No cookies, no analytics, no tracking. One third party, on one page, and only if you start writing to us. What follows is what happens when you load a page, the legal basis for it, and what you can demand of us.
The controller for data processing on this site is:
Delivering a page requires a small amount of data. This is the complete list:
GeoLite2 data created by MaxMind ↗
This site sets no cookies — not for analytics, not for advertising, not for preferences — which is why nothing here asked you to accept any: there is nothing to consent to. It runs no analytics, no tracking pixels, no advertising networks, no social media embeds, no cross-site identifiers and no A/B testing tools. The fonts are served from this domain rather than from Google, and the location lookup in § 02 runs against a file on our own server rather than against somebody’s API. There is one exception to all of it, on one page: the contact form is protected by Cloudflare Turnstile, a check that tells us whether you are a person or a bot. The moment you type into that form, your browser loads Turnstile from Cloudflare, which tells Cloudflare your IP address and something about your browser. Reading the contact page does not do this — only starting to write does — and nothing else on this site loads it at all. We do not receive anything from Cloudflare beyond a yes or no, and the check happens because we would otherwise have to read whatever a bot decided to send us. What Cloudflare does with what it sees is its own, and it is described here:
Cloudflare's Turnstile Privacy Addendum ↗
The site runs as a Node application on our own server, managed with Plesk, with Cloudflare in front of it as a reverse proxy and content delivery network. Every request therefore reaches us through Cloudflare, which on the way sees what any intermediary on the network sees: your IP address, the address you asked for, and what your browser says about itself. Because every request arrives relayed, the access log our own server keeps records the address of the Cloudflare machine that passed it on, and not yours. The application is handed your address in order to answer the request and to derive the approximate city in § 02, and it keeps no record of it. We run nothing on any of this to identify you.
The contact form sends what you put in it — your name, your organization if you name one, your e-mail address and your message — to our server, which checks it with Turnstile (§ 03) and then forwards it as an e-mail to the desk. It leaves through our mail provider, who carries it in the ordinary way mail is carried. We keep no copy anywhere else: there is no database behind this form, and your message lives in the desk mailbox and nowhere on this site. We process it and your address for as long as it takes to answer you and to meet any retention duty that applies to the correspondence. If you would rather not use the form at all, the desk address is written on the contact page and works exactly as well.
Delivering the site, keeping it secure, and answering the widget are carried out on the basis of our legitimate interest in operating a working website, Art. 6(1)(f) GDPR. Correspondence you start rests on Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on whether it concerns a contract. Nothing here relies on consent, because nothing here asks for any.
You may ask us what data we hold about you, and demand that it be corrected, deleted or restricted. You may object to processing based on legitimate interest, and you may ask for your data in a portable form. Write to the address below — we answer these ourselves. You may also complain to a data protection supervisory authority; for us that is the authority for North Rhine-Westphalia, but you may approach the one where you live.
Anything unclear here, or anything that does not match what you observe in your own browser? Write to us — for a security company, that is a bug report, and we want it.
[email protected]Request access — the first picture of your external exposure takes minutes, not weeks.