1. Data Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Daniel Böttner
Software Development & DevOps
Leipzig, Deutschland
Email: [email protected]
Phone: +49 163 420 20 11
2. Principles: No Tracking Cookies, No Cookie Banner Required
Protecting your privacy is a core principle of this website. This site operates purely as a technical portfolio and showcase.
- No Tracking or Advertising Cookies: No cookies are used for marketing, affiliate tracking, user profiling, or web analytics (such as Google Analytics).
- No Third-Party Font CDNs: Typography and static assets are delivered strictly from our own web server. No connections to external CDNs like Google Fonts occur.
- No Cookie Banner: Since no consent-requiring trackers or cookies are stored on your device, an opt-in cookie consent banner is neither technically needed nor legally required.
3. Website Provision and Server Log Files
Whenever this website is accessed, the web server (Traefik / Nginx) automatically logs technical connection data sent by your browser:
- IP address of the accessing client
- Date and timestamp of request
- Requested URI path and file
- HTTP status code and volume of transmitted bytes
- Browser type, version, and operating system
- Referrer URL (if transmitted)
Legal Basis: Data processing is conducted pursuant to Art. 6 (1) lit. f GDPR based on our legitimate interest in the error-free technical delivery, stability, and defense against malicious cyber-attacks (e.g., DDoS).
Retention Period: Server log entries are retained only for security analysis and diagnosis for a few days and then automatically deleted or anonymized.
4. Bot Protection & Abuse Prevention (Cloudflare Turnstile)
On this website, we employ Cloudflare Turnstile, provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).
Purpose: Turnstile is specifically utilized to protect our interactive live demo infrastructure (GoBD LogBook Showcase). Before triggering an isolated sandbox container deployment, Turnstile verifies whether the request originates from a human user or an automated script, bot, or brute-force tool. This shields our server resources from resource exhaustion (Denial of Service) and ensures test slots remain available for legitimate visitors.
Privacy-Preserving Mechanism: Turnstile represents a privacy-preserving alternative to traditional Captcha services. It does not store persistent tracking cookies on your terminal device and does not engage in cross-site tracking. Verification evaluates non-invasive browser heuristics and telemetry without requiring puzzle-solving tasks.
Legal Basis: Processing is based on Art. 6 (1) lit. f GDPR (legitimate interest in IT security, server resilience, and prevention of automated resource abuse).
International Data Transfers: Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF) and uses Standard Contractual Clauses (SCC) approved by the European Commission.
5. Ephemeral Demo Sandboxes (GoBD LogBook)
Launching an interactive live demo starts a short-lived Docker container with an isolated test database via CI/CD.
- The environment exists solely for exploratory inspection of the software.
- Please do not enter real personal, confidential, or business data into demo instances.
- Automated Destruction: After the 15-minute demo session expires, the container shuts down automatically, permanently deleting all session records, audit hashes, and logs without residue.
6. Direct Inquiries (Email / Phone)
When contacting me via email or phone, the data you transmit (e.g. name, contact details, message contents) is stored to process your inquiry and any follow-up questions.
Legal Basis: Processing relies on Art. 6 (1) lit. b GDPR (for pre-contractual or contractual requests) or Art. 6 (1) lit. f GDPR (legitimate interest in responding efficiently to incoming communication).
7. Your Rights as a Data Subject
Under the GDPR, you have the following rights regarding personal data concerning you:
- Right of Access (Art. 15 GDPR): Inquire about your personal data processed by us.
- Right to Rectification (Art. 16 GDPR): Demand correction of inaccurate or incomplete records.
- Right to Erasure (Art. 17 GDPR): Request deletion of your stored personal data.
- Right to Restriction of Processing (Art. 18 GDPR): Request restriction of data processing.
- Right to Data Portability (Art. 20 GDPR): Receive data in a structured, standard, and machine-readable format.
- Right to Object (Art. 21 GDPR): Object at any time to processing based on legitimate interests.
- Right to Lodge a Complaint (Art. 77 GDPR): Lodge a complaint with a competent data protection supervisory authority (in Saxony: Sächsischer Datenschutzbeauftragter, Dresden).