Legal
Privacy Policy
Last updated: June 2026
The German version of this Privacy Policy is authoritative. This English version is provided for convenience and transparency only.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Jialiang Lai
Norikerstr. 25
90402 Nuremberg
Germany
Email: leo@jialianglai.com
Phone: +49 152 59480439
Website: https://jialianglai.com
2. Overview
This Privacy Policy explains which personal data may be processed when this website is accessed or used, for which purposes such processing takes place, on which legal bases it is carried out and which rights data subjects have.
This website is a personal portfolio and professional profile website. It does not provide user accounts, an online shop, payment functionality, a newsletter system or a public comment system.
Contact is possible by email and via an embedded contact form.
This website may use technical storage functions, a consent management mechanism, web analytics and interaction analytics services, and individual services for search engine verification. Non-essential analytics, interaction and marketing services are activated only where the relevant consent has been given.
3. Legal Bases for Processing
Personal data is processed in particular on the following legal bases:
- Article 6(1)(a) GDPR: consent, especially for non-essential analytics, interaction and marketing technologies.
- Article 6(1)(b) GDPR: contractual or pre-contractual measures, where a request is to be classified accordingly.
- Article 6(1)(c) GDPR: compliance with legal obligations.
- Article 6(1)(f) GDPR: legitimate interests, in particular technical provision, security, abuse prevention, error analysis, operation of the website, handling of contact requests and basic technical functions.
For the storage of information on terminal equipment or access to information already stored on terminal equipment, Section 25 TDDDG also applies. Technically necessary storage may be based on Section 25(2) TDDDG. Non-essential cookies, tags, pixels or comparable technologies are used only with consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.
4. Accessing the Website and Server Log Files
When this website is accessed, technically necessary data is processed automatically in order to provide the website, deliver it reliably, analyse errors and prevent abuse. This may include in particular:
- page or file accessed,
- date and time of access,
- amount of data transferred,
- access status,
- browser type and version,
- operating system,
- referrer URL,
- IP address,
- requesting provider,
- technical device and connection information.
Processing is based on Article 6(1)(f) GDPR. My legitimate interest lies in the secure, stable and error-free provision of the website.
Log data is deleted or anonymised once it is no longer required for the stated purposes, unless longer retention is necessary for security or legal reasons.
5. Hosting by Vercel
This website is hosted by Vercel.
Provider:
Vercel Inc.
440 N Barranca Ave #4133
Covina, CA 91723
USA
Vercel may process technical data required for delivery, security, performance, error analysis and operation of the website. This may include IP addresses, access times, device information, request data, log data, diagnostic data and similar technical information.
The legal basis is Article 6(1)(f) GDPR. Where Vercel acts as a processor, processing is carried out on the basis of a data processing agreement pursuant to Article 28 GDPR.
Where data is transferred to the United States, appropriate safeguards such as the EU-U.S. Data Privacy Framework, standard contractual clauses or other statutory transfer mechanisms may be relevant.
Further information:
https://vercel.com/legal/privacy-notice
https://vercel.com/legal/privacy-policy
6. Domain and DNS via Squarespace
The domain of this website is managed through Squarespace.
Provider:
Squarespace Ireland Limited
Squarespace House
Ship Street Great
Dublin 8
Ireland
Squarespace is relevant in particular for domain administration, DNS-related functions and administrative domain processes. During a normal website visit, Squarespace may be indirectly involved in technical processes depending on the DNS and domain configuration.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest lies in the reliable management and accessibility of the domain.
Further information:
https://www.squarespace.com/privacy
7. Development and Technical Publication via GitHub
The source code of this website is managed via GitHub.
Provider:
GitHub, Inc.
88 Colin P. Kelly Jr. Street
San Francisco, CA 94107
USA
When this website is merely visited, no content is generally loaded directly from GitHub. GitHub is used for source code management, version control and the technical publication process of this website.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest lies in the secure and traceable development and maintenance of the website.
Further information:
https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
8. Contact by Email
If you contact me by email, I process the data you provide. This may include:
- name,
- email address,
- content of the message,
- time of contact,
- technical email metadata,
- any further information provided voluntarily.
Processing takes place solely for the purpose of handling your request. The legal basis is Article 6(1)(f) GDPR. If your request relates to a contract or pre-contractual measures, Article 6(1)(b) GDPR may additionally apply.
The data is deleted once the request has been finally processed and no statutory retention obligations or legitimate interests in further retention exist.
Please note that unencrypted email communication may involve security risks.
9. Contact Form via Tally
This website may embed a contact form provided by Tally.
Provider:
Tally BV
August Van Lokerenstraat 71
9050 Ghent
Belgium
Company number: 0776.979.007
Depending on the information entered, the following data in particular may be processed via the form:
- name,
- email address,
- message text,
- voluntary information,
- IP address and technical connection data,
- date and time of submission.
The purpose of processing is exclusively to handle your request.
The legal basis is Article 6(1)(f) GDPR; for pre-contractual or contract-related enquiries, Article 6(1)(b) GDPR may additionally apply.
Where Tally processes data on my behalf, this is carried out on the basis of a data processing agreement pursuant to Article 28 GDPR. The technical and legal setup depends on the specific Tally configuration and the provider terms applicable at the time.
Further information:
https://tally.so/help/privacy-policy
https://tally.so/help/gdpr
https://tally.so/help/data-processing-agreement
10. Consent Management, Local Preferences and Necessary Storage
This website uses a consent management mechanism. Your selections and necessary settings are stored locally in your browser so that the website can respect your decision.
The following may be stored in particular:
- your cookie and tracking selection,
- language preference,
- theme or display preference,
- technically necessary status information.
These data generally remain in your browser and serve to provide the website in a user-friendly, consistent and legally compliant manner.
The legal basis is Article 6(1)(f) GDPR and Section 25(2) TDDDG where the storage is technically necessary.
Non-essential services are activated only if you have consented to the respective category.
11. Email Delivery via Resend
This website may use the Resend service for the technical delivery of transactional emails, for example to answer contact requests or to send system- and process-related notifications.
Provider:
Resend, Inc.
USA
The data processed may include the recipient address, the name where provided, the subject and content of the message, sending timestamps and technical delivery and log data. Resend runs server-side and generally sets no cookies in the browser.
The legal basis is Article 6(1)(b) GDPR where delivery serves to handle a request or pre-contractual measures, and otherwise Article 6(1)(f) GDPR in reliable email delivery. Where Resend processes data on my behalf, this is carried out on the basis of a data processing agreement pursuant to Article 28 GDPR.
Technical delivery logs are generally deleted after around 30 days. Where data is transferred to the United States, standard contractual clauses or other statutory mechanisms may be relevant.
Further information:
https://resend.com/legal/privacy-policy
12. Server-Side Logging via Axiom
This website may use the Axiom service for server-side structured logging. Only server-side operational events are recorded; no collection takes place in the browser.
Provider:
Axiom, Inc.
USA
The data processed consists of technical operational data such as the route called, HTTP method, status code, processing duration and timestamp. IP addresses, user agents, cookies, headers and request parameters are deliberately not logged.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest lies in the secure, stable and traceable operation of the website. Where Axiom processes data on my behalf, this is carried out on the basis of a data processing agreement pursuant to Article 28 GDPR.
Log data is generally deleted after around 30 days. Where data is transferred to the United States, standard contractual clauses or other statutory mechanisms may be relevant.
Further information:
https://axiom.co/privacy
13. Error and Performance Monitoring via Sentry
This website may use the Sentry service for error, crash and performance monitoring. Sentry runs both server-side and in the browser and also includes session replays for usability and interaction analysis.
Provider:
Functional Software, Inc. (Sentry)
San Francisco, CA
USA
The data processed may include error and event data, technical device, browser and diagnostic information, page context and session replays that are masked by default. For this Sentry uses sessionStorage in the browser and, according to the provider, sets no cookies.
The legal basis is Article 6(1)(f) GDPR for technical error and stability monitoring, and Article 6(1)(a) GDPR together with Section 25(1) TDDDG for session replay and interaction analysis in the browser. Where Sentry processes data on my behalf, this is carried out on the basis of a data processing agreement pursuant to Article 28 GDPR.
Event and replay data is generally deleted after around 90 days. Where data is transferred to the United States, standard contractual clauses or other statutory mechanisms may be relevant.
Further information:
https://sentry.io/privacy/
14. Availability Monitoring via UptimeRobot
This website may be monitored externally for availability using UptimeRobot. The service retrieves the website from the outside at regular intervals and is not embedded in the page; no code runs in visitors' browsers.
Provider:
UptimeRobot
The data processed consists of technical retrieval data such as availability status, response times and the times of the checks. This generally does not involve any processing of personal data of website visitors.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest lies in monitoring the availability and stability of the website.
Monitoring data is generally deleted or aggregated after around 90 days.
Further information:
https://uptimerobot.com/privacy/
15. Availability and Status Monitoring via Better Stack
This website may be monitored externally for availability using Better Stack; the related status information is published on a separately hosted status page (status.jialianglai.com). The monitoring is carried out externally and is not embedded in this website.
Provider:
Better Stack
The data processed consists of technical retrieval data such as availability status, response times and the times of the checks. If you open the public status page, Better Stack may additionally process the technical access data customary in such cases.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest lies in monitoring availability and in transparent status communication.
Monitoring data is generally deleted or aggregated after around 30 days. Where data is transferred outside the EEA, standard contractual clauses or other statutory mechanisms may be relevant.
Further information:
https://betterstack.com/privacy
16. Web Analytics and Interaction Analytics
This website may use analytics, performance, user-experience and marketing services. Depending on the category, these services are activated only after your consent.
The categories used are:
- Necessary / technically necessary functions,
- Statistics / anonymous or pseudonymous analytics,
- Usability and Interaction / interaction and UX analytics,
- Marketing / professional reach.
The specific allocation is described in the Cookie Policy, in the Cookie Settings and in the “Third-Party Services” overview.
17. Google Analytics 4
This website may use Google Analytics 4.
Provider:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Parent company:
Google LLC
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA
Google Analytics is used for statistical analysis of website use. In particular, page views, interactions, technical device information, referrers, approximate location information, browser and operating system data, and pseudonymous identifiers may be processed.
According to Google, IP addresses of users from the EU, Switzerland and the United Kingdom are not logged or stored; Google states that IP data is used only to derive coarse location data and is then discarded.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Further information:
https://support.google.com/analytics/answer/6004245
https://support.google.com/analytics/answer/12017362
18. Google Tag Manager
This website may use Google Tag Manager.
Provider:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Google Tag Manager is a tag management system. It allows other services, such as analytics, UX or marketing tags, to be managed and deployed in a controlled manner.
Google Tag Manager itself primarily serves to organise and trigger other tags. What matters is which tags are integrated through it and whether those tags are activated only after consent.
Where this website uses Google Tag Manager, non-essential tags are triggered only after the relevant consent has been given.
The legal basis for use in connection with non-essential tags is Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Further information:
https://support.google.com/tagmanager/answer/10718549
19. Microsoft Clarity
This website may use Microsoft Clarity.
Provider:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland
Parent company:
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052
USA
Clarity is used to analyse the use of and interaction with this website. This may include heatmaps, click, scroll and interaction data as well as session replays.
Session replay and heatmap services may be particularly intrusive. They are therefore activated on this website only with consent and are configured, where technically available, so that personal entries, sensitive content and confidential form content are not recorded.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Further information:
https://clarity.microsoft.com/privacy
https://learn.microsoft.com/clarity/faq
20. Hotjar / Contentsquare
This website may use Hotjar or Contentsquare. Hotjar is part of Contentsquare.
Provider:
Contentsquare SAS
7 rue de Madrid
75008 Paris
France
Hotjar and Contentsquare are used to analyse user interactions, in particular to improve usability, navigation, reading flow, layout and technical operability. Depending on configuration, heatmaps, click data, scrolling behaviour, technical usage data and session replays may be processed.
These services are activated only with consent. They are configured, where technically available, so that personal entries, sensitive content and confidential form content are excluded from recording.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Further information:
https://www.hotjar.com/privacy/gdpr-compliance/
https://help.hotjar.com/hc/en-us/articles/36820004397713-Privacy-FAQs
https://contentsquare.com/privacy-center/cookie-policy/
https://docs.contentsquare.com/en/web/cookies/
21. Cloudflare Web Analytics
This website may use Cloudflare Web Analytics.
Provider:
Cloudflare, Inc.
101 Townsend St.
San Francisco, CA 94107
USA
Cloudflare Web Analytics is used for aggregated analysis of website visits and performance. Cloudflare describes this service as web analytics without cookies, without local storage and without individual fingerprinting for analytics purposes.
Where Cloudflare Web Analytics is used without cookies, without local identifiers and without personal tracking, processing may be based on Article 6(1)(f) GDPR. If the technical configuration nevertheless includes storage, access or tracking functions requiring consent, activation will occur only after consent.
Further information:
https://www.cloudflare.com/web-analytics/
22. Vercel Analytics
This website may use Vercel Web Analytics.
Provider:
Vercel Inc.
440 N Barranca Ave #4133
Covina, CA 91723
USA
Vercel Web Analytics is used for aggregated analysis of website visits, page views and performance. Vercel states that Web Analytics stores anonymised data and does not use cookies.
Where the service is used without cookies, without personal identifiers and without cross-site tracking, processing may be based on Article 6(1)(f) GDPR. For transparency, the service may nevertheless be controlled through the Statistics category in the Cookie Settings.
Further information:
https://vercel.com/docs/analytics
https://vercel.com/docs/analytics/privacy-policy
23. Umami
This website may use Umami.
Provider depending on configuration:
Umami Software, Inc. / Umami Cloud or a self-hosted Umami instance
Umami is a privacy-focused web analytics service. Depending on configuration, Umami can be operated without cookies and without storing directly identifying visitor data.
Where Umami is used cookie-free, without personal identifiers and without cross-site tracking, processing may be based on Article 6(1)(f) GDPR. If the specific configuration involves storage or tracking requiring consent, activation will occur only after consent.
Further information:
https://umami.is/
https://umami.is/docs
24. LinkedIn Insight Tag
This website may use the LinkedIn Insight Tag.
Provider:
LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
Ireland
Parent company:
LinkedIn Corporation
1000 W Maude Ave
Sunnyvale, CA 94085
USA
The LinkedIn Insight Tag may be used to obtain aggregated information on whether and how this website is perceived in professional contexts. Depending on configuration, page views, referrers, URL, IP address, device and browser information, and cookie or pixel identifiers may be processed.
LinkedIn may link data to LinkedIn member accounts where users are logged in to LinkedIn or where LinkedIn can set or recognise corresponding identifiers. I do not receive a named list of individual visitors, but only aggregated evaluations.
The LinkedIn Insight Tag is activated only after consent to the Marketing category.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Further information:
https://www.linkedin.com/help/lms/answer/a489169
https://www.linkedin.com/legal/privacy-policy
https://www.linkedin.com/legal/cookie-policy
https://www.linkedin.com/legal/l/cookie-table
25. Search Engine Verification
This website may use verification mechanisms for search engines, in particular:
- Google Search Console verification,
- Bing Webmaster Tools verification,
- Baidu verification.
These verifications serve to prove website ownership to search engines and to receive technical information on indexing, discoverability and display of the website.
Verification may take place via meta tags, HTML files or DNS records. During a normal website visit, this generally does not constitute active tracking by the verification mechanisms. Search engines may, however, retrieve the relevant files or meta information as part of their crawling and indexing processes.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest lies in the technical administration, discoverability and search engine optimisation of the website.
26. External Links
This website contains links to external platforms, such as LinkedIn, GitHub, universities, employers, project pages, documentation or other third-party services.
When you click external links, you leave this website. The respective provider is solely responsible for data processing on external websites.
27. Embedded Content
This website may embed external content, in particular the Tally contact form. Further embedded content, such as YouTube, Google Maps, Spotify or comparable services, is not used on a permanent basis unless expressly stated elsewhere.
When external content is embedded, technical data may be transferred to the respective provider. Non-essential embedded content is loaded only after consent where it is relevant for tracking or cookies.
This website also provides an interactive map view. It is loaded only when you actively open the map view. Mapbox or, if the primary map is unavailable, OpenFreeMap via MapLibre GL JS may then process technical access data such as your IP address, browser and device information, request time and requested map resources.
The map shows only the approximate city/postcode-level location “90402 Nürnberg, Germany” and not an exact private residential address. Your analytics or marketing cookie choices do not control this map feature. If no external map service can be loaded, a static display is shown without connecting to a map service.
Detailed information about providers, purposes and further notices can be found under “Third-Party Services”.
28. Self-Hosted Third-Party Photo Assets and Attribution Links
Individual pages, especially the photographic area of the About page, may contain photographs or visual materials that were originally obtained from third-party image platforms such as Unsplash, Pexels or Pixabay.
Where these files are served locally by this website, merely visiting the page does not cause your browser to load image files directly from Unsplash, Pexels or Pixabay.
If you click a source, license, photographer or platform link, however, you leave this website. The respective third-party provider is responsible for any personal data processing on that external website.
This does not make these image source platforms default analytics, cookie or tracking services of this website.
Further information on rights, licenses and attribution can be found under Licenses and Attribution.
29. Recipients of Personal Data
Depending on use and consent, recipients of personal data may include in particular:
- Vercel for hosting, delivery, technical logs and analytics,
- Squarespace for domain management and DNS,
- GitHub for source code management and technical publication processes,
- Tally for contact forms,
- Mapbox and OpenFreeMap for an interactive map view that you actively open,
- Google for Google Analytics, Google Tag Manager and Search Console,
- Microsoft for Clarity,
- Contentsquare / Hotjar for UX analytics,
- Cloudflare for Web Analytics,
- Umami for web analytics,
- LinkedIn for the Insight Tag,
- Resend for the delivery of transactional emails,
- Axiom for server-side logging,
- Sentry for error and performance monitoring,
- UptimeRobot and Better Stack for availability and status monitoring,
- authorities or other bodies where a legal obligation exists.
Further details can be found under “Third-Party Services”.
30. Transfers to Third Countries
Some of the services used have registered offices or parent companies outside the European Union or the European Economic Area, in particular in the United States.
Transfers of data to third countries take place only where a legal basis exists, such as:
- an adequacy decision by the European Commission,
- the EU-U.S. Data Privacy Framework, where the provider is appropriately certified,
- standard contractual clauses,
- additional technical and organisational safeguards,
- explicit consent,
- other statutory transfer mechanisms.
Despite such safeguards, a residual risk may remain in the case of third-country transfers, in particular that foreign authorities may access data.
31. Retention Period
Personal data is stored only for as long as necessary for the respective purposes or for as long as statutory retention obligations exist.
Contact requests are deleted once the request has been finally processed, unless legal obligations or legitimate interests justify longer retention.
Cookie and consent settings remain stored in your browser until you delete, reset or change them.
Analytics and tracking data are stored according to the settings of the respective providers and the technical configuration. Where possible, short retention periods, aggregation, anonymisation or pseudonymisation are preferred.
32. Your Rights
Subject to the conditions of the GDPR, you have in particular the following rights:
- right of access pursuant to Article 15 GDPR,
- right to rectification pursuant to Article 16 GDPR,
- right to erasure pursuant to Article 17 GDPR,
- right to restriction of processing pursuant to Article 18 GDPR,
- right to data portability pursuant to Article 20 GDPR,
- right to object pursuant to Article 21 GDPR,
- right to withdraw consent pursuant to Article 7(3) GDPR,
- right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR.
To exercise your rights, you can contact me at:
33. GDPR Data Request
You can submit a data protection request to the email address stated above. Please specify, where possible, which right you would like to exercise, for example:
- access to personal data being processed,
- rectification of inaccurate data,
- deletion of certain data,
- restriction of processing,
- data portability,
- objection to processing based on legitimate interests,
- withdrawal of consent.
To prevent unauthorised disclosures, reasonable identity verification may be required.
Requests are generally answered within one month. This period may be extended in accordance with the GDPR if the request is particularly complex or if numerous requests have been received.
34. Withdrawal of Consent
You may withdraw consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
You can change your cookie and tracking settings via “Cookie Settings”.
35. Objection to Processing Based on Legitimate Interests
Where personal data is processed on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
36. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority.
Competent supervisory authority:
Bavarian State Office for Data Protection Supervision
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Website:
https://www.lda.bayern.de
37. SSL/TLS Encryption
This website uses SSL/TLS encryption. You can recognise an encrypted connection by “https://” in your browser’s address bar.
38. Changes to This Privacy Policy
This Privacy Policy may be updated if technical functions, services used, legal requirements or organisational processes change.
The current version published on this website applies.
