Privacy Policy
This English version is provided for convenience only. The German version is the legally binding one. Read the German original
Preamble
With the following privacy policy I would like to explain to you which types of your personal data (hereinafter also referred to as "data") I process, for which purposes and to what extent. This privacy policy applies to all processing of personal data carried out by me, both in the provision of my services and in particular on my websites, in mobile applications and within external online presences such as my social media profiles (hereinafter collectively referred to as the "online offering").
As of 15 August 2026.
Controller
Kalix - Nico Frank
c/o Online-Impressum #10148
Europaring 90
53757 St Augustin, Germany
E-mail address: [email protected]
A data protection officer does not have to be appointed, because the conditions of Art. 37 GDPR and § 38 BDSG are not met.
Overview of processing operations
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
- Contact data.
- Content data.
- Usage data.
- Meta, communication and procedural data.
- Log data.
Categories of data subjects
- Users.
Purposes of processing
- Security measures.
- Provision of my online offering and user-friendliness.
- Information technology infrastructure.
Relevant legal bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which I process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your country or mine. Should more specific legal bases be relevant in an individual case, I will inform you of them in this privacy policy.
- Consent (Art. 6 (1) sentence 1 lit. a GDPR) - the data subject has given consent to the processing of personal data relating to them for one or more specific purposes.
- Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR) - processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection provisions in Germany: In addition to the data protection rules of the GDPR, national data protection provisions apply in Germany. These include in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, and automated decision-making in individual cases including profiling. In addition, the data protection acts of the individual federal states may apply.
Applicability of data protection requirements in the country of establishment: In the country in which the controller is established, national data protection provisions apply in addition to the General Data Protection Regulation (GDPR).
Security measures
In accordance with the legal requirements and taking into account the state of the art, the cost of implementation and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, I take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input of, disclosure of, securing of availability of and separation of the data. Furthermore, I have established procedures that ensure the exercise of data subject rights, the erasure of data and responses to threats to the data. I also take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections with TLS/SSL encryption technology (HTTPS): in order to protect the data of users transmitted via my online services against unauthorised access, I use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), which protects the data against unauthorised access. TLS, the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. Where a website is secured by an SSL/TLS certificate, this is signalled by HTTPS appearing in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
Transmission of personal data
In the course of my processing of personal data, it may happen that the data is transmitted to, or disclosed to, other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content embedded in a website. In such cases I observe the legal requirements and in particular conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.
International data transfers
Data processing in third countries: where I transfer data to a third country (that is, outside the European Union (EU) or the European Economic Area (EEA)), or where this happens in the course of using third-party services or the disclosure or transmission of data to other persons, bodies or companies (which is recognisable from the postal address of the respective provider, or where this privacy policy expressly refers to data transfer to third countries), this always takes place in accordance with the legal requirements.
For data transfers to the USA, I rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission of 10 July 2023. In addition, I have concluded standard contractual clauses with the respective providers which comply with the requirements of the EU Commission and set out contractual obligations to protect your data.
This twofold safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the standard contractual clauses serve as additional security. Should changes arise within the framework of the DPF, the standard contractual clauses take effect as a reliable fallback. In this way I ensure that your data remains appropriately protected even in the event of political or legal changes.
For the individual service providers, I inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.
For data transfers to other third countries, corresponding safeguards apply, in particular standard contractual clauses, express consent or transfers required by law. Information on third-country transfers and applicable adequacy decisions is available from the EU Commission at https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
General information on data storage and erasure
I erase personal data that I process in accordance with the statutory provisions as soon as the underlying consent is withdrawn or no further legal basis for processing exists. This concerns cases in which the original purpose of processing ceases to apply or the data is no longer required. Exceptions to this rule exist where statutory obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or the protection of the rights of other natural or legal persons, must be archived accordingly.
My privacy notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.
Where several statements on the retention period or erasure deadlines exist for a given item of data, the longest period always applies. Data that is no longer retained for the originally intended purpose but on the basis of statutory requirements or other reasons is processed by me exclusively for the reasons that justify its retention.
Period starting at the end of the year: where a period does not begin expressly on a particular date and is at least one year long, it starts automatically at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the context of which data is stored, the triggering event is the point at which the termination or other ending of the legal relationship takes effect.
Rights of data subjects
Rights of data subjects under the GDPR: as a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: you have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) lit. e or f GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: you have the right to withdraw consent you have given at any time.
- Right of access: you have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to that data as well as further information and a copy of the data in accordance with the statutory requirements.
- Right to rectification: in accordance with the statutory requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: in accordance with the statutory requirements, you have the right to request that data concerning you be erased without delay, or alternatively, in accordance with the statutory requirements, to request the restriction of processing of the data.
- Right to data portability: you have the right to receive data concerning you that you have provided to me in a structured, commonly used and machine-readable format, or to request its transmission to another controller, in accordance with the statutory requirements.
- Complaint to a supervisory authority: without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Provision of the online offering, hosting and server log files
This website is hosted and delivered by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When a page is requested, data is automatically transmitted and stored in server log files: the IP address of the requesting device, the date and time of access, the address requested, the volume of data transferred, the browser and operating system used, and the referring page.
This processing is necessary in order to deliver the site technically, detect faults and fend off attacks. The legal basis is Art. 6 (1) lit. f GDPR. My legitimate interest lies in the secure and stable operation of the website.
From the same request data, Cloudflare produces an aggregated analysis in my administration area, for example the number of page views, the most frequently visited pages, the country of origin and the type of device. This analysis is aggregated and does not allow any conclusions to be drawn about individual persons. No additional script is loaded for this purpose, and nothing is stored on or read from your device.
The log files are deleted after 30 days.
A data processing agreement pursuant to Art. 28 GDPR is in place with Cloudflare. As Cloudflare is established in the USA, a transfer to a third country may occur. The basis for this is the adequacy decision of the European Commission on the EU-US Data Privacy Framework, under which Cloudflare is certified, supplemented by standard contractual clauses.
Videos from YouTube and Twitch
Videos from YouTube and streams from Twitch are embedded on this site. The embedding uses a two-click solution: when the page is opened, no connection to YouTube or Twitch is established. At first only a preview image is displayed, and it is loaded from my own server.
Only when you click the button to load the player is the player fetched, and a connection to the servers of the respective provider established. Your IP address is transmitted in the process, and the provider may use cookies and similar technologies. If you are signed in to an account there, the provider can associate the request with your account.
Beneath the first video you open, you are asked once whether videos should be loaded automatically in future. If you answer yes, this counts as your consent for all further videos: the player is then loaded as soon as an episode is opened, and starts without sound. If you answer no, or ignore the question, the click remains necessary. Your answer is stored in your browser and does not leave your device.
The legal basis is your consent pursuant to Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG, which you give by clicking the player or by answering yes to that question. You can withdraw it at any time: in the System area, switch "Embeds automatisch laden" (load embeds automatically) off again, after which no video will load by itself.
The provider of YouTube is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider of Twitch is Twitch Interactive, Inc., 350 Bush Street, 2nd Floor, San Francisco, CA 94104, USA. YouTube videos are embedded via the address youtube-nocookie.com.
Comments on the videos
Beneath the videos I display the comments that have been published on YouTube for the respective video. The author's public display name, their public profile picture, the text of the comment, the time and the number of likes are shown.
This data is retrieved by my own server via the YouTube Data API and delivered to you. This also applies to the profile pictures: they are not embedded from Google but fetched by my server and delivered from this domain. No connection is established between your device and Google, and your IP address is not transmitted to Google. The retrieval only takes place once the comment area comes into your field of view.
The legal basis is Art. 6 (1) lit. f GDPR. My legitimate interest lies in making the public discussion about a video visible in the place where the video can be watched. The content in question was published publicly on YouTube by the authors themselves.
If you would prefer your comment no longer to appear here, you can delete it on YouTube. It will then also disappear from this site. Alternatively you can contact me at [email protected].
Signing in with your YouTube account
Beneath every video you can voluntarily sign in with your YouTube account in order to comment yourself and to give the video a thumbs up. Without signing in, none of this happens: the comment area remains a list to read, and no request goes to Google.
If you click the sign-in button, this site redirects you to Google. There you sign in and decide whether to allow this site to comment and rate videos on YouTube in your name. From that click onwards, Google processes your data under its own responsibility; Google's privacy policy applies.
When you come back, this site stores a cookie on your device. It contains, in encrypted form, the access keys issued by Google, as well as the name and profile picture of your YouTube channel so that the site can greet you. The cookie is set so that JavaScript cannot read it, and it is only sent to this domain. Nothing is stored on my server for this: there is no user database and no list of who is signed in. The cookie expires after 90 days.
What you write or rate goes to YouTube and appears there publicly under your channel name, exactly as if you had done it on YouTube itself. No separate copy is created on this site.
Who receives this data
The data that Google makes available to me through your sign-in — the access key, the name of your YouTube channel and its profile picture — is not passed on to anyone. There are exactly two places where it appears at all:
Google itself. What you write or rate is sent back, using your access key, to the YouTube Data API. There it appears publicly under your channel name. The data therefore goes back to where it came from.
Cloudflare, where this website runs. The request to YouTube is executed there, and your access key is briefly decrypted and processed in the course of it. Cloudflare is my processor pursuant to Art. 28 GDPR; details are given above under Hosting.
No further disclosure takes place. I do not sell this data, do not use it for advertising, do not pass it to third parties, data brokers or advertising networks, and do not use it to train AI models — neither myself nor through third parties. It serves exclusively the function for which you granted permission: commenting and rating in your name.
The use of data from Google APIs on this site adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The legal basis is your consent pursuant to Art. 6 (1) lit. a GDPR, which you give when signing in. The cookie is necessary for the service you have expressly requested, § 25 (2) no. 2 TDDDG. You can end the sign-in at any time: the "Abmelden" (sign out) button beneath the input field deletes the cookie. You withdraw the permission itself at Google, at myaccount.google.com/permissions.
Feedback list from Discord
On the Feedback und Bugs page I display the posts that have been created in a publicly accessible forum channel of my Discord server. The title, an excerpt of the text, the public display name of the person who created it, the time, the number of replies and the number of reactions are shown. Profile pictures are neither displayed nor loaded.
This information is retrieved by my own server via Discord's interface and delivered to you. No connection is established between your device and Discord, and your IP address is not transmitted to Discord. The retrieval only takes place once the area comes into your field of view.
The legal basis is Art. 6 (1) lit. f GDPR. My legitimate interest lies in making known bugs and requests publicly visible so that the same report does not arrive several times.
If you would prefer your post no longer to appear here, you can delete it on Discord. It will then also disappear from this site. Alternatively you can contact me at [email protected].
If you would like to create a post yourself, you need a Discord account. Discord Netherlands BV, Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands is responsible for that. Discord's privacy policy applies.
Settings in your browser
This site stores some information in your browser's local storage so that it is retained on your next visit: the choice between a light and a dark design, whether motion should be reduced, whether videos may be loaded automatically, whether the sound should come on for a video that starts by itself, whether a video in the header area starts by itself, as well as which episode you last opened and at which point you interrupted it, so that the site can offer to continue from there.
For the duration of a visit, one further item is added: whether your browser has already refused sound for a video that started by itself. It saves a second futile attempt and disappears as soon as you close the tab.
This information does not leave your device and is not read by me. Since you set it yourself and it serves exclusively the presentation you have asked for, no consent is required for it under § 25 (2) no. 2 TDDDG. You can reset all settings and the history in the System area.
Fonts
The fonts used on this site are loaded from my own server. There is no connection to Google Fonts or any other external provider, and no data is transmitted to third parties in the process.
Amendment and updating
Please inform yourself regularly about the content of my privacy policy. I adapt the privacy policy as soon as changes to the data processing I carry out make this necessary. I will inform you as soon as the changes require an act of participation on your part (for example, consent) or some other individual notification.
Definitions
This section provides an overview of the terms used in this privacy policy. Where the terms are defined by law, the statutory definitions apply. The following explanations are intended primarily to aid understanding.
- Content data: content data covers information generated in the course of creating, editing and publishing content of any kind. This category of data can include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content but also includes metadata providing information about the content itself, such as tags, descriptions, author information and publication dates.
- Contact data: contact data is essential information that enables communication with persons or organisations. It includes, among other things, telephone numbers, postal addresses and e-mail addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Meta, communication and procedural data: these are categories containing information about the manner in which data is processed, transmitted and managed. Metadata, also known as data about data, comprises information describing the context, origin and structure of other data. It can include details of file size, creation date, the author of a document and revision histories. Communication data records the exchange of information between users across various channels, such as e-mail traffic, call logs, messages in social networks and chat histories, including the persons involved, timestamps and transmission paths. Procedural data describes the processes and workflows within systems or organisations, including workflow documentation, records of transactions and activities, and audit logs used to trace and review operations.
- Usage data: usage data refers to information recording how users interact with digital products, services or platforms. This data covers a broad range of information showing how users use applications, which functions they prefer, how long they remain on particular pages and which paths they take through an application. Usage data can also include the frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Usage data also plays a decisive role in identifying trends, preferences and possible problem areas within digital offerings.
- Personal data: "personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (for example a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Log data: log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used to analyse system problems, for security monitoring or to produce performance reports.
- Controller: "controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collection, analysis, storage, transmission or erasure.
Erstellt mit kostenlosem Datenschutz-Generator.de von Dr. Thomas Schwenke