// privacy
Privacy Policy
1. Controller
Thomas Negele
Rigaer Straße 105
10247 Berlin, Germany
Phone: +49 176 93118758
Email: info@thomasnegele.de
This policy explains which personal data is processed when you visit this website, for which purpose, on which legal basis, who receives it and how long it is stored.
2. No cookies, no tracking
This website does not store any information on your device and does not access information already stored there. No cookies are set, and neither local storage nor session storage is used. Consent under § 25 TDDDG (the German ePrivacy implementation) is therefore not required, and there is no cookie banner.
No analytics, tracking or advertising services are used, and no user profiles are created. All fonts, images, scripts and stylesheets are served from my own server; simply opening a page establishes no connection to third-party servers.
3. Accessing the website and hosting
When you open a page, your browser transmits technically necessary data to the server. The server logs may contain:
- IP address of the requesting device
- date and time of access
- URL accessed and HTTP status code
- volume of data transferred
- browser and operating system details (user agent)
The purpose is to deliver the pages and to keep operation stable and secure. The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in a functioning website protected against abuse). This data is not combined with other sources, not used to analyse user behaviour, and kept only as long as necessary for operation and security.
The server is operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, acting as my processor. Hetzner also operates the authoritative name servers for the domain thomasnegele.de; IP addresses of the requesting resolvers may be processed there during DNS resolution. Further information: hetzner.com/legal/privacy-policy.
4. Contact form
Via the contact form you submit your name, your email address, the selected topic and your message. If you open the form using the contact button of a blog article, the article title, its short name (slug) and its URL are sent along so that I can see the context of your enquiry. These details are visible as parameters in the address bar and can be removed before sending.
To prevent automated abuse, your IP address is checked when you submit the form and held for at most one hour in the server's memory only, in order to limit the number of requests per sender. The IP address is not stored permanently and is not included in the message that is sent.
Your enquiry is delivered by email to my mailbox. For sending and receiving email I use the mailbox.org service operated by Heinlein Hosting GmbH, Schwedter Straße 8/9A, 10119 Berlin, Germany, acting as my processor (mailbox.org/de/datenschutz). Beyond this, I do not pass your details on to anyone.
The legal basis is Art. 6 para. 1 lit. b GDPR where your enquiry relates to a contract or its preparation, otherwise Art. 6 para. 1 lit. f GDPR (legitimate interest in answering enquiries and in preventing spam). I keep your enquiry until it has been dealt with and no follow-up questions are to be expected; statutory retention obligations, for example for business correspondence, remain unaffected.
5. Enquiry by email or phone
If you contact me directly by email or phone, I process your details (for email: sender address and content; for calls: phone number, name and content) in order to handle your request. Legal basis and retention correspond to section 4. The email provider named above also applies here.
6. View statistics for blog articles
For blog articles I keep a simple internal reach statistic. When an article is requested, a counter is incremented on the server; only the language, the article slug, a calendar date and the number of views are stored. No IP addresses, user agents, referrers, cookies, identifiers or individual events are stored, and the figures allow no conclusions about individual people.
Your browser's user agent is evaluated briefly in memory so that requests from automated programs (bots) are not counted; it is not stored. The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in roughly assessing the reach of my own articles). The statistic is not publicly accessible.
7. Links to external services
Below blog articles you will find buttons for sharing on LinkedIn and Xing as well as links to my profiles on LinkedIn, Xing and GitHub. These are plain links, not embedded content or tracking pixels: only when you click such a link does your browser connect to the respective provider, who then processes your data under its own responsibility and privacy policy.
8. Transfers to third countries
I do not transfer your data to countries outside the EU or the EEA. Server and mailbox are operated in Germany.
9. Your rights
You have the right of access to the data stored about you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to withdraw consent once given with effect for the future (Art. 7 para. 3). A message to info@thomasnegele.de is sufficient.
Where I process data on the basis of a legitimate interest (Art. 6 para. 1 lit. f GDPR), you may object to that processing under Art. 21 GDPR on grounds relating to your particular situation. I will then stop processing the data concerned unless I can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
Independently of this, you may lodge a complaint with a data protection supervisory authority, for example the authority responsible for me: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany.
Last updated: September 2026 · Structure based on e-recht24.de (heavily shortened and adapted)