Privacy policy
Courtesy translation. The German version is the legally operative one.
At a glance
This is a static website. We use no analytics, tracking or advertising services and build no usage profiles. The only things stored are technically necessary: what is needed to fend off automated access and, if you log in, an authentication token in your browser.
The only personal data we store permanently is your email address and the data needed to sign in — and only if you choose to create an account. Everything else in this notice concerns technically necessary steps in delivering the page to you.
1. Controller
The controller for data processing on this website is:
David ChristIm Wiesengrund 6
72119 Ammerbuch-Entringen
Deutschland
Email: [email protected]
No data protection officer has been appointed.
2. Server log files
Your request is handled by our content delivery and security provider (Cloudflare — see section 3), which sits in front of our hosting. This involves technically necessary connection data: IP address, date and time of access, the resource requested, referrer URL, user agent (browser and operating system), HTTP status code, and the volume of data transferred. Because content is cached at the edge, a proportion of requests never reaches our hosting provider at all.
Purpose and legitimate interest: this processing is technically necessary to deliver the website. Our legitimate interest under Art. 6(1)(f) GDPR is specifically to keep the site operating, to trace and fix faults, and to detect and defend against attacks and abusive access.
Retention: We do not store or evaluate this data ourselves and have no access to raw logs. It is held by the providers named in section 3 under their own retention policies. It is not combined with other data or analysed for any analytics purpose.
3. Processors and recipients
We use the following providers. They process personal data on our instructions under an Art. 28 GDPR data processing agreement. Where a provider additionally processes certain data as its own controller, that is noted below and its own privacy notice applies to it.
- Cloudflare, Inc. — DNS, content delivery network and protection against automated access. It sits in front of our hosting and therefore processes every request, including your IP address. Processing location: USA / global edge network. Applies to every page view. Processed by the provider as its own controller: Netzwerk- und Verkehrsdaten. Privacy notice
- Render Services, Inc. — Hosting and delivery of this static website and its assets. Processing location: USA / global edge network. Applies to every page view. Processed by the provider as its own controller: Konto- und Nutzungsdaten einschließlich Aktivitätsprotokollen. Privacy notice
- Supabase Pte. Ltd — Processing location: Singapur (Vertragspartner); Rechenzentrum Tokio (ap-northeast-1). Only when you use account features (signup, login, dashboard); simply viewing a page involves no processing by this provider. Sub-processors: Supabase, Inc. (USA), Amazon Web Services. Privacy notice
- Sand Dune Mail Ltd (SMTP2GO) — Delivery of authentication emails (signup confirmation, password reset). Processing location: Europäische Union (EU-Endpunkt); Unternehmenssitz Neuseeland. Only when you use account features (signup, login, dashboard); simply viewing a page involves no processing by this provider. Headers of all sent emails are retained for 35 days. For fault diagnosis, one email in a thousand is additionally retained in full for 35 days and can be reviewed by the provider's staff, after which it is deleted. Privacy notice
4. Transfers to third countries
The providers named in section 3 are US companies or process data outside the European Economic Area. Personal data is therefore transferred to a third country within the meaning of Chapter V GDPR. This affects in particular your IP address, which is technically necessary to deliver this website to you.
Transfers to Cloudflare, Inc. and Render Services, Inc. rest on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR); standard contractual clauses under Art. 46(2)(c) GDPR are additionally in place and take effect should that adequacy decision cease to apply. No adequacy decision is available for Supabase Pte. Ltd, so those transfers rest on standard contractual clauses under Art. 46(2)(c) GDPR. We will provide information about the safeguards in place on request.
Please note that for transfers to the United States, access by US authorities cannot be ruled out in every case.
5. Contacting us
If you contact us by email we process the data you send — your email address, your name and the content of your message — solely to deal with your enquiry.
Legal basis: Art. 6(1)(b) GDPR where the enquiry relates to entering into or performing a contract, otherwise Art. 6(1)(f) GDPR on the basis of our legitimate interest in answering enquiries.
Retention: we delete your enquiry once it has been dealt with. If the correspondence becomes a business transaction, the statutory retention periods under § 147 AO and § 257 HGB apply (generally 6 or 10 years).
Providing your data is voluntary, but without it we cannot answer your enquiry.
6. Account features
For signup, login and the dashboard we process your email address and the data required for authentication. The legal basis is Art. 6(1)(b) GDPR, as this processing is necessary to perform the user agreement. We delete the data when you delete your account, unless statutory retention obligations apply.
7. Cookies and local storage
We set no cookies for analytics, advertising or tracking. There is no audience measurement, and no social-media or advertising networks are embedded. Fonts are served from our own server and are not loaded from third parties.
Our content delivery and security provider adds its own security functions to the pages it serves. These include a script that obfuscates email addresses shown on the page against automated harvesting and monitoring of the scripts used on the page in order to detect unexpected changes. These scripts are served from our own domain and serve security only; your behaviour is not analysed.
Visiting this website sets no cookies — neither ours nor any set by the providers named in section 3.
If you log in, authentication tokens are placed in your browser's local storage to manage your session. Logging in is not possible without them. That storage is strictly necessary to provide the login function you expressly requested and therefore requires no consent under § 25(2) no. 2 TDDDG. You can remove the tokens at any time by logging out or clearing site data in your browser.
All of the above storage is strictly necessary either to provide the service you requested or to secure it. No consent is required for it under § 25(2) no. 2 TDDDG, and nothing is stored for analytics, advertising or tracking. This is why the site shows no consent banner.
8. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
9. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Please use the address above.
Right to object: you have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data carried out on the basis of Art. 6(1)(f) GDPR (Art. 21 GDPR).
You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg.