Last updated: 16 September 2026
This is a translation for your convenience. The operator is based in Germany; in case of doubt the German version of this policy prevails.
1. Data protection at a glance
This website is deliberately built to collect as little as possible. There is no user account, no contact form, no newsletter and no comment function. No web analytics are in use, no advertising is served, and no content is loaded from third-party servers — fonts, scripts, stylesheets and images are all hosted on this website’s own server.
For the same reason there is no consent banner here. It would have nothing to ask about. The only data processed is what necessarily arises when the site is requested, plus whatever you send me yourself.
2. Controller
The controller for data processing on this website within the meaning of the GDPR is:
Thomas Harnisch
Königskinderweg 74f
22457 Hamburg
Germany
E-mail: info@thomasharnisch.de
Phone: +49 40 69 79 76 69
3. Hosting and content delivery
This website runs with a hosting provider in Germany. Personal data arising from your visit is processed on that provider’s servers, in particular IP addresses and access metadata.
In front of it sits Cloudflare Inc. (101 Townsend St, San Francisco, CA 94107, USA) as a content delivery network and security service. Cloudflare analyses traffic in order to detect and repel attacks such as denial-of-service attempts, and serves content from a data centre near you.
As regards transfers to the USA, Cloudflare is certified under the EU-US Data Privacy Framework, which recognises an adequate level of protection pursuant to Art. 45 GDPR. The legal basis is Art. 6(1)(f) GDPR, the legitimate interest in the security and availability of the website. Further information is available at cloudflare.com/privacypolicy.
4. Server log files
When you access the website, the provider automatically records information in server log files:
- browser type and version
- operating system
- referrer URL, the page visited before
- host name of the accessing device
- time of the server request
- IP address
The legal basis is Art. 6(1)(f) GDPR, the legitimate interest in trouble-free operation. The data is deleted after seven days and is not combined with other sources.
5. Cookies and local storage
This website sets no cookies of its own and stores nothing in your browser’s local storage. There are no recognition, analytics or marketing cookies.
Cloudflare may in individual cases set a technically necessary cookie for attack prevention, for example when a request is classified as possible automated access. That cookie serves security only, not analysis of your behaviour. The legal basis is Section 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(f) GDPR.
6. No analytics, no advertising, no embedded services
No analytics services, advertising networks or social media components run on this website. No maps, videos or fonts are embedded from third-party servers either, so simply opening a page transfers no data to third parties.
The links to my LinkedIn and Xing profiles are ordinary links. A connection to those providers is established only once you click such a link and open the page there. The same applies to links to my projects, which run on their own domains and have their own privacy notices.
7. Contacting me
If you write or call, I process what you provide in order to deal with your request, in the case of an e-mail your address and the content of your message. The legal basis is Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR where a contract is being prepared or performed. Messages are kept until the matter has been dealt with, unless statutory retention periods apply.
8. Your rights
You have the right at any time to:
- access the personal data held about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
Please contact me at info@thomasharnisch.de.
9. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22, 7th floor
20459 Hamburg, Germany
datenschutz-hamburg.de
10. SSL/TLS encryption
For security reasons this site uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” in your browser’s address bar.
11. Changes to this privacy policy
I will amend this policy when the website changes or legal requirements make it necessary. The version in force at the time of your next visit then applies, shown by the date above.