VEITH.DEV

Legal · Datenschutzerklärung

Privacy Policy

The short version: this site sets no cookies, runs no analytics, and loads nothing from third-party trackers. It stores what any web server needs to run and defend itself, and what you send us when you email us. The long version follows.

Controller (Art. 4 (7) GDPR)

Falk Wittmann

Schopenhauerstraße 35C
70565 Stuttgart, Germany
Contact for privacy matters

[email protected]

No data protection officer is required for this site (§ 38 BDSG) and none has been appointed. Write to the address above for anything privacy-related.

1. Scope

This policy covers the website https://veith.dev including the blog and its RSS feed. It explains which personal data is processed when you use the site or contact us, for what purpose, on which legal basis, how long it is kept, and which rights you have. Personal data means any information relating to an identified or identifiable person (Art. 4 (1) GDPR).

2. Hosting and access logs

The site runs on servers rented from Hetzner Online GmbH in Germany. Every time your browser requests a page, image, or feed, the web server and reverse proxy record the request in a log file. A log entry contains:

Purpose: delivering the site, keeping it stable and secure, detecting and analysing attacks and errors. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a functioning and secure website. Log entries are not merged with other data sources or used to build profiles. They are deleted by automatic log rotation no later than 30 days after they are written, unless an entry has to be kept as evidence of a specific security incident.

Uploaded blog images are stored in Hetzner Object Storage in Nuremberg, Germany, and served through this site. Hetzner acts as our processor under a data processing agreement pursuant to Art. 28 GDPR.

3. Content delivery and attack protection (Cloudflare)

veith.dev is delivered through the network of Cloudflare, Inc. Cloudflare provides DNS, terminates TLS at its edge, caches static files, and filters malicious traffic before it reaches our server. To do this, Cloudflare processes the technical data of each request (IP address, request headers, URL, and the metadata listed above) on its edge servers, usually the one closest to you. Where possible this happens in the EU; some processing may take place in the USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework and additionally bound by the EU standard contractual clauses in its data processing addendum (Art. 46 (2) (c) GDPR). Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a fast, available, and attack-resistant website. Cloudflare only sets a strictly necessary cookie if it presents a security challenge to suspicious traffic (§ 25 (2) no. 2 TDDDG); normal visits set none.

4. Contact by email

The only way to contact us through this site is by email to [email protected]. When you write to us we process your email address, your name if you give it, the time of the message, and everything you put in it, in order to answer you and, if it comes to that, to prepare or perform a contract. Legal basis: Art. 6 (1) (b) GDPR for enquiries about our services, otherwise Art. 6 (1) (f) GDPR, our legitimate interest in answering the people who write to us. Our mailbox is hosted by Apple (iCloud Mail). Emails may therefore be processed on Apple servers inside and outside the EU, including in the USA; Apple is certified under the EU-U.S. Data Privacy Framework and bound by the EU standard contractual clauses.

We keep your messages as long as the matter is open and, where a message counts as business correspondence, for the statutory retention period of up to six years (§ 147 AO). After that they are deleted. Please do not send us confidential information by unencrypted email; ask us for a secure channel instead.

5. Blog, feed, and content management

The blog is served by a content management system on our own infrastructure. Reading it, or fetching the RSS feed, causes only the access-log processing described in section 2. There are no visitor accounts, no comments, and no newsletter. The system has a login area that we use to publish content; it is not intended for visitors and sets an authentication cookie only for editors who log in.

6. Cookies, analytics, and third-party content

This site sets no cookies for visitors and uses no analytics, tracking pixels, or advertising technology. Fonts are served from our own server, not from Google or any other font provider. We embed no videos, maps, social-media widgets, or other third-party content that would connect your browser to another company. Links to external sites (for example to 2kw.ai) are plain links: nothing is transferred to their operators until you click, and from then on their privacy policies apply.

7. Recipients and transfers

We pass personal data only to the processors named below, on our instructions and under a data processing agreement, or where a legal obligation requires it. We do not sell data and do not share it for advertising. Transfers to the USA are covered by the EU-U.S. Data Privacy Framework (adequacy decision of 10 July 2023) and by EU standard contractual clauses as a fallback.

Hosting and storage
Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Germany
Data centres in Germany
Privacy policy →
DNS, CDN, TLS termination, attack protection
Cloudflare, Inc.
101 Townsend St., San Francisco, CA 94107, USA
Global edge network; EU-U.S. Data Privacy Framework and EU standard contractual clauses
Privacy policy →
Apple Distribution International Ltd. (iCloud Mail)
Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
EU and USA; EU-U.S. Data Privacy Framework and EU standard contractual clauses
Privacy policy →

8. Your rights

Under the GDPR you can exercise the following rights against us at any time, informally, by email to [email protected]:

Right to object (Art. 21 GDPR). Where we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you may object at any time for reasons arising from your particular situation. We will then stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves to establish, exercise, or defend legal claims.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de

9. Security

All connections to this site are encrypted with TLS (HTTPS). Access to our servers, the content management system, and the mailbox is limited to us and protected by strong authentication. No system is perfectly secure; if you notice a problem, tell us at [email protected].

10. Automated decisions

We make no decisions based solely on automated processing, including profiling, that produce legal effects for you (Art. 22 GDPR).

11. Changes

We update this policy when the site or the law changes. The version published here is the one that applies; the date below tells you when it was last revised.

Last updated 2026-08-18

← Back to home

Next Step

You Bring the Problem. We Ship the System.

One call to scope it. If it's a fit, you'll usually see working software within days. No discovery workshop, no deck.