1. Infrastructure and Hosting
Hybrid Gateway Routing with VPN Security
To ensure availability, stability and security, we operate a multi-stage, privacy-friendly infrastructure:
- Technical entry point (gateway): The public accessibility of this website is provided by a server from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (Germany). This server exclusively provides a static IP address and routing.
- Encrypted transport (VPN): The connection between the gateway server and our internal infrastructure is exclusively via an end-to-end encrypted VPN connection. Direct access from the internet to internal systems is technically excluded.
- Data processing agreement: There is a legally compliant data processing agreement (DPA) with Hetzner Online GmbH in accordance with Art. 28 GDPR. Only technically unavoidable, transient connection data is processed.
- Legal basis: in accordance with Art. 6 para. 1 lit. f GDPR (legitimate interest in a secure, stable and technically controlled provision of the online service).
2. Server Configuration and Consistent Log Avoidance
OpenResty / Nginx
We strictly follow the principle of data minimization in accordance with Art. 5 para. 1 lit. c GDPR. Our webserver is deliberately configured so that personal data is not generated in the first place:
💡 No access logs: Access logging is completely disabled (
access_log off;). No IP addresses, user-agent strings, referrers or URLs accessed are stored.
💡 Heavily reduced error logs: Error logs are only maintained at the
critlevel. These logs serve exclusively for operational security and contain no personal data.
3. Transport Encryption
SSL/TLS, HTTP/3 (QUIC) and HSTS
Your data is transmitted exclusively in encrypted form:
HTTPS / SSL-TLS: The website is only accessible via encrypted connections.HTTP/3 (QUIC): Modern protocol architecture with integrated encryption and improved security.HSTS (HTTP Strict Transport Security): Your browser is instructed to only allow encrypted connections to this domain.
4. Web Analytics
Umami - privacy-hardened self-hosted installation
For purely statistical evaluation of usage, we use the open-source tool Umami in a maximally privacy-friendly configuration:
- Self-hosting: The Umami instance runs entirely within our own infrastructure. No data is transmitted to third parties.
- No IP collection (
DISABLE_IP_TRACKING=1): IP addresses are neither stored nor processed. - No cookies (
DISABLE_TRACKING_COOKIE=1): No tracking or identification cookies are set. - Do-Not-Track is respected (
RESPECT_DNT=1): If your browser has "Do Not Track" enabled, your visit is completely ignored.
💡 Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in anonymous, statistical analysis for technical optimization).
5. No Third-Party Resources
Zero-External-Requests Policy
This website does not load content from external servers:
- Local fonts: All fonts (e.g. webfonts or icons) are served locally from our own server.
- No CDNs, no APIs: No content delivery networks, Google services or comparable third-party providers are used.
This prevents your IP address or browser data from being transmitted to external parties.
6. Contact by Email
When you contact us by email, we process the data you transmit (e.g. email address, name, message) exclusively for processing your inquiry.
- No disclosure to third parties
- No use for advertising purposes
- Deletion after the purpose has been fulfilled, unless there are legal retention obligations
No automated decision-making or profiling takes place.
💡 Legal basis: Art. 6 para. 1 lit. b GDPR (pre-contractual communication) or Art. 6 para. 1 lit. f GDPR (legitimate interest in answering inquiries).
7. Your Rights as a Data Subject
You have the following rights in accordance with Art. 15-21 GDPR:
- Access to stored data
- Rectification or erasure of incorrect or inadmissible data
- Restriction of processing
- Objection to processing
⚠️ Important note: Since we neither store
IP addressesnor usetracking, there are generally no personal data about you on file. Access is therefore usually only possible for data you have actively transmitted to us (e.g. by email).
8. Right of Appeal to the Supervisory Authority
If you believe that the processing of your data violates data protection law, you have the right to lodge a complaint with the competent data protection supervisory authority in accordance with Art. 77 GDPR.
Privacy policy as of: April 9, 2026