Privacy Policy
Last updated: 30 June 2026
1. Overview
Protecting your personal data is important to me. This website is built to collect as little data as possible: there is no advertising, no cross-site tracking, and no tracking cookies. The following notice explains what data is processed when you visit this site and what rights you have under the General Data Protection Regulation (GDPR).
2. Controller
The controller responsible for data processing on this website is:
Tobias ArweilerMarienleuchter Weg 8
23769 Fehmarn
Germany
Email:
3. Hosting
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (“Hetzner”). When you access the site, Hetzner automatically processes technical connection data on my behalf. The legal basis is my legitimate interest in the secure and reliable provision of this website (Art. 6 (1)(f) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner. The servers are located in Germany.
4. Server log files
When you access this website, the server automatically collects and stores information in server log files that your browser transmits. This includes:
- browser type and version
- operating system used
- referrer URL
- date and time of the request
- IP address (in shortened/anonymized form where possible)
This data is not merged with other data sources. It is processed on the basis of Art. 6 (1)(f) GDPR to ensure the technical operation and security of the website, and is deleted after a short period.
5. Cookies
This website does not use any tracking or marketing cookies. A strictly necessary cookie is only set in the private administration area of the site (to keep the site owner logged in) and is never set when you browse the public pages. No consent banner is therefore required for normal visits.
6. Web analytics (Plausible)
To understand how this website is used, I run a self-hosted instance of Plausible Analytics. Plausible is a privacy-focused analytics tool that works without cookies and does not collect any personal data or store any information on your device. No data is shared with third parties, and all data is processed on my own infrastructure within the EU. Aggregated, anonymous metrics (such as page views and referrers) do not allow you to be identified. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in analysing and improving the website).
7. Contact form
If you use the contact form, the details you provide (your name, email address and message) are processed in order to handle your enquiry and to contact you. To deliver these messages by email, the submitted data is transmitted to the email service Plunk, which acts as a processor and forwards the message to my inbox. A data processing agreement pursuant to Art. 28 GDPR (Plunk’s standard data processing agreement, which takes effect automatically when its hosted service is used) is in place. Plunk stores its data within the EU/EEA (servers in Germany). For the actual email delivery, Plunk uses Amazon SES, which can involve a transfer of data in transit to the USA; this transfer is safeguarded by the EU Standard Contractual Clauses. Further details can be found in Plunk’s privacy policy at useplunk.com/privacy.
The legal basis is Art. 6 (1)(a) GDPR (your consent) and Art. 6 (1)(f) GDPR (my legitimate interest in responding to enquiries). The data is deleted once your enquiry has been fully dealt with, unless statutory retention periods apply. You may withdraw your consent at any time.
8. Fonts
This website uses the typefaces “DM Sans” and “DM Serif Display”. These fonts are hosted locally on my own server and are not loaded from Google servers. No connection to Google is established and no data is transmitted to Google when you visit this site.
9. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” in the address bar of your browser.
10. Your rights
Under the GDPR you have the right, at any time, to:
- request information about the data stored about you (Art. 15)
- request the correction of inaccurate data (Art. 16)
- request the erasure of your data (Art. 17)
- request the restriction of processing (Art. 18)
- data portability (Art. 20)
- object to processing (Art. 21)
- withdraw consent you have given, with effect for the future
To exercise any of these rights, please contact me using the details in the “Controller” section above. You also have the right to lodge a complaint with a data protection supervisory authority.