Privacy Policy

Privacy policy and data protection information in accordance with GDPR (last updated May 2026).

Privacy Policy

Last updated: May 2026

1. Controller & Contact

Responsible party within the meaning of the GDPR:

Stephan Gensch Brandenburger Str. 47 14467 Potsdam, Germany E-Mail: office@stephan-gensch.net

2. Hosting & Infrastructure

This website is hosted on a dedicated server operated by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in their Nuremberg (Germany) data centre. Personal data collected on this website is stored on that server. Data processing is governed by a Data Processing Agreement pursuant to Art. 28 GDPR.

3. Data We Collect

Data Category Details Purpose
Server logs IP address, browser info, timestamps Security & troubleshooting (auto-deleted after 30 days)
Contact form Name, email address, subject, message Processing your enquiry

4. Legal Basis (Art. 6 GDPR)

  • Contract performance (Art. 6(1)(b)) — Processing contact form data to respond to your enquiry.
  • Legitimate interest (Art. 6(1)(f)) — Server logs for security monitoring and abuse prevention.

5. Data Sharing

We do not sell, rent, or share your personal data with third parties, except:

  • Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany; data centre Nuremberg, Germany) — data processor under a DPA compliant with Art. 28 GDPR.
  • Brevo SAS (email delivery service; 7 rue de Madrid, 75008 Paris, France; EU infrastructure) — used solely to forward incoming contact enquiries to me. Only your email address and message content are transmitted. Brevo’s privacy policy is available at brevo.com/en/legal/privacypolicy.

6. Data Retention

  • Server logs are automatically deleted after 30 days.
  • Contact form enquiries are deleted once the matter is resolved, unless statutory retention obligations apply.

7. Your Rights (Art. 15–21 GDPR)

You have the right to:

  • Access your stored personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (“right to be forgotten”, Art. 17)
  • Restrict processing (Art. 18)
  • Data portability — receive your data in a machine-readable format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time

To exercise any of these rights, email office@stephan-gensch.net. We will respond within 30 days.

8. Cookies & Tracking

This website uses only essential session cookies required for authentication of the administration area. We do not use analytics cookies, tracking pixels, or any third-party tracking.

Visitors to the public website receive no cookies.

9. Data Security

All data is transmitted over TLS (HTTPS). The database is not publicly accessible and is restricted to the application server.

10. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. The competent authority for our place of residence is:

Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (LDA Brandenburg) Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany www.lda.brandenburg.de