Oliver Fries Logo Oliver Fries
Problem Services Results About me Legacy Insights Blog
DE/EN
Release Risk Check →

Privacy Policy

Draft for legal review: The additional information about Umami, PostHog, and Brevo is not legal advice. The marked legal bases, privacy safeguards, and data processing arrangements require review and approval by legal counsel before publication.

1. Privacy at a Glance

General Information

The following information provides a brief overview of what happens to your personal data when you visit this website. Personal data refers to any information that can be used to personally identify you.

Data Collection on This Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find the operator’s contact information in the legal notice section of this website.

2. Hosting

This website is hosted externally. The personal data collected on this website is stored on the host’s servers. This may include, in particular, IP addresses, contact requests, metadata and communication data, contractual data, contact information, names, website visits, and other data generated through the website.

3. General information and mandatory information

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.

Note on the responsible entity

The responsible entity for data processing on this website is:

Oliver Fries
Lemgo (OWL)
Germany

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).

Storage period

Unless a more specific retention period is stated in this Privacy Policy, we will retain your personal data until the purpose for which it was collected no longer applies.

Withdrawal of your consent to data processing

Many data processing operations are only possible with your explicit consent. You may withdraw any consent you have already given at any time. The lawfulness of the data processing carried out prior to the withdrawal remains unaffected by the withdrawal.

Right to file a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place where the alleged violation occurred.

4. Data collection on this website

Server log files

The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

These data are not merged with other data sources.

Umami Analytics

This website uses Umami Analytics to analyse website usage statistically and improve our services. Data includes page views, referring sources, technical browser and device information, and diagnostic flow events, including progress, total score, and risk level. Report downloads are also counted on the server without contact details or download tokens.

Umami operates without cookies and, according to the provider, does not create personal profiles. The analysis serves aggregate statistics. An IP address is technically transmitted when a connection is established; this does not mean that every processing step is legally anonymous.

We use Umami Cloud at cloud.umami.is. Legal review required: Verify the actual storage region, retention period, anonymisation, data processing agreement under Article 28 GDPR, subprocessors, and any international transfers against the applicable cloud contract, and specify these details before publication.

Legal review required: Where personal data is processed, Article 6(1)(f) GDPR is a potential legal basis. Our legitimate interest is the statistical analysis and improvement of the website. The balancing of interests, data minimisation, and any consent requirement under section 25 TDDDG must be assessed for this implementation; operating without cookies alone does not establish an exemption from consent.

You may object to processing based on legitimate interests on grounds relating to your particular situation under Article 21 GDPR using the contact details in the legal notice. You can prevent browser-side Umami tracking with a content blocker for cloud.umami.is. This does not prevent separate server-side download counts. Legal review required: Verify the effectiveness and accessibility of the objection mechanism for all processing paths.

PostHog and Session Recording (disabled)

Session Recording is intended to help understand user interactions and identify errors. This feature is fully disabled on this website (SessionRecording = false); no new session recordings are created. PostHog remains active for page views, page leaves, and explicitly captured diagnostic flow events. Data processed includes page URLs, browser and device information, a temporary identifier, diagnostic progress, total score, and risk level. Automatic capture of clicks and form inputs is disabled (Autocapture = false).

The input masking setting remains enabled (MaskAllReplayInputs = true), although recording is disabled. Persistence = "memory" keeps analytics state only in the open page’s memory (RAM), without cookies or persistent local storage entries for that state. This applies only to browser storage. Transmitted events and any previously created recordings may still be stored on PostHog servers.

PostHog Cloud EU is configured via eu.i.posthog.com; according to the provider, its hosting region is Frankfurt am Main, Germany. No retention period applies to new session recordings because recording is disabled. Disabling recording does not delete earlier recordings. Legal review required: Establish the actual retention periods for existing recordings and active event analytics in the project account, determine whether earlier recordings must be deleted, and add the periods here. Also review the data processing agreement, subprocessors, and possible access from outside the EEA.

Legal review required: Session Recording is not based on legitimate interests and remains disabled. Any future activation would require assessment of prior consent under Article 6(1)(a) GDPR and section 25 TDDDG, as well as other privacy obligations. Article 6(1)(f) GDPR is a potential basis for the continuing event analytics only after assessing the balancing of interests and possible consent requirements. The memory setting does not guarantee GDPR compliance or an exemption from consent.

No opt-out is necessary for disabled Session Recording. You may object to continuing processing based on legitimate interests on grounds relating to your particular situation under Article 21 GDPR using the contact details in the legal notice. You can block browser requests to eu.i.posthog.com and eu-assets.i.posthog.com with a content blocker. You may also contact us with access or erasure requests concerning earlier recordings. Legal review required: Review the objection procedure and handling of data already stored.

Brevo as a data processor

We use Brevo to email your requested diagnostic report and manage the engineering newsletter. This includes confirmation messages, report links, double opt-in emails, and newsletter cancellation confirmations. Your email address, name where provided, message content, and delivery data are transmitted to Brevo for these purposes. The application also checks whether a contact exists and belongs to the newsletter list. After a confirmed cancellation, it removes the contact from that list. Brevo may store name, company, language, risk level, and the subject and time of the last email.

Brevo acts as a service provider for this processing. The application transmits data over encrypted HTTPS connections. Brevo provides a data processing agreement (DPA) as part of its contractual terms. Legal review required: Confirm that a DPA under Article 28 GDPR is effectively in place for our account, and review processing instructions, technical and organisational measures, subprocessors, storage locations, international transfers, and specific deletion periods for contacts, messages, and delivery logs; add the details here. This draft does not confirm an executed DPA or full GDPR compliance.

Legal review required: The diagnostic flow requests consent to store contact details and the diagnostic result, send the report, and make one related follow-up contact. Newsletter registration requires separate consent and becomes effective only after the double opt-in link is confirmed. Article 6(1)(a) GDPR is the intended legal basis. Verify the validity, freely given nature, evidence, and scope of these consents, particularly for contact storage in Brevo and further emails.

You may withdraw your consent at any time with future effect using the contact details in the legal notice. You can cancel the newsletter through the newsletter management page. The cancellation is applied to the Brevo newsletter list after you confirm the link sent by email. A broader withdrawal may prevent any pending report delivery through Brevo. Processing carried out before withdrawal remains lawful if it was lawful at the time. Where processing is based on legitimate interests, the right to object under Article 21 GDPR applies. Legal review required: Verify implementation of withdrawal, deletion or suppression in Brevo, and any statutory retention obligations.

5. Your rights

You have the following rights:

  • Right to information about your stored personal data
  • Right to rectification of incorrect data
  • Right to erasure of your data
  • Right to restriction of data processing
  • Right to data portability
  • Right to object to data processing

Last updated: September 9, 2026