Diese Datenschutzerklärung unterliegt deutschem Recht. Rechtsgrundlage für die Verarbeitung personenbezogener Daten ist die DSGVO in Verbindung mit den einschlägigen deutschen Datenschutzgesetzen.
1. Datenschutz auf einen Blick
In dieser Datenschutzerklärung erfährst du, welche personenbezogenen Daten verarbeitet werden, wenn du meinen Blog besuchst, und zu welchen Zwecken dies geschieht. Personenbezogene Daten sind alle Informationen, die dich persönlich identifizierbar machen. Ich erhebe grundsätzlich nur die Daten, die notwendig sind, um den Blog sicher und stabil bereitzustellen oder mit dir zu kommunizieren.
2. Verantwortliche
Betreiberin dieses Blogs ist:
Minna S.
Die vollständigen Kontaktdaten findest du im Impressum.
3. Hosting & Server-Logfiles
Mein Blog wird bei der Strato AG gehostet. Beim Besuch der Website werden automatisch sogenannte Server-Logfiles erstellt. Dazu gehören u. a. Browsertyp, Betriebssystem, Referrer-URL, Uhrzeit des Seitenaufrufs sowie deine gekürzte/anonymisierte IP-Adresse. Diese Daten werden benötigt, um den stabilen Betrieb der Website zu gewährleisten und Sicherheitsvorfälle erkennen zu können. Die Verarbeitung erfolgt aufgrund meines berechtigten Interesses an einem technisch zuverlässigen und sicheren Betrieb der Website (Art. 6 Abs. 1 lit. f DSGVO).
Mit Strato besteht ein Vertrag zur Auftragsverarbeitung.
4. SSL-/TLS-Verschlüsselung
Zum Schutz deiner Daten nutze ich eine SSL-/TLS-Verschlüsselung. So können Inhalte, die du über die Website übermittelst, nicht von Dritten mitgelesen werden. Diese Maßnahme erfolgt im Rahmen meiner Pflicht, angemessene technische und organisatorische Sicherheitsmaßnahmen nach Art. 32 DSGVO umzusetzen.
5. Datenerfassung auf diesem Blog
Daten, die du aktiv bereitstellst
Wenn du z. B. Kommentare schreibst oder mich per E-Mail kontaktierst, werden die von dir eingegebenen Daten verarbeitet. Dies geschieht, weil du diese Informationen freiwillig übermittelst und damit in die Verarbeitung einwilligst (Art. 6 Abs. 1 lit. a DSGVO) oder weil ich deine Anfrage beantworten möchte (Art. 6 Abs. 1 lit. b bzw. lit. f DSGVO).
Automatisch erfasste Daten
Technisch notwendige Daten wie Browserinformationen oder Zeitstempel werden automatisch beim Seitenaufruf erfasst. Dies geschieht, um die Website technisch bereitstellen zu können (Art. 6 Abs. 1 lit. f DSGVO).
6. Cookies
Mein Blog verwendet ausschließlich technisch notwendige Cookies. Dazu zählen z. B. WordPress-Cookies, die – falls du es aktiv auswählst – deinen Namen und deine E-Mail-Adresse für künftige Kommentare speichern. Solche Cookies sind erforderlich, um bestimmte Grundfunktionen anbieten zu können und beruhen auf meinem berechtigten Interesse an einer funktionierenden Benutzerführung (Art. 6 Abs. 1 lit. f DSGVO). Tracking- oder Marketing-Cookies kommen nicht zum Einsatz.
7. Kommentarfunktion
Wenn du einen Kommentar hinterlässt, werden der Kommentar selbst, der Zeitpunkt seiner Erstellung sowie die Angaben, die du machst (Name, E-Mail-Adresse), gespeichert. Durch das Absenden des Kommentars willigst du in diese Verarbeitung ein (Art. 6 Abs. 1 lit. a DSGVO).
Kommentar-Abonnements
Du kannst Kommentare zu einem Beitrag abonnieren. Dafür erhältst du eine Bestätigungsmail, um die Richtigkeit deiner E-Mail-Adresse zu prüfen. Solange du das Abo nicht abbestellst, werden die dafür notwendigen Daten gespeichert. Die Rechtsgrundlage ist auch hier deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO).
Speicherdauer
Kommentare bleiben gespeichert, solange der zugehörige Inhalt online ist oder rechtliche Anforderungen eine Löschung nötig machen. Du kannst jederzeit die Löschung deiner Kommentare verlangen – eine kurze Nachricht genügt. Grundlage ist hier deine jederzeit widerrufbare Einwilligung (Art. 6 Abs. 1 lit. a DSGVO).
8. Antispam Bee
Um Spam-Kommentare zu verhindern, verwende ich das datenschutzfreundliche Plugin Antispam Bee. Das Plugin arbeitet vollständig lokal, sendet keine Daten an Dritte und überprüft Kommentare anhand interner Kriterien. Die Verarbeitung erfolgt aufgrund meines berechtigten Interesses an einem sicheren und spamfreien Kommentarbereich (Art. 6 Abs. 1 lit. f DSGVO).
9. E-Mail-Kontakt
Wenn du mich per E-Mail kontaktierst, verarbeite ich die von dir übermittelten Daten, um deine Anfrage zu bearbeiten. Dies geschieht entweder zur Vorbereitung oder Erfüllung einer Kommunikation bzw. eines Austauschs (Art. 6 Abs. 1 lit. b DSGVO) oder aufgrund meines berechtigten Interesses an einer verlässlichen Beantwortung deiner Nachricht (Art. 6 Abs. 1 lit. f DSGVO). Ich speichere E-Mails nur so lange, wie es für dein Anliegen notwendig ist oder gesetzliche Pflichten es vorsehen.
10. Analyse mit Matomo (ohne Cookies)
Ich nutze den Webanalysedienst Matomo, den ich vollständig auf meinem eigenen Server hoste. Dadurch bleiben sämtliche Analysedaten bei mir und werden nicht an Dritte weitergegeben.
Erfasst werden u. a.:
- besuchte Seiten
- Zeitpunkte und Dauer
- Referrer
- Browser- und Betriebssysteminformationen
- Klickverhalten
Deine IP-Adresse wird automatisch gekürzt, sodass keine Rückschlüsse auf deine Person möglich sind. Da Matomo auf meinem Blog ohne Cookies betrieben wird, erfolgt die Analyse ausschließlich auf Basis meines berechtigten Interesses, den Blog weiterzuentwickeln und zu verbessern (Art. 6 Abs. 1 lit. f DSGVO).
11. Google Fonts (lokales Hosting)
Ich nutze Google Fonts ausschließlich lokal, sodass keine personenbezogenen Daten an Google übertragen werden. Die lokale Nutzung dient meinem berechtigten Interesse an einer stimmigen und optisch einheitlichen Darstellung des Blogs (Art. 6 Abs. 1 lit. f DSGVO).
12. Fontawesome (lokales Hosting)
Ich nutze die Icon-Schriftbibliothek Font Awesome, um Symbole darzustellen. Die benötigten Dateien (Fonts, CSS) werden lokal auf meinem Server gespeichert und nicht von externen Servern geladen. Die lokale Nutzung dient meinem berechtigten Interesse an einer stimmigen und optisch einheitlichen Darstellung des Blogs (Art. 6 Abs. 1 lit. f DSGVO).
13. Instagram-Inhalte (Social Feed Gallery)
Auf dieser Website binde ich Inhalte meines Instagram-Accounts ein. Dafür nutze ich das WordPress-Plugin „Social Feed Gallery”. Die Bilder werden über meinen Server zwischengespeichert (gecacht) und von dort an euren Browser ausgeliefert. Es findet dabei keine direkte Verbindung zwischen eurem Browser und den Servern von Meta Platforms, Inc. statt.
Betreiberin des Instagram-Accounts bin ich.
Weitere Informationen zum Datenschutz bei Instagram findest du in der Datenschutzerklärung von Meta: https://privacycenter.instagram.com/policy
14. Deine Rechte
Du hast jederzeit das Recht auf:
- Auskunft über die zu dir gespeicherten Daten (Art. 15 DSGVO)
- Berichtigung unrichtiger Daten (Art. 16 DSGVO)
- Löschung deiner Daten (Art. 17 DSGVO)
- Einschränkung der Verarbeitung (Art. 18 DSGVO)
- Widerspruch gegen bestimmte Verarbeitungen (Art. 21 DSGVO)
- Datenübertragbarkeit (Art. 20 DSGVO)
- Beschwerde bei einer Datenschutzaufsichtsbehörde (Art. 77 DSGVO)
Wenn du eines dieser Rechte ausüben möchtest oder Fragen hast, kannst du dich jederzeit über die im Impressum angegebenen Kontaktdaten an mich wenden.
This privacy policy is governed by German law. The legal basis for the processing of personal data is the GDPR in conjunction with the applicable German data protection legislation.
1. Data Protection at a Glance
In this privacy policy, you will find out what personal data is processed when you visit my blog, and for what purposes this is done. Personal data is any information that identifies you personally. As a general rule, I only collect the data that is necessary to ensure the blog runs securely and reliably, or to communicate with you.
2. Data Controller
The operator of this blog is:
Minna S.
You can find the full contact details in the legal notice.
3. Hosting & Server Log Files
My blog is hosted by Strato AG. When you visit the website, so-called server log files are automatically created. These include, amongst other things, browser type, operating system, referrer URL, time of page view and your truncated/anonymised IP address. This data is required to ensure the stable operation of the website and to detect security incidents. Processing is carried out on the basis of my legitimate interest in the technically reliable and secure operation of the website (Art. 6(1)(f) GDPR).
A data processing agreement is in place with Strato.
4. SSL/TLS encryption
To protect your data, I use SSL/TLS encryption. This ensures that content you transmit via the website cannot be read by third parties. This measure is taken as part of my obligation to implement appropriate technical and organisational security measures in accordance with Article 32 of the GDPR.
5. Data collection on this blog
Data that you actively provide
For example, if you post comments or contact me by email, the data you enter will be processed. This is because you provide this information voluntarily and thereby consent to its processing (Article 6(1)(a) of the GDPR) or because I wish to respond to your enquiry (Article 6(1)(b) or (f) of the GDPR).
Data collected automatically
Technically necessary data, such as browser information or timestamps, is collected automatically when you visit the page. This is done to enable the website to function technically (Article 6(1)(f) of the GDPR).
6. Cookies
My blog uses only technically necessary cookies. These include, for example, WordPress cookies which – if you actively choose to do so – save your name and email address for future comments. Such cookies are necessary to provide certain basic functions and are based on my legitimate interest in ensuring a functional user experience (Article 6(1)(f) of the GDPR). Tracking or marketing cookies are not used.
7. Comment function
When you leave a comment, the comment itself, the time it was posted and the details you provide (name, email address) are stored. By submitting the comment, you consent to this processing (Article 6(1)(a) of the GDPR).
Comment subscriptions
You can subscribe to comments on a post. To do so, you will receive a confirmation email to verify the accuracy of your email address. The data required for this will be stored for as long as you do not unsubscribe. The legal basis here is also your consent (Article 6(1)(a) of the GDPR).
Retention period
Comments remain stored for as long as the associated content is online or until legal requirements necessitate their deletion. You may request the deletion of your comments at any time – a brief message is sufficient. The legal basis here is your consent, which may be withdrawn at any time (Article 6(1)(a) of the GDPR).
8. Antispam Bee
To prevent spam comments, I use the privacy-friendly Antispam Bee plugin. The plugin operates entirely locally, does not send any data to third parties and checks comments against internal criteria. Processing is carried out on the basis of my legitimate interest in a secure and spam-free comments section (Article 6(1)(f) of the GDPR).
9. Email contact
If you contact me by email, I will process the data you provide in order to deal with your enquiry. This is done either to prepare for or fulfil a communication or exchange (Article 6(1)(b) of the GDPR) or on the basis of my legitimate interest in providing a reliable response to your message (Article 6(1)(f) of the GDPR). I only store emails for as long as is necessary to deal with your enquiry or as required by law.
10. Analysis with Matomo (without cookies)
I use the web analytics service Matomo, which I host entirely on my own server. This ensures that all analytics data remains with me and is not passed on to third parties.
The data collected includes, amongst other things:
- pages visited
- times and duration
- referrer
- Browser and operating system information
- Click behaviour
Your IP address is automatically truncated so that no conclusions can be drawn about your identity. As Matomo is operated on my blog without cookies, the analysis is carried out solely on the basis of my legitimate interest in further developing and improving the blog (Article 6(1)(f) of the GDPR).
11. Google Fonts (locally hosted)
I use Google Fonts exclusively on my own server, so no personal data is transferred to Google. This local use serves my legitimate interest in ensuring a coherent and visually consistent presentation of the blog (Article 6(1)(f) of the GDPR).
12. Font Awesome (local hosting)
I use the Font Awesome icon font library to display symbols. The necessary files (fonts, CSS) are stored locally on my server and are not loaded from external servers. This local use serves my legitimate interest in ensuring a coherent and visually consistent presentation of the blog (Article 6(1)(f) of the GDPR).
13. Instagram Content (Social Feed Gallery)
On this website, I embed content from my Instagram account. For this purpose, I use the WordPress plugin ‘Social Feed Gallery’. The images are cached on my own server and delivered to your browser from there. No direct connection is established between your browser and the servers of Meta Platforms, Inc.
The Instagram account is operated by me.
For more information on data protection at Instagram, please refer to Meta’s privacy policy: https://privacycenter.instagram.com/policy
14. Your rights
You have the right at any time to:
- Access the data stored about you (Article 15 of the GDPR)
- Rectification of inaccurate data (Article 16 of the GDPR)
- Erasure of your data (Article 17 of the GDPR)
- Restriction of processing (Article 18 of the GDPR)
- Object to certain processing activities (Article 21 of the GDPR)
- Data portability (Article 20 of the GDPR)
- Lodging a complaint with a data protection supervisory authority (Article 77 of the GDPR)
If you wish to exercise any of these rights or have any questions, you can contact me at any time using the contact details provided in the legal notice.