Skip to content
mygdpr
How it worksFeaturesPrivacyQuestions
DeutschEnglish
Log in

GDPR Article 13

Privacy notice

Updated: 11 October 2026

  1. Controller
  2. What this notice covers
  3. Hosting
  4. Connection data
  5. Waitlist
  6. Audience measurement with Umami
  7. Error monitoring with Sentry
  8. Sign-in with GitHub
  9. Cookies
  10. Whether you must provide data
  11. Automated decisions
  12. Your rights
  13. Complaint to a supervisory authority

Controller

The controller under GDPR Article 4(7) is Waldemar Enns. Privacy requests go to the address below.

Waldemar EnnsSole proprietorWeb and software developmentEbersteinstraße 1076437 RastattGermany

Phone: +49 173 682 4410

Email: kontakt@waldemarenns.de

What this notice covers

This notice applies to the mygdpr website. It describes running the site, the waitlist, optional audience measurement, optional error monitoring, and sign-in.

We do not sell this data and we do not pass it to ad networks. Recipients are only the parties named here.

The footprint check, access and erasure requests, and the draft complaint to a supervisory authority are not switched on yet. This notice will be updated before those features process personal data.

Hosting

The website and the PostgreSQL database run on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

The purpose is the technical operation of the website. The legal basis is GDPR Article 6(1)(f). The legitimate interest is a site that stays available and protected. Processing takes place in Germany.

Connection data

When you open the site, the web server or the reverse proxy may record connection data: IP address, date and time, requested address, volume of data transferred, HTTP status, and user agent. That happens only where the hosting environment keeps such logs.

The logs are deleted once they are no longer required to run the site and to defend it against abuse.

The legal basis is GDPR Article 6(1)(f). The legitimate interest is delivering the site and protecting it against abuse.

Waitlist

If you join, we store:

  • your email address
  • the fact, the wording version, and the time of your consent
  • the time you signed up and, after you confirm, the time of confirmation

The records sit in a PostgreSQL database on the hosting infrastructure in Germany. We do not store the IP address of the signup in plain text.

The purpose is the waitlist: confirming the signup and writing to you when the footprint check opens. To confirm, we send an email with a link (double opt-in). The link is valid only for a limited time. We store the related token only as a hash and delete it after confirmation or expiry.

The legal basis is GDPR Article 6(1)(a). You can withdraw consent at any time with effect for the future. Processing before the withdrawal stays lawful. Send the withdrawal to kontakt@waldemarenns.de.

The email address and the consent are required to add you. Without both, we do not store the address (GDPR Article 13(2)(e)).

We keep the record until you withdraw consent or the waitlist purpose ends. We then delete it, unless a statutory retention duty says otherwise.

Postmark sends the email. Postmark is a service of ActiveCampaign (formerly Wildbit) in the United States. Postmark receives the email address and the content of the message.

The transfer to the United States relies on the EU-US Data Privacy Framework or on standard contractual clauses.

Audience measurement with Umami

Umami runs only when it is switched on in the configuration. Otherwise the site loads no analytics script.

When Umami is on, it sets no cookies and builds no usage profiles. The configured host receives page views with technical details: page, referrer, browser, device, and language. The software is built so that it does not store the IP address as a profile.

The legal basis is GDPR Article 6(1)(f). The legitimate interest is a rough, aggregated view of which pages are used, without advertising profiles. Because nothing is stored on the device, we do not ask for consent under § 25(1) TDDDG for this.

The configuration decides where the host is. If it is in a third country, in particular the United States, the transfer relies on the EU-US Data Privacy Framework or on standard contractual clauses.

Error monitoring with Sentry

Sentry runs only when a DSN is set. Without a DSN, no error report leaves the application.

When Sentry is on, error and performance data go to Sentry (Functional Software, Inc.). The application records performance data only for a sample of 10 percent of activity. A report can in particular include the time, the address opened, the browser, and the stack trace. On the server, the report can also include the requested URL, query parameters, headers, and cookies. The IP address is not attached on purpose. A forwarded header can still contain it.

How long a report is kept is set by the Sentry project. The application does not set its own period. The data stays stored while it is needed to diagnose errors.

The legal basis is GDPR Article 6(1)(f). The legitimate interest is finding errors and keeping the application stable.

The region depends on the Sentry project. If the project is in the United States, the transfer relies on the EU-US Data Privacy Framework or on standard contractual clauses.

Sign-in with GitHub

Sign-in is optional and uses GitHub OAuth. If you sign in, we receive from GitHub:

  • the user id
  • the login name
  • the display name
  • the email address, if GitHub provides it
  • the address of the profile image

These details live in the encrypted session. We do not keep a separate user database for them.

GitHub (GitHub, Inc., United States) processes the sign-in on its side. Where that sends data to the United States, the transfer relies on the EU-US Data Privacy Framework or on standard contractual clauses.

The legal basis is GDPR Article 6(1)(b). Sign-in provides the access you start.

The details stay for the life of the session, at most seven days. Signing out deletes them sooner.

Cookies

The site does not set an advertising cookie. Two cookies can appear.

Session

The nuxt-session cookie is set when you sign in. Its content is the encrypted session: the GitHub details above, the time of sign-in, and a session id. The cookie is HttpOnly, SameSite=Lax, and Secure, applies to the path /, and expires after seven days. Signing out deletes it.

The legal basis is § 25(2) No. 2 TDDDG, because the cookie is required to provide the sign-in service you asked for, and GDPR Article 6(1)(b).

Language

The i18n_redirected cookie stores the language code de or en so the chosen language stays in place. It lasts one year, SameSite is Lax, and the path is /. It is not HttpOnly. The Secure flag is not set in the default configuration.

The legal basis is GDPR Article 6(1)(f). The legitimate interest is a stable language. Because the cookie stores only that language and is required for the language version, we do not ask for consent under § 25(2) No. 2 TDDDG.

Whether you must provide data

The waitlist needs your email address and your consent. Sign-in with GitHub is voluntary. Connection data arises technically when you open the site, even if you type nothing.

Automated decisions

There is no automated decision-making, including profiling, under GDPR Article 22.

Your rights

You have these rights against the controller:

  • access to the data stored, GDPR Article 15
  • rectification of inaccurate data, GDPR Article 16
  • erasure, GDPR Article 17
  • restriction of processing, GDPR Article 18
  • data portability, GDPR Article 20
  • objection to processing we base on GDPR Article 6(1)(f), GDPR Article 21

If we rectify, erase, or restrict data, we inform recipients to whom we disclosed it where GDPR Article 19 requires that and it is not impossible or disproportionate.

Where processing is based on consent, you can withdraw that consent at any time with effect for the future, GDPR Article 7(3).

Send your request to the email address of the controller. We reply within the period in GDPR Article 12. kontakt@waldemarenns.de

Complaint to a supervisory authority

You can lodge a complaint with a supervisory authority, GDPR Article 77, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement. For the controller in Baden-Württemberg, that authority is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW).

mygdpr

GDPR access and erasure requests.

Legal noticePrivacy notice