Skip to content
Coming soon · Hondicard is launching soon.

Privacy Policy

1. Controller

The controller responsible for data processing on this website is:

Noah Bauditz
Untere Walsumermarkstraße 23
46147 Oberhausen
Germany
Email: [email protected]

2. Hosting

This website is hosted on a server provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Nuremberg, Germany. Hetzner processes personal data on our behalf as a processor in accordance with Art. 28 GDPR.

We use the hosting infrastructure to deliver this website securely and reliably. Because the website is protected by Cloudflare, requests to the origin server are generally forwarded by Cloudflare.

3. Cloudflare DNS, proxy and security services

We use Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, as the authoritative DNS provider for this domain and, for DNS records configured as proxied, as a reverse proxy and content-delivery service. Cloudflare provides, among other things, DNS resolution, traffic routing, caching and delivery, TLS termination, DDoS protection, abuse prevention, and security features.

When you access a proxied part of this website, Cloudflare processes technical connection and request data. Depending on the service and configuration, this may include your IP address, the date and time of the request, the requested host, URL or path, HTTP method, referrer, browser and user-agent information, response status, traffic-routing information, security signals, and the Cloudflare Ray ID. Cloudflare may also receive technical network-error reports from browsers via its reporting endpoint. This processing is necessary to deliver and secure the website and to ensure its stability.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and efficient operation of this website. Cloudflare processes end-user traffic data on our behalf as a processor under the applicable Cloudflare Customer Data Processing Addendum. To the extent Cloudflare processes data as an independent controller, Cloudflare's own Privacy Policy applies.

Cloudflare's retention depends on the Cloudflare products, plan and settings enabled for this domain. Cloudflare states that HTTP request logs are not retained by default; where Logpull retention is enabled, the logs are available for at least three and up to seven days. Security events, analytics, operational data, and account audit logs can be subject to different, product-specific retention periods. We do not make a general promise that all data processed within Cloudflare is deleted after seven days. For details, see Cloudflare's current log-retention documentation and the applicable contractual terms.

4. Origin server and container logs

Routine HTTP access logging is disabled in the origin Nginx configuration. The container runtime may nevertheless record technical error and operational logs. Depending on the event, these logs may include the date and time, requested resource, HTTP status, referrer, browser and user-agent information, and network addresses or proxy headers. Because this website is accessed through Cloudflare and an additional reverse proxy, the origin may receive Cloudflare and forwarded client IP information.

Such logs are processed only to the extent necessary for the secure and reliable operation of the website and for the investigation of misuse or security incidents. The legal basis is Art. 6(1)(f) GDPR. Logs under our control are retained only for as long as necessary for these purposes, according to the applicable host-level retention and rotation policy. Only logs relevant to an identified security incident or a legal obligation may be retained longer, and only for as long as necessary. The retention of Cloudflare data is governed separately by section 3.

5. Contact by email

If you contact us by email, we process your email address, the content of your message, and any other personal data you provide in order to handle your request. The legal basis is Art. 6(1)(b) GDPR where your request relates to pre-contractual measures or a contract, and Art. 6(1)(f) GDPR in all other cases. Our legitimate interest is responding to your request.

We delete this data when it is no longer required to handle your request, unless statutory retention obligations apply.

6. Cookies and tracking technologies

This website does not set its own cookies, and we do not use third-party analytics, marketing, or advertising technologies for tracking or profiling visitors. Cloudflare may set strictly necessary security cookies, such as __cf_bm or cf_clearance if a Cloudflare security or challenge feature requires them. These cookies are used to identify legitimate traffic, prevent abuse, or preserve a security challenge result; we do not use them for cross-site analytics or advertising. The available cookies and their lifetimes depend on the Cloudflare features enabled for this domain. Further information is available in Cloudflare's Cookie documentation .

7. Recipients and transfers to third countries

The recipients or categories of recipients are:

  • Hetzner Online GmbH as our hosting processor; the website's origin server is located in Nuremberg, Germany.
  • Cloudflare, Inc. as our DNS, reverse-proxy, content-delivery and security processor.
  • Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany, as our processor for the email service used for [email protected] .

Cloudflare is headquartered in the United States and operates a global network. Depending on the Cloudflare service, plan and configuration, personal data may therefore be processed or accessed outside the European Economic Area. For transfers from the EEA, Cloudflare states that it relies, where applicable, on the EU-U.S. Data Privacy Framework and otherwise on the EU Standard Contractual Clauses together with supplementary measures as required. The relevant safeguards are set out in the applicable Cloudflare Customer Data Processing Addendum . Cloudflare's current sub-processors are listed here .

8. SSL/TLS encryption

This website uses SSL/TLS encryption to protect data transmitted between your browser and our server. You can recognize an encrypted connection by the https:// prefix and the lock symbol in your browser's address bar.

9. Your rights

You have the right to request access to your personal data, rectification or erasure of your personal data, restriction of processing, data portability, and to object to processing based on Art. 6(1)(f) GDPR. You also have the right to withdraw consent at any time with future effect, where processing is based on consent.

You have the right to lodge a complaint with a supervisory authority. The competent authority for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2-4
40213 Düsseldorf
Germany
www.ldi.nrw.de

10. Changes to this Privacy Policy

We may update this Privacy Policy when this website or the legal requirements change. The version published here is the current version.

Last updated: 29 September 2026