Privacy Policy

Protecting your personal data matters to me. This privacy policy informs you, in accordance with Art. 13 of the General Data Protection Regulation (GDPR), about the nature, scope, and purpose of the processing of personal data within this website.

I. Information pursuant to Art. 13 GDPR

1. Controller

The controller within the meaning of the General Data Protection Regulation is:

Christian Schmidt
Email: privacy@jcs-net.de

No data protection officer has been appointed, as the legal requirements for doing so (Art. 37 GDPR, Section 38 of the German Federal Data Protection Act) do not apply to this privately operated website.

2. Data processing when visiting the website (server log files)

When you access this website, the web server and the infrastructure in front of it automatically collect and store information in so-called server log files, which your browser automatically transmits. This includes in particular:

  • date and time of the request
  • IP address of the accessing device
  • the page or file requested
  • the previously visited page (referrer URL), if transmitted
  • browser type and version, operating system used
  • amount of data transferred and HTTP status code

This data is technically necessary to correctly deliver the website, to ensure the stability and security of ongoing operations, and to defend against attacks. This data is not combined with other data sources.

The legal basis is Art. 6 (1)(f) GDPR. The legitimate interest arises from the purposes of data collection stated above.

Log files are rotated automatically on a daily basis; the log files of the last 7 days are kept in compressed form and then automatically deleted, unless a specific security incident requires longer retention for evidentiary purposes.

3. Security and abuse detection (page-insights)

In addition to the general server log files, I use a self-developed plugin ("page-insights") that detects suspicious access patterns indicating automated scanning or attack attempts and notifies me by email.

The IP addresses processed in this context are truncated before storage (IPv4 addresses to the first two bytes, IPv6 addresses to the first four bytes), so that it is no longer possible to draw conclusions about a specific person or device. Since the truncated data no longer constitutes personal data within the meaning of Art. 4 No. 1 GDPR, it is evaluated for statistical purposes for an unlimited period; the storage limitation under Art. 5 (1)(e) GDPR does not apply to it.

To the extent that a brief personal reference exists before truncation, the legal basis for processing is Art. 6 (1)(f) GDPR (legitimate interest in the security of my IT systems and the defense against attacks).

4. Hosting

This website is operated on a root server rented from an external provider. The hosting provider exclusively provides the technical infrastructure (hardware, network connection) and, in the context of this pure server provisioning, has no access to the content and data I process on the server.

5. Embedded content and external links

Mastodon profile: This website contains a link to my Mastodon profile. This is a plain hyperlink, not an embedded element – visiting this page does not transmit any data to the Mastodon provider. Only after clicking the link and accessing the target page does that provider's own privacy policy apply.

News teasers: Teasers of external news sources shown on the homepage (e.g. tagesschau.de, heise online) are fetched by my server on the server side and embedded into the page. Your browser does not establish its own connection to these third-party providers, and no data is transmitted to them.

Fonts: The icon/font files used (Font Awesome) are hosted entirely on my own server. There is no connection to external font or CDN providers.

6. Cookies

No cookies are set in the public area of this website. Only in the password-protected administration area is a technically necessary session cookie used; this relates exclusively to the controller's own login and not to visitors of the public pages.

7. Your rights as a data subject

As a data subject, you have the following rights against the controller:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR, see Section II below)

You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). The supervisory authority responsible for me is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Postfach 221
30002 Hannover, Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de

II. Right to object pursuant to Art. 21 GDPR

You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you which is based on Art. 6 (1)(f) GDPR (processing based on a balancing of interests).

If you object, I will no longer process your personal data unless I can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.


Last updated: September 1, 2026