Privacy Policy
Last updated: August 13, 2026
The Short Version
This blog is hosted on a server in Germany provided by netcup GmbH and delivered to you through Bunny.net’s content delivery network, which caches pages closer to you so the site loads faster, and which, as a side effect, sees somewhat more connection data per request than a plain web server would (details below). No cookies. No third-party scripts. No Google Analytics, no Facebook pixel, no ad networks, nothing of the sort. Beyond that CDN hop, the only data involved is what your browser sends to any web server when you visit a page, plus privacy-friendly visitor statistics through a self-hosted analytics tool that doesn’t track you.
This isn’t accidental. I run this blog precisely because I don’t want to feed the surveillance machine. No external fonts pulled from Google, no embedded YouTube videos that drop tracking cookies before you’ve even pressed play, no ad tech riding along with the CDN. If a feature needs me to share your data with someone else beyond what it takes to actually deliver the page, I don’t add the feature.
If you just wanted the gist, that’s it. The rest is the legally required detail.
Applicable Law
Processing of personal data on this site is governed by the GDPR (Regulation (EU) 2016/679) and the law of the Federal Republic of Germany, including the BDSG and the TDDDG.
Who’s Responsible
The controller for data processing under the GDPR is:
hmmr – Alexander Hammer
c/o Online-Impressum #8062
Europaring 90
53757 St. Augustin
Germany
Email: blog@hmmr.online
If you have any questions about your data, this is who you talk to.
A designated data protection officer is not required (§ 38 BDSG — fewer than 20 persons engaged in automated processing of personal data).
Hosting
This website is hosted by netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. Because Bunny’s CDN caches most pages (see “Content Delivery Network” below), most visits are served entirely from Bunny’s edge and never reach this server. When a request does reach it, netcup processes connection data (including your IP address) as part of delivering the website to you.
For more information, see netcup’s privacy policy:
https://www.netcup.de/kontakt/datenschutzerklaerung.html
A data processing agreement under Article 28 GDPR has been concluded with netcup GmbH.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in reliable and secure hosting of this website.
Content Delivery Network (CDN)
This site is delivered to you through Bunny.net, a content delivery network operated by BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia. Instead of every request travelling all the way to the server in Germany, Bunny caches and serves pages from a location closer to you, which makes the site load faster.
To do that, Bunny’s edge servers process more than a plain web server log would: your IP address, the URL requested, timestamp, HTTP status code, your browser’s user agent and referrer, a JA4 TLS client fingerprint, your network’s ASN/organization and country, cache status, bytes transferred, a request ID, and which edge location served you. Raw request data sits in edge memory for roughly 20–30 seconds before being cleared and sent on to Bunny’s central log processing (based in the EU). IP addresses are anonymized by default; I haven’t changed that setting or enabled Bunny’s permanent log storage.
Because Bunny’s edge servers terminate the TLS connection on my behalf (see “TLS Encryption” below), Bunny technically has access to the decrypted content of each request, not just the connection metadata above, for the moment it takes to route it onward.
I’ve left Bunny’s global edge network enabled rather than restricting it to EU-only locations, so delivering this site can involve processing your connection data at edge locations outside the EU/EEA. That onward transfer is Bunny’s own, to the data center and network providers behind its edge infrastructure, under contracts that oblige those providers to GDPR-level protections; Bunny doesn’t name those specific infrastructure providers, citing business confidentiality. (That’s separate from the published sub-processor list linked below, which covers support and business tools Bunny itself uses — customer support, messaging, and similar services. None of them are involved in delivering this site.) I rely on Bunny’s Article 28 data processing agreement for this rather than a separate transfer safeguard of my own.
Why: Faster, more reliable delivery of this site, and reduced load on the origin server.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in fast and resilient delivery of the website.
How long: Request logs are retained for 3 days at Bunny before automatic deletion. I don’t have access to or store a separate copy of them.
For more information, see Bunny.net’s GDPR page and its (business, not infrastructure) sub-processor list: https://bunny.net/gdpr/ https://bunny.net/gdpr/sub-processors/
TLS Encryption
This site uses HTTPS/TLS encryption for security reasons and to protect the transmission of personal data and other confidential content. You can recognize an encrypted connection by the “https://” prefix and the lock icon in your browser’s address bar.
TLS protects your connection from being read or tampered with by anyone eavesdropping on the network in between. It doesn’t extend past the point where it’s terminated: Bunny.net’s edge servers terminate TLS on my behalf as part of delivering this site (see “Content Delivery Network” above), so Bunny, as a processor, technically has access to the decrypted content passing through its edge, the same way any CDN or reverse proxy would.
What Happens When You Visit a Page
Server Log Files
Every web server logs incoming requests. Mine does too, using the visitor IP that Bunny’s CDN forwards for this purpose, not Bunny’s own edge IP. For each page view, the following gets written to a log file:
- Your IP address
- Date and time of the request
- The URL you requested
- HTTP status code and amount of data transferred
- Your browser’s user agent string
- The referring URL, if your browser sent one
Why: These logs are technically necessary to deliver the website, ensure system security, and troubleshoot errors.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in operating a working, secure website.
How long: Log files are kept for 7 days, then automatically deleted.
I don’t combine these logs with any other data. I don’t try to identify you from them.
Analytics with Umami
I use Umami, a privacy-focused analytics tool I run on my own server hosted by netcup GmbH in Germany. No analytics data leaves my infrastructure.
Umami doesn’t set cookies and no persistent identifiers are stored on your device. Your IP address is processed only transiently to derive your approximate geographic region, then immediately discarded. It is not stored. A daily-rotating hash is derived from your IP, user agent, and the current date — this hash is discarded after 24 hours.
The analytics setup is intentionally configured in a privacy-preserving way and is not used to identify or track individual users across sessions or across different websites.
What Umami records:
- The page you visited
- Approximate country and region (derived from IP, then discarded)
- Your browser and operating system
- Referring page
Notably absent: screen dimensions and language settings. The analytics script is configured to not read any device properties via JavaScript. All data comes from HTTP headers (URL, referrer, user agent) or server-side IP geolocation — not from active JavaScript reads.
Why: I want to know which posts people actually read. That’s it.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in understanding which content works. No consent is required under § 25 TDDDG because the script does not actively access the end device: no device properties are read via JavaScript, no data is written to or read from storage on your device.
Contact Form
This website includes a contact form that allows you to send me a message directly. When you use the contact form, the following data is collected:
- Your name
- Your email address
- Your message
Your submission reaches my server the same way any request to this site does, through Bunny.net’s CDN (see “Content Delivery Network” above) on the way in. Each leg of that path is TLS-encrypted, but Bunny terminates the connection first and, as a processor, technically has access to the decrypted form data (your name, email address, and message) for the moment it takes to pass it on, the same way it does for the rest of the site (see “TLS Encryption” above). From there it’s processed on my server and forwarded to me via my email server, both hosted by netcup GmbH in Germany. The data is used exclusively to respond to your inquiry.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in providing a way to get in touch, or Article 6(1)(b) GDPR if your inquiry relates to a contractual matter.
How long: Contact form submissions are deleted within 3 months after the conversation has concluded, unless a longer retention period is required by law.
I don’t share your contact form data with third parties.
What I Don’t Do
- I don’t use cookies
- I don’t load fonts, scripts, or images from Google, Meta, or any other third party
- I don’t have ads
- I don’t have social media share buttons that track you
- I don’t have a newsletter
- I don’t do automated decision-making or profiling (Art. 22 GDPR)
Your Rights
Under the GDPR, you have the following rights regarding your personal data. To exercise any of them, email me at blog@hmmr.online — no formal request needed, just send a message.
- Right of access (Art. 15 GDPR) — you can ask me whether I process data about you, and if so, get a copy of that data along with information on what I do with it.
- Right to rectification (Art. 16 GDPR) — if any data I hold about you is wrong or incomplete, you can ask me to correct or complete it.
- Right to erasure (Art. 17 GDPR) — also known as the “right to be forgotten.” You can ask me to delete your data, and I will, unless I’m legally required to keep it.
- Right to restriction of processing (Art. 18 GDPR) — instead of deletion, you can ask me to just stop using the data while we sort something out (e.g. while you contest its accuracy).
- Right to data portability (Art. 20 GDPR) — you can ask for a copy of your data in a structured, machine-readable format, so you can take it elsewhere.
- Right to object (Art. 21 GDPR) — you can object to processing based on legitimate interest (which is most of what happens here: logs, analytics, contact form replies). See the notice below.
Right to Object (Art. 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on legitimate interest (Article 6(1)(f) GDPR). If you object, I will no longer process the personal data unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.
To object, email blog@hmmr.online with a brief description of your situation.
Right to Lodge a Complaint
Under Art. 77 GDPR, you also have the right to lodge a complaint with a supervisory authority. The authority responsible for me is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2-4
40213 Düsseldorf
Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Web: https://www.ldi.nrw.de
External Links
This blog may contain links to external websites. When you follow such a link, you leave this website and the privacy policy of the respective external site applies instead.
I have no control over how external websites process personal data and cannot continuously monitor their content or privacy practices. If you notice problematic or unlawful content on a linked site, feel free to contact me.
Changes to This Policy
If I add features that change how data gets processed (comments, additional forms, etc.), I’ll update this page accordingly. The current version published here always applies.