Privacy Policy
Note: legal review of this version is underway. Until it is complete, these particulars are provisional.
1. Controller
Ivan Adamov, Silberberger Str. 33, 49076 Osnabrück, Deutschland
Email: [email protected]
2. Hosting and delivery (DigitalOcean, Cloudflare)
This website is delivered from a server we operate at DigitalOcean, LLC in the Frankfurt am Main data centre; delivery therefore takes place within the European Union. Upstream of it sits the delivery and security network of Cloudflare, Inc. (USA): every request first reaches a Cloudflare location, that is where your encrypted connection ends, and from there the request is passed on to our server in encrypted form. In doing so Cloudflare processes your IP address, the time of the request, the address requested, the page you came from (Referrer) and the identifier of your browser (User-Agent), wards off overload attacks and automated bulk requests, and derives from your IP address the coarse location described in section 6. On our own server the same items are recorded in an access log; this log is deleted after 14 days. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest consists in delivering the service free of technical faults and at a reasonable speed, securing its availability and warding off automated bulk requests that endanger the operation. On the transfer to the United States, see section 14. For the event of a fault we additionally keep a ready-to-run standby delivery at Vercel Inc. (USA); in normal operation it is not part of the route your request takes and processes no data of readers.
To ward off automated bulk requests we limit the number of requests per sender. The identifier derived from your IP address is held for that purpose solely in the working memory of the processing instance as a counter, for at most 60 seconds, and is then discarded. It is not logged, not stored in a database and linked with nothing.
3. Database
The content database (articles, sections, source register) runs on a server we operate at DigitalOcean, LLC in the Frankfurt am Main data centre. Processing therefore takes place within the European Union. Backup copies are held, first, on that same server, where they are deleted after seven days, and second, in the DigitalOcean Spaces object storage in the fra1 region (Frankfurt am Main), where they are deleted after 30 days. The object storage is not publicly accessible and transmission to it is encrypted.
Personal data of readers is stored in this database only if you have subscribed to our Telegram bot (see section 15). The legal basis for this is your consent; see section 15.
4. Editorial system and media storage
We use an editorial system and Vercel Blob as media storage for editorial content and our own pictures. No visitor data is processed there either.
Images from Wikimedia Commons, Openverse and Wikipedia we do not embed directly. We fetch the file with our own server and deliver it from our own address. For you that means: when you view a report none of those image providers learns that you have opened this page, and your IP address does not reach them.
5. Search
What you enter in the search field is sent to our own server and matched there against the stock of our reports. The matching runs in our content database in the Frankfurt am Main data centre (section 3); no third-party search service is involved. Search queries are not stored in the database, are not assigned to any account or person, and no search profiles are formed. A search term is held for up to one hour in the application’s cache so that the same query need not be executed repeatedly; there it is associated with the term itself and with no person.
Frankly: as part of the address requested your search term appears in the access log of our server (section 2), where it may stand next to your IP address until it is deleted after 14 days; since your encrypted connection ends at Cloudflare, it is visible there too. It does not reach our audience measurement (section 6): before transmission the address is stripped of the search part. The legal basis is Art. 6 Abs. 1 lit. f DSGVO; our legitimate interest is the answering of the query you yourself submitted.
6. Audience measurement and consent
For the audience measurement described below we ask you before it takes place. On your first visit a notice appears with two identically styled buttons: one that agrees and one that declines — nothing preselected, neither answer given more weight than the other. Until you agree, nothing is measured. If you decline, the site stays exactly as it is and remains fully usable; no content and no function is missing.
There are two entries to choose from. Essential covers delivering the page, warding off automated bulk requests, and the display settings you chose yourself; this entry is always active, because without it no page would be delivered at all — which is also why it is not something we would let you decide about. Audience measurement is off until you switch it on; it is the only thing this notice is really about. You can accept everything, decline everything, or save your choices one by one.
Your decision is kept solely in your own browser: in local storage, under the entry “tagblick:consent:v1”, holding the categories you chose and the time you chose them. It is not transmitted to us and is linked with nothing. We keep no register of consents given, and so we cannot connect your decision to any record held by us. Storing this entry and reading it back later require no consent under § 25(2) no. 2 TDDDG: both happen for the sole purpose of carrying out the decision you made yourself.
You may withdraw your consent at any time with effect for the future, and just as easily as you gave it: . The same button sits in the footer of every page. Withdrawal takes effect immediately — from that moment nothing further is measured. The lawfulness of the processing carried out until then is unaffected (Art. 7(3) GDPR). If you clear your browser’s data for this site, the starting position applies again: no measurement, and we ask afresh on your next visit.
The legal basis for the measurement is your consent (Art. 6(1)(a) GDPR); in so far as it is regarded as access to your terminal equipment, it is at the same time the consent required by § 25(1) TDDDG. In our assessment there is no such access: the measurement works without a cookie, stores nothing on your device and reads nothing from it — nor does it ask your device for its screen size or language setting, as the usual measurement tools do. We ask nonetheless. The supervisory authorities recognise no general exemption for audience analysis of this scope, and expressly decline to make any such statement (Conference of the Independent Federal and State Data Protection Supervisory Authorities of Germany, Guidance for providers of digital services, version 1.2, November 2024, paras. 87–90). Asking for your consent is the position that does not depend on winning that argument.
We count which pages are read — because otherwise we would not know which subjects reach our readers at all. For that we run our own installation of the open-source software Umami on our own server in the Frankfurt am Main data centre (DigitalOcean, LLC): a separate instance with its own database. No third-party analytics service is embedded. The data does not leave our own infrastructure, is not combined with other sources, not passed on, not sold and not used for advertising. The legal basis is your consent (Art. 6(1)(a) GDPR); on withdrawing it, see above.
The route the data takes. Your browser reports the page view to THIS website (/api/besuch), not to the statistics server. Our server receives the report, takes from your request the coarse location the upstream network of Cloudflare, Inc. (section 2) has already worked out, and passes on only that, together with the items listed below. Your IP address is not passed on: in its place the statistics server receives a placeholder address reserved for documentation purposes by RFC 5737 and belonging to nobody (203.0.113.1). It never knows your actual address — and has no field in which it could store it either.
The identifier. It is a random number your browser generates when the tab is opened and holds only in that tab’s memory. It is not placed on your device and not read from your device; close the tab and it is gone. Its sole purpose is to count several page views of one visit as one visit. Recognising you on a later visit, on another device or on another website is therefore impossible.
What is not stored. Your IP address. A cookie. An entry on your device. Your name, your email address, your screen size, your language setting. The last two are named here deliberately, because the usual measurement tools ask the device for them — ours does not.
We do not call this data anonymous. Taken on its own it names nobody, but the combination of place, time, device details and pages read may establish a link to a person. We therefore treat it as personal data throughout.
Retention. Individual measurement data is deleted after three months. Three months is the period during which we still work with individual page views at all; after that the individual row answers no question we still ask and would remain only as a risk. Before a month is deleted we aggregate it into totals — four separate tables of daily values: pages read, country and region, referrer, and browser, operating system and device type. We keep these totals permanently; they are our statistics over the years. Not carried over are the visit identifier, the sequence of pages read within a visit, and the time of day; they are deleted with the month. Above all the link between the four tables is broken: that a particular visit from a particular region with a particular device read a particular page can no longer be reconstructed from the totals — and it was precisely that link which made the individual rows referable to a person. If a region records fewer than five visits on a given day it is dropped from the totals and the visit is attributed only to the country; the count per country remains complete in every case. Deletion takes place only after the totals have been written and checked against the source data. We regard the totals as anonymous and therefore no longer treat them as personal data; there is then no period after which they would have to be deleted.
The server is in the European Union, the provider is not. DigitalOcean, LLC is established in the United States. Processing takes place in the Frankfurt am Main data centre; access from the United States in the course of operation and support cannot, however, be ruled out. On the basis for that transfer, see the section “International data transfers”.
Exactly the following is stored for each page view:
- the address of the page requested on this website — including the campaign identifiers (utm_…) of a link that brought you to us; other parameters appended to it, a search term for instance, are trimmed off before we pass the address on
- the title of the page
- the address you came to us from (referrer), in so far as your browser transmits it
- browser, operating system and device type — in each case only the family and not the version, i.e. “Chrome” and not “Chrome 128”, “Windows” and not “Windows 11” —, as they follow from the identifier your browser sends with every request anyway
- country and region, i.e. state and federal state, as the delivery network derives them from your IP address — coarsely, and without the address itself; the delivery network also determines the place and passes it to our server, but we do not accept it and store it nowhere
- the time of the request
- the random identifier of the open browser tab (see above)
7. Error diagnostics (Sentry)
To keep the service stable we collect technical error reports using Sentry (Functional Software Inc.) via its EU region. Reports are reduced to the necessary minimum: the IP address, cookies and request headers are removed from the report before it is sent (Art. 6(1)(f) GDPR). Our legitimate interest consists in being able to notice and remedy faults and errors in the operation at all before they affect readers.
8. Use of artificial intelligence
Our own items are produced automatically and with AI assistance from the headlines and short teasers of the newsrooms reporting an event, and are machine-translated into the other language editions of this service. No individual editorial review takes place before publication. Only those headlines and teasers and our own texts are transmitted to the language service used (OpenAI, L.L.C., USA) — no reader data. Every item produced this way is marked as AI-assisted at the end of the article (Art. 50 AI Act).
The hourly processing of our content runs on the infrastructure of GitHub, Inc. (USA). Data of readers are not processed in the course of it. Access credentials for our services we manage with Doppler, Inc. (USA); no reader data are processed there either.
9. Newsletter
No newsletter is offered at present. Should one be introduced, we will set out the provider, the double opt-in procedure and how to withdraw here.
10. Contacting us
If you contact us by email we process your details in order to deal with your enquiry (Art. 6 Abs. 1 lit. f DSGVO; our legitimate interest is the answering of enquiries addressed to us — in the case of enquiries concerning a contractual relationship, for example partner content, Art. 6 Abs. 1 lit. b DSGVO) and delete them once they are no longer needed and no statutory retention period applies.
11. Cookies and local storage
On a visit to this website a cookie is, as a rule, placed in your browser. It does not come from our application but from the upstream delivery and security network of Cloudflare, Inc., through which every request to this website passes (section 2); under data protection law we are the controller for it. For this Cloudflare embeds a script in every page, which your browser executes and which is intended to distinguish automated from human access; your browser reports the result back, and with that response the security cookie “cf_clearance” is set. It sits on the domain of this website, but is sent along to Cloudflare on every further visit, because that is where your encrypted connection ends. It expires after one year; for this check your browser is thereby recognised again. Set as “HttpOnly”, no script in your browser can read it — not even Cloudflare’s own. It measures no audience, does not serve advertising and forms no profile; your decision on audience measurement does not affect it, and it is set even when you decline the measurement. For our own purposes we set no cookies — neither for analytics nor for advertising; audience measurement (section 6) likewise works without a cookie. We did not switch this check on, and in the plan currently in use it cannot be switched off through the interface; the decision to deliver this website through this network is nevertheless ours. The legal basis for the processing this involves is, in our assessment, Art. 6(1)(f) GDPR, with the legitimate interest named in section 2; on the transfer to the United States, see section 14, and on objecting, the section “Right to object (Art. 21 DSGVO)”. The execution of the script, the storing of the cookie and its later reading we regard as consent-free under § 25 Abs. 2 Nr. 2 TDDDG, because in our assessment they serve solely to deliver the page you requested in protected form at all. That is our assessment and not a settled legal position — whether a security cookie with a lifetime of one year counts in full as strictly necessary has not been conclusively decided; were that assessment to prove incorrect, the only course left to us would be to change the delivery of this website so that the check no longer takes place.
In the local storage of your browser we store exclusively settings that you yourself have chosen. They are not transmitted to us, not evaluated and linked with nothing; you can delete them at any time via your browser settings:
These entries are read when every page is built — otherwise your setting could not be applied. Both the storing and the reading are consent-free under § 25 Abs. 2 Nr. 2 TDDDG: they happen only because you expressly chose the setting in question, and are strictly necessary to provide you with the service in the form you requested. Before your first own input this storage is empty — on the first visit it is read, but nothing is written.
- tagblick:consent:v1 — your decision on audience measurement including the time
- tagblick:theme — light or dark appearance
- tagblick:font — chosen reading typeface
- tagblick:motion — switching off of animations
- tagblick:a11y — reading aids: text size, line and character spacing, high contrast, colour-vision-friendly mode, underlining of links
- tagblick:ticker — whether you have closed the breaking-news ticker
12. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Consent given may be withdrawn at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
The supervisory authority competent for us is: Der Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover (postal address: Postfach 221, 30002 Hannover), telephone 0511 120-4500, [email protected]. Independently of that you may also turn to the supervisory authority of your habitual residence or place of work (Art. 77 Abs. 1 DSGVO).
No automated decision-making. We take no decisions concerning you that are based solely on automated processing — including profiling — and that produce legal effects concerning you or similarly significantly affect you (Art. 22 DSGVO). That our reports are machine-written and translated (section 8) is not such a decision: it concerns the content of our service, not your person. There is also no profiling of readers; audience measurement (section 6) evaluates exclusively aggregated figures and does not know you beyond a single visit.
Provision of your data. To read this service you need not provide us with anything — there is no account, no registration and no form that requires an entry. Data are required only where you yourself make use of an additional service: the chat identifier assigned by Telegram if you subscribe to our bot (section 15), and your sender details if you write to us (section 10). You are under neither a legal nor a contractual obligation to provide them; without them, however, the respective service cannot be provided. There are no further consequences.
Right to object (Art. 21 DSGVO)
Where we process personal data on the basis of legitimate interests (Art. 6 Abs. 1 lit. f DSGVO) — that concerns the delivery of the page and the server logs (section 2), the warding off of automated bulk requests including the security check of the upstream network and the cookie set in the course of it (sections 2 and 11), the search (section 5) and the technical fault diagnosis (section 7) —, you may object to this processing at any time on grounds relating to your particular situation.
An informal message to [email protected] is sufficient; there is no particular form and none is required. We then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms. We reply to you in every case and give reasons if we do not follow the objection.
Audience measurement (section 6) does not rest on a legitimate interest but on your consent. There you need no objection: a click on ends the measurement immediately.
13. Retention
We process personal data only for as long as it is needed for the purposes stated or a statutory retention period applies; after that it is deleted or anonymised.
14. International transfers
Where service providers established in a third country — in particular the United States — are used, that concerns Cloudflare, Inc. (delivery and warding off of automated access, section 2), Vercel Inc. (media storage and standby delivery, sections 2 and 4) and the further providers named in this policy. Transfers take place on the basis of adequacy decisions (EU-US Data Privacy Framework) or EU standard contractual clauses.
15. Telegram channels and Telegram bot
We also offer our reports via Telegram: one channel per edition, and a bot that lets you choose the language, the sections and how often you receive them. Use is voluntary; the website works fully without Telegram.
When you start the bot we store only: the chat identifier assigned by Telegram, the chosen language, the chosen sections and the chosen delivery interval. We store neither your name nor your telephone number nor the history of your messages. The legal basis is your consent, given by starting the bot (Art. 6(1)(a) GDPR).
With the command /stop the record is deleted from the live database. The same happens if you block the bot. In the encrypted backup copies (section 3) the chat identifier may still be contained for up to 30 days; these copies are kept solely for recovery in the event of a fault and are then deleted automatically.
Telegram is itself independently responsible for the messenger service; we have no influence over its processing. The operator is Telegram FZ-LLC or Telegram Messenger Inc., established outside the European Union. No adequacy decision of the European Commission is in place. Please refer to Telegram's own privacy policy.
When you start the bot, Telegram transmits to us technically more than we retain: in addition to the chat identifier also the first name stored in your Telegram profile, if applicable the surname and username, and the language code of your device. We store none of that except the chat identifier; the other details are discarded as soon as the message has been processed and are not logged either.
The use of Telegram necessarily involves a transfer to a country for which there is no adequacy decision of the European Commission and for which no standard contractual clauses exist either. This transfer rests solely on your express consent under Art. 49 Abs. 1 Unterabs. 1 lit. a DSGVO. We expressly draw your attention to the associated risks: a level of protection equivalent to European law may not be guaranteed there, access by state authorities to your data cannot be ruled out, and effective legal remedies may not be available to you. You can avoid this risk entirely: the website is fully usable without Telegram, and you receive the same reports there.