Privacy
This is a personal blog. I collect as little as I can get away with: the site works fully without cookies, without an account, and without analytics. Everything below describes what happens in the cases where data is processed.
Who is responsible
- Controller
- Stefan Haas
- Address
- Schusterweg 34, 4072 Alkoven, Austria
- stefan.haas.privat@gmail.com
No data protection officer is appointed; the blog does not meet the thresholds of Art 37 GDPR.
Hosting and server logs
The site is hosted by Netlify, Inc. (San Francisco, USA). Delivering a web page technically requires your IP address, and Netlify writes short-lived request logs containing IP address, timestamp, requested URL, referrer and user agent. I use these only to keep the site running and secure.
- Legal basis: Art 6(1)(f) GDPR, legitimate interest in operating a secure website.
- Transfer to the USA is covered by the EU–US Data Privacy Framework and Netlify's standard contractual clauses.
Fonts
All fonts are served from this domain. No request is made to Google Fonts, so your IP address is never disclosed to Google in order to render text.
Local storage on your device
Four things may be stored in your browser. None of them is used to track you across websites.
- theme
- Whether you chose light or dark mode. Strictly necessary, no consent required.
- abb.consent
- Written only if you press Accept, together with the date, so that I do not ask again. Pressing Decline stores nothing that outlives the browser tab, which is why the question comes back on a later visit.
- abb.newsletter
- Written only if you submit the newsletter form, so the invitation stops appearing on every article. It never leaves your device, and unsubscribing removes it again.
- Firebase Auth tokens
- Written only after you deliberately sign in to comment. Strictly necessary for a service you requested.
Comments and reactions
Reading comments and reaction counts requires no account and no personal data. If you want to react or write a comment, you sign in with Google or GitHub. Sign-in and storage run on Firebase, a service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), with infrastructure operated by Google LLC.
When you sign in and post, the following is stored:
- your display name and profile picture URL, as provided by Google or GitHub;
- your account identifier (a random user id) and email address;
- the text of your comment, its timestamp, and which comment it replies to;
- your reactions and up/down votes, linked to your user id.
Your name, picture, comment text and timestamp are publicly visible. Please do not put anything in a comment that you would not put on a postcard.
- Legal basis: Art 6(1)(b) GDPR, performing the discussion service you asked for, and Art 6(1)(f) for keeping the discussion readable and free of abuse.
- Retention: comments stay until you ask me to delete them or I remove them for being abusive, spam or off-topic. Email me and I will delete yours.
- Signing in with Google or GitHub also means those providers learn that you authenticated here. Their own policies apply to that.
Newsletter
The newsletter is entirely optional and the site works identically without it. If you enter your address, it is passed to my server, which is the only place that can reach the mailing list, and you are added in a pending state.
Nothing is sent to you and you are not on the list until you click the link in the confirmation email. This is double opt-in, which is what §174 TKG 2021 expects for unsolicited commercial email in Austria. If the link is never clicked, the pending entry expires and the address is deleted.
- Data stored: your email address, plus the date you confirmed. No name, no behavioural profile, and no record of which article you signed up from.
- Legal basis: Art 6(1)(a) GDPR, your consent, which you may withdraw at any time.
- Processor: Resend (Plus Five Five, Inc., trading as Resend, 2261 Market Street, San Francisco, CA 94114, USA), which stores the list and delivers the mail. Transfers to the USA rest on the EU standard contractual clauses together with the EU-US Data Privacy Framework.
- Retention: until you unsubscribe. Unsubscribing deletes the address rather than flagging it as inactive, so nothing about you is kept afterwards.
- Every email carries a one click unsubscribe link and the technical unsubscribe headers that let your mail client do it for you. No tracking pixels, no click tracking, no open tracking, and the address is never sold, rented or shared.
Analytics, only if you say yes
If, and only if, you press Accept in the cookie banner, I loadGoogle Analytics 4 (Google Ireland Limited). Until then no Google Analytics script is loaded at all, and Google Consent Mode is set to deny every storage category.
When enabled, it sets cookies and processes:
- pages viewed, time on page and referrer;
- a truncated IP address, approximate region, device type, browser and language;
- a randomly generated identifier that recognises your browser on a return visit.
- Legal basis: Art 6(1)(a) GDPR, your consent, plus §165(3) TKG 2021 for the cookies.
- Transfer to the USA is covered by the EU–US Data Privacy Framework, to which Google LLC is certified.
- Retention: at most 14 months at Google.
- Withdrawal: press Cookies in the footer at any time. Withdrawal removes the analytics cookies and takes effect immediately, without affecting the lawfulness of processing before it.
What I never do
- No advertising, no ad networks, no remarketing, no data sales.
- No newsletter, no tracking pixels in email.
- No profiling and no automated decision-making under Art 22 GDPR.
- Nothing here is aimed at children under 16.
Your rights
Under the GDPR you can ask me, at any time and free of charge, for:
- access to the data I hold about you (Art 15);
- correction of anything inaccurate (Art 16);
- erasure (Art 17), which for comments is immediate on request;
- restriction of processing (Art 18);
- a portable copy (Art 20);
- objection to processing based on legitimate interest (Art 21);
- withdrawal of consent at any time (Art 7(3)).
One email to stefan.haas.privat@gmail.com is enough, no particular form required.
Complaints
If you think I am handling your data unlawfully, you can complain to the Austrian supervisory authority:
Österreichische Datenschutzbehörde Barichgasse 40–42, 1030 Wien, Austria dsb@dsb.gv.at · www.dsb.gv.at
Changes
If I add a service that processes personal data, I update this page and, where the change concerns consent, ask you again rather than reusing an old answer.