Last updated: September 13, 2026
1. Controller
The controller responsible for the processing of personal data through this website within the meaning of the General Data Protection Regulation (GDPR) is:
Sumaia Darra Future Blick Str des 18 Oktober 10 04103, Leipzig Germany
Email: info@futureblick.com Website: futureblick.com
2. General information about data processing
We process personal data only where necessary to provide this website, maintain its security and functionality, respond to enquiries, take steps prior to entering into a contract, or comply with legal obligations.
We do not sell personal data.
We currently do not use personal data collected through this website for advertising profiles or marketing tracking.
3. Website hosting through Vercel
This website is hosted by:
Vercel Inc. 440 N Barranca Avenue #4133 Covina, California 91723 USA
The application's server-side functions are configured to run in Vercel's Frankfurt, Germany region. Static files may be delivered through Vercel's global network. The Frankfurt configuration therefore does not mean that all technical or account data is processed exclusively in Germany.
When you access this website, Vercel may process technical information required to deliver, operate and secure the website. This may include your IP address, date and time of access, requested pages or files, referrer URL, browser and device information, HTTP status codes, diagnostic information and similar technical data.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable and reliable operation of this website.
Website runtime logs are currently available to us for up to one day. Other provider records may have different retention periods, as explained in the Data retention section below.
Vercel processes this technical information as part of providing and securing the hosting service, subject to the applicable contractual and privacy terms.
4. Email hosting through Bluehost
We use Bluehost email services for our business email communication, including info@futureblick.com.
If you contact us by email, we may process your email address, name, technical email metadata and the content of your message.
Where the communication relates to entering into or performing a contract, the legal basis is Art. 6(1)(b) GDPR.
For other business enquiries, processing is based on Art. 6(1)(f) GDPR, our legitimate interest in receiving and responding to business communication.
5. Contact and project enquiry form
You may contact us through the contact or project enquiry form available on this website.
We may process your name, email address, an optional company or organisation name, and your project description or message.
We use this information only to respond to your enquiry, communicate with you, discuss a potential service or project and, where applicable, take steps before entering into a contract.
Where your enquiry relates to a potential contractual relationship, the legal basis is Art. 6(1)(b) GDPR.
For other business enquiries, processing is based on Art. 6(1)(f) GDPR, our legitimate interest in responding to enquiries addressed to us.
Information submitted through the form is currently not additionally stored in a CRM system or our own customer database. The information is transmitted to us by email for the purpose of handling your enquiry.
6. Form email delivery through Resend
We use Resend for the technical delivery of messages submitted through our website forms.
Resend is provided by:
Plus Five Five, Inc. 2261 Market Street #5039 San Francisco, CA 94114 USA
Resend may process information necessary to transmit the message, including email addresses, message content and technical metadata.
Resend processes this information on our behalf as a processor.
Regardless of the selected email-sending region, Resend states that customer data, including message content, email metadata, logs and API records, is stored in the United States.
The legal basis corresponds to the purpose of the underlying communication, in particular Art. 6(1)(b) GDPR for pre-contractual enquiries and Art. 6(1)(f) GDPR for other business enquiries.
We do not use Resend as a standalone CRM or permanent archive for project enquiries.
7. Protecting the contact form from abuse
We use Vercel's firewall to prevent excessive contact requests. Vercel processes your IP address and technical request information to count requests and temporarily block further submissions when a limit is reached.
We also use Upstash Redis, provided by Upstash Inc., to count submission attempts using pseudonymous identifiers derived from your email address and, where available, your IP address. These identifiers remain personal data and are used only to prevent abuse.
These counters expire one hour after the first counted request. We do not send your name, company name, message content, or original email or IP address to Upstash Redis.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests are preventing spam and misuse, protecting our email service, and keeping the contact form available for legitimate enquiries. If a request is blocked, you can contact us directly at info@futureblick.com.
9. Recipients and international data transfers
In connection with operating this website, personal data may in particular be processed by:
Vercel Inc., for website hosting and firewall protection; Bluehost Inc., for business email infrastructure; Plus Five Five, Inc. (Resend), for the technical delivery of messages submitted through website forms; and Upstash Inc., for short-lived contact-form abuse-prevention counters.
These providers are based in the United States and may process information outside the European Economic Area. Configuring the application's server-side functions to run in Frankfurt does not mean that all provider account, security or technical data remains exclusively within Germany or the European Economic Area.
Transfers outside the European Economic Area require an applicable transfer basis. Where an adequacy decision covers the recipient and processing, the transfer may rely on Art. 45 GDPR. For transfers requiring safeguards under Art. 46 GDPR, the providers' data-processing agreements contain provisions incorporating the European Commission's Standard Contractual Clauses (SCCs). An adequacy decision concerning a framework does not automatically cover every recipient or every transfer.
The provider agreements linked below explain their data-processing responsibilities and transfer safeguards. Bluehost uses the Newfold data-processing addendum. Upstash's agreement provides for the EU-US Data Privacy Framework where applicable and SCCs where that framework does not cover a transfer.
You can read the providers' data-processing and transfer provisions using the links below. You can also contact info@futureblick.com to request details of the safeguards applicable to your data and a copy of the relevant safeguards. We may redact unrelated confidential information while preserving the information needed to understand the protection of your data.
10. Legal bases
- Art. 6(1)(b) GDPR for pre-contractual steps and contract-related communication.
- Art. 6(1)(f) GDPR for secure website operation, technical logs, contact-form abuse prevention and responding to general business enquiries.
- Art. 6(1)(c) GDPR where processing or retention is required to comply with a legal obligation.
- We rely on Art. 6(1)(a) GDPR only where we explicitly request your consent.
11. Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected.
Enquiries that do not lead to a contractual relationship are generally deleted once they have been fully dealt with and no further communication is reasonably expected. Business enquiry emails may normally be retained for up to 12 months after the last relevant communication.
Where a contractual or business relationship is established, statutory commercial or tax-law retention requirements may require longer storage.
Vercel's runtime-log access periods are described in the hosting section above. Separate firewall, security, deployment and account records may be kept for different periods, determined by their operational purpose, the need to investigate misuse or faults, the applicable service settings and legal obligations. A request-counting window is not a promise that all associated security records are deleted when that window ends.
According to Resend's published retention policy applicable to our service, email and log data is retained for 30 days while the account is active; backups persist for seven days. Following account termination, remaining customer data is deleted within 90 days. These provider copies are separate from enquiry emails retained in our Bluehost mailbox.
Our active Upstash Redis counters expire after one hour. Provider backups, account records and operational or security logs, where retained, are separate from these counters and follow the applicable provider terms and legal obligations. We do not use Redis to archive enquiries.
The enquiry-retention criteria above apply to messages in our Bluehost mailbox. Deletion of a message from the mailbox does not establish the expiry of every provider backup or technical record; those records are subject to the email service's applicable backup, security and legal requirements. You can contact us for information about retention or to exercise your data-protection rights.
12. Your rights
Subject to the applicable legal requirements, you have the right of access under Art. 15 GDPR, rectification under Art. 16 GDPR, erasure under Art. 17 GDPR, restriction of processing under Art. 18 GDPR and data portability under Art. 20 GDPR.
Where processing is based on consent, you may withdraw that consent at any time with effect for the future.
Right to object under Art. 21 GDPR
Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation.
You may exercise your rights by contacting us at info@futureblick.com.
13. Right to lodge a complaint
You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.
For our establishment in Saxony, the relevant supervisory authority is in particular:
Sächsische Datenschutz- und Transparenzbeauftragte Maternistraße 17 01067 Dresden Germany
14. Requirement to provide information
You are generally not legally required to provide personal data through our contact form.
However, we need the fields marked as required, in particular your name, email address and project description or message, in order to process and respond to your enquiry.
Providing a company or organisation name is optional.
15. Automated decision-making
We currently do not use automated decision-making, including profiling within the meaning of Art. 22 GDPR, through this website.
16. Security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration or disclosure.
However, no transmission of information over the internet can be guaranteed to be completely risk-free.
Please do not submit passwords, API keys or highly sensitive or confidential information through general contact forms unless necessary.
17. Changes to this Privacy Policy
We may update this Privacy Policy when our website, service providers, processing activities or applicable legal requirements change.
In particular, we will update this Privacy Policy before introducing additional analytics, marketing, AI or tracking technologies.
Current business information is available in the Legal Notice.
