Privacy Notice
Controller
AmeisenKI UG (haftungsbeschränkt)
Stresemannstraße 123
10963 Berlin
Germany
Email: contact@ameisenki.com
Website delivery
We use Amazon Web Services (AWS) to deliver and operate this website. Amazon CloudFront processes technical request information required to deliver and protect the website. This can include the IP address, date and time, requested resource, browser and connection information, and a country derived from the request for the configured geographic access restriction. CloudFront is a global service.
Standard CloudFront access logging is disabled. We do not use the website for client-side analytics, advertising tracking, marketing pixels, visitor fingerprinting or cross-session profiling.
The legal basis for processing required to provide and secure the website is Article 6(1)(f) GDPR. Our legitimate interest is to provide a reliable and secure public business website.
Contact form
The contact form processes your name if you provide it, your email address and your message. Your email address and message are required. We also process technical HTTP information needed to receive and secure the request, such as request and connection metadata.
The request is processed by Amazon API Gateway and AWS Lambda in the AWS region eu-central-1 and is sent through Amazon Simple Email Service (SES) to the fixed address contact@ameisenki.com. The server uses website@ameisenki.com as the sender and your validated email address as the Reply-To address. The resulting email is delivered to AmeisenKI's Google Workspace mailbox.
We process contact requests to receive, assess and respond to business enquiries. Article 6(1)(b) GDPR applies where processing is necessary to take steps at your request before entering into a contract or in connection with a contractual relationship. For other business communications, the legal basis is Article 6(1)(f) GDPR and our legitimate interest in receiving and responding to business enquiries.
Contact service logs
API Gateway access logs contain the request identifier, route, response status and response size. Lambda application logs contain an event type and request identifier and, if sending fails, a generic error name. The configured application does not place your name, email address or message in these logs.
The API Gateway and Lambda log groups have a configured retention period of 30 days. This 30-day period applies only to these technical service logs; it does not apply to contact correspondence in Google Workspace.
Contact correspondence
The email delivered to the mailbox contains your email address, your optional name and message, as well as email transport metadata. We retain correspondence from new website enquiries for up to 12 months after the last exchange. We review this correspondence monthly and delete it when that period has expired. We retain it longer only where a longer period is justified by business, contractual, accounting or legal requirements, or by the establishment, exercise or defence of legal claims; the reason is documented. This is an organisational review and deletion policy, not a statement that automatic deletion is configured in Google Workspace. It is separate from the 30-day retention configured for API Gateway and Lambda logs.
Service providers and recipients
AWS provides the website, API, compute and email-delivery infrastructure. Google Workspace provides the mailbox used to receive and handle contact enquiries. Personal data is disclosed to these providers only as required for those purposes and may also be disclosed where required by law.
Cookies and tracking
The website does not use analytics or marketing cookies, third-party marketing analytics, advertising pixels, persistent visitor identifiers or client-side behavioural tracking. The contact form does not store its data in local or session storage. Your browser may independently offer to remember form entries through its autocomplete functionality.
Your rights
Subject to the applicable legal requirements, you may have rights to access, rectification, erasure, restriction of processing and data portability. You may object to processing based on Article 6(1)(f) GDPR. Where processing is based on consent, you may withdraw that consent for the future. You also have the right to lodge a complaint with a competent data protection supervisory authority.
Automated decision-making
We do not use the website or contact form for automated decision-making or profiling within the meaning of Article 22 GDPR.
Privacy enquiries
For privacy-related enquiries, contact contact@ameisenki.com.