Privacy policy
1. Controller
The controller for data processing on this website is:
Lennart Werner
Bottigstraße 5
61381 Friedrichsdorf
Germany
mail@lewerner.eu
2. Hosting and server log files
This website is operated on a server of IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS.
When pages are accessed, the web server records technically necessary data in server log files: IP address, date and time of access, requested URL, referrer and user agent. This data is required to operate and secure the website; it is not combined with other data sources. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation). Log files are deleted automatically after 14 days.
3. Analysis of server log files
Within the retention period stated above, I analyse the log files statistically in order to understand which posts are read and how readers find their way here. The analysis runs entirely on the same server; no data is transmitted to third parties.
Before anything is stored, the IP address is replaced by a pseudonym. The random key used for this is generated afresh for every analysis run and discarded afterwards. Requests from the same connection therefore cannot be linked beyond a single day, not even by me.
While the address is still present, it is used once for two lookups whose results are retained without any reference to a person:
- the approximate location (country, region and city), resolved against a database held locally. This mapping is inherently imprecise; city-level results in particular are frequently wrong, because access providers do not assign addresses geographically.
- the network the request came from (its autonomous system number). For requests from corporate networks this yields the name of the organisation. I use it to gauge which industries my posts reach. Requests from residential connections and from data centres are combined into collective groups and never listed individually.
Organisations, regions and cities are named regardless of how many requests they account for; even a single request appears in the analysis with an organisation name and a location. This does not involve, and does not allow me to make, any attribution to individual people, because the IP address is replaced by a pseudonym before anything is stored and the key used for this is discarded after every analysis run.
In addition, the device class (mobile, tablet, computer), operating system and browser are recorded in grouped form from the user agent that is transmitted, as are the page requested, the language version and, where your browser sends it, the website you came from. This involves no access to your device: no information is stored on your device or read from it beyond what is transmitted as part of the HTTP request anyway. Consent under § 25 TDDDG is therefore not required.
The result of the analysis consists solely of aggregate figures with no reference to a person, such as “412 page views from Germany in August”. I retain these figures permanently in order to see developments over longer periods. This does not change the retention period of the underlying log files: they are deleted after 14 days as before.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in learning how my own content is used). You may object to this processing using the address given above.
4. Analytics in the browser (Plausible)
In addition to analysing the log files, I use Plausible Analytics. The software runs on the same server as this website; there is no connection to an external service and no data is transmitted to third parties. The measurement script is served from this domain as well.
No cookies are set, and neither local storage nor comparable techniques are used. There is no access to your device beyond what is part of the HTTP request anyway. Consent under § 25 TDDDG is therefore not required, and neither is a cookie banner.
The following is recorded: the page requested, the referring website, the approximate location (country, region, city), device class, operating system, browser and screen size in broad categories, and clicks on links that lead away from this website or open a file.
In order to group requests belonging to one visit, Plausible derives an identifier from the IP address, the user agent and a random value. The IP address itself is not stored, and the random value is discarded every 24 hours. Recognising anyone beyond a single day is therefore impossible, for me as well. No tracking across different websites takes place.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in learning how my own content is used). You may object to this processing using the address given above. You can also prevent the measurement yourself by enabling “Do Not Track” in your browser or by using a content blocker.
5. No third-party services
This website embeds no third-party analytics or tracking services, no advertising networks and no external fonts. All content is served from my own server; loading a page creates no connections to third parties. No usage profiles of individuals are created and no data is combined across websites.
6. Cookies
This website sets no cookies and uses neither local storage nor comparable techniques. Consent under § 25 TDDDG is therefore not required, and neither is a cookie banner.
7. Getting in touch
If you contact me by email, your details are processed in order to handle your enquiry (Art. 6(1)(b) or (f) GDPR) and are not passed on without your consent. I delete such messages once they are no longer needed and no statutory retention periods apply.
8. Your rights
You have the right to information, rectification, erasure, restriction of processing, data portability and objection. Please use the address given above.
You also have the right to lodge a complaint with a supervisory authority. The
competent authority is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Germany
9. Last updated
This privacy policy is dated 1 August 2026.