LEGAL

Privacy

How this site handles your data, and how little of it there is. No cookies, no tracking, no consent banner — the reasons are set out below.

01

Who is responsible

The controller for the processing described here is Apex Digital GmbH, Neuer Wall 80, 20354 Hamburg, Germany, represented by its Managing Director Dr. Bernhard Schulz. The full provider details are in the imprint.

For anything to do with your data — a question, a request, an objection — write to [email protected]. We are not required to appoint a data protection officer and have not appointed one; your enquiry reaches the people who run the site.

02

What this site does not do

It sets no cookies. It runs no advertising, no social plugins, no embedded videos or maps from other companies, no chat widget, no A/B testing and no cross-site tracking of any kind. There is no contact form, so there is nothing here that asks you for your data.

The typeface is served from this domain: it is compiled into the site at build time, so opening a page sends no request to Google or to any other font service.

One thing is stored in your browser, and only for as long as the tab is open: a single sessionStorage entry that records that you have already seen the opening animation, so it does not play again on every page. It contains no identifier, it is never sent to us, and closing the tab deletes it. Nothing else is written to or read from your device — which is why this site has no cookie banner and does not need one.

03

Server log files

Every request to a web server leaves a record, and this one is no exception. Our server writes a log entry for each page and file it delivers:

We use these entries to deliver the site, to keep it stable, and to recognise and defend against attacks. They are not combined with any other data, they are not used to build a profile, and no attempt is made to identify you from them.

  • the IP address the request came from
  • the date and time of the request
  • the page or file requested, and the HTTP status returned
  • the amount of data transferred
  • the referring page, where your browser sends one
  • your browser type and version, and your operating system
Legal basis
Art. 6 (1) (f) GDPR — our legitimate interest in a site that is delivered reliably and can be defended when it is attacked.
Retention
No longer than 30 days, after which the entries are deleted.
04

Visitor statistics

We want to know roughly how many people read these pages and which ones they read. For that we use Plausible Analytics, run by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia, on servers inside the European Union.

Plausible was chosen because of what it does not collect. It sets no cookie and stores nothing on your device. It does not store your IP address: to count a repeat visit within the same day it derives a hash from your IP address and browser, salted with a value that is regenerated every day and then thrown away, which makes yesterday's visitors unrecognisable today and makes the hash impossible to reverse. There is no identifier that follows you to another site, or back to this one tomorrow.

What is recorded is the page you opened, the site that referred you if any, your browser, operating system and device type, and the country your request came from. All of it is aggregated. None of it identifies you, and none of it is sold, shared or used for advertising.

Legal basis
Art. 6 (1) (f) GDPR — our legitimate interest in knowing whether the site is read. Because nothing is stored on or read from your device, § 25 TDDDG does not apply and your consent is not required.
Retention
Aggregate statistics are kept indefinitely; the daily salt that makes a visitor countable is discarded every 24 hours.
05

If you write to us

The addresses on this site are ordinary mailboxes. If you write to one, we receive your email address, whatever else you put in the message, and the technical headers your mail carries — and we use them to answer you.

Email is not encrypted end to end unless you encrypt it yourself. It travels through our mail provider and yours, and neither of us controls every step. Please keep that in mind before sending anything confidential.

Legal basis
Art. 6 (1) (b) GDPR where your message concerns a contract or the steps leading to one, otherwise Art. 6 (1) (f) — our legitimate interest in answering the people who write to us.
Retention
Until the matter is settled and no longer needed, unless commercial or tax law requires the correspondence to be kept for longer.
06

Who else processes this data

The site runs on infrastructure operated by DigitalOcean, LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA, which processes the server log files described above on our behalf. DigitalOcean is a US company, so this is a transfer to a third country: it is covered by a data processing agreement and by the European Commission's standard contractual clauses, together with the technical and organisational measures those clauses require.

Plausible Insights OÜ processes the visitor statistics on our behalf, inside the EU, under a data processing agreement. Our mail provider processes email you send us, likewise on our behalf.

Nobody else receives this data. We do not sell it, and we do not pass it to anyone for their own purposes. It would only ever leave that circle if a law or a court required it.

08

Your rights

Under the GDPR you can ask us for a copy of the data we hold about you (Art. 15), have it corrected (Art. 16) or erased (Art. 17), have its processing restricted (Art. 18), and receive it in a portable form (Art. 20).

You can also object to any processing we base on our legitimate interest, on grounds arising from your particular situation (Art. 21). If you do, we stop unless we can show compelling grounds that override your interests. In practice, the processing on this site that rests on legitimate interest is the server log and the visitor count, and neither of them holds anything we could use to find you again.

Exercising any of this costs nothing and needs no form. Write to [email protected].

09

Complaints

If you think we are handling your data unlawfully, you can complain to a supervisory authority — the one where you live, where you work, or where the alleged infringement took place. The authority responsible for us is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany.

You are of course welcome to raise it with us first, and we would rather you did.

10

Whether you have to provide anything

You do not. Nothing on this site is behind a form, a login or a sign-up, and reading it requires you to give us nothing. The server log is the unavoidable by-product of your browser asking for a page — the only way not to produce one is not to open the page.

We make no automated decisions about anyone, and we build no profiles. There is no processing here that produces a legal effect for you or affects you in any comparable way.

11

Security

The site is served over TLS throughout, which you can check in the address bar of your browser: the connection is encrypted between your device and our server, and a request to the unencrypted address is redirected to the encrypted one.

12

Changes to this notice

We will update this notice when what the site does changes — a new tool, a new provider, a different retention period. The version in force is always the one published here, and it carries the date it was last changed.

Last updated: 31 July 2026