Privacy Statement
Personal data (usually referred to just as “data” below) will only be processed by us to the extent necessary and for the purpose of providing a functional and user-friendly website, including its contents, and the services offered there.
Per Art. 4 No. 1 of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as the “GDPR”), “processing” refers to any operation or set of operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction performed on personal data, whether by automated means or not.
The following privacy policy is intended to inform you in particular about the type, scope, purpose, duration, and legal basis for the processing of such data either under our own control or in conjunction with others. We also inform you below about the third-party components we use to optimize our website and improve the user experience which may result in said third parties also processing data they collect and control.
I. Information about us as controllers of your data
The party responsible for this website (the “controller”) for purposes of data protection law is:
Fabian Zankl
Kindergartenweg 4
97959 Assamstadt
Germany
Phone: +49 6294 4280632
E-Mail: info (at) fzankl.de
II. The rights of users and data subjects
With regard to the data processing to be described in more detail below, users and data subjects have the right
- to confirmation of whether data concerning them is being processed, information about the data being processed, further information about the nature of the data processing, and copies of the data (cf. also Art. 15 GDPR);
- to correct or complete incorrect or incomplete data (cf. also Art. 16 GDPR);
- to the immediate deletion of data concerning them (cf. also Art. 17 GDPR), or, alternatively, if further processing is necessary as stipulated in Art. 17 Para. 3 GDPR, to restrict said processing per Art. 18 GDPR;
- to receive copies of the data concerning them and/or provided by them and to have the same transmitted to other providers/controllers (cf. also Art. 20 GDPR);
- to withdraw, at any time and with future effect, any consent they have previously given for the processing of their data (cf. also Art. 7 Para. 3 GDPR);
- to file complaints with the supervisory authority if they believe that data concerning them is being processed by the controller in breach of data protection provisions (see also Art. 77 GDPR).
In addition, the controller is obliged to inform all recipients to whom it discloses data of any such corrections, deletions, or restrictions placed on processing the same per Art. 16, 17 Para. 1, 18 GDPR. However, this obligation does not apply if such notification is impossible or involves a disproportionate effort. Nevertheless, users have a right to information about these recipients.
Likewise, under Art. 21 GDPR, users and data subjects have the right to object to the controller’s future processing of their data pursuant to Art. 6 Para. 1 lit. f) GDPR. In particular, an objection to data processing for the purpose of direct advertising is permissible.
III. Information about the data processing
Your data processed when using our website will be deleted or blocked as soon as the purpose for its storage ceases to apply, provided the deletion of the same is not in breach of any statutory storage obligations or unless otherwise stipulated below.
Server data
For technical reasons, the following data sent by your internet browser will be collected, especially to ensure a secure and stable website: these log files record the type and version of your browser, operating system, the website from which you came (referrer URL), the webpages on our site visited, the date and time of your visit, as well as the IP address from which you visited our site.
Requests to our website first pass through the network of our CDN and security provider, Cloudflare, before reaching our hosting provider, Microsoft Azure, where the website is actually hosted. Both Cloudflare and Microsoft may process the data described above as part of operating their respective infrastructure; see the “Cloudflare” section below for details on Cloudflare’s role, including its processing of data in the United States.
Our website is hosted in an Azure data center within the EU (West Europe), provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (a subsidiary of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA). Hosting itself therefore does not involve a routine transfer of your data to a third country. Microsoft may nonetheless access data from outside the EU in individual cases, for example for support purposes; for such cases, Microsoft Corporation is self-certified under the EU-U.S. Data Privacy Framework (DPF), which the European Commission has recognized as ensuring an adequate level of data protection pursuant to Art. 45 GDPR. Microsoft’s standard Online Services Terms include a Data Protection Addendum pursuant to Art. 28 GDPR, which applies automatically to our use of Azure.
The data thus collected will be temporarily stored, but not in association with any other of your data. The basis for this storage is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality, and security of our website.
This data will be deleted as soon as it is no longer required for the purposes stated above, unless continued storage is required for evidentiary purposes — for example following a security incident — in which case all or part of the data will be excluded from deletion until the investigation is finally resolved.
Cookies
Our website itself does not set any cookies. We do not use session cookies, do not offer a login or shopping cart, and do not embed third-party advertising or tracking cookies.
Our CDN and security provider, Cloudflare, is configured for DNS resolution and reverse-proxying only (see the “Cloudflare” section below); as currently configured, it does not set any cookies on your device either. Should this change in the future — for example, if we activate a Cloudflare feature such as bot management or challenge pages, which do set cookies for security purposes — we will update this section accordingly.
If you nonetheless wish to review or clear any cookies already stored by your browser from prior visits to other websites, you can do so through your browser settings. The steps required vary depending on the browser you use; consult its help function or documentation for details.
Social media links via graphics or text-based links
We also integrate the following social media sites into our website. The integration takes place via a linked graphic of the respective site. The use of these graphics stored on our own servers prevents the automatic connection to the servers of these networks for their display. Only by clicking on the corresponding graphic will you be forwarded to the service of the respective social network.
Once you click, that network may record information about you and your visit to our site. GitHub, LinkedIn, and Medium are all US companies and may process this data in the United States as well as the EU. GitHub and LinkedIn (both part of Microsoft) are self-certified under the EU-U.S. Data Privacy Framework (DPF), which the European Commission has recognized as ensuring an adequate level of data protection pursuant to Art. 45 GDPR. We are not aware of a corresponding DPF certification for Medium; please refer to Medium’s own privacy policy, linked below, for the safeguards it applies to such transfers.
Initially, this data includes such things as your IP address, the date and time of your visit, and the page visited. If you are logged into your user account on that network, however, the network operator might assign the information collected about your visit to our site to your personal account. If you interact by clicking Like, Share, etc., this information can be stored your personal user account and possibly posted on the respective network. To prevent this, you need to log out of your social media account before clicking on the graphic. The various social media networks also offer settings that you can configure accordingly.
The following social networks are integrated into our site by linked graphics:
GitHub
GitHub Inc, 88 Colin P Kelly Jr Street, San Francisco, CA 94107 USA, a subsidiary of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA.
Privacy policy:
https://docs.github.com/en/github/site-policy/github-privacy-statement
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085 USA.
Privacy policy:
https://www.linkedin.com/legal/privacy-policy
Medium
A Medium Corporation, 799 Market Street, San Francisco, CA 94103 USA.
Privacy policy:
https://policy.medium.com/medium-privacy-policy-f03bf92035c9
Integration of services and content from third parties
We use content or service offers from third-party providers within our website on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 Para. 1 lit. f) like services such as Embed source code, videos or fonts (hereinafter uniformly referred to as “content”).
GitHub
We use GitHub, a source code management service provided by GitHub Inc, 88 Colin P Kelly Jr Street, San Francisco, CA 94107 USA, a subsidiary of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA (hereinafter: GitHub), to store some of the source content for this website.
Unlike a typical embed, this connection to GitHub does not happen when you visit our website. Our website is generated in advance (“statically built”) and the corresponding content is retrieved from GitHub only during this build process, which runs on our infrastructure, not in your browser. As a result, visiting our website does not cause any connection to GitHub or transmission of your data to GitHub.
We nonetheless mention GitHub here for the sake of transparency, since it is involved in producing the content you see. GitHub offers further information about its data collection and processing as well your rights and your options for protecting your privacy at this link: https://docs.github.com/en/github/site-policy/github-privacy-statement.
Cloudflare
We use Cloudflare for DNS resolution and as a reverse proxy in front of our actual hosting provider, to protect our website against attacks and to optimize loading times. This is a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA, hereinafter referred to as “Cloudflare”.
The legal basis for this processing is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the secure and reliable operation of our website. Because all traffic to our website is routed through Cloudflare’s network, Cloudflare processes the same access data described in the “Server data” section above (in particular your IP address, browser type, referrer URL, and the pages you access) for every visit to our website.
As currently configured, Cloudflare does not set any cookies on your device as part of this proxying. We also use Cloudflare Web Analytics to understand how our website is used. Unlike conventional analytics tools, Cloudflare Web Analytics does not use cookies or any other client-side storage and does not track individual visitors or create visitor profiles; it only produces aggregated statistics (e.g. number of page views, referrers, approximate country of origin, device type). The legal basis for this is likewise Art. 6 Para. 1 lit. f) GDPR, our legitimate interest lying in understanding and improving the usage of our website.
Cloudflare, Inc. is a US company and processes data both within the EU and in the United States. This transfer is based on Cloudflare’s self-certification under the EU-U.S. Data Privacy Framework (DPF), recognized by the European Commission as ensuring an adequate level of data protection pursuant to Art. 45 GDPR, supplemented by Standard Contractual Clauses pursuant to Art. 46 Para. 2 lit. c) GDPR for any processing not covered by the DPF. Cloudflare’s standard terms include a data processing addendum pursuant to Art. 28 GDPR, which applies to our use of its services.
We have not enabled any extended log retention or log export (e.g. Log Explorer retention or Logpush) on our Cloudflare account. As a result, Cloudflare does not retain detailed request logs beyond what is required for the real-time operation of its network (such as routing, caching, and attack mitigation).
Cloudflare offers further information about its data collection and processing as well as your rights and your options for protecting your privacy at this link: https://www.cloudflare.com/privacypolicy/.