Personal data
Privacy notice
Last updated: 29 August 2026
This English translation is provided for convenience. The German privacy notice is the authoritative version.
1. Controller
Martin LangeKrefeldstraße 4
38108 Braunschweig
Deutschland
Privacy requests: privacy@lange-donnern.de
2. Website delivery
When pages are requested, the platform processes technically necessary connection and log data, in particular the IP address, timestamp, requested address, HTTP method, status code, transferred volume and browser information. This is necessary to deliver pages, diagnose faults and defend against attacks. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is secure and reliable operation. Proxy and security logs are retained for no more than 30 days unless a specific security incident requires longer preservation.
3. Account and sign-in
The self-hosted ZITADEL identity service processes sign-in data. The account portal receives a technical user identifier, verified email address and verification status. It also processes the pseudonym, timestamps and versions of age and rules confirmations, account status, blocks and deletion information, and data-copy requests. This data is required to provide and manage the requested shared account. The legal basis is Article 6(1)(b) GDPR.
Only confirmation of the minimum age of 18 is recorded; no date of birth is requested. Platform access cannot be provided without a verified email address, pseudonym, and age and rules confirmations.
4. Sessions and local storage
The platform uses only technically necessary secure HTTP cookies for sign-in and sessions. The short-lived OIDC cookie expires after no more than ten minutes. An account session ends after seven days of inactivity and after no more than 30 days. Cookies use Secure, HttpOnly and SameSite=Lax. Consent is not required under section 25(2)(2) TDDDG because this storage is necessary for the account and sign-in service explicitly requested by the user.
No advertising, analytics or cross-service tracking technology is used. The language choice is not stored persistently in the browser.
5. Security, audit and abuse prevention
Security-relevant account and administrative activity is recorded in an audit log protected against subsequent modification. Identities appear only as secret HMAC pseudonyms; event type, timestamp and necessary technical details are retained for up to twelve months. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is accountability, abuse prevention and system security.
6. Data copies, blocks and deletion
A requested data copy is made available for authenticated download for 24 hours after administrative preparation and its content is then removed. A deletion request ends platform access immediately. It may be cancelled for seven days; the account and connected-service data are then deleted. The last pseudonym remains reserved for 180 days. A non-reversible HMAC of the deleted identity is retained to prevent a completed deletion from being reversed through a new sign-in.
7. Recipients and infrastructure
The production systems, including ZITADEL and PostgreSQL, run on a European VPS at OVHcloud. Encrypted backups are stored in Hetzner Object Storage in Falkenstein; the provider does not receive a decryption key. Emails to the published contact addresses are processed by mailbox.org. DNS services are provided through Webtropia. These providers receive data only to the extent required for the respective infrastructure or communication service.
No transfer of personal data outside the European Economic Area is intended by the controller. Where processors use subprocessors, the legally required safeguards and the applicable data-processing agreements apply.
8. Backups and retention
Production data is backed up daily in encrypted form. Retention comprises 14 daily, eight weekly and twelve monthly snapshots; at least seven days are technically protected against deletion. Individual records cannot be removed retrospectively from existing encrypted backups. Upon restoration, a separate deletion ledger prevents finally deleted accounts from being reactivated. Backup snapshots are deleted automatically after their retention period.
9. Contact by email
When you contact us by email, sender address, content and technical delivery information are processed to answer the request. Depending on the request, the legal basis is Article 6(1)(b) or (f) GDPR. Correspondence is deleted when no longer required for handling or evidence and when no statutory obligation prevents deletion.
10. Your rights
Subject to the GDPR, data subjects have rights including access, rectification, erasure, restriction, portability and objection. The account also provides a machine-readable data copy and deletion process. Requests can be sent to privacy@lange-donnern.de.
You may lodge a complaint with a data protection supervisory authority. For controllers in Lower Saxony, the State Commissioner for Data Protection of Lower Saxony is available.
11. Automated decisions
There is no advertising, profiling or solely automated decision producing legal or similarly significant effects. Technical platform access is determined by verified email address, pseudonym, current confirmations, and an account that is neither blocked nor scheduled for deletion.