Privacy notice
How Untaken handles personal data on this website, under the EU General Data Protection Regulation (GDPR / DSGVO). Last updated: 2026-10-01.
General privacy information
1. Introduction
This website is operated by: Uwe Rosche.
It is very important to us to handle our website visitors' data confidentially and to protect it in the best possible way. For this reason, we make every effort to comply with the requirements of the GDPR.
Below we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you really understand what happens to your data.
2. General information
2.1 Processing of personal data and other terms
Data protection applies to the processing of personal data. Personal data means all data with which you can be personally identified. This is, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently sitting in front of. Such data is processed when 'something happens to it'. Here, for example, the IP is transmitted from the browser to our provider and automatically stored there. This is then a processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).
These and other legal definitions can be found in Art. 4 GDPR.
2.2 Applicable regulations/laws - GDPR, BDSG and TDDDG
The scope of data protection is regulated by law. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.
In addition, the TDDDG supplements the provisions of the GDPR as far as the use of cookies is concerned.
2.3 The person responsible
The controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
You can reach the person responsible at:
Uwe Rosche
Warnemünde-Ring 30b 24576 Bad Bramstedt
hello@untaken.name
2.4 How data is generally processed on this website
As we have already established, there is data (e.g. IP address) that is collected automatically. This data is mainly required for the technical provision of the website. If we also use personal data or collect other data, we will inform you of this or ask for your consent.
You consciously provide us with other personal data.
You will find detailed information on this below.
2.5 Your rights
The GDPR provides you with comprehensive rights. These include, for example, free information about the origin, recipient and purpose of your stored personal data. You can also request the rectification, blocking or erasure of this data or lodge a complaint with the competent data protection supervisory authority. You can revoke your consent at any time.
You can find out what these rights look like in detail and how to exercise them in the last section of this Privacy Policy.
2.6 Data protection - Our view
Data protection is more than just a chore for us! Personal data has great value and careful handling of this data should be a matter of course in our digitalized world. As a website visitor, you should also be able to decide for yourself what "happens" to your data, when and by whom. That is why we are committed to complying with all legal regulations, only collect the data we need and, of course, treat it confidentially.
2.7 Forwarding and deletion
The transfer and deletion of data are also important and sensitive issues. We would therefore like to briefly inform you in advance about our general approach to this.
Data will only be passed on on the basis of a legal basis and only if this is unavoidable. This may be the case in particular if it is a so-called Data Processor and a Data Processing Agreement has been concluded in accordance with Art. 28 GDPR.
We delete your data when the purpose and legal basis for processing no longer apply and the deletion does not conflict with any other legal obligations. Art. 17 GDPR also provides a 'good' overview of this.
For further information, please refer to this Privacy Policy and contact the person responsible if you have any specific questions.
2.8 Hosting
Railway
Our website uses hosting and backend infrastructure services provided by Railway. Railway is operated by Railway Corporation, 548 Market St PMB 68956, San Francisco, California 94104, USA, with EU representation provided by Rickert Rechtsanwaltsgesellschaft mbH, Colonnaden 18, 20354 Hamburg, Germany. The service enables the hosting, deployment, and operation of web applications, APIs, databases, and other software projects. Railway provides functions for the deployment, monitoring, and management of program code and infrastructure. In the course of this, we typically process account and billing data (e.g., name, email address, billing address, payment information), application and deployment data (e.g., source code, configuration files, build and deployment logs), usage metrics (such as resource consumption and access statistics), operational and security logs, and analytical usage data. Data processing is carried out for the purpose of the technical provision, maintenance, backup, and optimization of our web services, as well as for billing and administration of the service. The legal basis for the processing is Article 6(1)(b) of the GDPR for the fulfillment of contractual obligations regarding website provision and Article 6(1)(f) of the GDPR based on our legitimate interest in the secure, efficient, and scalable provision of onlinecontent. To the extent that Railway uses cookies for functional or analytical purposes, this is done only with prior consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Personal data is transferred to the United States. The EU Standard Contractual Clauses are used as an appropriate safeguard to protect the data; details can be found in the service’s Privacy Policy. The retention period depends on the respective purpose of processing. Data is generally deleted as soon as it is no longer necessary for the stated purposes or statutory retention periods have expired; this also applies if consent has been revoked. Further information is available at: https://railway.com/legal/privacy
Supabase
We use Supabase on our website as a backend-as-a-service solution that provides functions such as database management, authentication, file storage and serverless edge functions. Supabase is operated by Supabase, Inc, 3500 S Dupont Hwy, Dover, DE 19901, United States. Supabase enables the management of user databases, the provision of login and registration functions including social login, the synchronization of data in real time and the storage and delivery of files. In particular, personal data such as email addresses and other information provided during registration or authentication, authentication data, IP addresses, usage and interaction data, uploaded files and all content managed via the database are processed. Data processing is carried out for the purpose of technical provision and security of the website, user administration, storage and synchronization of web content and for the implementation of serverless functions. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures, otherwise Art. 6 para. 1 lit. f GDPR due to our legitimate interest in the secure and high-performance operation of the website and Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG for the use of cookies or comparable technologies, insofar as consent is obtained for this. Supabase may use cookies for functional and security-related purposes; their use is only based on prior consent. Personal data is transferred to a third country (USA). Supabase relies on the EU standard contractual clauses as suitable guarantees within the meaning of Art. 46 GDPR. Data is only stored for as long as is necessary to fulfill the purpose or until consent is revoked; statutory retention periods remain unaffected by this. Further information can be found in Supabase's Privacy Policy at: https://supabase.com/privacy
2.9 Legal basis
The processing of personal data always requires a legal basis. The GDPR provides the following possibilities in Art. 6 para. 1 sentence 1:
a) The data subject has given their consent to the processing of their personal data for one or more specific purposes;
b) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
c) The processing is necessary for compliance with a legal obligation to which the controller is subject;
d) Processing is necessary in order to protect the vital interests of the data subject or of another natural person;
e) The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
f) Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
In the following sections, we will provide you with the specific legal basis for the respective processing.
3. What happens on our website
When you visit our website, we process your personal data.
We use SSL or TLS encryption to protect this data in the best possible way against unauthorized access by third parties. You can recognize this encrypted connection by the https:// or lock symbol in the address bar of your browser.
Below you can find out what data is collected when you visit our website, for what purpose this is done and on what legal basis.
3.1 Data collection when accessing the website
When you visit the website, information is automatically stored in so-called server log files. This is the following information:
• Browser type and browser version
• Operating system used
• Referrer URL
• Host name of the accessing computer
• Time of the server request
• IP address
This data is temporarily required in order to be able to display our website to you permanently and without any problems. In particular, this data is used for the following purposes:
• System security of the website
• System stability of the website
• Troubleshooting on the website
• Establishing a connection to the website
• Presentation of the website
Data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR and is based on our legitimate interest in the processing of this data, in particular our interest in the functionality of the website and its security.
Where possible, this data is stored in pseudonymized form and deleted once the respective purpose has been achieved.
If the server log files make it possible to identify the data subject, the data is stored for a maximum period of 14 days. An exception is made if a security-relevant event occurs. In this case, the server log files are stored until the security-relevant event has been resolved and finally clarified.
Otherwise, no merging with other data takes place.
3.2 Data processing through user input
3.2.1 Use of AI
Personal data of visitors to this website may be processed using artificial intelligence (e.g. for the automatic evaluation of contact forms, by means of an AI chatbot or to optimize internal processes).
In particular, contact data and form or chat content may be recorded and analyzed by AI models. The legal basis for this is Art. 6 para. 1 lit. a GDPR (if consent has been given) or Art. 6 para. 1 lit. f GDPR (legitimate interest in increasing efficiency). Data is only transferred to third parties (e.g. CRM providers or external AI service providers) if this is necessary to achieve the stated purposes. The tools used are listed in this Privacy Policy in the context of their functionality and details are provided.
3.2.2 Own data collection
We offer the following service on our website: Naming brief (free during the private alpha).
We collect the following data for this purpose:
• Name
• E-mail address
• Project details from the naming brief: product, target audience, market, competitors, budget, timeline, decision-maker roles, naming preferences
The legal basis for this data processing is Art. 6 para. 1 lit. b GDPR.
The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.
3.2.3 Contact us
a) e-mail
When you contact us by email, we process your email address and any other data contained in the email. This data is stored on the mail server and in some cases on the respective end devices. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.
b) Telephone
If you contact us by telephone, the call data may be stored in pseudonymized form on the respective end device and with the telecommunications provider used. Personal data collected during the telephone call will only be processed in order to process your request. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.
3.3 AI services
Anthropic
The Anthropic API is used on our website to provide AI-supported functions. Anthropic is offered by Anthropic PBC, 548 Market Street, PMB 64534, San Francisco, CA 94104-5401, USA. Anthropic's API enables the automated generation, processing and analysis of content as well as the integration of conversational AI solutions into internal and external workflows. In particular, user requests, responses generated by the AI, metadata such as timestamps and device information and, if applicable, data marked as critical by content recognition are processed. The purpose of data processing is to provide AI-based automation, text generation and the optimization of business and communication processes. The legal basis is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in the efficient provision and improvement of interactive content; for the use of any analysis or functionality cookies and the storage of information on end devices, consent is required in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. No cookies are currently set by the API connection. Personal data is transferred to the USA. The EU standard contractual clauses are used as guarantees for an adequate level of data protection. Personal data is only stored for as long as is necessary to achieve the stated purpose or until it is deleted following revocation or on the basis of statutory retention obligations. Further information on data protection at Anthropic can be found at: https://privacy.claude.com/en/
3.4 Audio and video conferencing
Google Meet
The Google Meet service is used on our website to conduct audio and video conferences. Google Meet is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Meet enables virtual meetings, audio and video conferences and functions such as screen sharing, live subtitling, chat and collaboration in real time. In particular, we process participants' identity data (such as name and email address), attendance data (e.g. joining and leaving times, roles in the meeting), device information and technical metrics (device type, network data such as latency and packet loss for audio/video), location data, meeting events (e.g. presentations, surveys, reports of abuse), meeting artifacts (recordings, transcripts, if activated) as well as browser and network analysis data. The data processing is carried out for the purpose of organizing and conducting online conferences and virtual collaboration, including the provision, safeguarding and analysis of the technical functionality of the meetings. The legal basis for the processing is Art. 6 para. 1 lit. b GDPR for contractual and pre-contractual purposes and Art. 6 para. 1 lit. f GDPR based on our legitimate interest in efficient, secure and modern communication. If functions such as recording or extended analyses are used, additional consent may be required in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. Google Meet may use functional and analytical cookies to ensure the stability of the connection and to analyze performance. These cookies are only set with prior consent. The legal basis for this is Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. A transfer of personal data to third countries, in particular to the USA, cannot be ruled out in the context of support or maintenance processes. Google guarantees compliance with an appropriate level of data protection by concluding EU standard contractual clauses in accordance with Art. 46 para. 2 lit. c GDPR. The data will be deleted as soon as the purpose of the processing no longer applies, consent has been revoked or statutory retention periods have expired. Further information can be found in Google's Privacy Policy: https://policies.google.com/privacy?hl=de
4. What else is important
Finally, we would like to inform you in detail about your rights and how you will be informed about changes to data protection requirements.
4.1 Your rights in detail
4.1.1 Right to information in accordance with Art. 15 GDPR
You can request information about whether your personal data is being processed. If this is the case, you can request further information on the type and manner of processing. A detailed list can be found in Art. 15 para. 1 lit. a to h GDPR.
4.1.2 Right to rectification in accordance with Art. 16 GDPR
This right includes the correction of incorrect data and the completion of incomplete personal data.
4.1.3 Right to erasure in accordance with Art. 17 GDPR
This so-called 'right to be forgotten' gives you the right, under certain conditions, to request the deletion of personal data by the controller. This is generally the case if the purpose of the data processing no longer applies, if consent has been withdrawn or the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 para. 1 lit. a to f GDPR. This "right to be forgotten" also corresponds to the controller's obligation under Art. 17 para. 2 GDPR to take reasonable steps to ensure that the data is generally erased.
4.1.4 Right to restriction of processing in accordance with Art. 18 GDPR
This right is subject to the conditions set out in Art. 18 para. 1 lit. a to d.
4.1.5 Right to data portability in accordance with Art. 20 GDPR
This regulates the basic right to receive your own data in a commonly used form and to transfer it to another controller. However, this only applies to data processed on the basis of consent or a contract in accordance with Art. 20 (1) (a) and (b) and insofar as this is technically feasible.
4.1.6 Right to object pursuant to Art. 21 GDPR
In principle, you can object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the legitimate interest of the controller in the processing and if the processing relates to direct marketing and/or profiling.
4.1.7 Right to "individual decision-making" pursuant to Art. 22 GDPR
In principle, you have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. However, this right is also restricted and supplemented by Art. 22 (2) and (4) GDPR.
4.1.8 Further rights
The GDPR contains comprehensive rights to inform third parties about whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this only applies insofar as this is possible or feasible with reasonable effort.
We would like to take this opportunity to draw your attention once again to your right to withdraw your consent in accordance with Art. 7 (3) GDPR. However, this does not affect the lawfulness of the processing carried out up to that point.
We would also like to draw your attention to your rights under §§ 32 ff. BDSG, which, however, are largely congruent with the rights just described.
4.1.9 Right to lodge a complaint pursuant to Art. 77 GDPR
You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this Regulation.
5. What if the GDPR is abolished tomorrow or other changes take place?
The current version of this Privacy Policy is dated October 1, 2026. From time to time, it may be necessary to update the content of the Privacy Policy to reflect factual and legal changes. We therefore reserve the right to amend this Privacy Policy at any time. We will publish the amended version in the same location and recommend that you review the Privacy Policy regularly.
Created with the kind support of Dieter macht den Datenschutz
6. Additional information on the naming brief
This section adds detail to sections 2.8, 3.2.1, 3.2.2, 3.2.3 and 3.3 above. It does not replace them.
6.1 What we process
When you submit the naming brief, we store your name, your email address and your answers about your company, product, audience, market and naming preferences. Please don’t include personal data of third parties unless it’s necessary. Providing this data is voluntary, but without it we cannot assess your enquiry or prepare a proposal.
The brief is stored in our database (Supabase, see section 2.8). During the private alpha, applying is free and no payment data is processed.
When you submit the brief, the page shows a reference beginning UT-. Quote it when you ask for a copy of your data or for its deletion, and we can find your brief immediately. Both requests go to hello@untaken.name.
6.2 Use of AI
To generate and evaluate name candidates, we send the content of your brief to the Anthropic API (see section 3.3). We review all AI-generated results before delivering them to you. No decisions producing legal effects concerning you, or similarly significantly affecting you, are made on a purely automated basis (Art. 22 GDPR).
This processing is carried out at your request to prepare a proposal or to perform a contract with you (Art. 6(1)(b) GDPR).
6.3 Retention
A brief that does not lead to a contract is deleted 12 months after submission. If a contract results, we delete briefs and project data 12 months after the engagement has been completed. Either way, we delete earlier if you ask us to. Invoices and other accounting records are kept for the statutory retention periods of up to 10 years (§ 147 AO, § 257 HGB).
6.4 Email provider
Our email address hello@untaken.name is hosted by Namecheap Private Email, a service of Namecheap, Inc., 4600 East Washington Street, Suite 305, Phoenix, AZ 85034, USA. When you email us, or we reply to your brief by email, your email address and the content of the messages are stored on Namecheap’s mail servers. The legal basis is Art. 6(1)(b) GDPR, or Art. 6(1)(f) GDPR for general enquiries (see section 3.2.3). A transfer of personal data to the USA cannot be ruled out; Namecheap uses the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a safeguard. More information: namecheap.com/legal/general/privacy-policy
6.5 Your right to object (Art. 21 GDPR)
Where we process your personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time, on grounds relating to your particular situation. We will then no longer process your data, unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. To object, simply email hello@untaken.name.
6.6 Cookies and tracking
These pages set no cookies, use no analytics and no advertising tools, and load no fonts, scripts or images from other companies’ servers — every file comes from this website’s own domain. Your visit is not profiled.
6.7 Competent supervisory authority
In addition to your right to lodge a complaint under section 4.1.9, you can contact the authority responsible for us:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany
www.datenschutzzentrum.de