Server log files & hosting
When visiting the site, the hosting provider automatically processes log data (requested URL, time, referrer, browser, operating system, truncated IP address). This is necessary for technical delivery, stability, and security.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in a secure, functional service). Log data is usually deleted within 7 days unless required for security analysis.
Self-hosted analytics (Matomo)
We run a self-hosted Matomo instance to understand resonance – how many people engage with the platform – not to identify individuals.
IP addresses are anonymised, no marketing or cross-site profiles are created. Legal basis: Art. 6 (1) lit. f GDPR (interest in safeguarding this resonance space).
Cookies & external services
Only technically required cookies (e.g. session cookies) are used. No external fonts, ad networks, or social plugins are embedded.
If an external service should become necessary in the future, visitors will be informed transparently beforehand.
Contact via email
If you contact us via email, we process the transmitted data (email address, content, name if provided) to handle the request.
Legal bases: Art. 6 (1) lit. b GDPR (contractual communication) and Art. 6 (1) lit. f GDPR (interest in orderly communication). Data is deleted once the request is finalised unless retention obligations apply.
Storage & deletion
Data is stored only as long as necessary for the stated purposes or to comply with legal retention duties.
Afterwards the data is deleted or anonymised.
Security measures
Transmission is encrypted (TLS/HTTPS). Infrastructure and application layers are continuously hardened and monitored.
Access is limited to the responsible circle; every processing activity follows the principle of data minimisation.