Privacy policy
13 September 2026
Privacy at a glance
General information
The following notes provide a brief overview of what happens to your personal data when you visit my website. Personal data means any data that can be used to identify you personally. Detailed information on data protection is provided in the privacy policy below.
Who is responsible for data collection on this website?
As the website operator, I am responsible for data processing on this website. You can find my contact details in the Data controller section below.
How do I collect your data?
Some data is collected when you provide it to me, for example by email or telephone. Other data is collected automatically by my IT systems when you visit the website. This primarily consists of technical data, such as your internet browser, operating system or the time of your visit. This data is collected automatically when you access my website.
What do I use your data for?
Some data is collected to ensure that the website operates correctly. With your prior consent, page views and selected link clicks are also evaluated for audience measurement.
What rights do you have regarding your data?
You have the right to obtain information at any time, free of charge, about the source, recipients and purpose of your stored personal data. You also have the right to request its rectification, restriction or erasure. In addition, you have the right to lodge a complaint with the competent supervisory authority.
General notes and mandatory information
Data protection
As the operator of this website, I take the protection of your personal data very seriously. I treat your personal data confidentially and in accordance with statutory data protection requirements and this privacy policy.
Various personal data is collected when you use this website. Personal data is data that can be used to identify you personally. This privacy policy explains what data I collect and what I use it for. It also explains how and for what purpose this happens.
Health data
My website is solely intended to provide general information. Neither this website nor the email address provided here is intended for the transmission of health data. Please do not send me medical information, such as diagnoses, medication or symptoms, by email.
Please note that data transmission over the internet, for example in email communications, may have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Data controller
The data controller within the meaning of the GDPR is:
Sina Rampe
Address:
c/o IP-Management #7576, Ludwig-Erhard-Str. 18, 20459 Hamburg, Germany
Email: sina@sinarampe.de
Explanation: My actual place of business, where the business is managed and the key decisions on data processing are made, is in Berlin. The Hamburg address is my contact address and the address used in my legal notice.
There is no statutory obligation to appoint a data protection officer (Article 37 GDPR in conjunction with Section 38 BDSG). You can nevertheless contact me at any time with questions about data protection.
Withdrawal of your consent to data processing
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. An informal email to me is sufficient. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Right to lodge a complaint with a supervisory authority
In the event of a data protection violation, you have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. The authority responsible for my place of business in Berlin is:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61, 10555 Berlin
Telephone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Web: www.datenschutz-berlin.de
Your rights
The GDPR grants you comprehensive rights regarding your personal data. These are summarised below.
Right to data portability
You have the right to receive data that I process by automated means on the basis of your consent or in performance of a contract, or to have it provided to a third party, in a commonly used, machine-readable format. If you request direct transmission to another controller, this will only be done where technically feasible.
Right to object
Where I process your personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you have the right to object to the processing under Article 21 GDPR. This applies in particular to processing of your data in server logs and in communications by email or telephone, where such processing is based on legitimate interests.
When objecting, please explain the reasons why I should not process your personal data. I will then cease processing unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Please send your objection to: sina@sinarampe.de
Automated decision-making
No automated decision-making, including profiling, within the meaning of Article 22(1) and (4) GDPR takes place.
SSL/TLS encryption
This website is served over HTTPS. TLS encrypts data transmitted between your browser and the web server and protects it against interception and modification during transmission. You can recognise HTTPS by the “https://” prefix in the website address.
This protection applies to the connection to the website. It does not provide end-to-end encryption for emails that you send me using your email application.
Access, rectification, erasure and restriction
Within the scope of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its source and recipients, and the purpose of processing. You also have the right to rectification, erasure and restriction of processing under Article 18 GDPR where you contest the accuracy of the data, the processing is unlawful or I no longer need the data. You can contact me at the address above at any time about these rights or other questions relating to personal data.
Objection to unsolicited advertising emails
I object to the use of contact details published to comply with legal notice requirements for sending advertising and information materials that have not been expressly requested. As the website operator, I expressly reserve the right to take legal action in the event of unsolicited advertising, such as spam emails.
Data collection on my website
The following sections explain what data is collected when you use my website.
Hosting and servers
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located exclusively in Germany. Personal data is not transferred to third countries, in particular the USA. Hetzner acts as a processor; a data processing agreement (DPA) under Article 28 GDPR is in place. The legal basis is Article 6(1)(f) GDPR, reflecting my legitimate interest in providing the website securely and efficiently.
Data processed: Your IP address and the technical data of your request are processed to deliver the website. Continuous recording of individual page visits in access logs is not enabled on the web server or the reverse proxy in front of it.
Technology: The website is built with Astro and served through a Node.js server. There is no contact form. Optional Umami measurement uses a separate database. Information on technical operational and error logs is provided in the Server logs.
External services and GDPR compliance
This website was developed with the aim of GDPR compliance. No external services that process user data are embedded.
Fonts
This website uses the fonts “IBM Plex Serif”, “IBM Plex Sans” and “JetBrains Mono”. The font files are hosted locally on my server. No data is transmitted to external servers such as Google Fonts. When the page first loads, the fonts are loaded into the browser cache to display text correctly.
Styling (CSS)
This website uses Tailwind CSS for styling. The CSS files are hosted locally and no data is transmitted to external servers.
No external scripts
The consent interface and the analytics module, loaded only after consent, are served by this website. Measurement requests are sent only to my server and restricted there to the described data for self-hosted Umami measurement. No scripts are loaded from external analytics providers.
Audience measurement with Umami
With your prior voluntary consent, I use self-hosted Umami to understand which information and documents are requested and whether visitors click the email contact link. Declining has no effect on website functionality. No analytics module is loaded and no measurement request is sent before consent. The locally loaded consent interface only manages your choice.
Data: the path of a visited page, its German or English language version, the time of the event, selected referral sources (for example Google or LinkedIn), and clicks on the email contact link, CV, talks, handout and working translation. Only predefined source domains are retained, not full referring URLs; other sources remain unknown. Query strings, fragments, page titles and free-form event data are excluded. A link click does not prove that a document was read or an email sent. Direct PDF requests without a website click are not measured.
Technical processing: your IP address reaches the website server. After consent, the server derives a pseudonymous value from it using a random secret that changes daily (UTC) and is not stored permanently. Only this value, not the raw IP address, is forwarded to Umami. The visitor’s User-Agent is neither forwarded to Umami nor used to calculate the identifier. Browser, operating system and device categories are not collected. The resulting identifier can group events within a day; it is pseudonymous, not a promise of anonymity. People sharing an IP address can be counted together, so visitor numbers are estimates. No location or screen resolution is collected. No cross-day or cross-site identification, session recordings, health inferences or advertising profiles are created. Restarting the website server also replaces the random secret.
Legal basis: Article 6(1)(a) GDPR and, for storage of or access to information on your device where applicable, Section 25(1) TDDDG. Measurement is optional. Do Not Track and Global Privacy Control signals are respected in addition to the consent setting.
Recipients and retention: Umami is operated on my hosting infrastructure at Hetzner Online GmbH in Germany under the hosting data processing agreement. The Umami software provider receives no visitor data; application telemetry is disabled. Analytics uses a separate database. Events are deleted after 90 days, with daily cleanup and therefore a maximum live retention of 91 days. Associated session data is removed when no retained events require it. Encrypted rolling backups expire within 7 further days and are used only for recovery; expired data is removed before a restored database is put back into service. Access is restricted to administration. Data is not sent to advertising or external AI services.
Withdrawal: use “Privacy settings” in the footer and select “Withdraw consent”. This stops further measurement; processing before withdrawal remains lawful. The necessary analytics-consent cookie stores only your accepted/declined choice, the notice version and the time of your choice for 180 days. It contains no visitor identifier. Deleting it also resets your choice: the next visit starts without analytics until you consent again. Closing the interface or continuing to browse is not consent. Your other rights, including erasure, remain unaffected; see the rights sections above.
Server logs
Regular page visits are not stored in access logs. Technical operational and error logs for the website and the reverse proxy are generated for operation and troubleshooting. Depending on the error, these may also contain information about the affected request and therefore personal data.
These logs are rotated based on size: the website and reverse proxy are each configured to retain no more than three log files, with a rotation threshold of 10 MB per file. Older files are replaced when the rotation limits are reached. No fixed time-based deletion period is configured; the actual retention period depends on the volume of log output.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest is in the stability and security of the website and the diagnosis of technical errors. The logs are not used to analyse your browsing behaviour.
Contact by email
If you contact me by email, the data you provide (name, email address, subject and message) is stored to handle your enquiry and any follow-up questions. The email service provider mailbox.org, described below, is used for this purpose.
If your enquiry relates to entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR. Other enquiries are processed under Article 6(1)(f) GDPR, based on my legitimate interest in handling your enquiry. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation; see the section Right to object.
Providing your data is voluntary; there is no legal obligation to contact me. Without the information needed for your enquiry and a way to reply, I may be unable to answer it or may only be able to give a limited response. Please provide only the information necessary for your enquiry.
Data provided by email is deleted 6 months after the enquiry has been concluded, unless statutory retention obligations apply. You may request erasure at any time.
For email communications I use mailbox.org, operated by Heinlein Support GmbH, Schwedter Str. 8/9b, 10119 Berlin, Germany. The provider acts as a processor and a data processing agreement (DPA) under Article 28 GDPR has been concluded. Processing takes place on servers in Germany; no transfers to third countries take place. Further information: https://mailbox.org/de/datenschutzerklaerung
Important note:
Please do not send health information by email. Health data is subject to special protection requirements under Article 9 GDPR; the email contact offered here is not intended for such information.
Contact by telephone
If you contact me by telephone, your telephone number, if displayed, is stored to handle your enquiry and any follow-up questions.
If your enquiry relates to entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR. Other enquiries are processed under Article 6(1)(f) GDPR, based on my legitimate interest in handling your enquiry. Processing based on legitimate interests is subject to the above-mentioned Right to object. Providing information is voluntary. Without the information needed for your enquiry, I may be unable to handle it; without a callback number, I cannot call you back. The data is deleted 6 months after the enquiry has been concluded, unless statutory retention obligations apply.
Overview of my data processing
The following overview summarises the processing activities that actually take place in connection with this website.
| Processing activity | Details |
|---|---|
| Umami | Optional audience measurement with prior consent (Article 6(1)(a) GDPR; Section 25(1) TDDDG where applicable). Page paths, selected referral sources, page language, time and selected link clicks; daily changing pseudonymous identifier. Processor: Hetzner Online GmbH, Germany. Events: 90 days, daily cleanup (at most 91 days); encrypted backups expire within 7 further days. No advertising profiles. Details and withdrawal |
| Server logs | Purpose: Technical operation, troubleshooting and security Data: Operational and error messages, possibly including information about the affected request; no regular access logs Legal basis: Article 6(1)(f) GDPR Recipient: Hetzner Online GmbH, Germany (servers in Germany; DPA under Article 28 GDPR) Retention: Size-based rotation, with no more than three files each for the website and reverse proxy, a rotation threshold of 10 MB per file and no fixed time-based deletion period |
| Contact by email | Purpose: Handling your enquiry, including pre-contractual communications where applicable Data: Name, email address and message content Legal basis: Article 6(1)(b) or (f) GDPR Recipient: Heinlein Support GmbH (mailbox.org, Germany; DPA under Article 28 GDPR) Retention: 6 months after the enquiry has been concluded, unless statutory retention obligations apply |
| Contact by telephone | Purpose: Handling your enquiry, including pre-contractual communications where applicable Data: Telephone number, if displayed Legal basis: Article 6(1)(b) or (f) GDPR Recipient: Telecommunications providers involved in the connection Retention: 6 months after the enquiry has been concluded, unless statutory retention obligations apply |
Disclosure of data to third parties
The processors named above are used for hosting and email communications to the extent described. During telephone calls, the telecommunications providers involved in the connection process the data needed for the connection under their own responsibility. Further disclosures may occur in particular where there is a legal obligation or you have given consent. No disclosure for advertising purposes takes place. No contracts are concluded and no payments are processed through this website.