Privacy Policy
Last updated: August 16, 2026
This page explains what personal data is processed when you visit julianhasreiter.eu, why, on what legal basis, and what rights you have. It is written to satisfy Articles 13 of the General Data Protection Regulation (GDPR) and the TDDDG
This is a static personal website. It has no user accounts, no comment section, no advertising, no embedded third-party content, and no tracking.
Controller
The controller responsible for data processing on this website within the meaning of Art. 4(7) GDPR is:
Julian Hasreiter
Germany
Email: [email protected]
Data processed when you visit
Serving a web page technically requires your device to transmit certain data to the servers delivering it. The infrastructure providers named below process, in server log files:
- your IP address
- the date and time of the request
- the page or file requested and the amount of data transferred
- the HTTP status code
- the HTTP referrer information, where provided by your browser
- your browser type, version and operating system
Purpose: delivering the website reliably, protecting it against attack and abuse (including DDoS mitigation and bot filtering), and diagnosing faults.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest pursued is the secure, stable and functional operation of this website. The data is not used for advertising, profiling, or unrelated purposes.”
Retention: I do not independently retain or otherwise store server logs. Retention periods are determined by the respective provider’s applicable retention policies and the technical configuration of the services used.
Infrastructure providers
GitHub and Cloudflare process personal data in connection with providing the hosting, delivery and security services described below. Where they process personal data on my behalf, the relevant processing is governed by a data processing agreement under Art. 28 GDPR.
GitHub Pages
The site’s files are hosted on GitHub Pages, operated by GitHub, Inc. (88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA). For users in the EEA, GitHub names its subsidiary GitHub B.V. (Prins Bernhardplein 200, 1097 JB Amsterdam, Netherlands) in its privacy statement. See GitHub’s Privacy Statement.
Cloudflare
Requests are routed through Cloudflare, operated by Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA), for caching, TLS termination, DDoS protection and traffic filtering. Requests from Europe are normally served from Cloudflare edge locations within Europe. See Cloudflare’s Privacy Policy.
Cookies and access to your device
No cookies are set for analytics, advertising or personalisation.
Cloudflare’s security layer may set strictly necessary cookies — typically
__cf_bm (bot management, lifetime around 30 minutes) and, where a challenge
is issued, cf_clearance. These distinguish automated traffic from human
visitors and record that a security check was passed. They contain no
advertising identifier and are not used to build a profile.
Storing or accessing this information is covered by the exemption in § 25(2) no. 2 TDDDG, because it is strictly necessary to provide a service you have expressly requested. No consent banner is therefore displayed. If you would rather not have them set, you can block or delete cookies for this domain in your browser settings; the site remains usable, though Cloudflare may challenge your requests more often.
Analytics
This site uses Cloudflare’s privacy-focused analytics to see aggregate traffic trends. It reports page views, referrers, and coarse country-level and device-type breakdowns.
It sets no cookies, assigns no persistent identifier, does not track visitors across sessions or across websites, and does not build individual profiles. The measurement is derived from request data that Cloudflare already processes to serve the page.
Legal basis: Art. 6(1)(f) GDPR — the legitimate interest in understanding, in aggregate, whether the site works and which pages are read.
No other analytics service is used. In particular, this site does not use Google Analytics, Google Fonts, Google Tag Manager, Meta Pixel, or any comparable service. All fonts are system fonts rendered locally by your device; no font files, scripts or assets are loaded from third-party CDNs.
Contacting me by email
If you write to me at the address above, your email address, your message and any information you include in it are processed for the purpose of handling your enquiry.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries directed at me), or Art. 6(1)(b) GDPR where your message concerns the initiation or performance of a contract.
Retention: correspondence is kept as long as needed to deal with the matter and afterwards only where a statutory retention obligation applies. You may ask for your correspondence to be deleted at any time.
Transfers outside the EU/EEA
GitHub, Inc. and Cloudflare, Inc. are established in the United States, and processing may take place there or in other third countries.
Depending on the processing and transfer concerned, the providers rely on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses as applicable. The applicable transfer mechanism may differ depending on the provider, service and processing concerned. You can verify current certification status in the Data Privacy Framework List.
You should be aware that, despite these safeguards, US authorities may under certain conditions have access rights to data held by US providers, and that enforcing your rights against them may be more difficult than within the EU.
Links to other websites
This site links to external services such as GitHub, Discord, Telegram and the Microsoft Store. Nothing is embedded: no data is transmitted to those services until you actively click a link. Once you do, that provider’s own privacy policy applies, and I have no control over their processing.
Photo gallery
Images in the gallery are stored on this site’s own hosting and served through the same infrastructure described above. They are not loaded from a third-party image host.
Automated decision-making
No automated decision-making or profiling within the meaning of Art. 22(1) and (4) GDPR takes place on this website.
Obligation to provide data
You are under no statutory or contractual obligation to provide personal data. The data described under “Data processed when you visit” is transmitted automatically by your browser and is technically unavoidable when accessing any website; the only way to avoid it is not to visit the site.
Your rights
Where personal data relating to you is processed, you have the following rights under the GDPR:
- Access (Art. 15) — confirmation of whether your data is processed, and a copy of it
- Rectification (Art. 16) — correction of inaccurate or incomplete data
- Erasure (Art. 17) — deletion of your data where the conditions are met
- Restriction of processing (Art. 18)
- Data portability (Art. 20) — receipt of data you provided, in a structured, commonly used, machine-readable format
- Objection (Art. 21) — see the notice below
- Withdrawal of consent (Art. 7(3)) — where processing is based on consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out beforehand
- Complaint to a supervisory authority (Art. 77) — you may lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement
To exercise any of these rights, write to [email protected]. There is no charge, and I will respond within one month as required by Art. 12(3) GDPR.
A list of German supervisory authorities and their contact details is published by the Federal Commissioner for Data Protection and Freedom of Information at bfdi.bund.de.
Because much of the processing described here is carried out by GitHub and Cloudflare acting as processors, a request may need to be passed on to them to be fulfilled.
Right to object
Where processing of your personal data is based on Art. 6(1)(f) GDPR (legitimate interests), you have the right under Art. 21(1) GDPR to object at any time, on grounds relating to your particular situation, to that processing. Should you object, the data concerned will no longer be processed unless compelling legitimate grounds for the processing can be demonstrated which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Data security
This site is served exclusively over HTTPS (TLS), so traffic between your browser and the server is encrypted in transit.
Changes to this policy
This policy may be updated to reflect changes in the site’s technical setup or in the applicable law. The version published on this page is always the current one, and the date at the top shows when it last changed. Please review it occasionally.
Contact
For any question about this policy or about data protection on this site: [email protected]