Legal · Datenschutzerklärung
Privacy Policy
The short version: this site sets no cookies, runs no analytics, and loads nothing from third-party trackers. It stores what any web server needs to run and defend itself, and what you send us when you email us. The long version follows.
Falk Wittmann
Schopenhauerstraße 35C70565 Stuttgart, Germany
No data protection officer is required for this site (§ 38 BDSG) and none has been appointed. Write to the address above for anything privacy-related.
1. Scope
This policy covers the website https://veith.dev including the blog and its RSS feed. It explains which personal data is processed when you use the site or contact us, for what purpose, on which legal basis, how long it is kept, and which rights you have. Personal data means any information relating to an identified or identifiable person (Art. 4 (1) GDPR).
2. Hosting and access logs
The site runs on servers rented from Hetzner Online GmbH in Germany. Every time your browser requests a page, image, or feed, the web server and reverse proxy record the request in a log file. A log entry contains:
- the IP address of the requesting device,
- date and time of the request,
- the requested URL, HTTP method, status code, and response size,
- the referring page, if your browser sends one,
- browser type and version, operating system (user agent),
- TLS version and cipher.
Purpose: delivering the site, keeping it stable and secure, detecting and analysing attacks and errors. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a functioning and secure website. Log entries are not merged with other data sources or used to build profiles. They are deleted by automatic log rotation no later than 30 days after they are written, unless an entry has to be kept as evidence of a specific security incident.
Uploaded blog images are stored in Hetzner Object Storage in Nuremberg, Germany, and served through this site. Hetzner acts as our processor under a data processing agreement pursuant to Art. 28 GDPR.
3. Content delivery and attack protection (Cloudflare)
veith.dev is delivered through the network of Cloudflare, Inc. Cloudflare provides DNS, terminates TLS at its edge, caches static files, and filters malicious traffic before it reaches our server. To do this, Cloudflare processes the technical data of each request (IP address, request headers, URL, and the metadata listed above) on its edge servers, usually the one closest to you. Where possible this happens in the EU; some processing may take place in the USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework and additionally bound by the EU standard contractual clauses in its data processing addendum (Art. 46 (2) (c) GDPR). Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a fast, available, and attack-resistant website. Cloudflare only sets a strictly necessary cookie if it presents a security challenge to suspicious traffic (§ 25 (2) no. 2 TDDDG); normal visits set none.
4. Contact by email
The only way to contact us through this site is by email to [email protected]. When you write to us we process your email address, your name if you give it, the time of the message, and everything you put in it, in order to answer you and, if it comes to that, to prepare or perform a contract. Legal basis: Art. 6 (1) (b) GDPR for enquiries about our services, otherwise Art. 6 (1) (f) GDPR, our legitimate interest in answering the people who write to us. Our mailbox is hosted by Apple (iCloud Mail). Emails may therefore be processed on Apple servers inside and outside the EU, including in the USA; Apple is certified under the EU-U.S. Data Privacy Framework and bound by the EU standard contractual clauses.
We keep your messages as long as the matter is open and, where a message counts as business correspondence, for the statutory retention period of up to six years (§ 147 AO). After that they are deleted. Please do not send us confidential information by unencrypted email; ask us for a secure channel instead.
5. Blog, feed, and content management
The blog is served by a content management system on our own infrastructure. Reading it, or fetching the RSS feed, causes only the access-log processing described in section 2. There are no visitor accounts, no comments, and no newsletter. The system has a login area that we use to publish content; it is not intended for visitors and sets an authentication cookie only for editors who log in.
6. Cookies, analytics, and third-party content
This site sets no cookies for visitors and uses no analytics, tracking pixels, or advertising technology. Fonts are served from our own server, not from Google or any other font provider. We embed no videos, maps, social-media widgets, or other third-party content that would connect your browser to another company. Links to external sites (for example to 2kw.ai) are plain links: nothing is transferred to their operators until you click, and from then on their privacy policies apply.
7. Recipients and transfers
We pass personal data only to the processors named below, on our instructions and under a data processing agreement, or where a legal obligation requires it. We do not sell data and do not share it for advertising. Transfers to the USA are covered by the EU-U.S. Data Privacy Framework (adequacy decision of 10 July 2023) and by EU standard contractual clauses as a fallback.
8. Your rights
Under the GDPR you can exercise the following rights against us at any time, informally, by email to [email protected]:
- Access (Art. 15 GDPR): what data we hold about you.
- Rectification (Art. 16 GDPR): correction of inaccurate data.
- Erasure (Art. 17 GDPR): deletion, where no retention duty applies.
- Restriction (Art. 18 GDPR): limiting how we use your data.
- Portability (Art. 20 GDPR): your data in a machine-readable format.
- Objection (Art. 21 GDPR): see the highlighted note below.
Right to object (Art. 21 GDPR). Where we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you may object at any time for reasons arising from your particular situation. We will then stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves to establish, exercise, or defend legal claims.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de
9. Security
All connections to this site are encrypted with TLS (HTTPS). Access to our servers, the content management system, and the mailbox is limited to us and protected by strong authentication. No system is perfectly secure; if you notice a problem, tell us at [email protected].
10. Automated decisions
We make no decisions based solely on automated processing, including profiling, that produce legal effects for you (Art. 22 GDPR).
11. Changes
We update this policy when the site or the law changes. The version published here is the one that applies; the date below tells you when it was last revised.
Last updated 2026-08-18