1. Infrastructure and Hosting
Hybrid Gateway Routing with VPN Security
To ensure availability, stability, and security, we operate a multi-level, privacy-friendly infrastructure:
-
Technical Entry Point (Gateway)
Public access to this website is provided via a server of Hetzner Online GmbH Industriestr. 25, 91710 Gunzenhausen (Germany). This server exclusively provides a static IP address and routing.
-
Encrypted Transport (VPN)
The connection between the gateway server and our internal infrastructure takes place exclusively via an end-to-end encrypted VPN connection. Direct access from the internet to internal systems is technically excluded.
-
Order Processing
A legally compliant Data Processing Agreement (DPA) exists with Hetzner Online GmbH according to Art. 28 GDPR.. Only technically unavoidable, volatile connection data is processed.
-
Legal Basis
according to Art. 6 Para. 1 lit. f GDPR (Legitimate interest in a secure, stable, and technically controlled provision of the online offer)
2. Server Configuration and Consistent Log Avoidance
OpenResty / Nginx
We strictly follow the principle of Data Minimization according to Art. 5 Para. 1 lit. c GDPR
Our web server is deliberately configured so that personal data is not created in the first place:
No Access Logs:
Access logging is completely disabled (access_log off;). No IP addresses, User-Agent strings, Referrers, or accessed URLs are stored.
Greatly Reduced Error Logs:
Error logs are kept exclusively at the level crit (critical). These logs serve exclusively for operational security and contain no personal data.
3. Transport Encryption
SSL/TLS, HTTP/3 (QUIC) and HSTS
The transmission of your data takes place exclusively encrypted:
-
HTTPS / SSL-TLS The website is only accessible via encrypted connections.
-
HTTP/3 (QUIC) Modern protocol architecture with integrated encryption and improved security.
-
HSTS (HTTP Strict Transport Security) Your browser is instructed to allow exclusively encrypted connections to this domain.
4. Web Analytics
Umami – Privacy-Hardened Self-Instance
For purely statistical evaluation of usage, we use the open-source tool Umami – in a maximum privacy-friendly configuration:
-
Self-Hosting:
The Umami instance runs completely in our own infrastructure. No data is transferred to third parties.
-
No IP Collection
(
DISABLE_IP_TRACKING=1)
IP addresses are neither stored nor processed.
-
No Cookies
(
DISABLE_TRACKING_COOKIE=1)
No tracking or identification cookies are set. Returning page visits are recorded exclusively via an anonymous, rotating hash that allows no personal reference.
-
Do-Not-Track is Respected
(
RESPECT_DNT=1)
If your browser has "Do Not Track" enabled, your visit is completely ignored.
Legal Basis:
Art. 6 Para. 1 lit. f GDPR (Legitimate interest in an anonymous, statistical analysis for technical optimization)
5. No Third-Party Resources
Zero-External-Requests-Policy
This website does not load any content from external servers:
-
Local Fonts:
All fonts (e.g., web fonts or icons) are delivered locally from our own server.
-
No CDNs, No APIs:
No Content Delivery Networks, Google services, or comparable third-party providers are used.
This prevents your IP address or browser data from being transmitted to external parties.
6. Contact via E-Mail
If you contact us via e-mail, we process the data you provide (e.g., e-mail address, name, message) exclusively for processing your request.
-
No transfer to third parties
-
No use for advertising purposes
-
Deletion after purpose ceases to exist, provided there are no legal retention obligations
No automated decision-making or profiling takes place
Legal Basis:
Art. 6 Para. 1 lit. b GDPR (pre-contractual communication) or
Art. 6 Para. 1 lit. f GDPR (legitimate interest in answering inquiries)
7. Your Rights as a Data Subject
According to Art. 15–21 GDPR, you have the following rights:
-
Access
to stored data
-
Rectification or Erasure
of incorrect or inadmissible data
-
Restriction
of processing
-
Objection
against processing
Important Note
Since we neither store IP addresses nor use tracking, we usually do not have any personal data about you. Access is therefore usually only possible via data that you have actively provided to us (e.g., via e-mail).
8. Right of Appeal to the Supervisory Authority
If you believe that the processing of your data violates data protection law, you have the right to complain to a competent data protection supervisory authority according to Art. 77 GDPR.
Privacy Policy Status: January 30, 2026