Privacy Policy
Note: This is a draft. This privacy policy will be reviewed by a lawyer before the official launch. Details in square brackets are still to be completed.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
David Schubert [Street and number] [Postal code and city], Germany E-mail: mail@davidschubert.com
2. General
We process personal data only where necessary to provide a functional website and our services. The legal bases are in particular Art. 6 (1) (b) GDPR (performance of a contract), Art. 6 (1) (f) GDPR (legitimate interest in a secure and stable operation) and, where consent is obtained, Art. 6 (1) (a) GDPR.
3. Hosting and server logs
This website is hosted on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, under a data processing agreement (Art. 28 GDPR). When you visit the site, the server automatically processes technical access data (IP address, date and time, requested page, browser type) to deliver the site, ensure stability and prevent abuse (Art. 6 (1) (f) GDPR).
4. Cookies
We only use technically necessary cookies: a session cookie after login (authentication) and a language cookie (remembers your chosen language). Technically necessary cookies do not require consent. We do not use analytics or marketing cookies; should this change, we will ask for consent first.
5. Registration and account
When you register we process your e-mail address, display name and a password (stored only as a cryptographic hash) or a one-time login code (Art. 6 (1) (b) GDPR). You can delete your account at any time in the settings; your personal data will then be deleted or your contributions anonymised. You can also request an export of your data (Art. 20 GDPR) in the settings.
6. Comments and posts
If you publish comments or posts, we store the content, the time and your display name; these are visible to other visitors (Art. 6 (1) (b) GDPR). Reported or unlawful content may be moderated, hidden or deleted.
7. E-mail delivery
For transactional e-mails (e.g. login codes, notifications you have enabled) we use Resend (Resend, Inc., USA). Your e-mail address is transmitted to Resend; transfers to the USA are based on the EU Standard Contractual Clauses (Art. 46 GDPR). Notification e-mails are disabled by default and can be switched on and off in the settings at any time.
8. Payments
Paid plans are processed by Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland). Payment data (e.g. card details) is collected and processed directly by Stripe; we never receive or store full payment details (Art. 6 (1) (b) GDPR). More information: https://stripe.com/privacy.
9. Retention
We store personal data only for as long as required for the purposes described above or as required by statutory retention obligations (e.g. tax law for invoice data).
10. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6 (1) (f) GDPR (Art. 21). Contact us informally at the e-mail address above. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
11. Changes
We will update this privacy policy when the legal situation or our services change. The version published here applies.