Skip to content

Introduction

With the following privacy policy we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us within the scope of our online offering.

The terms used are not gender-specific.

This English version is provided for your convenience. In the event of any discrepancy, the German version of this privacy policy prevails.

Last updated: 2 September 2026


Controller

Christian Götze Rathenaustr. 3 16761 Hennigsdorf Germany

Email: mail@cgoetze.de Phone: +49 33022015238 Legal notice (Impressum): https://www.cgoetze.de/imprint

A data protection officer is not required by law (Section 38 BDSG).


Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects.

Types of data processed

  • Inventory data (e.g. names)
  • Contact data (e.g. email)
  • Content data (e.g. text entered in the contact form)
  • Meta/communication data (e.g. IP addresses, access times, browser type)

Categories of data subjects

  • Communication partners (persons who contact us via the contact form)
  • Users (visitors to our website)

Purposes of processing

  • Provision of our online offering and web hosting
  • Contact requests and communication
  • Spam protection for the contact form
  • Security measures
  • Audience measurement / web analytics

Relevant legal bases

Below we share the legal bases of the General Data Protection Regulation (GDPR) on which we process personal data. In addition, the national data protection requirements in Germany apply, in particular the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).

  • Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract or for taking pre-contractual steps.
  • Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary to safeguard our legitimate interests, provided that the interests or fundamental rights and freedoms of the data subject do not override them.

Security measures

We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, in order to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling access to the data as well as its input and disclosure. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures.

TLS encryption (https): To protect the data transmitted via our online offering, we use TLS encryption. You can recognise encrypted connections by the prefix https:// in the address bar of your browser.

Collection from the data subject: We collect personal data exclusively directly from the data subjects.

Automated decision-making: Automated decision-making within the meaning of Art. 22 GDPR takes place within the scope of the CrowdSec protection insofar as IP addresses may be blocked automatically for 24 to 96 hours. A review of the block is possible on request. Otherwise, no automated decision-making takes place.


Transfer to recipients and processors

To operate this online offering we use service providers who act for us within the scope of processing on our behalf (Art. 28 GDPR). Corresponding data processing agreements have been concluded with all processors. In addition, within the scope of our IT security measures we transfer the IP addresses of detected attackers to CrowdSec SAS, which processes this data as an independent controller (see section "Provision of the online offering and web hosting"). No transfer to third countries outside the EEA takes place.


Provision of the online offering and web hosting

We operate this online offering on a dedicated server in a data centre in Falkenstein, Germany.

Collection of access data and log files: When our online offering is accessed, access data is recorded on the server side in so-called server log files. This regularly includes: IP address, date and time of access, requested URL, HTTP method, amount of data transferred, status message, browser type and version (user agent), and referrer URL. The storage serves to ensure operation, IT security (in particular the detection and prevention of attacks) and error analysis. The log files are stored exclusively on our own server in Germany and are not transmitted to any external service provider. They are deleted as soon as they are no longer required for the stated purposes, as a rule after 30 days. If log data continues to be required to investigate a specific security incident, storage is restricted until the matter has been finally clarified.

Defence against attacks (intrusion detection): To detect and defend against attacks (e.g. brute-force attempts, automated scanners) we use the open-source software CrowdSec. CrowdSec analyses the above-mentioned log files and can block suspicious IP addresses for a limited period (as a rule 24 to 96 hours). As part of the standard configuration, information about detected attacks (in particular the attacker's IP address and the type of detection) is transmitted to the central CrowdSec API of CrowdSec SAS, 24 Rue Saint Lazare, 75009 Paris, France in order to participate in a community block list. The transfer takes place exclusively for IT security purposes and relates to IP addresses that have been associated with an attack attempt, not to regular website visitors. CrowdSec SAS processes the transmitted IP addresses as an independent controller for the purposes of the collective protection of its network; this is not processing on our behalf. As CrowdSec SAS is based in France, the transfer takes place within the European Economic Area. Our legitimate interest lies in defending against automated attacks and participating in a collective protection system. The transfer is limited to IP addresses that have been associated with a documented attack attempt; regular visitors are not affected. Conflicting interests of the data subjects worthy of protection do not override this, as only attacker IPs and no content data are transmitted. CrowdSec privacy policy: https://www.crowdsec.net/privacy-policy.

DNS resolution: The DNS zones of our domain are hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; the authoritative name servers are operated in Germany. No transfer to third countries outside the EEA takes place in this context. Legal basis: legitimate interests in the reliable accessibility of our online offering (Art. 6(1)(f) GDPR).

  • Types of data processed: Meta/communication data (e.g. IP addresses, access times, browser type).
  • Data subjects: Users (website visitors).
  • Purposes of processing: Provision of the online offering, IT security, error analysis.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR – interest in secure and stable operation).

Hosting provider used


Web analytics (Matomo)

Self-hosted audience measurement with Matomo: To statistically analyse how our online offering is used, we use Matomo, an open-source web analytics tool. Matomo runs exclusively on our own infrastructure at https://matomo.cgoetze.de; the collected data is processed solely on our own server in Germany and is not shared with any third party — in particular not with the makers of Matomo (InnoCraft Ltd.). No transfer to third countries outside the EEA takes place. The tool is embedded via a self-hosted Matomo Tag Manager container; a page view is recorded on the initial page load and on client-side navigations within the online offering (single-page navigation). In addition, aggregate content-free interaction events may be recorded as Matomo actions (fixed category/action/name enums only, e.g. optional display modes) — without form content, free-text user input, or a User ID.

Cookieless processing without consent: Matomo is configured in a privacy-friendly way. It sets no cookies and does not access information already stored on your device; local browser storage (local storage, session storage) is not used for analytics. Because no information within the meaning of Section 25(1) TDDDG is stored on or read from your device, neither consent nor a consent banner is required. Your IP address is anonymised (the final bytes are truncated) before any storage, and any geolocation is derived only from the already-anonymised IP address. There is no cross-site tracking. As no cookies are used, the page views within a session are linked only by means of a server-side value derived from the already-anonymised IP address and general browser information (e.g. browser type and language setting), which is regenerated daily. This does not allow any persistent or cross-device recognition of individual visitors — in particular, no persistent device fingerprinting takes place. No individual user profiles are built and no User ID is used; the resulting statistics are aggregated and do not allow any conclusions about individual persons. The raw data collected for audience measurement (visitor logs) is automatically deleted after 90 days; aggregated, anonymous reports are deleted after 12 months.

Objection and "Do Not Track": Our Matomo installation respects your browser's "Do Not Track" setting. If your browser sends a "Do Not Track" signal, you are not included in the audience measurement. You may also object to this processing at any time with effect for the future (Art. 21 GDPR).

  • Types of data processed: Meta/communication data (e.g. shortened/anonymised IP addresses, access times, pages viewed, anonymised referrer URL (domain only), approximate region, device and browser type, screen resolution, language setting).
  • Data subjects: Users (website visitors).
  • Purposes of processing: Audience measurement / web analytics; needs-based, statistically sound optimisation of the online offering.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR – interest in the statistical analysis and optimisation of the online offering); Section 25(1) TDDDG does not apply, as nothing is stored on or read from the device.

Contact

When you contact us (e.g. via the contact form or by email), the information you provide is processed insofar as this is necessary to respond to your request. The information is deleted as soon as it is no longer required for the purpose, as a rule no later than 6 months after the request has been finally processed, unless statutory retention obligations apply.

Spam protection with Altcha: To protect against automated requests (spam, abuse), we use a self-hosted challenge solution (Altcha) in the contact form. Altcha performs the challenge on the client side in the browser. In doing so, technical information (e.g. challenge status) may be stored temporarily in your browser's storage (session storage). This storage is strictly necessary pursuant to Section 25(2)(2) TDDDG in order to provide the service you have requested (spam protection of the contact form) and therefore takes place without consent. No data is transmitted to third parties and no cookies are set.

Email dispatch: To send the emails generated via the contact form, we use an external email dispatch service provider (see below).

  • Types of data processed: Inventory data (e.g. names), contact data (e.g. email), content data (text entries).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact requests and communication, spam protection.
  • Legal bases: Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

Email dispatch service provider used


Cookies and similar technologies

Our online offering uses a single, strictly necessary cookie for its own purposes: the first-party cookie "NEXT_LOCALE" stores the language you have chosen (German or English) so that the server can deliver pages in the right language version straight away. It is set as soon as you open a language version that differs from your browser's language; it contains nothing but the language code, is sent only to our own server, is not used for tracking, and is a session cookie that is deleted when you close your browser. This storage is strictly necessary under Section 25(2)(2) TDDDG to provide the language version you have expressly requested and therefore takes place without consent. We set no other cookies. Local browser storage (session storage) is used for the strictly necessary spam protection of the contact form (see section "Contact") and for the optional session-only 1990s view (current browser tab only, not across visits). Local storage may hold your explicit light/dark preference. This storage, too, is strictly necessary under Section 25(2)(2) TDDDG for the presentation you requested or for spam protection and therefore takes place without consent. Cookieless, consent-free audience measurement takes place via a self-hosted Matomo installation (see section "Web analytics (Matomo)"); no tracking in the sense of cross-device recognition or profiling takes place.


Deletion of data

The data processed by us is deleted in accordance with the legal requirements as soon as the consents permitted for processing are revoked or other permissions cease to apply (e.g. if the purpose of processing this data no longer applies or it is not required for the purpose).

If the data is not deleted because it is required for other and legally permissible purposes, its processing is restricted to those purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for the assertion, exercise or defence of legal claims.


Amendment and updating of the privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing carried out by us make this necessary.


Rights of data subjects


Right to object (Art. 21 GDPR)

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR.


As a data subject, you are also entitled to further rights under the GDPR, which arise in particular from Art. 15 to 18 and 20 GDPR:

  • Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether data concerning you is being processed and to obtain information about this data as well as further information and a copy of the data.
  • Right to rectification (Art. 16 GDPR): You have the right to request the completion or rectification of data concerning you.
  • Right to erasure (Art. 17 GDPR): You have the right to request the erasure of data concerning you.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of the processing of your data.
  • Right to data portability (Art. 20 GDPR): You have the right to receive data concerning you in a structured, commonly used and machine-readable format or to request its transmission to another controller.
  • Complaint to the supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow; phone: +49 33203 356-0; email: poststelle@lda.brandenburg.de.

Definitions of terms

In this section you will find an overview of the terms used in this privacy policy. Many of the terms are taken from the law and defined primarily in Art. 4 GDPR. The legal definitions are binding.

  • Personal data: Any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier.
  • Controller: The natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: Any operation or set of operations performed on personal data, whether or not by automated means. The term covers practically any handling of data, be it collection, analysis, storage, transmission or erasure.
  • Processor: A natural or legal person that processes personal data on behalf of the controller (e.g. a hosting provider or an email dispatch service provider).