTP status code
This data is required to deliver the site, keep it running and defend against attacks. It is not combined with other data sources. The legal basis is Art. 6(1)(f) GDPR.
According to the host, IP addresses are anonymised after 24 hours (the last octet is set to zero). Log files are generally deleted after 7 days at the latest.
6. SSL/TLS encryption
The connection to this website is encrypted via HTTPS. Data you transmit cannot be read by third parties in transit.
7. Contact
There is no contact form. You can reach me by email, phone or post.
If you get in touch, I process the data you provide (for example name, email address, phone number and the content of your message) in order to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to preparing or performing a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in proper communication).
Incoming emails to mail@caze.eu pass through the host’s spam and virus filter (Mailgate / secure-mailgate.com of the dogado group). Sender address, recipient, subject and technical metadata may be checked. The purpose is protection against spam, phishing and malware. Legal basis: Art. 6(1)(f) GDPR.
I delete enquiries once the purpose has been fulfilled, unless statutory retention duties apply. Business correspondence may be stored for up to 6 or 10 years under German commercial and tax law (Section 147 AO, Section 257 HGB).
8. Newsletter (Mailchimp)
If you subscribe to the newsletter, I process your email address as well as your first and last name. Sign-up is handled via the “Mailchimp for WordPress” plugin. The data is transferred to the newsletter service Mailchimp.
Provider: The Rocket Science Group LLC d/b/a Mailchimp, a company of Intuit Inc., 2700 Coast Avenue, Mountain View, CA 94043, USA.
Registration uses the double opt-in procedure: after submitting the form you receive an email in which you confirm the subscription. Only then are you added to the mailing list. The time of registration and confirmation as well as the IP address are stored in order to document the sign-up process.
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with Section 7(2) no. 3 of the German Unfair Competition Act (UWG). You may withdraw your consent at any time — via the unsubscribe link in every newsletter email or by writing to mail@caze.eu. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Mailchimp processes the data in the USA. Intuit is certified under the EU–US Data Privacy Framework (DPF). In addition, Standard Contractual Clauses (SCCs) apply under Mailchimp’s Data Processing Addendum. Further information: Intuit Privacy Statement, Mailchimp Privacy and Mailchimp DPA.
8.1 Newsletter performance measurement
Mailchimp may use tracking pixels and clickable tracking links in HTML newsletters. This can show whether and when an email was opened and which links were clicked. This information is used to improve the newsletter. The legal basis is your consent (Art. 6(1)(a) GDPR). This analysis ends when you unsubscribe.
If you do not want this tracking, you can disable HTML/images in your email client or unsubscribe from the newsletter.
9. Cloudflare Turnstile
To protect the newsletter form against spam and automated sign-ups, I use Cloudflare Turnstile (plugin “Simple Cloudflare Turnstile”).
Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Turnstile checks whether the input comes from a human. IP address, browser and device information and interaction data may be transmitted to Cloudflare. A classic image puzzle is usually not required.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the website and newsletter against abuse and bots) and — where information is stored on or accessed from your device and this is not strictly necessary — your consent under Section 25(1) of the German TDDDG. Where Turnstile is strictly necessary for the security of the form you requested, Section 25(2) no. 2 TDDDG may apply.
Cloudflare is certified under the EU–US Data Privacy Framework. Cloudflare also relies on Standard Contractual Clauses for transfers to the USA. A Data Processing Addendum is in place. See: Cloudflare Privacy Policy.
10. Reach measurement (WP Statistics)
To statistically analyse how the website is used, I use the plugin WP Statistics. The data is stored on my own server (with the host in Germany) and is not sent to external analytics providers such as Google Analytics.
The following may be recorded:
- pages viewed
- time of the visit
- referrer
- device type, browser and operating system
- approximate geographic origin (derived from the IP address)
- a truncated or hashed IP address
The purpose is to understand which content is used and to improve the website technically and editorially. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in reach analysis on my own systems). The data is not combined with other sources in order to identify you. It is not shared with third parties.
If WP Statistics stores information on your device that is not strictly necessary, Section 25 TDDDG also applies.
11. Fonts
The website uses the typeface Work Sans. The files are hosted locally on my own server. Google Fonts and other external font services are not loaded.
12. Cookies and storage on your device
This website does not use third-party advertising or tracking cookies. There is currently no cookie banner because no marketing cookies are set.
The following storage operations may occur:
- WPML (language selection): may store the chosen language (German/English) in a cookie so that the language version is remembered. Legal basis: Art. 6(1)(f) GDPR, Section 25(2) TDDDG (necessary for the service you requested).
- Turnstile / Cloudflare: may briefly store information in the browser for bot detection (see section 9).
- WordPress: sets cookies only if you log in to the protected admin area (not for regular visitors).
You can delete or block cookies in your browser. Some functions (for example remembering the language) may then no longer work.
13. Social media links
In the footer and in a few other places I link to profiles on Instagram, Facebook and Houzz, and on the press page to YouTube videos. These are ordinary links. No social plugins, like buttons or tracking pixels of these providers are embedded in the website.
Only when you click such a link does data reach the respective provider (at least your IP address and the information that you came from this website). Subsequent processing is governed by the privacy notices of those services:
- Meta Platforms Ireland Ltd. (Facebook, Instagram): Privacy Policy
- Houzz Inc.: Privacy Policy
- Google Ireland Ltd. (YouTube): Privacy Policy
14. Recipients and processors
In addition to me as controller, the following processors or service providers may have access to personal data:
- Alfahosting GmbH / dogado GmbH — hosting, server logs, email filtering
- Intuit Inc. / Mailchimp — newsletter delivery and management
- Cloudflare, Inc. — bot protection (Turnstile)
Data processing agreements pursuant to Art. 28 GDPR are or will be in place with these providers insofar as they act as processors.
Data is not otherwise disclosed unless you have consented, a legal obligation exists, or disclosure is necessary to establish, exercise or defend legal claims.
15. Transfers to third countries
Transfers to countries outside the EU/EEA take place in the following cases:
- Mailchimp / Intuit (USA) — EU–US Data Privacy Framework and Standard Contractual Clauses
- Cloudflare (USA) — EU–US Data Privacy Framework and Standard Contractual Clauses
The USA does not have a level of data protection fully equivalent to the EU. Under certain conditions, US authorities may access data (including under the CLOUD Act and FISA 702). The Data Privacy Framework and Standard Contractual Clauses are intended to address this risk contractually and organisationally. Details are set out in the providers’ privacy notices.
Instagram, Facebook, Houzz and YouTube also regularly process data in the USA once you visit their sites via the links.
16. Retention period
I store personal data only for as long as needed for the respective purposes or as required by law.
- Server log files: generally up to 7 days (IP anonymisation after 24 hours according to the host)
- Contact enquiries: until the matter has been dealt with, then any statutory retention if applicable
- Newsletter: until consent is withdrawn; proof of sign-up may be kept for as long as legal claims remain possible
- WP Statistics data: according to internal policy, regularly aggregated or deleted once the analysis purpose no longer applies
17. Obligation to provide data
You are not legally obliged to provide personal data. Visiting the website technically involves an IP address. Without an email address I cannot send the newsletter. Without contact details I cannot reply to enquiries.
18. No automated decision-making
There is no automated decision-making within the meaning of Art. 22 GDPR and no profiling with legal effect. Turnstile only makes a technical assessment of whether an input comes from a bot.
19. Updates
I will update this privacy notice if the processing changes or legal requirements so require. The version published on this page applies.