RequestChange

Privacy notice

Controller

The controller responsible for processing personal data on this website is:

Marcus Görner · Request Change
An der Beermahd 12 · 82229 Hechendorf am Pilsensee · Germany
Telephone: +49 177 773 1187
Email: marcus.goerner@requestchange.eu

Scope and principles

This notice explains how personal data is processed when you visit the website or contact us. We do not use analytics, marketing or profiling services and do not make automated decisions within the meaning of Article 22 GDPR.

Hosting, delivery and security logs

The website is provided by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Server functions for the contact form are assigned to the Frankfurt region (fra1). Use of this region does not mean that all operational, security and contractual data is processed exclusively in the EU.

When the website is accessed, Vercel processes in particular the IP address, time, requested URL or resource, technical request and browser information, response status, and firewall and security signals. This processing is necessary for secure delivery, error analysis, abuse prevention and website stability. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the website.

We do not write form contents to runtime logs. On the Vercel Pro plan, runtime logs are normally available for one day. Firewall events and temporarily blocked IP addresses are processed for the periods applicable to the service and the relevant security rule and are then deleted or aggregated.

Processing on our behalf is governed by the Vercel Data Processing Addendum applicable to Pro customers, which becomes binding with the service agreement under its terms. Processing in, or access from, the United States cannot be excluded. Vercel is certified under the EU-US Data Privacy Framework; the contract also includes EU Standard Contractual Clauses.

Bot and abuse protection

To protect the contact form, we use Vercel BotID Basic, an unobtrusive browser challenge, and a Vercel WAF rule limiting repeated requests. BotID runs JavaScript when the page is loaded and sends technical challenge information in request headers with the protected request. The WAF processes IP and request metadata in particular to identify automated or unusually frequent access.

The purpose is to prevent spam, attacks and abusive use. The legal basis is Article 6(1)(f) GDPR. The check is not used for advertising or to create marketing profiles, and no visible CAPTCHA is used.

Contact form and other communications

When you use the form, we process your name, business email address, optional company, message, language, source page and time of receipt. Required fields are marked in the form. Providing the data is voluntary; without a name, email address and message, we cannot meaningfully respond to the enquiry.

The data is processed to handle the enquiry and to take steps towards a business relationship. Where you are the prospective contracting party and processing is necessary to take pre-contractual steps at your request, the legal basis is Article 6(1)(b) GDPR. Enquiries made on behalf of a business and general business enquiries are processed under Article 6(1)(f) GDPR and our legitimate interest in efficient communication.

The Vercel function sends the enquiry over encrypted SMTP to our existing Google Workspace mailbox. There is no separate lead database and no automated confirmation to the sender. The message is, however, stored as an email in the Google Workspace mailbox. Under Google’s current online terms, the contracting entity for German billing addresses is Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; the agreement applicable to our account remains authoritative. Technical services may be provided by Google LLC and other subprocessors.

Google’s current standard agreement incorporates the Cloud Data Processing Addendum. For transfers of personal data from the EU or EEA to the United States, Google uses the EU-US Data Privacy Framework, under which Google LLC is certified. Where no adequacy mechanism applies to another restricted third-country transfer, the Cloud Data Processing Addendum provides for the applicable EU Standard Contractual Clauses. The agreement applicable to our account remains authoritative.

We regularly delete enquiries that do not lead to a business relationship after six months. If a contractual relationship arises, or correspondence is subject to statutory evidence or retention duties, deletion takes place only after the applicable period has expired. Following a deletion instruction, Google removes the affected data from its systems as soon as reasonably practicable and generally within no more than 180 days under the Cloud Data Processing Addendum, unless storage is required by law.

If you contact us directly by email or telephone, we process the information you provide for the same purposes and on the same legal bases.

Cookies, browser storage and analytics

The language is determined by the /de or /en URL path. Request Change does not set its own language cookie. We do not use analytics, marketing or tracking cookies and do not store advertising identifiers in local or session storage. Technically necessary security checks are used solely to protect the website function requested. Section 25 TDDDG applies to any storage of, or access to, information on an end device.

Fonts and media

Instrument Sans and all media currently used are served locally by this website. Loading the font or visible media does not create a connection to Google Fonts, video platforms or external content delivery networks.

Your rights

Subject to the statutory requirements, you have the right to access, rectification, erasure, restriction of processing and data portability. To exercise your rights, it is sufficient to contact us at the email address stated above.

Right to object under Article 21 GDPR

Where we process data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.

Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority. The authority responsible for private-sector organisations based in Bavaria is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

Last updated: July 2026