Privacy Policy
Last updated: 8 October 2026
Preamble
This privacy policy explains which types of your personal data (hereinafter also referred to as "data") we process, for which purposes and to what extent. It applies to all processing of personal data carried out by us on this website (hereinafter "online service").
Contents
- Preamble
- Controller
- Overview of processing
- Relevant legal bases
- Security measures
- International data transfers
- Rights of data subjects
- Provision of the online service and web hosting
- Cookies
- Contact form and email
- Spam protection (ALTCHA)
- Embedded videos (Vimeo, YouTube)
- Changes and updates
- Definitions
Controller
Markus Heckmann
c/o POSTFLEX PFX-017-583
Emsdettener Straße 10
48268 Greven
Germany
Email: markus.gg7nb [at] passmail.net
Overview of processing
The following overview summarises the types of data processed and the purposes of processing, and refers to the data subjects concerned.
Types of data processed
- Master data (e.g. names).
- Contact data (e.g. email addresses).
- Content data (e.g. the text of messages).
- Usage data.
- Meta, communication and process data.
- Log data.
Categories of data subjects
- Users.
- Communication partners.
Purposes of processing
- Security measures.
- Provision of our online service and usability.
- Information technology infrastructure.
- Communication and responding to enquiries.
- Display of video content (only with consent).
Relevant legal bases
Relevant legal bases under the GDPR: Below is an overview of the legal bases of the General Data Protection Regulation (GDPR) on which we process personal data. Please note that, in addition to the GDPR, national data protection regulations may apply in your or our country of residence. Where more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6 (1) (a) GDPR) – the data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual requests (Art. 6 (1) (b) GDPR) – processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legitimate interests (Art. 6 (1) (f) GDPR) – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the GDPR, national data protection regulations apply in Germany, in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transmission, and automated individual decision-making including profiling. The data protection laws of the individual German federal states may also apply. Storing information on your device and accessing it (e.g. cookies) is additionally governed by § 25 of the Telecommunications Digital Services Data Protection Act (TDDDG).
Security measures
In accordance with the legal requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input, transfer, securing of availability and separation of the data. We have also established procedures to ensure that data subjects' rights can be exercised, that data is deleted, and that we can respond to threats to the data. Furthermore, we take the protection of personal data into account when developing or selecting hardware, software and procedures, in line with the principles of data protection by design and by default.
Securing online connections with TLS/SSL encryption (HTTPS): To protect users' data transmitted via our online service from unauthorised access, we use TLS/SSL encryption. This technology encrypts the information transmitted between the website and the user's browser, protecting the data from unauthorised access. A website secured with an SSL/TLS certificate is indicated by HTTPS in the URL.
International data transfers
Our web host is based in Iceland and therefore within the European Economic Area (EEA). In operating this website, we do not ourselves transfer any data to third countries.
A transfer to a third country (i.e. outside the EU or EEA) can only occur if you play an embedded video (see Embedded videos), as the providers also process data in the USA. For transfers to the USA, these providers rely on the EU-U.S. Data Privacy Framework (DPF), which was recognised as providing an adequate level of protection by an adequacy decision of the European Commission of 10 July 2023, and additionally on the European Commission's standard contractual clauses. Further information on the DPF and a list of certified companies is available on the website of the U.S. Department of Commerce at dataprivacyframework.gov.
Rights of data subjects
As a data subject, you have various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR, including profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to processing of that data for such marketing, including profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time, with effect for the future.
- Right of access: You have the right to obtain confirmation as to whether data concerning you is being processed, and to access this data as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with the legal requirements, you have the right to have incomplete data concerning you completed or inaccurate data concerning you rectified.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without undue delay or, alternatively, to request restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller, in accordance with the legal requirements.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. A complaint may be lodged in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement.
Provision of the online service and web hosting
We process users' data in order to provide our online service to them. For this purpose, we process the user's IP address, which is necessary to deliver the content and functions of our online service to the user's browser or device.
- Types of data processed: Usage data (e.g. pages visited, browsers and operating systems used); meta, communication and process data (e.g. IP addresses, times); log data (e.g. log files relating to the retrieval of data or access times).
- Data subjects: Users (e.g. website visitors).
- Purposes of processing and legitimate interests: Provision of our online service and usability; information technology infrastructure (operation and provision of information systems and technical equipment); security measures.
- Retention and deletion: see the information on log files below.
- Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Provision of the online service on rented server space: To provide our online service, we use storage space, computing capacity and software that we rent from a server provider ("web host"). Service provider: FlokiNET ehf., Iceland; Website: flokinet.is; Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR).
- Collection of access data and log files: Access to our online service is logged in so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful retrieval, browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used for security purposes, e.g. to prevent server overload (especially in the event of abusive attacks, so-called DDoS attacks), and to ensure the utilisation and stability of the servers; Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR). Deletion of data: Log file information is archived monthly and deleted after two months at the latest. Data whose further retention is necessary for evidentiary purposes is exempt from deletion until the respective incident has been finally resolved.
We do not use any analytics or tracking services, do not load any external fonts and do not use any social media plugins. The icons linking to social networks and other websites are plain links; no data is transmitted to these providers unless you follow a link.
Cookies
The public pages of this online service do not set any cookies. The only exceptions are strictly necessary cookies:
- Contact form: When you open the page containing the contact form, a session cookie (
kirby_session) is set. It contains a random identifier that the server uses to associate a security token (protection against forged form submissions, "CSRF") and the time the page was opened (protection against automated spam submissions). The cookie expires at the end of the session or after a few hours at the latest. - Administration area: Logging in to the non-public administration area of the website also sets a session cookie; this only affects the site operator.
Legal basis: § 25 (2) no. 2 TDDDG (strictly necessary storage); the subsequent processing is based on our legitimate interests (Art. 6 (1) (f) GDPR) in a secure contact form protected against abuse.
Contact form and email
When you contact us (via the contact form or by email), the information you provide is processed to the extent necessary to respond to your enquiry and any requested measures.
- Types of data processed: Master data (name); contact data (email address); content data (text of the message); meta, communication and process data (e.g. times).
- Data subjects: Communication partners.
- Purposes of processing: Communication and responding to enquiries.
- Retention and deletion: Data entered in the contact form is not stored on the web server but only forwarded to us by email. We delete enquiries once they have been dealt with, unless statutory retention obligations (e.g. for business correspondence) apply.
- Legal basis: Performance of a contract and pre-contractual requests (Art. 6 (1) (b) GDPR), where your enquiry relates to a commission or collaboration; otherwise legitimate interests (Art. 6 (1) (f) GDPR) in responding to enquiries.
An email address is required in the contact form so that we can reply.
Spam protection (ALTCHA)
To protect the contact form against automated spam submissions, we use "ALTCHA", an open-source method that runs entirely on our own server. Your browser solves a small computational task ("proof of work"); no cookies are set, no data is transmitted to third parties, and no tracking takes place.
In addition, we limit the number of form submissions per IP address (at most five per hour). For this, we do not store the IP address itself, only a hash value created with a secret key, together with a counter. This entry is deleted automatically after one hour at the latest.
- Types of data processed: Meta, communication and process data (hashed IP address, times).
- Purposes of processing: Security measures (protection against spam and abuse).
- Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR).
Embedded videos (Vimeo, YouTube)
On some pages, we embed videos from the platforms Vimeo and YouTube. These are only loaded after you click the respective preview image; the preview image itself is hosted on our server. No data is transmitted to Vimeo or YouTube before this click.
By clicking, you consent to the video player being loaded from the respective provider. The provider then receives your IP address and information about your browser, and may use cookies or similar technologies on your device. YouTube videos are embedded in "privacy-enhanced mode" (domain youtube-nocookie.com), Vimeo videos with the "Do Not Track" parameter (dnt=1). The providers also process data in the USA (see International data transfers).
- Types of data processed: Usage data (e.g. interactions with the video); meta, communication and process data (e.g. IP addresses, times).
- Data subjects: Users.
- Purposes of processing: Display of video content.
- Legal basis: Consent (Art. 6 (1) (a) GDPR; § 25 (1) TDDDG). Consent applies only to the video clicked and is not stored; the next time the page is loaded, the video is again only loaded after a click.
Services used:
- Vimeo: Vimeo.com, Inc., Attention: Data Protection Officer, 330 West 34th Street, 10th Floor, New York, New York 10001, USA; Privacy policy: vimeo.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses.
- YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Privacy policy: policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses.
Changes and updates
Please check the content of this privacy policy regularly. We will update it as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as such changes require action on your part (e.g. consent) or another individual notification.
Where we provide addresses and contact details of companies and organisations in this privacy policy, please note that these may change over time; please check the details before contacting them.
Definitions
This section provides an overview of the terms used in this privacy policy. Where terms are defined by law, the legal definitions apply. The following explanations are primarily intended to aid understanding.
- Meta, communication and process data: Categories of information about how data is processed, transmitted and managed. Metadata ("data about data") describes the context, origin and structure of other data, e.g. file size, creation date, author and change history. Communication data covers the exchange of information between users via various channels, such as email, call logs, social network messages and chats, including the persons involved, timestamps and transmission routes. Process data describes processes and workflows within systems or organisations, including workflow documentation, transaction and activity logs, and audit logs used to track and review operations.
- Usage data: Information about how users interact with digital products, services or platforms, e.g. which functions they use, how long they stay on certain pages and which paths they take through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information and location data.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Log data: Information about events or activities recorded in a system or network, typically including timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used to analyse system problems, for security monitoring or to produce performance reports.
- Controller: The "controller" is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, such as collection, analysis, storage, transmission or erasure.
This text is based on Datenschutz-Generator.de by Dr. Thomas Schwenke, translated into English and extended with the sections on cookies, contact, spam protection and embedded videos.