Privacy policy
This page is a translation, and only the German version is legally binding.
Last updated:
This site sets no cookies and loads everything from my own server, delivered through Cloudflare. Personal data only comes into play when your browser requests pages and when you write to me. Here's what happens in each case.
Controller
The controller responsible for processing personal data on this website is:
FelixTheDevFelix Grad
c/o Online-Impressum #9380
Europaring 90
53757 Sankt Augustin
Deutschland
Email: contact@
Visiting the site and server log files
The site runs on a dedicated Linux server that I operate myself. The server is provided by netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, location: Nuremberg, Germany.
Every request to felixthedev.com first goes through the network of Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Cloudflare sets up the encrypted connection to your browser, protects the site against overload attacks and passes the request on to my server. In doing so, Cloudflare processes your IP address, the address you requested, the request headers (for example browser identifier and preferred language) and technical connection data. Cloudflare sets no cookies through this site and adds no scripts of its own.
When you come to the site from elsewhere, my server reads the language set in your browser (Accept-Language) and the page you came from (referrer). If your browser prefers German or English, it sends you once to the matching language version. Nothing is stored for this; the details only appear in the server log like with any other request.
Every time a page or file is requested, the web server (Nginx Proxy Manager) writes an entry to a log file. It contains:
- the IP address of your device,
- the date and time,
- the request method (for example GET), the protocol (http or https) and the host name requested,
- the address requested, including any parameters,
- the status code of the response, including the one from the application behind the web server, and whether the response came from a cache,
- the name of the internal server the request was passed to,
- the amount of data transferred and how much it was compressed,
- the address of the page you came from (referrer), if your browser sends it,
- your browser's identifier (user agent), which shows your browser and operating system.
If an error occurs, the web server also writes a message with your IP address, the time and the request concerned to an error log. The application behind the web server doesn't log individual requests.
- Purpose
- Delivering the website, tracking down errors, and detecting and fending off attacks and misuse.
- Legal basis
- Art. 6(1)(f) GDPR. My legitimate interest is running the site securely and reliably.
- Retention
- 14 days. After that the server deletes the log files automatically.
- Recipients
- My hosting provider (netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe) and Cloudflare process the data on my behalf (Art. 28 GDPR). Cloudflare may also process it in the USA (seeTransfers outside the EU).
Encryption
The connection to this site is encrypted with TLS, which you can tell from the https:// in the address bar. Your browser remembers for one year that it should only open the site over an encrypted connection (HSTS). That entry contains no information about you.
Contact form
When you write to me using the contact form, I process your name, your email address, your message and the topics you selected, if you ticked any (for example website or maintenance). The server checks what you've entered and sends it to me by email, with your address as the reply-to address so I can answer you directly. None of it is stored on the web server, and the content of your message never ends up in a log. Sending the form shows up in the server log like any other request (see above), but without the details you entered.
- Purpose
- Answering your enquiry and, if you'd like one, sending you a quote.
- Legal basis
- Art. 6(1)(b) GDPR if your enquiry is aimed at a contract, for example a quote for a website. Otherwise Art. 6(1)(f) GDPR; my legitimate interest is answering enquiries.
- Retention
- I delete your message once your enquiry has been dealt with, unless I'm legally required to keep it, for example because your enquiry turned into an order.
- Recipients
- On its way to my server, the form passes through Cloudflare like any other request (seeabove). The email is sent by my own mail server on the same server to my mailbox, which is also there. My hosting provider processes the data on my behalf (Art. 28 GDPR). No other provider's mail service is involved.
- Do you have to provide data?
- You don't have to write to me. Without your name, email address and message, though, I can't reply. The topics are optional.
Protecting the form from misuse
To stop anyone from flooding the form, the server accepts no more than 5 requests from one IP address within 15 minutes. To do that, it keeps your IP address and the number of your requests in memory. For IPv6 it only keeps the first 64 bits of the address (the /64 prefix). Nothing is written to disk.
- Purpose
- Protection against spam and misuse without adding a third-party service such as a captcha.
- Legal basis
- Art. 6(1)(f) GDPR. My legitimate interest is protecting the form from misuse.
- Retention
- No more than 15 minutes after your last request, then the server removes the entry. If the server restarts, the entry is gone immediately.
- Recipients
- None.
Contact by email
When you email me at contact@
Your email goes straight to my mailbox on my own mail server, which runs on the same server as the website (see above). There is no forwarding and no other provider's mail service.
- Purpose, legal basis and retention
- The same as for the contact form.
- Recipients
- My hosting provider (netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe) on my behalf (Art. 28 GDPR).
Cookies, browser storage and scripts
This site sets no cookies. It doesn't store anything else in your browser either, such as in local storage. There are no services that count or analyse visits.
Fonts, images and scripts are served from the same server as the pages and reach you through Cloudflare just like the pages, so your browser doesn't load anything from other addresses, including Google Fonts or other font providers. The site's scripts run only in your browser and don't send anything, except when you submit the contact form.
Your browser keeps files such as fonts and stylesheets in its cache so it doesn't have to download them again on your next visit.
Links to other websites
Links to other websites, for example to GitHub, are plain links. Your browser only opens the other site when you click one, and that site's privacy policy applies there. All the other site learns about where you came from is the domain felixthedev.com.
Transfers outside the EU
Cloudflare, Inc. may process data in the USA whenever the site is requested (seeabove). This transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), under which Cloudflare, Inc. is certified. Beyond that, I don't pass any data to countries outside the European Union or the European Economic Area. My mailbox is on my own server in Germany.
Your rights
You have the right to:
- get access to the data I process about you (Art. 15 GDPR),
- have incorrect data corrected (Art. 16 GDPR),
- have your data erased (Art. 17 GDPR),
- have the processing restricted (Art. 18 GDPR),
- receive data you gave me for a contract in a common, machine-readable format, or have it passed on to someone else (Art. 20 GDPR).
If I correct or erase data or restrict its processing, I tell everyone I've passed the data to, where that's possible (Art. 19 GDPR). To use any of these rights, email me at contact@
Right to object under Art. 21 GDPR
Where I process your data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you can object to that processing at any time on grounds relating to your particular situation.
On this site that covers the server log files, the protection of the form against misuse, and enquiries that aren't aimed at a contract. Once you object, I'll stop processing that data unless I can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
An informal message to contact@
Complaints to a supervisory authority
If you think I'm not processing your data lawfully, you can complain to a data protection supervisory authority (Art. 77 GDPR), for example in the country where you live or work. The authority responsible for me is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)Holstenstraße 98
24103 Kiel
datenschutzzentrum.de
Automated decisions
I don't make automated decisions within the meaning of Art. 22 GDPR, and I don't create profiles.