Jan Barkhau.

Privacy.

// DocumentPrivacy Policy // BasisArt. 13 GDPR // Scopejanbarkhau.com // UpdatedMay 03, 2026
// 01 · Controller

Responsible for data processing.

Name
Jan Barkhau
Address
Burggrabenstraße 20, 68649 Groß-Rohrheim, Germany
E-Mail
jan@janbarkhau.com

Controller within the meaning of the GDPR and applicable national data protection law. The full provider information is available in the Impressum (German).

// 02 · Scope

What this policy covers.

This privacy policy applies to all surfaces under janbarkhau.com, including the marketing site and the Day Rate Check application available at /day-rate-check.

The marketing site (sections 03-05) uses no tracking, analytics or marketing tools. No cookies are set, no external fonts are loaded, and no third-party content is embedded.

The Day Rate Check (section 06) is a separate application with its own processing logic. Processing there is based exclusively on your explicit consent.

// 03 · Server log files

On every page request.

When you access this website, the hosting provider automatically records data in server log files. This is technically necessary to deliver the page and protect it from attacks. The following data is collected:

// Data collected

IP address of the requesting device, date and time of the request, name and URL of the file requested, amount of data transferred, success status of the request, browser type and version, operating system, referrer URL.

// Legal basis

Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and stable delivery of the website.

// Retention

Log files are stored for a maximum of 14 days and then deleted, unless they are required to investigate a specific attack.

// Processor

Hosting is provided by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. A data processing agreement under Art. 28 GDPR is in place. Processing takes place exclusively on servers located in Germany.

// 04 · Contact

When you write to me.

This website does not include a contact form. You can only reach me by email at jan@janbarkhau.com.

// Data collected

When you contact me by email, I process your email address, your name (if provided), and the contents of your message in order to respond to your inquiry.

// Legal basis

Art. 6(1)(b) GDPR (taking steps prior to entering into a contract, or performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding to your inquiry), depending on the contents of your message.

// Retention

Your message is deleted as soon as it is no longer needed to handle the inquiry, provided no statutory retention obligations apply - in particular commercial and tax-related obligations under § 147 AO (German Tax Code) and § 257 HGB (German Commercial Code).

// 06 · Day Rate Check

When you use the Day Rate Check at /day-rate-check.

The Day Rate Check is an online questionnaire that generates a personalised day rate report based on a few inputs and delivers it by email. The processing involves several service providers, each listed individually below.

// Data collected

Answers to the questionnaire (including field of work, experience level, current day rate, region), your email address for delivery of the report, and technical metadata (timestamps, device information).

// Legal basis

Art. 6(1)(a) GDPR (consent), and for any data transfers to third countries Art. 49(1)(a) GDPR (explicit consent for international transfer). Consent is given explicitly at the end of the questionnaire before submission.

// International data transfers

As part of the Day Rate Check, personal data may be transferred to countries outside the European Economic Area, in particular to the United States. Such transfers take place on the basis of your consent and appropriate safeguards (Standard Contractual Clauses, EU-US Data Privacy Framework). You acknowledge that the level of data protection in third countries may not match that of the EU and accept this when giving your consent.

// Retention

Questionnaire answers and your email address are stored until you withdraw your consent or request deletion, but no longer than 24 months. Aggregated, no longer personally identifiable analyses may be retained beyond that.

// Service providers used

The following processors are involved in the Day Rate Check:

Hetzner Online GmbH DE

Hosting of the application page at /day-rate-check.

Industriestraße 25, 91710 Gunzenhausen · Data centre Germany · DPA under Art. 28 GDPR

Fillout, Inc. US

Hosting the online questionnaire and storing your submitted answers.

San Francisco, USA · Data may be processed in the US · Transfer based on SCCs / EU-US Data Privacy Framework

Make.com (Celonis s.r.o.) EU / US

Workflow automation: routing your answers to the downstream services (OpenAI, PDFMonkey, Brevo).

Prague, Czech Republic · Processing may occur in the EU or US · SCCs / EU-US Data Privacy Framework

OpenAI Ireland Limited EU / US

AI-powered benchmark calculation and generation of personalised report text.

Dublin, Ireland · Onward processing by OpenAI OpCo, LLC in the US · DPA and SCCs in place

PDFMonkey SAS EU

Generating the personalised PDF report from your answers and the OpenAI output.

Paris, France · Data processed in the EU (AWS Frankfurt / Paris)

Brevo SAS EU

Delivering the finished report by email to the address you provided.

Paris, France · Data processed in the EU (France / Germany)

// Withdrawing consent

You can withdraw your consent at any time, with effect for the future, by sending an email to jan@janbarkhau.com. The lawfulness of processing carried out before withdrawal is not affected. On request, your data will be deleted across all of the systems listed above.

// 07 · Your rights

What you can request.

As a data subject, you have the following rights:

Art. 15 GDPR
Access to information about which of your data I process, for what purposes, and to whom I disclose it.
Art. 16 GDPR
Rectification of inaccurate or incomplete data.
Art. 17 GDPR
Erasure of your data, provided no retention obligations apply.
Art. 18 GDPR
Restriction of processing in specific circumstances.
Art. 20 GDPR
Data portability in a structured, commonly used, machine-readable format.
Art. 21 GDPR
Objection to processing based on legitimate interest.
Art. 7(3) GDPR
Withdrawal of consent with effect for the future, in particular for the Day Rate Check.
Art. 77 GDPR
Complaint to a data protection supervisory authority if you believe that the processing of your data violates the GDPR.

To exercise your rights, an informal email to jan@janbarkhau.com is sufficient.

// 08 · Supervisory authority

Competent data protection authority.

Authority
Hessischer Beauftragter für Datenschutz und Informationsfreiheit
Address
Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany
Web
datenschutz.hessen.de
A quick chat? Send email