Privacy policy
Courtesy translation. Only the German version is legally binding.
In short: this site has no advertising, no social media plugins and no tracking embedded. The public pages set no cookies; only the login area uses a technically necessary session cookie (see User accounts). No profiles are created and no data is passed on to third parties unsolicited. The only thing counted is which pages are accessed – pseudonymously and on my own server (see Reach measurement).
There is one exception: the four videos on the home page. They are loaded from YouTube only after a click – until then there is only a still image from my own server there, and no request goes out to Google. For anyone who does not click, nothing changes (see Videos).
Controller
Timo Britz · Sülzgürtel 47 · 50937 Köln · info@timobritz.de
Hosting & server log files
The website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur. When the site is accessed, the server automatically stores technical access data in log files:
- anonymised or truncated IP address
- date and time of access
- page / file accessed
- browser type and operating system, referrer where applicable
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation). A data processing agreement has been concluded with IONOS. Transmission is encrypted via SSL/TLS.
Storage in the browser (instead of cookies)
Four places on this site store something locally in your browser (localStorage) – none of it is transmitted to the server:
- the chosen colour setting (light/dark) on the home page,
- in the household budget, your entries, but only if you explicitly switch on storage there,
- in the tools of the protected area (only with an account and separate approval), the data created there and the colour setting; a running simulation state is kept in sessionStorage and ends with the tab. These tools compute entirely in the browser. No data is transmitted to the server and no external servers are contacted,
- in the game Merger under
/merger/spielen/the saved game, the high score, a leaderboard of the ten best games and the settings for sound and video mode (keymerger.*). The game also runs entirely in the browser; no data is transmitted to the server or to third parties. You can delete this information via your browser settings. - in the game Squishly under
/squishly/spielen/the saved game with progress, coins and settings (keyjumpmaster.*). It is separate from the Android app. This game also runs entirely in the browser; no data is transmitted to the server or to third parties, and there are neither purchases nor an account there.
All of this serves solely the purpose you requested and does not leave your device. As this storage is strictly necessary for the service you requested, no consent banner is required (§ 25(2) TDDDG, the German Telecommunications and Digital Services Data Protection Act). You can delete it at any time via your browser settings.
Reach measurement (statistics)
To see which pages are accessed, this website counts page views itself and without cookies – no external services (such as Google Analytics) are embedded and no data is transmitted to third parties. When a page is accessed, the following is stored: the time, the page accessed, the origin (only the domain name of the referring page, not the full address) and, roughly, the device type (mobile/desktop).
To count unique visitors, a pseudonymous check value (hash) that changes daily is formed from the IP address, browser identifier and date. The IP address itself is not stored; on the next day, the same person produces a different value. Permanent recognition is therefore not possible, nor is attribution to a person without additional information. Search engine bots are not counted.
The legal basis is the legitimate interest in data-minimising reach measurement (Art. 6(1)(f) GDPR). No cookies are set and no information is stored on your device; consent is not obtained for this. The counting data is kept for 12 months and then deleted automatically.
If you do not want to be counted: If “Do Not Track” or “Global Privacy Control” is switched on in your browser, the site does not send the counting request; if it arrives nevertheless, the server discards it. Browsers without these settings achieve the same by blocking /zaehler.php with any content blocker.
User accounts and protected area
User accounts exist for downloading the project files. The following are stored: user name, e-mail address, a hash value of the password (not the password itself), the time of registration and of the last login, and an optional free-text message from the application; an internal note on the account may be added. If you agree to the terms of use of the download area, the version, time and IP address of the consent are stored as evidence until the account is deleted. The legal basis is Art. 6(1)(b) and (f) GDPR. The data is used exclusively for access control and abuse prevention and is deleted on request. If something is unlocked for an account, a short confirmation is sent to the e-mail address on file.
Session cookie: The pages of the login area – log in, request an account, reset password, account, downloads and the 3D print gallery – set a technically necessary cookie named tbsitzung. It contains a random identifier, is valid until the browser is closed, is only transmitted via HTTPS and cannot be read by scripts. It serves for logging in and for protecting the forms. The legal basis is § 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(b) and (f) GDPR.
In addition, a security log is kept (logins and failed attempts, registration, approvals, downloads, password changes). Failed login attempts without an account are also logged with the identifier entered. Each entry also stores the full IP address of the access – unlike the reach measurement, where this explicitly does not happen. The reason is that attacks on accounts could not otherwise be traced. The legal basis is Art. 6(1)(f) GDPR (security of processing, Art. 32 GDPR). Log entries are kept for 24 months and then deleted automatically.
File storage: Logged-in users can store files. The file, its original name, size, file type, an optional description and the time are stored. Anyone who shares a file makes it visible, together with their user name, to all logged-in users. Deletion is carried out by the user themselves or together with the account (Art. 6(1)(b) GDPR).
Password reset
Anyone who has forgotten their password can have a link sent to the e-mail address on file. What is stored is only a check value (hash) of the link, not the link itself – anyone reading the database could do nothing with it. The link is valid for 60 minutes and can be used once; older open links of the same account expire immediately. The records are kept for 7 days and then deleted. The e-mail is sent via the IONOS mail server. The legal basis is Art. 6(1)(b) GDPR.
For data protection reasons, the form’s response is always the same – regardless of whether an account exists for the entry. This means the form cannot be used to find out who has an account here.
Protection against automated access
To prevent mass registrations and password guessing, the login, registration and password forms are rate-limited. For this purpose, a truncated part of the IP address is stored (for IPv4 the first three blocks, for IPv6 the first four groups) – not the full address. These entries are kept for 24 hours and then deleted automatically. In addition, the forms contain a field that is invisible to humans and a time check; neither produces stored data. The legal basis is Art. 6(1)(f) GDPR. A service such as Google reCAPTCHA is deliberately not used.
The same limitation applies to the contact form. In addition, the fact that an arithmetic task already solved has been used up is recorded there – only a checksum without any personal reference is stored for this, likewise for no longer than 24 hours.
Downloads and 3D print gallery
The gallery can be viewed without an account. For project packages and model files, you use your account to submit a download request. The following are stored: package or model, the time, for project packages an optional free-text justification, my decision (approval or rejection) with time and note, and the number and times of downloads. The sole purpose is the individual approval of the files that I have provided for (Art. 6(1)(b) GDPR). The requests are deleted together with the account. Please do not write any sensitive information in the free-text field – it is read only by me.
Videos (YouTube, only on click)
In the “On video” section on the home page there are four short videos. Nothing is fetched from YouTube when the page loads. At first, only a still image stored on my own server is shown. At this point, therefore, there is no request to Google, no cookies and no transmission of your IP address.
Only when you press a play button is the YouTube player loaded. From that moment on, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) processes data – in particular your IP address, information about your device and browser, and the information about which video was accessed on which page. If you are logged in to Google at the time, Google can associate the access with your account. I have no influence on the nature and extent of this processing.
I use the address youtube-nocookie.com; according to Google, data for personalised advertising is only set when a video is played. The legal basis for loading the player is your
consent (Art. 6(1)(a) GDPR), which you give by clicking the play button – without a click nothing happens. The consent applies to the respective page view; it is not stored and lapses when the page is reloaded. Data may be transferred to the USA in the process; Google LLC is certified under the EU-US Data Privacy Framework. More information from Google:
policies.google.com/privacy.
Contacting me
If you write to me by e-mail or via LinkedIn, I process your details in order to handle the enquiry (Art. 6(1)(b) or (f) GDPR). The LinkedIn reference on the home page is a simple link – no social media plugins are embedded, so no data flows to LinkedIn as a result when the page loads.
Contact form
There is a form on the home page and at the end of every project page. When you submit it, I process:
- Name and e-mail address – so that I know whom I am replying to;
- the text of your message;
- the project, from whose page the form was sent;
- the time and a truncated part of your IP address (for IPv4 the first three blocks, for IPv6 the first four groups) – not the full address.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by ticking the box in the form and can withdraw at any time with effect for the future; for the reply itself, additionally Art. 6(1)(b) or (f) GDPR. For enquiries about purchasing Aktenlage, the legal basis is Art. 6(1)(b) GDPR (pre-contractual measures, see Ordering Aktenlage). Providing the data is voluntary – without an address, however, I cannot reply.
The message is delivered to me by e-mail and additionally stored on the server so that it is not lost should the mail dispatch ever fail. I delete both as soon as the enquiry has been dealt with, at the latest after six months. Enquiries that lead to an order are exempt; I retain these in accordance with the statutory retention periods. No data is passed on to third parties. A letter or e-mail without the form reaches me just as well at the address in the legal notice.
For spam protection, the form contains a field that is invisible to humans, a signed time check and an arithmetic task shown as an image. This task is drawn and checked by my own server – there is no third-party captcha service embedded, in particular not Google reCAPTCHA. No cookies are set for this and no data is transmitted to third parties. The legal basis for spam protection is Art. 6(1)(f) GDPR (protection against automated mass mailing). If the arithmetic task is not legible, an e-mail to the address in the legal notice is equally valid.
Ordering Aktenlage
For orders of the program Aktenlage, I process your name (it appears on the licence certificate), your e-mail address, the billing address, the order and payment data and the licence number. The purpose is the performance of the contract and the reissue of lost licence certificates (Art. 6(1)(b) GDPR). I retain invoices and accounting records for eight years and business letters for six years (Art. 6(1)(c) GDPR in conjunction with § 147 AO, the German Fiscal Code, and § 257 HGB, the German Commercial Code). I keep the register of issued licence certificates for as long as a certificate can be used. No data is passed on to third parties, apart from the bank in the course of the bank transfer.
Version check of the program Aktenlage
The Windows program Aktenlage can check whether a newer version is available. To do so, it retrieves the public file
/aktenlage/fassungen.json from this server, at most once a week. In the process, no identifier, no licence number and no count is transmitted, and nothing is downloaded.
As with any retrieval of a web address, this creates an entry in the server log files of the host, containing the IP address, time and requested file. I do not evaluate these entries and do not combine them with anything. The legal basis is Art. 6(1)(f) GDPR (provision and security of the service).
The check can be switched off in the program’s settings. All other operations in Aktenlage – scanning, text recognition, evaluation, filing and search – run without a network connection; documents and their contents never reach this server.
Only at the push of a button does the program download, once, the optional language model via the bundled Ollama service from Ollama’s public model registry. In the process, this provider receives your IP address and the name of the model; documents and licence data are not transmitted. You trigger this download yourself; the processing by the provider is governed by its privacy policy.
Storage periods at a glance
| What | How long |
|---|---|
| Server log files (IONOS) | short-term by the provider, then deleted |
| Counting data of the reach measurement | 12 months |
| Security log of the accounts | 24 months |
| Rate limiting of automated access | 24 hours |
| Password reset links | 7 days (valid for 60 minutes) |
| Account data, proof of consent, download requests and file storage | until the account is deleted |
| Session cookie in the login area | until the browser is closed |
| E-mails to me | until the enquiry has been dealt with |
| Messages from the contact form | until the enquiry has been dealt with, at most 6 months |
| Aktenlage orders: invoices and accounting records | 8 years |
| Aktenlage orders: business letters | 6 years |
| Register of licence certificates | as long as a certificate can be used |
| Aktenlage version check | only the host’s log entry; no storage of my own |
| Videos (YouTube, only after a click) | no storage by me; Google’s policy applies |
Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability. You also have the right to lodge a complaint with a data protection supervisory authority (in North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, the State Commissioner for Data Protection and Freedom of Information).
Objection and withdrawal of consent: Where I process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). You may withdraw any consent you have given at any time with effect for the future.
As of 26 September 2026.