Privacy Policy
This Privacy Policy explains how personal data is processed when visiting and using the website essen-messen.de.
1. Controller
2. Scope of this Privacy Policy
This Privacy Policy applies only to this website. It does not describe the processing of data in connection with studies, app use, wearable data, health data, or nutrition data.
The website provides information about ESSEN-MESSEN, publishes blog and recipe content, enables newsletter sign-up, and includes internal administration areas. There is no public registration and no public visitor login.
External font CDNs are not used; fonts are served locally. Social media plugins, marketing pixels, and remarketing services are not used.
3. Hosting, domain, and server logs
The website is technically provided through Vercel. Domain and DNS services are provided through STRATO.
- Hosting: Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA
- Domain/DNS: STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany
When the website is accessed, technically required access data is processed. This may include the requested URL or file, date and time, IP address, referrer URL, browser, operating system, device type, HTTP status codes, and technical headers.
The purposes are delivery of the website, technical security, stability, error analysis, abuse prevention, and domain resolution. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the website.
Server log files are stored only for as long as required for operation, security, and error analysis, and are then deleted or anonymized.
4. Web analytics with Plausible via Exord
We use Plausible Analytics for privacy-friendly, aggregated reach measurement. The Plausible instance is embedded via analytics.exord.de and operated by Exord GmbH, Maria-Goeppert-Str. 5, 23562 Lübeck, Germany, as a service provider.
According to Plausible's concept, no cookies, no local storage, and no persistent identifiers are used. Analytics are aggregated and are not used for advertising, profiling, or tracking individual people across websites or days.
Processed data includes page URL, referrer, browser, operating system, device type, and coarse location information such as country, region, or city derived from the IP address. According to Plausible, raw IP addresses and full User-Agent data are not stored; visitor counting uses a daily rotating hash.
The purpose is to understand general website usage so that we can improve content, performance, and user flow. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is privacy-friendly improvement and performance measurement of the website.
According to Plausible, Plausible itself does not set cookies or comparable browser storage. To the extent technically required connection data is generated when loading the analytics script, it is processed for the purposes described above.
5. Bot and spam protection with Cloudflare Turnstile
To protect forms, especially newsletter sign-up, newsletter unsubscribe, and the internal admin login, we use Cloudflare Turnstile, a service provided by Cloudflare, Inc.
Cloudflare processes technical signals required for risk and bot detection. These may include client IP address, User-Agent, TLS fingerprint, sitekey, origin information, and other technical browser or security characteristics.
The purposes are abuse and spam prevention as well as the security and functionality of forms. The legal basis is Art. 6(1)(f) GDPR. Where technically necessary access to or storage on the user's device takes place, this is based on Section 25(2) TDDDG.
6. Supabase backend, content, downloads, and admin area
We use Supabase as backend infrastructure. The Supabase project is hosted in the Europe, Central EU (Frankfurt) region on AWS.
Supabase is used to retrieve blog posts, blog images, recipe lists, signed recipe downloads, newsletter functions, Turnstile key and verification functions, and the internal admin area.
When content is retrieved or functions are executed, technically required connection data such as IP address, timestamp, requested resource, and technical headers may be processed.
The internal admin area uses Supabase Auth. For authorized admin users, login data such as email address, password verification, session information, and role checks are processed. Admin sessions may be stored in the browser.
The purposes are content delivery, recipe downloads, technical security, service operation, admin authentication, and error analysis. The legal basis is Art. 6(1)(f) GDPR.
7. Newsletter
For newsletter sign-up, first name, last name, email address, consent status, and captcha token are processed. Sign-up uses a double opt-in procedure.
To manage the newsletter subscription, we store in particular email address, first and last name, consent status, sign-up time, confirmation time, time of the last confirmation email, unsubscribe time, status, confirmation and unsubscribe tokens or token hashes, and technical delivery or contact identifiers such as a Resend Contact ID.
We use Resend to send confirmation emails and newsletter emails. For this purpose, in particular email address and name are transmitted to Resend. Open or click tracking is not used.
The legal bases are Art. 6(1)(a) GDPR for newsletter delivery, Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR for proof of consent, and Art. 6(1)(f) GDPR for technical operation and abuse prevention.
After unsubscribing, we store an unsubscribe note and suppression list information to prevent further emails. Evidence is generally stored until the regular civil limitation period expires, unless longer legal obligations or legitimate reasons apply.
8. Contact by email
When you contact us by email, we process your email address and the contents of your message. The purpose is to process and respond to your inquiry and to communicate with you.
The legal bases are Art. 6(1)(f) GDPR and, where required, Art. 6(1)(c) GDPR. Data is generally stored for as long as required for processing, documentation, or legal defense.
9. Cookies and browser storage
We do not use cookies or similar technologies for marketing or remarketing purposes. The website does, however, use certain technically or functionally required browser storage mechanisms.
| Name/technology | Purpose | Storage/duration |
|---|---|---|
| essen-messen-locale | Stores the selected language so the website can be displayed in that language. | Local Storage, until changed or deleted by the browser. |
| Supabase Auth Session | Stores the session for authorized internal admin users. | Local Storage, until logout, session expiry, or deletion by the browser. |
| essen_messen_turnstile_site_key | Short-term cache of the public Turnstile sitekey for form security. | Session Storage, for approximately 10 minutes. |
| Cloudflare Turnstile | Bot and spam protection for forms. | Technically necessary signals or storage according to Cloudflare's specifications. |
| Plausible Analytics | Aggregated reach measurement. | According to Plausible, no cookies, no Local Storage, and no persistent identifiers. |
Where technically necessary access to or storage on the user's device is used, this is based on Section 25(2) TDDDG. Subsequent processing of personal data, where applicable, is based on Art. 6(1)(f) GDPR.
10. Recipients
Personal data is shared only where required for operation, security, communication, or the functions provided. Recipients or categories of recipients are:
- Vercel Inc. (website hosting and CDN)
- STRATO GmbH (domain and DNS)
- Exord GmbH (operation of the Plausible analytics instance)
- Cloudflare, Inc. (bot and spam protection with Turnstile)
- Supabase and infrastructure partners such as AWS (backend, content, storage, edge functions, newsletter data, admin auth)
- Resend (email delivery)
- Email provider of the controller (email communication)
Where required, processing is carried out under a data processing agreement pursuant to Art. 28 GDPR.
11. International transfers
Processing of personal data outside the EU/EEA may occur in particular with Vercel, Cloudflare, Resend, and in individual cases in connection with Supabase-related operations or support processes.
Where international transfers take place, they are based on suitable safeguards such as adequacy decisions, EU-US Data Privacy Framework certifications, or EU Standard Contractual Clauses.
12. Your rights
You have, in particular, rights of access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.
Contact to exercise your rights: paul-beier@gmx.de. We generally respond to requests within one month; in exceptional cases, this period may be extended under the GDPR.
13. Right to lodge a complaint with a supervisory authority
You may lodge a complaint with a data protection supervisory authority. The competent authority is in particular the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany, email: mail@datenschutzzentrum.de, phone: +49 431 988-1200.
14. No automated decision-making
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place on this website.
15. Changes to this Privacy Policy
We update this Privacy Policy when content, processes, or services used change. The version published on this website applies.