Website delivery and security access logs
When a page is requested, our Hetzner server processes the IP address, date and time, requested host and path, request method, response status, transferred volume, referrer, and browser or user-agent. We do not request browser geolocation or precise coordinates.
The purposes are delivery of the requested page, technical stability, error analysis, prevention and investigation of attacks or abuse, and protection of the website and its users. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are secure, reliable operation and defence of legal claims.
Standard server access logs are configured to rotate and be deleted after 14 days. Data linked to a detected security incident may be retained until the incident has been investigated and legal claims are resolved. Complete IP addresses will not be reused for marketing or behavioural profiling.
The form service stores only a keyed pseudonymous hash derived from the IP address for rate limiting and consent evidence, not the complete address. For an anonymous page request, these technical records do not reliably identify the natural person behind the device. We associate activity with a named person only when that person knowingly submits identifying information through a form.