Privacy Policy

Last updated: 23 August 2026

1. Controller

Simon Schwitz
Wolfsried 22
78464 Konstanz
Germany

datenschutz@calucon.de

No data protection officer has been appointed; the statutory thresholds requiring one are not met.

2. About this site

This is a personal portfolio site. It contains no advertising, no advertising trackers, no profiling and no automated decision-making. There is no comment function, no newsletter, and no visitor login.

Visits are counted, and only counted: Cloudflare Web Analytics records page views without cookies, without an identifier for you, and without any ability to follow you to another website. Section 3.3 sets out exactly what it does and what reaches Cloudflare.

Specifically not used: Google Analytics, or any comparable service that sets cookies or recognises visitors across sites; Google Fonts (all fonts are served from our own server); social media plugins; ad networks.

The site itself sets no cookies that would require consent. Third-party cookies are set only if you actively choose to load an embedded item (section 6).

3. Hosting and content delivery

3.1 Hosting

This site is self-hosted on our own hardware. No external hosting provider is involved and no data is passed to one, so there is no Art. 28 GDPR processing relationship in that respect. Operating and securing the server is the direct responsibility of the controller named above.

3.2 Cloudflare

Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, sits in front of this site as a content delivery network and protection layer. All traffic between your device and the site passes through Cloudflare’s servers, which process your IP address in order to route requests, detect malicious traffic and deliver content. Cloudflare also collects technical error reports via Network Error Logging (a.nel.cloudflare.com).

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, available and fast website.

Transfers outside the EEA: Cloudflare, Inc. is based in the USA. Transfers rely on the European Commission’s Standard Contractual Clauses; Cloudflare is additionally certified under the EU-US Data Privacy Framework.

3.3 Cloudflare Web Analytics

We use Cloudflare Web Analytics to see how many people read which pages. The following is measured behaviour of the running site, not a description copied from the vendor:

  • It sets no cookies and writes nothing to your device — no cookie, no localStorage, no sessionStorage entry. Because nothing is stored on or read from your device, § 25 (1) TDDDG does not apply and no consent is needed.
  • It assigns you no identifier and does not fingerprint your browser, so it cannot recognise you on a later visit or follow you to another site.
  • The measurement is sent to this domain, at calucon.de/cdn-cgi/rum, and collected from there.

What does reach Cloudflare directly is the request for the measurement script at static.cloudflareinsights.com. Like every request for a file, it carries your IP address and the address of the page you were reading.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in knowing which pages are read, by a method chosen because it neither identifies you nor follows you. Recipient, and the basis for transfers outside the EEA, are as in section 3.2.

If you would rather not be counted: block static.cloudflareinsights.com in your browser or a content blocker. Nothing on this site depends on it, and nothing else changes.

4. Server log files

Your browser automatically transmits, and the server records: IP address, date and time, requested URL and volume of data, referrer URL, browser type and version, and operating system. This data is not combined with other sources and is not used to identify individuals.

Legal basis: Art. 6(1)(f) GDPR — technically error-free and secure operation. Retention: 14 days. Log files are rotated daily and deleted automatically after 14 days.

4.1 Content Security Policy violation reports

Browsers report blocked content to an endpoint on the same server. These reports are evaluated in aggregate only: the violated directive, the affected page (without its query string), a coarse browser family and a counter.

Client IP address, full user agent, cookies and query strings are deliberately not recorded, so the aggregates contain nothing attributable to an individual. They are deleted automatically after 30 days.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in detecting whether malicious code is being injected into the site.

4.2 Login protection

The login area is protected against automated login attempts by a security plugin. It counts failed login attempts per IP address: after five failures the IP address is blocked for 30 minutes, and progressively longer on repeated attempts (up to a maximum of 24 hours).

The IP address and a counter are stored temporarily for this purpose. The storage is tied to the block and ends when it expires; there is no permanent logging and no evaluation beyond that.

This affects visits to the login page only. It does not apply to ordinary browsing of the site.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in preventing automated login attempts.

5. Contact form

The form at /contact/ (WPForms plugin) transmits your first and last name, email address and message, which are used to answer your enquiry and forwarded to us by email. WPForms Lite is used, which does not store submissions in the WordPress database — it only delivers them by email. The optional “Lite Connect” feature, which would additionally back submissions up to the plugin vendor’s servers, is disabled, so no data is transmitted to the vendor.

Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract, otherwise Art. 6(1)(f) GDPR. Retention: deleted once your enquiry has been dealt with, unless statutory retention periods apply. You may object at any time.

5.1 Spam protection: Cloudflare Turnstile

Cloudflare Turnstile (challenges.cloudflare.com, Cloudflare, Inc., USA) checks that submissions are made by a human. Technical characteristics of your browser and your IP address are transmitted to Cloudflare. Turnstile is designed as a privacy-friendly CAPTCHA alternative and uses no advertising cookies.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in preventing spam.

5.2 Email delivery

Form emails are sent through Proton Mail, operated by Proton AG, Geneva, Switzerland (via the WP Mail SMTP plugin). The content of your message and your email address are transmitted to Proton, delivered and stored there; the receiving mailbox is also hosted at Proton.

Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract, otherwise Art. 6(1)(f) GDPR — legitimate interest in reliable delivery.

Transfers outside the EEA: Switzerland is recognised as providing an adequate level of protection under an European Commission adequacy decision (Art. 45 GDPR), reaffirmed on 15 January 2024. No additional safeguards such as Standard Contractual Clauses are required.

Proton’s privacy policy: https://proton.me/legal/privacy

6. Embedded third-party content — loaded only on request

Some pages contain content hosted by others: Strava activities, YouTube videos, one preview of an external website, and — on the demonstration page described in section 6.4 — embeds from a wider list of providers.

None of it is loaded automatically. In each case you first see a placeholder with a notice and a button. Until you press that button, no connection to the provider is made, nothing is requested from it, and no cookie is set.

Legal basis in every case below: Art. 6(1)(a) GDPR and § 25(1) TDDDG — your consent, given by pressing the button.

Consent is not stored. Nothing is written to your device to remember it, so on your next visit every placeholder is active again and you are asked afresh. You can therefore withdraw it simply by not pressing the button again: there is no setting to find and nothing to undo.

One detail, stated because it is not obvious: some providers deliver all of their embeds through a single script. Where a page carries several embeds from such a provider — several Strava activities on one page, for example — loading one of them loads the others from that same provider on that same page, because their script renders all of them together. It does not affect embeds from any other provider, and it does not carry over to another page or another visit.

Each placeholder also offers a plain link to the content on the provider’s own site. Following that link is your decision to visit them, and their privacy policy applies to it.

6.1 Strava

Embedded activities from Strava, Inc., 208 Utah Street, Suite 400, San Francisco, CA 94103, USA.

Once loaded, data is transmitted to Strava and its content delivery network (strava-embeds.com, c.strava.com, Amazon CloudFront): your IP address, the address and title of the page you are on, and technical details of your browser and operating system. Strava then sets its own cookie (sp) on the strava.com domain. If you are logged in to Strava, it may associate the request with your account.

Transfers to the USA rely on Art. 49(1)(a) GDPR — your explicit consent.

Strava’s privacy policy: https://www.strava.com/legal/privacy

6.2 YouTube

Embedded videos operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Once loaded, your IP address, the page you are on and technical details of your browser are transmitted to Google, and the video is delivered from Google’s servers. If you are logged in to YouTube, Google can associate the playback with your account.

Two details worth stating plainly, because they are the reason this embed is gated at all:

  • Videos are loaded from youtube-nocookie.com, not youtube.com. Measured on the same video with no playback started, the ordinary youtube.com embed set five cookies — including two with a lifetime of roughly 18 months — while the youtube-nocookie.com embed set none. Cookies may still be set once you start playback.
  • Google may transfer data to the USA. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023 (Art. 45 GDPR); your consent under Art. 49(1)(a) GDPR covers the transfer in addition.

Google’s privacy policy: https://policies.google.com/privacy

6.3 Preview of an external website

The page /ankommen/ embeds a preview of mediale-ausstellungsgestaltung.de. Once loaded, your IP address and the page you are on are transmitted to that server, which sets a cookie recording a language preference (pll_language, lifetime one year).

6.4 Demonstration pages

Two pages demonstrate a WordPress plugin that gates embeds: /third-party-embed-gate-showcase/ and its German counterpart /zwei-klick-loesung-demo/. Both carry the same set — one embed from each provider the plugin recognises by name, 36 of them:

YouTube, Vimeo, Dailymotion, TED, VideoPress, TikTok, Spotify, SoundCloud, Apple Music, Mixcloud, Pocket Casts, Strava, X (Twitter), Bluesky, Tumblr, Pinterest, Instagram, Facebook, Reddit, Scribd, Speaker Deck, Issuu, Wolfram Cloud, Amazon Kindle, Google Maps, OpenStreetMap, Matterport, Sketchfab, Crowdsignal, Google Calendar, Google Forms, Typeform, Calendly, Imgur, GIPHY and Kickstarter.

They also carry one widget from example.com, a host the plugin does not recognise, included to demonstrate that an unknown third party is held back in the same way.

Everything in section 6 applies to all of them without exception: nothing is loaded, requested or stored until you press that embed’s button, and each placeholder names its provider and links to that provider’s own privacy policy before you decide. Verified on the published pages: loading them contacts none of those providers, and neither does scrolling through them. The one third-party request those pages do make is the Cloudflare Web Analytics script (section 3.3), which is inserted into every page on this site and has nothing to do with the embeds.

Pressing a button there transmits your IP address, the page you are on and technical details of your browser to that one provider, which may set its own cookies — the same as any other embed on this site. Six of the embeds point at a target that no longer exists or was never public; pressing their buttons still contacts the provider, which is why they are listed here like the rest. Most of those providers are based outside the EEA; where no adequacy decision applies, the transfer rests on your explicit consent under Art. 49(1)(a) GDPR.

7. Encryption

This site uses TLS encryption (visible as https:// in the address bar), so transmitted data cannot be read by third parties.

8. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21), and to withdraw consent with future effect (Art. 7(3)). Contact .

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular with the authority responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart.

9. Changes

We update this policy when the site or the legal position changes. The version published here is the one that applies.