{"id":3,"date":"2025-06-15T22:34:31","date_gmt":"2025-06-15T20:34:31","guid":{"rendered":"https:\/\/a11ybridge.de\/?page_id=3"},"modified":"2026-01-09T01:19:49","modified_gmt":"2026-01-09T00:19:49","slug":"datenschutzerklaerung","status":"publish","type":"page","link":"https:\/\/a11ybridge.de\/en\/datenschutzerklaerung\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<p>The controller responsible for data processing on this website in accordance with the General Data Protection Regulation (GDPR) is:<\/p>\n\n\n\n<p><strong>Hamid Aminirad<\/strong><br>Residenzstra\u00dfe 99<br>13409 Berlin<br>E-Mail: <a>info@a11ybridge.de<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">1. Hosting, DNS and Email Services<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Our website and backend infrastructure are operated on servers hosted by:<br>Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (server location: Nuremberg, Germany)<br><br><\/li>\n\n\n\n<li>In addition, our domain management, DNS and email services are provided by:<br>one.com A\/S, Kalvebod Brygge 24, 1560 Copenhagen, Denmark (domain registration\/DNS and email services for @a11ybridge.de and @scienceapps.io)<br><\/li>\n<\/ul>\n\n\n\n<p><br>A data processing agreement (DPA) has been concluded with the above providers in accordance with Art. 28 GDPR.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">2. Data Collection and Processing on This Website<\/h2>\n\n\n\n<p>When visiting our website, the following data is automatically collected and stored:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address (processed as part of server and security logs; depending on the log configuration, it may be truncated\/pseudonymized)<\/li>\n\n\n\n<li>Date and time of access<\/li>\n\n\n\n<li>Visited pages<\/li>\n\n\n\n<li>Referrer URL<\/li>\n\n\n\n<li>Browser type, version, language and operating system<\/li>\n<\/ul>\n\n\n\n<p>This data is collected to ensure the functionality and security of the website. The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest).<\/p>\n\n\n\n<p>Which data the plugin sends to our backend:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>installation_id (pseudonymous identifier)<\/li>\n\n\n\n<li>domain (host)<\/li>\n\n\n\n<li>license_key_hash (pseudonymous identifier)<\/li>\n\n\n\n<li>usage\/quota (counts)<\/li>\n\n\n\n<li>where applicable: request metadata (without IP forwarding)<\/li>\n<\/ul>\n\n\n\n<p>purposes: license verification, quota management, abuse prevention<\/p>\n\n\n\n<p><strong>Server log files (web server \/ reverse proxy Caddy)<\/strong><br>When our website is accessed, our web server (Caddy) automatically processes information in so-called server log files. This includes in particular: IP address, date and time of access, requested URL, HTTP method, HTTP status code, volume of data transferred, referrer where applicable, and user agent.<br><strong>Purposes:<\/strong> Operation of the website, ensuring IT security (e.g., prevention\/analysis of attacks), error analysis and tracking misuse.<br><strong>Retention period:<\/strong> 30 days<br><strong>Recipients\/hosting:<\/strong> Hetzner Online GmbH (hosting\/infrastructure, Germany \u2013 Nuremberg)<br><strong>Legal basis:<\/strong> Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation).<\/p>\n\n\n\n<p><strong>Note on email routing:<\/strong><br>Emails sent to addresses ending with @a11ybridge.de or @scienceapps.io are processed via one.com\u2019s email infrastructure.<\/p>\n\n\n\n<p><strong>Security &amp; Abuse Prevention (Fail2ban \/ Server Security Logs)<\/strong><br>To protect our infrastructure and customer data against unauthorized access attempts, brute-force attacks and abuse, we operate an intrusion prevention system (\u201cFail2ban\u201d).<\/p>\n\n\n\n<p><strong>What happens:<\/strong><br>Fail2ban automatically detects suspicious login attempts and abusive patterns and temporarily blocks the corresponding IP addresses.<\/p>\n\n\n\n<p><strong>Processed data:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address (of the attacking client)<\/li>\n\n\n\n<li>date\/time of the event<\/li>\n\n\n\n<li>affected service \/ rule (\u201cjail\u201d), e.g. SSH login attempts (\u201csshd\u201d) or WordPress login attempts (\u201cwp-login-caddy\u201d)<\/li>\n\n\n\n<li>technical event information (e.g. ban\/unban events, number of failed attempts)<\/li>\n<\/ul>\n\n\n\n<p><strong>Configuration (current):<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>sshd<\/strong>: maxretry <strong>5<\/strong> within <strong>10 minutes<\/strong> (findtime), ban duration <strong>12 hours<\/strong> (bantime).<\/li>\n\n\n\n<li><strong>wp-login-caddy<\/strong>: maxretry <strong>5<\/strong> within <strong>10 minutes<\/strong> (findtime), ban duration <strong>12 hours<\/strong> (bantime).<\/li>\n\n\n\n<li><strong>recidive<\/strong> (repeat offenders): maxretry <strong>3<\/strong> within <strong>24 hours<\/strong> (findtime), ban duration <strong>7 days<\/strong> (bantime).<\/li>\n<\/ul>\n\n\n\n<p><strong>Where the data is stored:<\/strong><br>Fail2ban writes security logs on our servers in the file <strong>\/var\/log\/fail2ban.log<\/strong>.<\/p>\n\n\n\n<p><strong>Retention period:<\/strong><br>The Fail2ban log file is rotated and retained for <strong>30 days<\/strong> (current log file plus several rotated archives).<br>Block rules (bans) are applied temporarily for the ban durations stated above;<br>longer retention may occur only if necessary to investigate or defend against security incidents.<\/p>\n\n\n\n<p><strong>Access:<\/strong><br>Access to these logs is restricted to authorized administrators (e.g. server administrators) for security purposes.<\/p>\n\n\n\n<p><strong>Purpose:<\/strong><br>Ensuring the security, integrity and availability of our systems;<br>preventing brute-force attacks, account compromise and abuse.<\/p>\n\n\n\n<p><strong>Legal basis:<\/strong><br>Art. 6(1)(f) GDPR (legitimate interests in maintaining the security of our systems and preventing abuse).<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">3. Cookies &amp; Consent<\/h2>\n\n\n\n<p>On our pages, a consent tool is used to obtain and document consent (Cookie Notice &amp; Compliance for GDPR\/CCPA).<\/p>\n\n\n\n<p>The cookie banner ensures that no non-essential cookies are stored before consent is given (compliant with Art. 6(1)(a) GDPR).<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">4. External Services and Plugins<\/h2>\n\n\n\n<p>Depending on the project and page you access, the following third-party tools and services may be used:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hetzner (Hosting)<\/li>\n\n\n\n<li>one.com (DNS\/Email)<\/li>\n\n\n\n<li>Paddle (Billing\/Payments)<\/li>\n\n\n\n<li>Cookie-Consent Plugin<\/li>\n\n\n\n<li>Only if enabled \/ used on specific pages: embedded videos<\/li>\n<\/ul>\n\n\n\n<p>If personal data is transferred to a third country, this will be carried out using appropriate safeguards (e.g. Standard Contractual Clauses) in accordance with Art. 46 GDPR, where applicable.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">5. Contacting Us<\/h2>\n\n\n\n<p>When you contact us (e.g. via email or form), we collect and store the personal data you provide via email or contact form (such as name, email, message).<\/br>\nThis processing is based on Art. 6(1)(b) GDPR (contract initiation \/ performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in responding to general inquiries).<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">6. Your Rights<\/h2>\n\n\n\n<p>As a data subject, you have the following rights under GDPR:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Right to access (Art. 15 GDPR)<\/li>\n\n\n\n<li>Right to rectification (Art. 16 GDPR)<\/li>\n\n\n\n<li>Right to erasure (Art. 17 GDPR)<\/li>\n\n\n\n<li>Right to restriction of processing (Art. 18 GDPR)<\/li>\n\n\n\n<li>Right to data portability (Art. 20 GDPR)<\/li>\n\n\n\n<li>Right to object (Art. 21 GDPR)<\/li>\n\n\n\n<li><strong>Right to lodge a complaint:<\/strong> You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). For Berlin, the competent authority is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte f\u00fcr Datenschutz und Informationsfreiheit), Alt-Moabit 59\u201361, 10555 Berlin, email: <a>mailbox@datenschutz-berlin.de<\/a>, Website: <a href=\"https:\/\/www.datenschutz-berlin.de?utm_source=chatgpt.com\">https:\/\/www.datenschutz-berlin.de<\/a>.<\/li>\n<\/ul>\n\n\n\n<p>Please contact: <strong><a><\/a><a>info@a11ybridge.de<\/a><\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7. Data Retention<\/h2>\n\n\n\n<p>We only retain personal data for as long as necessary for the purposes for which it was collected, or as required by law.<\/p>\n\n\n\n<p>Retention period: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>free_installations: <strong>180 days of inactivity<\/strong><\/li>\n\n\n\n<li>webhook_logs: <strong>30 days<\/strong><\/li>\n\n\n\n<li>event_log (processed): <strong>30 days<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">8. Security<\/h2>\n\n\n\n<p>We use technical and organizational security measures such as SSL encryption, firewalls, and secure server configurations to protect your personal data.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">9. Changes to this Privacy Policy<\/h2>\n\n\n\n<p>We reserve the right to update this privacy policy to reflect legal requirements or changes to our services.\nPlease check this page regularly for updates.<\/br>\n<\/br><\/br>\n<b>10. Legal Validity<\/b><\/br>\nThis English version of the privacy policy is for informational purposes only. In case of discrepancies, the German version shall prevail.<\/p>","protected":false},"excerpt":{"rendered":"<p>Verantwortlicher im Sinne der Datenschutzgesetze: Hamid AminiradResidenzstra\u00dfe 9913409 BerlinE-Mail: info@a11ybridge.de 1. Hosting, DNS- und E-Mail-Dienste Mit den oben genannten Anbietern [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"class_list":["post-3","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/a11ybridge.de\/en\/wp-json\/wp\/v2\/pages\/3","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/a11ybridge.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/a11ybridge.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/a11ybridge.de\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/a11ybridge.de\/en\/wp-json\/wp\/v2\/comments?post=3"}],"version-history":[{"count":34,"href":"https:\/\/a11ybridge.de\/en\/wp-json\/wp\/v2\/pages\/3\/revisions"}],"predecessor-version":[{"id":301,"href":"https:\/\/a11ybridge.de\/en\/wp-json\/wp\/v2\/pages\/3\/revisions\/301"}],"wp:attachment":[{"href":"https:\/\/a11ybridge.de\/en\/wp-json\/wp\/v2\/media?parent=3"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}