Back to Home

Privacy Policy

How this website handles personal data, under the GDPR (DSGVO). It is written to be read rather than to be survived.

Who is responsible

Rati Vardiashvili, Uhthoffstraße 18, 28757 Bremen-Vegesack, Germany. Email: [email protected]. There is no separate data protection officer; this is a personal site.

Where the site is hosted

On a server rented from Hetzner Online GmbH, located in Helsinki, Finland — inside the EU.

Since September 2026 the site is reached through Cloudflare, which sits between your browser and that server. It terminates the connection, filters automated attacks and serves cached copies of static files. Cloudflare therefore sees your IP address, the page you asked for and your browser details before this server does. Cloudflare, Inc. is based in the United States; its data processing addendum and the EU standard contractual clauses apply to that traffic. The legal basis is Art. 6(1)(f) GDPR — the operator's legitimate interest in keeping the site available and defending it against attack.

Beyond that, no analytics service, advertising network or social media tracker is loaded. The single further exception is the Spotify player, and it is not loaded until you ask for it. See below.

Cookies

This site sets no cookies of its own. None at all. There is therefore no cookie banner, because there is nothing to consent to until you choose to load the Spotify player, which asks first.

Two things are stored in your own browser and never sent anywhere: the high score of the snake game, if you play it, and a random identifier for the current tab used to measure reading time (see below). The second is deleted the moment you close the tab.

Server logs and reading time

Every request to this site is recorded on the server. Each entry holds your IP address, the date and time, the page requested, the referring page if any, your browser's user-agent string and preferred language, and the HTTP status returned.

From the IP address the server derives the country and the network operator only — no city, no coordinates. The automated tooling used to administer this site — which includes an AI assistant — is given only a generated handle that changes every week, never the address.

Server logs containing raw IP addresses are automatically deleted after 7 days. This is the maximum recommended by the German data protection authorities (BayLDA) for server logs kept under legitimate interest.

After 7 days, the behavioral record (pages visited, time spent) is retained for up to 30 days under a weekly-rotating pseudonym with no IP attached. Because the mapping key is destroyed when the week ends, it is no longer possible — even for the operator — to determine which address is behind that record. The data is at that point genuinely anonymous and falls outside the scope of the GDPR.

The site additionally measures how long each page was open, and sends that measurement to the same server when you leave the page. It is tied to a random identifier held for the lifetime of the browser tab, which links the pages of a single visit together and is destroyed when the tab closes. It cannot recognise you on a later visit.

Legal basis: Art. 6(1)(f) GDPR — the operator's legitimate interest in understanding how his site is used, in operating it securely and in detecting abuse.

Retention: server logs with raw IPs are deleted automatically after 7 days. Anonymised behavioral records are deleted after 30 days. Both run on timers, not manual promises.

This data is never sold and never shared. Apart from Cloudflare's role described above, it is not transmitted anywhere else.

Blocking abusive traffic

Addresses that attack the site — scanning for vulnerabilities, probing for credentials, attempting to break in — are blocked at the web server.

So that a block is not quietly forgotten a week later when the pseudonym key rotates, the site keeps a one-way cryptographic digest of the blocked address. The address itself is not stored: the digest cannot be reversed, and it cannot be used to look anyone up. Its only purpose is to answer one question when a new request arrives — has this address been blocked before? Nothing else is compared against it, and it is never used to link ordinary visits together.

Legal basis: Art. 6(1)(f) GDPR. Recital 49 names network and information security — including preventing unauthorised access and stopping attacks — as a legitimate interest. Storing a digest instead of the address is the data-minimisation required by Art. 5(1)(c).

Retention: each entry carries a review date and is removed when the block is no longer needed. You may ask for a block to be reviewed or lifted using the contact details above.

Device fingerprinting

No code on this site interrogates your device. There is no canvas or WebGL fingerprinting, no font or plugin enumeration, no screen or hardware profiling, no cross-site tracking and no advertising identifiers. Nothing is stored on your device.

What is recorded is what your browser announces by itself in every request it sends: the user-agent string, which names your browser and operating system, and your preferred language. Together with your IP address that is a weak identifier — not unique to you, but not nothing either, and it would be dishonest to describe it as collecting nothing. It is not used to recognise you across visits, and no attempt is made to sharpen it.

Contact form

If you use the contact form, the name, email address, phone number and message you type are stored on the same server and emailed to the site owner's own mailbox, which is also on that server. Nothing is passed to a third party.

Legal basis: Art. 6(1)(b) and (f) GDPR — responding to an enquiry you initiated.

Retention: messages are kept for up to twelve months so a conversation can be picked up again, then deleted automatically. Ask sooner and they go sooner.

Spotify player and external links

The home page can show a Spotify playlist. It is not embedded until you click to load it: until then nothing has been requested from Spotify and they know nothing about your visit. If you do load it, your IP address and browser details go to Spotify AB and they may set cookies on your device, under their own privacy policy. That choice is not remembered — reload the page and it is unloaded again.

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG — your consent, given by clicking, and withdrawable by reloading the page.

Every other mention of GitHub, LinkedIn or similar is an ordinary link. Nothing is loaded from those services while you are here, so they learn nothing unless you click through.

Your rights

Under the GDPR you may ask for access to the data held about you (Art. 15), correction of it (Art. 16), its deletion (Art. 17), restriction of its processing (Art. 18), a copy in portable form (Art. 20), and you may object to processing based on legitimate interest (Art. 21).

Email [email protected] and it will be dealt with. There is no form to fill in and no fee. For a deletion request, say roughly when you visited and from what connection, so the right entries can be found — an IP address alone is not linked to a name here.

You also have the right to complain to a supervisory authority. The competent one is Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen.

Changes

If this policy changes, the updated version appears here. There is no mailing list to notify, because there is no mailing list.

These documents were drafted for a personal, non-commercial site and are not legal advice. If this site ever becomes commercial, have them reviewed by a lawyer.