1. Data Controller
The data controller as defined by the General Data Protection Regulation (GDPR) is:
Anjou Media – Martin Dilger
Settelinweg 20
88400 Biberach an der Riß
Germany
Phone: +49 172 2526408
Email: [email protected]
2. Hosting and Server Log Files
This website is hosted on a Virtual Private Server (VPS) by Hostinger International Ltd. The server is located in a data center within the European Union. All processing of personal data takes place exclusively within the EU.
When you access our website, the web server automatically records the following data in server log files:
- IP address of the requesting device (anonymized after 7 days)
- Date and time of access
- Requested page / URL
- HTTP status code
- Amount of data transferred
- Referrer URL
- Browser type and version
The processing of this data is technically necessary for the operation of the website. Legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the secure and reliable provision of the website).
3. SSL/TLS Encryption
For security reasons, this website uses SSL/TLS encryption for the transmission of all data.
4. Reader Intelligence — Usage Analytics (Opt-in)
We use our own analytics tool called "Reader Intelligence", developed by Anjou Media, to analyze the use of our website. This system processes data exclusively as a first party — no data is shared with external analytics services or third parties.
4.1 Consent Required
Reader Intelligence is only activated when you actively grant your consent via our consent banner. Without your explicit consent, no processing takes place. Legal basis is Art. 6 (1) (a) GDPR (consent). You can withdraw your consent at any time via the "Cookie Settings" link in the footer.
4.2 Data Collected
- event_type — type of event (e.g. "page_view", "scroll_50", "read_time")
- path — requested page URL (without domain)
- session_id — random identifier for a browser session (30 minutes)
- reader_id — pseudonymous identifier in browser localStorage
- user_agent — browser identifier
- referrer — referring page (if available)
- article_slug — identifier of the requested article
- utm_source, utm_medium, utm_campaign — campaign parameters in URL (if present)
- created_at — timestamp of the event
4.3 No Cookies
Reader Intelligence does not set any cookies. The pseudonymous reader identifier is stored in the browser's localStorage. You can delete this identifier at any time via your browser settings.
4.4 Purpose of Processing
The usage data is used exclusively to improve our content, for editorial optimization, and to analyze reader behavior. No individual profiling and no automated decision-making within the meaning of Art. 22 GDPR takes place.
5. Retention Period
Usage data is automatically deleted after 12 months. Server log files are anonymized after 7 days and deleted after 30 days. Newsletter data is retained until you withdraw your consent.
6. Data Sharing with Third Parties
In principle, personal data is not shared with third parties. Exceptions exist only for technically necessary data processors.
6.1 Data Processors
- Supabase Inc. (San Francisco, USA) — database hosting. Certified under the EU-US Data Privacy Framework. Database servers within the EU. A data processing agreement pursuant to Art. 28 GDPR is in place.
- Hostinger International Ltd. (Kaunas, Lithuania) — web hosting. Server location: EU (Frankfurt, Germany). A data processing agreement pursuant to Art. 28 GDPR is in place.
- Resend Inc. (USA) — newsletter delivery (only for active subscribers). A data processing agreement pursuant to Art. 28 GDPR is in place.
7. Newsletter
When you subscribe to our newsletter, we store your email address and the time of signup for the purpose of sending the newsletter. Signup is done via a double-opt-in procedure: after signing up, you will receive an email in which you must confirm your subscription.
Legal basis is Art. 6 (1) (a) GDPR (consent). You can unsubscribe from the newsletter at any time via the unsubscribe link contained in every newsletter. The withdrawal of your consent does not affect the lawfulness of the processing carried out before the withdrawal.
8. Your Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR) — you can request information about your stored data.
- Right to rectification (Art. 16 GDPR) — you can request the correction of incorrect data.
- Right to erasure (Art. 17 GDPR) — you can request the deletion of your data.
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7 (3) GDPR)
To exercise your rights, please contact: [email protected]
9. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR.
Competent supervisory authority:
Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg
(State Commissioner for Data Protection and Freedom of Information)
Lautenschlagerstraße 20
70173 Stuttgart, Germany
Phone: +49 711 615541-0
Email: [email protected]
www.baden-wuerttemberg.datenschutz.de
10. Data Breaches
In the event of a data breach likely to result in a high risk to your personal rights and freedoms, we will notify you without undue delay in accordance with Art. 34 GDPR and inform the competent supervisory authority in accordance with Art. 33 GDPR.
11. Changes to This Privacy Policy
We reserve the right to adjust this privacy policy to ensure it always complies with current legal requirements. The current version is available on this page.
In case of discrepancies between language versions, the German version of this privacy policy is legally binding.