Legal

Privacy Policy / Datenschutz

Preamble

With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites and within external online presences, such as our social media profiles (collectively referred to as the "online offering").

The terms used are not gender-specific.

Last updated: 31 May 2026

Controller

Michael Hauß

Kreuzstr. 19 a, 47877 Willich, Germany

Email: [email protected]

Overview of Processing

The following overview summarises the types of data processed and the purposes of their processing.

Types of data processed: usage data (e.g. content accessed, access times); meta, communication and procedural data (e.g. IP addresses, timestamps); content data (embedded photos/videos); log data (server log files).

Categories of data subjects: users (e.g. website visitors).

Purposes of processing: provision of the online offering and user-friendliness; security measures; information technology infrastructure; public relations.

Relevant Legal Bases

Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data:

Consent (Art. 6(1)(a) GDPR): The data subject has given consent to the processing of their personal data for a specific purpose.

Legitimate interests (Art. 6(1)(f) GDPR): Processing is necessary to protect the legitimate interests of the controller or a third party, provided that the interests and fundamental rights of the data subject do not override them.

In addition to the GDPR, national data protection regulations apply in Germany, in particular the Federal Data Protection Act (BDSG).

Security Measures

We take appropriate technical and organisational measures in accordance with the legal requirements to ensure a level of protection appropriate to the risk.

Securing online connections using TLS/SSL encryption (HTTPS): To protect users' transmitted data against unauthorised access, we use TLS/SSL encryption. You can recognise this by the "https://" in your browser's address bar.

International Data Transfers

When using third-party services (in particular YouTube and Instagram), data may be transferred to the USA. For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), recognised as a secure legal framework by an EU Commission adequacy decision of 10 July 2023, as well as additionally on standard contractual clauses. Further information: https://www.dataprivacyframework.gov/.

General Information on Data Storage and Deletion

We delete personal data in accordance with the statutory provisions as soon as the underlying consents are revoked or there are no further legal grounds for processing. Exceptions apply where statutory obligations require longer retention.

Rights of Data Subjects

As a data subject, you have various rights under the GDPR, in particular under Articles 15 to 21 GDPR:

Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR.

Right to withdraw consent: You have the right to withdraw consent given at any time.

Right of access: You have the right to request confirmation as to whether data concerning you is being processed, as well as information about this data and a copy of the data.

Right to rectification: You have the right to request the completion or rectification of data concerning you.

Right to erasure and restriction of processing: You have the right to request the erasure of data concerning you or, alternatively, a restriction of processing.

Right to data portability: You have the right to receive the data concerning you in a structured, commonly used and machine-readable format.

Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a supervisory authority if you consider that the processing infringes the GDPR.

Provision of the Online Offering and Web Hosting

We process users' data in order to provide them with our online offering. For this purpose, we process the user's IP address, which is necessary to transmit the content to the user's browser.

Collection of access data and log files: Access to our online offering is logged in the form of "server log files" (including pages accessed, date/time, amount of data transferred, browser type, operating system, referrer URL and IP address). The log files are stored for a maximum of 30 days and then deleted. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).

Hosting provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. Privacy policy: https://www.ionos.de/terms-gtc/terms-privacy. A data processing agreement is in place with IONOS.

Use of Cookies

This website only uses technically necessary storage in the browser: your cookie/consent decision is stored locally in your browser ("localStorage") so that we do not ask you again on every visit and so that external content (YouTube, Instagram) is only loaded after your consent. No tracking or marketing cookies are set.

Before loading external media, we obtain your consent via a consent banner. You can withdraw or change this consent at any time via "Cookie settings" in the footer. Legal bases: consent (Art. 6(1)(a) GDPR) or legitimate interests for the technically necessary storage (Art. 6(1)(f) GDPR).

Presence on Social Networks (Social Media)

We maintain online presences within social networks in order to communicate with users active there and to provide information about us. In this context, users' data may be processed outside the EU. Users' data is generally also processed by the networks for market research and advertising purposes. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).

Instagram – provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfer: DPF.

YouTube – provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://business.safety.google/privacy/. Basis for third-country transfer: DPF.

Integrated Third-Party Functions and Content

We embed functional and content elements that are obtained from the servers of their respective providers. This requires that the providers process the user's IP address, as they could not send the content to the browser without it. The external content listed below is only loaded after your consent. Legal bases: consent (Art. 6(1)(a) GDPR) or legitimate interests (Art. 6(1)(f) GDPR).

YouTube (thumbnails & links): In the "Latest videos" section, we display thumbnails of our channel's latest videos, which are loaded from YouTube (Google) servers; clicking opens the respective video or channel directly on youtube.com. A video player is NOT embedded in the page. Provider: Google Ireland Limited. Privacy policy: https://business.safety.google/privacy/. Third-country transfer: DPF.

Retrieval of the YouTube feed via a CORS proxy: To determine the list of latest videos, your browser retrieves the public YouTube RSS feed of our channel. As this retrieval is technically not possible directly, it is routed through a proxy service (primarily "CodeTabs", https://codetabs.com, alternatively comparable services). In doing so, your device's IP address is transmitted to the proxy service. Retrieval only takes place after your consent to external media.

Instagram gallery via Behold.so: The photo gallery is provided via the Behold service (Behold.so), which delivers the public posts of our Instagram profile as a data feed; the images themselves are loaded from Instagram/Meta servers. In doing so, your device's IP address may be transmitted to Behold and Meta. Retrieval only takes place after your consent. Provider: Behold.so; privacy information: https://behold.so/privacy/.

Fonts (self-hosted): The fonts used (including "Quicksand", "Nunito", "DM Mono") are delivered from our own server. NO data is transmitted to Google or third parties for this purpose.

Content Delivery Network / security service (Cloudflare): This website is delivered via Cloudflare's CDN and security network (provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA). Cloudflare acts as a reverse proxy: all traffic between your browser and our server is routed through Cloudflare's servers. In doing so, technically necessary connection data is processed — in particular your IP address, browser/device information and the requested URL — in order to deliver the site securely and efficiently, mitigate attacks (e.g. DDoS) and ensure availability. The legal basis is our legitimate interest in secure, efficient operation (Art. 6(1)(f) GDPR); as this processing is technically required for delivery, it is not based on consent. Cloudflare acts as a processor (Art. 28 GDPR); a data processing agreement is in place. Cloudflare may set a technically necessary cookie ("__cf_bm") for bot detection. Basis for the third-country transfer (USA): Data Privacy Framework (DPF) and Standard Contractual Clauses. Privacy policy: https://www.cloudflare.com/privacypolicy/.

Link to Ko-fi: The "Buy me a coffee" button is purely a link to Ko-fi; no payment processing takes place on this website. Only when you follow the link do Ko-fi's privacy terms apply (Ko-fi Labs Ltd, United Kingdom; https://more.ko-fi.com/privacy).

Changes and Updates

Please review the content of our privacy policy regularly. We will adapt the privacy policy as soon as changes to the data processing we carry out make this necessary.

Note

This privacy policy was created with the help of the free privacy policy generator by Dr. Thomas Schwenke and shortened to the services actually used on this website.

← Back to michaelhauss.de