Privacy Policy
Effective Date September 1, 2026
1. Introduction
This Privacy Policy describes the type, scope, and purpose of the processing of personal data on this website. Processing follows the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and, where end-device information is stored or accessed, Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).
2. Controller
The controller responsible for data processing on this website is
Volker Schwaberow
c/o Block Services
Stuttgarter Str. 106
70736 Fellbach
Germany
Email: volker@schwaberow.de
No data protection officer has been appointed. Contact the controller at the address above for any privacy request.
3. Overview of processing
| Processing | Data | Purpose | Legal basis | Storage |
|---|---|---|---|---|
| Server log files | IP address, browser and OS data, referrer URL, hostname, time of request | Delivery of the site, stability, security, abuse detection | Art. 6(1)(f) GDPR | IP addresses are truncated or deleted after at most 14 days. Remaining log metadata is kept only as long as needed for security review, then deleted. |
| Email contact | Content of the message and any personal data you include (for example name and email address) | Handling and answering your inquiry | Art. 6(1)(f) GDPR | Until the conversation is closed and any applicable retention duties end |
| Client-side search (Pagefind) | Search queries run in your browser against a static local index | On-site search | No server-side processing of search queries. Loading is limited to local static assets for the search UI | Remains in the browser. Not sent to the controller for analytics |
4. Legitimate interests (Art. 6(1)(f) GDPR)
Where processing is based on Art. 6(1)(f) GDPR, the controller pursues the following interests
- operating a stable and secure website
- detecting and defending against attacks and abuse
- answering messages sent to the published contact address
These interests are weighed against your rights and freedoms. Log retention is short. No advertising profiles are built. No tracking tools are used.
5. Hosting
This website is hosted on a server operated by the controller. The server is located in a data centre of
netcup GmbH
Emmy-Noether-Straße 10
D-76131 Karlsruhe, Germany
netcup provides hosting infrastructure only. netcup is not engaged as a processor under Art. 28 GDPR for the editorial operation of this site. Personal data in server logs is processed under the controller’s responsibility on that infrastructure.
6. Server log files
When you visit the website, the web server records technical request data that your browser transmits. That typically includes browser type and version, operating system, referrer URL, hostname of the accessing computer, time of the request, and the IP address.
Under EuGH C-582/14 (Breyer), IP addresses can be personal data for the website operator. IP addresses are truncated or deleted after at most 14 days. Log data is not merged with other data sources for profiling.
7. Contact by email
If you write to the controller by email, the data you send is stored to process and answer the request. The legal basis is Art. 6(1)(f) GDPR (answering correspondence). Data is deleted when the conversation has ended, unless statutory retention rules require longer storage.
8. End-device storage under Section 25 TDDDG
Section 25 TDDDG governs the storage of information on your terminal equipment or access to information already stored there.
This website does not set cookies and does not use localStorage, sessionStorage, or comparable browser storage for analytics, advertising, or site features. No consent banner is required for end-device storage because no such storage is written by this site.
Tracking and analytics
This website does not use tracking cookies, analytics tools, advertising identifiers, or fingerprinting for marketing.
Client-side search (Pagefind)
Search runs in your browser against a static index shipped with the site. Search queries are not sent to an external search provider and are not used to build usage profiles. Loading the search UI only retrieves local static assets from this site.
9. Recipients and transfers
Recipients of personal data are limited to the controller and, at infrastructure level, the hosting environment described above. There is no intentional transfer of personal data to a third country or international organisation for the operation of this site. The hosting location is Germany.
10. Your rights
You have the following rights under the GDPR, subject to the statutory conditions
-
Right of access (Art. 15 GDPR)
Confirmation whether personal data about you is processed, and access to that data. -
Right to rectification (Art. 16 GDPR)
Correction of inaccurate personal data. -
Right to erasure (Art. 17 GDPR)
Deletion of personal data in the cases set out by law. -
Right to restriction of processing (Art. 18 GDPR)
Restriction of processing in the cases set out by law. -
Right to data portability (Art. 20 GDPR)
Receipt of data you provided, in a structured, commonly used, machine-readable format, where the processing is based on consent or contract and is carried out by automated means (where applicable). -
Right to object (Art. 21 GDPR)
You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. The controller will no longer process the personal data unless compelling legitimate grounds for the processing override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims. -
Right to lodge a complaint (Art. 77 GDPR)
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. An overview of supervisory authorities and contact details is published by the Federal Commissioner for Data Protection and Freedom of Information (BfDI)
https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_node.html
To exercise your rights, contact the controller at the email address in Section 2.
11. Data security
The site is served over TLS. Access to the hosting environment is restricted to the controller. Technical and organisational measures are oriented to Art. 32 GDPR, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing.