Privacy Policy
Last updated: Aug 28, 2026
This English version is provided for convenience. The German version is legally binding.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Dr. Christian Czauderna
Gartenstr. 25B
51519 Odenthal, Germany
Email: contact@czauderna.de
2. Principles
This website is designed according to the principle of data minimisation. There are no ads, no tracking, no analytics, no social media plugins and no embedded third-party services (no external fonts or scripts either). The connection is TLS-encrypted throughout (https). Personal data is processed only to the extent necessary to operate the website and the features you use.
3. Hosting and server log files
The website is hosted by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, under a data processing agreement pursuant to Art. 28 GDPR. When you visit the site, the host automatically records server log files transmitted by your browser: IP address, date and time, requested page, data volume, browser type and version, operating system and referrer. This serves to ensure smooth operation and defend against attacks (Art. 6(1)(f) GDPR). The host deletes the logs according to its retention periods; they are not merged with other data.
4. Cookies
Only technically necessary cookies are used, for which no consent is required (Section 25(2) no. 2 TDDDG): czsession (login session and CSRF protection, deleted when the browser closes), lang (selected language, 12 months) and theme (light/dark mode, 12 months). No cookies are used for advertising, analytics or tracking, which is why no cookie banner is shown.
5. Registration and user account
A user account is required to comment on or like posts. During registration we process: email address, display name, an optional headline, password (stored only as an Argon2id hash with a server-side secret) and the time and version of the accepted Terms of Use and the commitment to respectful content. The email address is stored encrypted in the database and used only to send verification codes and for sign-in; it is not visible to other members. A one-time code is emailed to verify the address. Legal basis: performance of the user agreement (Art. 6(1)(b) GDPR). Accounts not verified within 48 hours are deleted automatically.
To prevent abuse (e.g. automated sign-in attempts) the site stores a non-reversible hash of the IP address with a timestamp for at most 24 hours (Art. 6(1)(f) GDPR – legitimate interest in the security of the service). The IP address itself is not stored in the database.
6. Comments and likes
Published comments are publicly visible together with your display name, headline and time. Likes are shown only as a total per post; which person liked a post is not visible to other members. You can edit and delete your own comments at any time. Legal basis: Art. 6(1)(b) GDPR. The operator may hide or delete comments that violate the Terms of Use (Art. 6(1)(f) GDPR).
7. Emails
Verification and password codes are sent via the host's mail server. No newsletters are sent and no email addresses are passed on to third parties.
8. Contact
If you contact me by email, your details are stored to process the request and any follow-up questions (Art. 6(1)(b) or (f) GDPR) and deleted once no longer required, unless statutory retention obligations apply.
9. Links to LinkedIn and share function
Posts may contain a link to the corresponding LinkedIn post, and a share function is provided. These are plain links – no LinkedIn content is embedded and no data is transferred to LinkedIn unless you click such a link. After clicking, the privacy policy of LinkedIn Ireland Unlimited Company applies.
10. Data security
In addition to TLS encryption of the connection, stored data is protected by technical measures: passwords are stored only as hashes, email addresses encrypted, verification codes only as hashes with short validity. Access to configuration and system files is blocked server-side; sign-in and code entry are rate-limited against automated attempts.
11. Retention
Account data is stored as long as the account exists. You can delete your account yourself at any time under "My profile"; your comments and likes are deleted as well. Verification codes are deleted after expiry (15 minutes), security hashes after 24 hours.
12. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). You can download a copy of your account data at any time under "My profile". To exercise your rights, simply email contact@czauderna.de. You also have the right to lodge a complaint with a supervisory authority; the competent authority is the Data Protection Commissioner of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.
13. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
14. Changes
This privacy policy is updated whenever the data processing on this website changes. The version published here applies.