Privacy Policy

Protecting your personal data is not a marketing promise for me, but a fundamental technical and organizational principle. This privacy policy informs you transparently about whether, how, and why personal data is processed when visiting this website — and above all, where data is deliberately not collected.


Data Controller

Sebastian Palencsár
c/o Block Services
Stuttgarter Str. 106
70736 Fellbach
Deutschland

E-Mail: blog(at)palencsar.pro

1. Infrastructure and Hosting

Self-hosted without external cloud providers

This website is operated entirely on its own hardware. There are no outsourced cloud servers or third-party gateways:


  • Direct Connection (Backbone): The server is directly connected to the internet via the Vodafone GmbH network. Vodafone acts solely as a telecommunications service provider (line provision), not as a web hoster.
  • Full Data Sovereignty: All systems, storage, and network components are within my exclusive physical and logical access area. Server access by cloud providers is technically and physically excluded.
  • No Data Processing Agreement (DPA): Since no classic web hosts are used to process website data and pure telecommunications passthrough does not constitute data processing, no data is shared with hosting third parties.

Legal basis:   Art. 6 Abs. 1 lit. f DSGVO (Legitimate interest in the secure, stable, and technically controlled operation of the online service).


2. Server Configuration and Consistent Log Avoidance

OpenResty / Nginx

I strictly follow the principle of data minimization according to Art. 5 para. 1 lit. c GDPR. My web server is deliberately configured so that personal data does not arise in the first place.


  • No Access Logs: Access logging is completely disabled (access_log off;). No IP addresses, user-agent strings, referrers, or requested URLs are stored.
  • Heavily Reduced Error Logs: Error logs are only maintained at the crit (critical) level. These logs serve exclusively for operational safety and contain no personal data.

3. Transport Encryption

SSL/TLS, HTTP/3 (QUIC) and HSTS


  • SSL/TLS: The website is only accessible via encrypted connections.
  • HTTP/3 (QUIC): Modern protocol architecture with integrated encryption and improved security.
  • HSTS: Your browser is instructed to only allow encrypted connections to this domain.

4. Web Analytics

Umami — Hardened Self-hosted Installation

For purely statistical evaluation of usage, I use the open-source tool Umami — in a maximally privacy-friendly configuration:


  • Hosting entirely on own infrastructure. No data is transmitted to third parties.
  • No IP collection TRACKING=1
  • No cookies DISABLE_TRACKING_COOKIE=1
  • Do-Not-Track is respected RESPECT_DNT=1

Legal basis:   Art. 6 Abs. 1 lit. f DSGVO (Legitimate interest in anonymous, statistical analysis for technical optimization).


5. No Third-Party Resources

Zero-External-Requests Policy

This website does not load any content from external servers:


  • Local Fonts: All fonts (e.g., webfonts or icons) are served locally from the own server.
  • No CDNs, no APIs: No content delivery networks, Google services, or comparable third parties are used.

This prevents your IP address or browser data from being transmitted to external parties.


6. Contact via Email

If you contact me via email, I process the data you provide (e.g., email address, name, message) solely to process your inquiry.


  • No disclosure to third parties.
  • No use for advertising purposes.
  • Deletion after purpose has been fulfilled, unless statutory retention periods apply.

No automated decision-making or profiling takes place.


Legal basis:

  Art. 6 Abs. 1 lit. b DSGVO (pre-contractual communication) or   Art. 6 (1) lit. f GDPR (legitimate interest in responding to inquiries).


7. Your Rights as a Data Subject

You have the following rights under Art. 15–21 GDPR:


  • Access to stored data.
  • Rectification or deletion of incorrect or inadmissible data.
  • Restriction of processing.
  • Objection to processing.

Important Note: Since I neither store IP addresses nor use tracking, there are generally no personal data about you on file. Access is therefore usually only possible for data you actively provided to me (e.g., via email).


8. Right of Appeal to the Supervisory Authority

If you believe that the processing of your data violates data protection law, you have the right to lodge a complaint with the competent data protection supervisory authority under Art. 77 GDPR.