What happens to your data when you visit this website.
This website is deliberately data-frugal. We do not make money from your data, so we do not collect any.
What does occur: the technical connection data every web server needs in order to deliver a page, and whatever you actively send us when you write to us. Both are described in detail below.
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
Check whether a data protection officer must be appointed (Section 38 BDSG — as a rule from 20 persons permanently engaged in automated processing of personal data) and, if so, list them here with contact details. The previous website named none.
This website is operated for us by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. When you open a page, Vercel processes the resulting technical connection data as our processor (see section 4).
The legal basis is Art. 6(1)(f) GDPR: we have a legitimate interest in providing this website reliably and securely.
This involves a transfer to the USA. Vercel Inc. is certified under the EU-U.S. Data Privacy Framework; in addition, the European Commission's standard contractual clauses apply. For details see Vercel's privacy policy.
To be clarified before launch and added here: (a) conclude or document the data processing agreement with Vercel, (b) the binding retention period for server logs, (c) the DNS/CDN provider for weareheyhey.com, (d) the email provider handling messages sent to the address above.
Each page request automatically transmits data that your browser sends and that is technically necessary to deliver the page:
The legal basis is Art. 6(1)(f) GDPR. We do not merge this data with other sources, do not build usage profiles from it and do not evaluate it for marketing purposes.
This website sets no advertising or analytics cookies and embeds no third-party cookies. A consent banner is therefore not required. Only the following is stored:
Both are strictly necessary to provide the service you explicitly requested — without them you would have to make your choice again on every page (Section 25(2) no. 2 TDDDG). For the subsequent processing we rely on Art. 6(1)(f) GDPR. You can delete both at any time in your browser settings; the website will keep working, it simply will not remember your choice.
The form on our contact page sends nothing to a server of ours. On submit, your own email client opens with a pre-filled message. Your input leaves your device only once you send that email yourself — the website itself never transmits anything to us.
If you write to us, we process your details in order to handle your enquiry and any follow-up questions. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract or its initiation; in all other cases Art. 6(1)(f) GDPR (legitimate interest in handling incoming enquiries) or Art. 6(1)(a) GDPR if you have given consent. You may withdraw consent at any time.
We do not pass this data on without your consent. It stays with us until you ask us to delete it, withdraw your consent, or the purpose ceases to apply. Mandatory statutory retention periods — in particular under Section 257 HGB and Section 147 AO — remain unaffected.
All fonts used on this website (Biennale and Poppins) are served exclusively from our own server. No connection to Google Fonts or any other font service is established, and your IP address is not transmitted to anyone for this purpose. The previous website embedded Google Fonts — that ended with the relaunch.
This website embeds neither a map service nor an analytics tool nor a captcha. Google Maps, Google reCAPTCHA and the analytics functions of the previous website were removed with the relaunch and not replaced.
We embed no social media plugins, like buttons, tracking pixels or embedded posts. The references to Instagram, TikTok, YouTube, Twitch and LinkedIn are plain hyperlinks. Only when you click one does the respective provider receive data about you; from that moment their privacy policy applies, not this one.
For the protected media kit area (access via a password or a personal link) a strictly necessary cookie will be set. It remembers a successful unlock for a limited time — otherwise you would have to enter the password again on every page. It serves that purpose only, is not evaluated and is not shared with third parties (Section 25(2) no. 2 TDDDG, Art. 6(1)(f) GDPR). This section describes a planned feature; once it goes live, it will appear here without this notice.
We disclose personal data only where this is necessary to perform a contract, where we are legally obliged to do so, where a legitimate interest under Art. 6(1)(f) GDPR exists, or where you have consented. We engage processors only on the basis of a data processing agreement. The processor involved in this website is our host (section 3).
Unless a more specific period is stated in this policy, your personal data stays with us until the purpose of processing ceases to apply. If you assert a legitimate request for erasure or withdraw your consent, we delete the data unless other legally permissible grounds for storing it exist — for instance retention periods under tax or commercial law. In that case we delete once those periods expire.
You have the following rights vis-à-vis us:
An informal message to privacy@weareheyhey.com is enough. Access is free of charge.
Where we process data on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to that processing; this also applies to profiling based on those provisions. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Where your data is processed for direct marketing purposes, you have the right to object at any time; your data will then no longer be used for that purpose.
You have the right to lodge a complaint with a data protection supervisory authority — in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany (www.baden-wuerttemberg.datenschutz.de).
This website is delivered exclusively over a TLS-encrypted connection (recognisable by the “https://” in the address bar). Transmission between your browser and our server therefore cannot be read by third parties. Please note that data transmission over the internet — for example when communicating by email — can nonetheless have security gaps; complete protection against access by third parties is not possible.
We update this privacy policy whenever the technology used on this website changes — for example when the protected media kit area goes live. The version published here, with the date given below, is the one that applies.
Last updated: 7 August 2026. The German version is authoritative; this English translation is provided for convenience.