ἀκρίβεια — exactness EN · DE
Privacy

No cookies. No banners. No tricks.

The short version: this site sets no cookies, shows no consent banner because it doesn’t need one, and measures traffic anonymously on my own domain. You are never profiled across sites, and nothing here is sold or shared for advertising.

Last updated: 21 July 2026 · draft, pre-launch

Draft — finalised before public launch. This page documents the already-implemented, intended data practices. Still to be filled in with the imprint: the controller’s name and address, the final competent supervisory authority, and exact retention periods. Third-country transfer mechanisms (below) are re-verified at launch, and the whole page is reviewed by a data-protection lawyer before anything commercial goes live.
§

Controller

The controller responsible for data processing on this site is the individual who operates it. [Legal name, postal address (a full, court-serviceable address) and contact email are supplied with the imprint before launch.] No data protection officer is appointed, as the statutory thresholds (§ 38 BDSG) are not met.

§

What I process, and on what basis

I keep data collection to the minimum each purpose needs (Art. 5(1)(c) GDPR). In short: hosting and analytics run on my legitimate interest in operating and understanding my own site (Art. 6(1)(f) GDPR); the newsletter runs only on your consent (Art. 6(1)(a) GDPR); enquiries you send me are processed to answer them (Art. 6(1)(b) and (f) GDPR). Each is detailed below.

§

Hosting & server logs

The site is served as static files via Cloudflare Pages (Cloudflare, Inc.). Like every host, Cloudflare processes technical connection data — including your IP address and user agent — in server logs, to deliver the site and defend it against abuse. Legal basis: my legitimate interest in the secure, stable operation of the site (Art. 6(1)(f) GDPR). I do not use this data to identify you. Cloudflare is certified under the EU–US Data Privacy Framework, so this transfer to the USA rests on the European Commission’s adequacy decision of 10 July 2023 (see international transfers).

§

Analytics

I use PostHog, self-served through this domain and hosted in the EU (Frankfurt), in cookieless, anonymous mode. It sets no cookies, writes nothing to your device, and creates no persistent or cross-site identifier. Your IP address is processed only transiently to handle the request and is not stored to identify you or build a profile. What I see is aggregate, page-level usage — which pages are read, roughly where visitors arrive from, how far posts are read — never who you are, and no personal data stored over time. Legal basis: my legitimate interest in measuring and improving my own site (Art. 6(1)(f) GDPR); you can object at any time (see right to object).

Session replay and surveys are disabled. Replay would only ever run if you explicitly opted in on a page that asks — and no such opt-in exists anywhere.

§

Cookies & device storage

This site stores nothing on your device and reads nothing from it — no cookies, no local or session storage, no fingerprinting. Because § 25 TDDDG (Germany’s transposition of the ePrivacy rules) is triggered only by storing or accessing information on your device, and this site does neither, no consent banner is required. The site also loads no third-party fonts, embeds, or widgets that would reintroduce such storage.

§

Newsletter

If you subscribe, your email address is processed by beehiiv, Inc. (the newsletter platform) for the sole purpose of sending you the issues you signed up for. Legal basis: your consent (Art. 6(1)(a) GDPR; § 7 UWG for email in general).

Signup is double opt-in: you enter your address, receive a confirmation email containing no advertising, and are subscribed only after you click the link. To prove your consent, the time and IP address of your registration and confirmation are logged (Art. 7(1) GDPR). You can withdraw consent at any time — every issue carries an unsubscribe link that works immediately and completely, with no effect on the lawfulness of processing before withdrawal. beehiiv is US-based and transfers data to the USA under EU Standard Contractual Clauses (see international transfers).

§

Contact & enquiries

If you contact me — by email, or through a contact form if one is offered — I process the details you provide (such as your name, your message, and a reply address) to handle your enquiry. Legal basis: steps prior to a possible contract where relevant (Art. 6(1)(b) GDPR), otherwise my legitimate interest in answering correspondence (Art. 6(1)(f) GDPR). I ask only for what an answer needs, and I delete enquiries once they are dealt with, unless a statutory retention period applies.

§

Analytics for subscribers (planned)

Should I later measure how subscribers use the newsletter or the site to improve it, that would be done through server-side events tied to your account — not by storing anything on your device — on the basis of my legitimate interest in improving the product (Art. 6(1)(f) GDPR), following a documented balancing test and subject to your right to object (Art. 21 GDPR). This is not active yet; this section is confirmed before it is.

§

International transfers (USA)

Two processors are US-based, on two different legal footings:

  • Cloudflare (hosting) — certified under the EU–US Data Privacy Framework; the transfer rests on the European Commission’s adequacy decision of 10 July 2023.
  • beehiiv (newsletter) — not DPF-certified; the transfer rests on EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). A copy of the safeguards is available on request.

Both are re-verified before launch, since certifications and adequacy decisions can change.

§

Retention

I store personal data only as long as the purpose requires. Server logs are kept briefly for security and then deleted; analytics data is anonymous and aggregate; newsletter data is kept until you unsubscribe (with the consent record kept for a limited period afterwards as proof); enquiries are deleted once resolved, subject to statutory retention obligations. [Exact periods are finalised with the imprint.]

§

Your rights

Under the GDPR you have the right to:

  • access your data (Art. 15), and rectify (Art. 16) or erase it (Art. 17);
  • restrict processing (Art. 18) and to data portability (Art. 20);
  • object to processing based on legitimate interest (Art. 21 — see below);
  • withdraw any consent you have given, at any time, with future effect (Art. 7(3));
  • lodge a complaint with a supervisory authority (Art. 77 — see below).

For anything newsletter-related the unsubscribe link is the fastest route; for everything else, the contact in the imprint.

§

Right to object

Where I process your data on the basis of legitimate interest (Art. 6(1)(f) GDPR) — hosting, analytics, and correspondence — you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). On objection I stop that processing unless I can show compelling legitimate grounds that override your interests.

§

Complaint to a supervisory authority

You have the right to lodge a complaint with a data-protection supervisory authority — in particular the competent authority of the federal state of your residence, workplace, or the place of the alleged infringement. As the controller is based in Bavaria, the competent authority here is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Ansbach. [Confirmed against the controller’s final seat in the imprint.]

§

Encryption & automated decisions

The site is served exclusively over TLS/HTTPS. There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.

§

Changes

I update this policy when the site’s data practices change, and note the date at the top. The current version always lives at this address.