Privacy policy
Information on the processing of personal data on this website under Art. 13 GDPR.
Last updated: 7 September 2026.
Controller
Nico Jahn
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
Email: nico.k.jahn@gmail.com
Phone: +49 175 8989393
Website delivery and security
This static website and the MCP endpoint described below are provided through Cloudflare Pages and Cloudflare Pages Functions by Cloudflare, Inc., USA. Cloudflare processes data including the IP address, timestamp, requested resource, HTTP headers, technical browser information, and security events. The purpose is to deliver, stabilize, and protect the service. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is reliable and secure website operation. Cloudflare processes this data on my behalf.
I do not store separate copies of connection or security logs. Cloudflare processes them according to the products enabled for the account and the contractual retention rules. Aggregated Function metrics may be available for up to three months. If Workers Logs are enabled, their retention is at most three or seven days depending on the plan. The website has no separate logging or profiling database.
Cloudflare may send a Network Error Logging policy in an HTTP header with a validity of up to seven days. Supporting browsers may consequently send technical error reports to Cloudflare. This is used to identify transmission and availability problems.
Cloudflare may process data outside the EU/EEA. Transfers to certified US recipients rely on the EU-US Data Privacy Framework (Art. 45 GDPR). Where required, the EU Standard Contractual Clauses apply as an additional safeguard (Art. 46 GDPR). Further information is available in the Cloudflare Data Processing Addendum.
Analytics
Cloudflare Web Analytics provides aggregated usage and performance statistics. It does not use cookies or local storage and does not create cross-site or cross-device visitor profiles. The beacon processes the visited path without the query string, referrer, country, browser, operating system, device type, and performance metrics. Cloudflare states that the IP address arising during transmission is discarded at the edge.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is understanding and improving website usage and technical performance in a data-minimizing way. Unsampled beacon data is retained for seven days; aggregated dashboard data is available for the previous six months.
Browser storage
The site stores a display preference in local storage only when you select a color scheme. This is necessary to provide the requested setting (section 25(2) no. 2 TDDDG). It remains stored until you change it or clear your browser storage. The site uses no optional marketing or tracking cookies and no service worker for persistent content caching. A technical retirement file removes any service-worker and cache installation left by an older version of the website.
Cloudflare security functions may use technically necessary, short-lived browser information. This is likewise used only to deliver and protect the service expressly requested by the visitor.
Whitepaper download and lead form
This section applies only if a whitepaper landing page and its download form
are enabled. I process the email address you provide and, if entered, your name
and company. The form also sends the selected whitepaper and language,
submission time, IP address, user-agent information, and campaign parameters
in the landing-page URL (utm_* and gclid) to the backend. These campaign
parameters are read from the current URL and are not stored in your browser.
The data is used to provide the document you requested and to protect the form against misuse. The legal basis is Art. 6(1)(b) GDPR for providing the requested download and Art. 6(1)(f) GDPR for protecting the form and recording the delivery request. The legitimate interest is preventing automated misuse and being able to operate the download service reliably.
The form uses Cloudflare Turnstile in invisible mode to distinguish human visitors from automated requests. Turnstile processes technical browser and security signals for that purpose; it does not receive the other form fields. Pre-Clearance is not enabled, so the widget is configured to use its normal one-time validation token rather than issue a clearance cookie. More information is available in the Cloudflare Turnstile Privacy Addendum.
The lead backend runs in AWS eu-central-1 and uses AWS Lambda, DynamoDB, and
Amazon SES. DynamoDB stores the lead record; SES sends the optional confirmation
email described below. I receive a notification of a new download request that
contains the whitepaper and language, but not the form fields themselves. AWS
and Cloudflare act as processors under the respective data-processing terms.
Both providers may process data outside the EU/EEA; the safeguards described
above for Cloudflare and the safeguards stated in the applicable AWS data
processing terms apply.
Download-only records are deleted automatically after six months. If you opt in to marketing, I retain the consent and withdrawal record for as long as needed to document that consent. Personal contact details for unconfirmed or withdrawn marketing requests are removed as part of the regular retention review, unless statutory retention or legal-defense interests require longer storage.
The marketing checkbox is optional and separate from the download. If you opt in, the legal basis is your consent under Art. 6(1)(a) GDPR. You receive a double-opt-in email and receive marketing messages only after confirmation. You can withdraw consent at any time with future effect through the unsubscribe link in every such email. The backend records the consent text version, submission time, confirmation time, and withdrawal time as proof of consent.
MCP endpoint for AI tools
The public MCP endpoint makes this website's content available to compatible AI tools. In addition to the connection data described above, the Cloudflare Pages Function processes the JSON-RPC request, in particular its method, request ID, and tool inputs such as search terms, document paths, language filters, and result filters. The purpose is to list, search, and deliver the publicly available documentation.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is providing my public content in a machine-readable form. The MCP endpoint does not store inputs in an application database, create user profiles, or transmit inputs to an AI model. The Cloudflare metrics and possible platform logs described above apply. Do not include personal, confidential, or secret information in MCP requests.
Contact by email
When you contact me by email, I process your message, contact details, and the additional information needed to handle the enquiry. This is done to take steps toward or perform a contract under Art. 6(1)(b) GDPR or, for other enquiries, under Art. 6(1)(f) GDPR. The legitimate interest is handling business communication.
The mailbox is provided through services of Google Ireland Limited and related Google companies. Processing in the USA may rely on the EU-US Data Privacy Framework or, where applicable, appropriate safeguards under Art. 46 GDPR. Further information is available in Google's privacy policy. Messages are deleted when they are no longer needed to handle and document the matter, unless statutory retention duties or legal-defense interests require longer retention.
Contact by phone
When you call, I process data including your phone number, the time and duration of the call, and the information you provide. My telecommunications provider processes connection data needed to establish the call. Calls are not recorded. The legal bases and deletion criteria are the same as for business communication described above.
Contact by post
Mail sent to the c/o address stated in the Impressum is accepted, opened, digitized, and made available in a protected Anschrift.net customer account by COCENTER GmbH, Koppoldstr. 1, 86551 Aichach, Germany. This processing includes sender and recipient data, shipment information, and the content of the letter. COCENTER processes the mail content on my behalf. I receive an email notification when new mail is available.
The legal basis is Art. 6(1)(b) GDPR for contract-related correspondence and Art. 6(1)(f) GDPR for other correspondence. The legitimate interest is reliable receipt and handling of business mail while protecting the private residential address. According to Anschrift.net, scans remain available until the customer account is closed or deletion is requested; originals are retained for six months. Statutory retention duties and legal-defense interests may prevent earlier deletion. Further information is available in Anschrift.net's privacy policy.
Contact by email, phone, or post is voluntary. Without the information required to handle your enquiry, I may be unable to answer it or take steps toward or perform a contract.
Your rights
Subject to the statutory conditions, you have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), and data portability (Art. 20). You may withdraw consent at any time with future effect (Art. 7(3)). Contact the email address above to exercise these rights.
Right to object
Where processing is based on Art. 6(1)(f) GDPR, you may object to that processing at any time on grounds relating to your particular situation (Art. 21 GDPR).
You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
No solely automated decision-making with legal or similarly significant effects takes place (Art. 22 GDPR).