Thank you for your interest in this blog. Protecting your personal data matters to me. You can read the English edition of Linux und Ich without giving any personal data – data is only processed when you comment, contact me via the contact form or actively use optional features such as embedded videos. In addition, ads from Google AdSense are shown (see section 10); whether data is processed for them is up to you in a separate consent dialog. This privacy policy explains which data that is in detail, how it is processed and what rights you have.
The English edition at linuxundich.de/en/ is a separate WordPress installation of the German blog linuxundich.de, run by the same person on the same server. The German original of this policy is the Datenschutzerklärung; where the two differ, this English version describes the English edition.
1. Definitions
This privacy policy uses the terms of the EU General Data Protection Regulation (GDPR). In particular:
- Personal data is any information relating to an identified or identifiable natural person (the “data subject”), for example a name, an online identifier or an IP address.
- Processing is any operation performed on personal data, such as collection, storage, use, disclosure or erasure.
- Controller is the person who decides on the purposes and means of the processing – for this website, me (see section 2).
- Processor is a person or body that processes personal data on behalf of the controller, such as the hosting provider.
- Consent is a freely given, specific, informed and unambiguous indication of your wishes by which you agree to the processing of your personal data.
2. Controller
The controller within the meaning of the GDPR and other data protection provisions is:
Christoph Langner
Charlottenstr. 43/1
88212 Ravensburg, Germany
Phone: +49-89-21554030 (voicemail only, please leave a message)
Email: christoph AT linuxundich DOT de
Website: https://linuxundich.de/
3. Cookies and local storage
This website uses cookies (small text files stored by your browser) and your browser’s localStorage (a similar local storage without a fixed expiry). You can view, block or delete both at any time in your browser settings; some features of the website may then no longer be available.
Strictly necessary cookies
These cookies are required to run the website or a feature you actively chose, and fall under the exemption of section 25(2) of the German TDDDG; no separate consent is needed:
- lui_edit_tok_[comment ID] – 5 minutes, not readable by JavaScript – lets you edit the comment you just submitted within 5 minutes.
- comment_author_* (WordPress’s own cookies) – about 347 days – only set if you tick “Save my name, email, and website in this browser” when commenting.
- When logged in as an editor, also WordPress’s own login cookies – these do not affect regular visitors.
Local storage in the browser (localStorage)
Technically not cookies, but treated the same way:
- lui-theme – remembers your choice between the light and dark design.
- lui-privacy-notice-seen – remembers that you already confirmed the notice banner at the bottom of the page.
Advertising cookies (only with your consent)
This blog shows ads from Google AdSense (details in section 10). Depending on your choice in Google’s consent dialog, Google may set or read cookies, for example __gads and __gpi (13 months each), IDE (13 to 24 months), DSID (2 weeks) and test_cookie (15 minutes); Google sets the last three via the domain doubleclick.net. Google determines the names and lifetimes; you can find an up-to-date overview in Google’s overview of advertising cookies. According to Google, without your consent no personalised ads are served and no cookies are set for them.
So that the dialog does not ask you again on every visit, it stores your choice in the cookies FCCDCF (about 13 months) and FCNEC (about 1 year). These are required to manage your consent.
Notice banner and consent dialog
On your first visit, a short notice about the strictly necessary storage appears at the bottom of the page. It is a voluntary transparency measure: no consent is needed for this storage, you simply confirm it with “Got it”.
Separately – because ads run here – Google asks in its own consent dialog whether and how personalised ads may be shown (see section 10). Google runs this dialog, not me. Until you have answered it, this website holds back its own notice so the two do not overlap.
A complete technical list of all cookies is in the cookie policy.
4. Server log files
Each time this website is accessed, the web server automatically records data in log files: the browser type and version, the operating system, the previously visited page (referrer), the page requested, the date and time of access and the IP address. This data is used solely to deliver the page correctly and to keep the systems stable and secure (for example to fend off attacks). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the website). This website is hosted by tiggersWelt, which acts as a processor on my behalf.
5. Contact form
You can reach me directly via the contact form. Required fields are name, subject and message; providing an email address is optional – without it you can write to me anonymously, but I cannot reply. The data you enter is sent to me by email and used solely to handle your request; it is not stored in a database beyond that. It is not passed on to third parties. The legal basis is Art. 6(1)(a) GDPR (your consent by submitting the form) and Art. 6(1)(f) GDPR (my legitimate interest in answering enquiries).
6. Comments
You can comment below every article. Required fields are your name and the comment text; providing an email address is deliberately optional – so you can also comment anonymously without having to give an address (or a made-up one). In addition to the comment itself, the time of submission and your IP address are stored. This serves security and the prevention of abuse (for example if a comment infringes the rights of third parties or contains unlawful content) and is my legitimate interest under Art. 6(1)(f) GDPR. Comments on the English edition are stored separately from those on the German blog.
To detect spam comments, I use the plugin Antispam Bee. It is designed to be data-minimal: comments are mainly checked against local rules on this server (patterns, a local spam database, language filters) – by default, your data is not sent to an external service.
If available, an image stored with Gravatar is used as your profile picture. The lookup is done server-side by my website, not directly by your browser: viewing the comments does not connect your browser to Gravatar’s servers. If no Gravatar image exists for your email address (or you did not provide one), a simple avatar made from your initials is generated instead – also entirely without contacting a third party.
You can still edit your own comment for 5 minutes after submitting it; this works through the short-lived lui_edit_tok_ cookie described in section 3. If you also tick “Save my name, email, and website in this browser”, WordPress sets the cookies described in section 3 – only at your explicit request.
7. Routine erasure and blocking of data
I process and store personal data only for as long as necessary for the respective purpose or as required by statutory retention periods. Once the purpose no longer applies or a statutory period expires, the data is routinely erased or blocked.
8. Your rights
Under the GDPR you have the following rights regarding your personal data. To exercise any of them, simply contact me (see section 2):
- Right to confirmation and access (Art. 15 GDPR) – whether and which data about you I process, for what purposes, for how long, to whom it is disclosed, where it comes from and whether automated decision-making takes place, and a free copy of this information.
- Right to rectification (Art. 16 GDPR) – correction of inaccurate data and completion of incomplete data.
- Right to erasure (“right to be forgotten”, Art. 17 GDPR) – for example if the data is no longer needed, you withdraw your consent, you object to the processing or the data was processed unlawfully. If I made the data public, I take reasonable steps to inform other controllers of your request.
- Right to restriction of processing (Art. 18 GDPR) – for example while the accuracy of the data is being checked or if you need the data to establish, exercise or defend legal claims.
- Right to data portability (Art. 20 GDPR) – to receive the data you provided in a structured, commonly used and machine-readable format, or to have it transmitted directly to another controller where technically feasible.
- Right to object (Art. 21 GDPR) – on grounds relating to your particular situation, against processing based on Art. 6(1)(e) or (f) GDPR, including profiling based on these provisions. I will then no longer process the data unless I can demonstrate compelling legitimate grounds or the processing serves legal claims. You can object to processing for direct marketing at any time.
- Rights relating to automated decisions (Art. 22 GDPR) – not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.
- Right to withdraw consent (Art. 7(3) GDPR) – at any time, with effect for the future.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR), for example the one in your country of residence or the one responsible for me: the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.
9. Audience measurement (Statify)
To get a rough idea of which articles are read, I use the open-source WordPress plugin Statify. It runs directly in this WordPress installation; the counting never leaves this server and no third-party service is involved.
For each page view, Statify stores exactly three things: the date (the day only, no time), the address visited on this website and – if you followed a link from another website – that website’s address. Nothing else: no IP address, no device or browser identifier, no country, no ID and no cookie. A single view can therefore not be linked to you or to any other view – not even two views from the same browser. Your browser’s identifier (user agent) is only checked at the moment of the request to filter out search engine crawlers, and is not stored.
Because pages are served from a cache, counting works through a small JavaScript request to this server (/en/wp-json/statify/v1/track). Here, too, nothing is stored in your browser and nothing is sent to third parties.
The counts are deleted automatically after 365 days. The legal basis is my legitimate interest (Art. 6(1)(f) GDPR) in a basic understanding of how this website is used; you have a right to object here as well (see section 8).
10. Advertising (Google AdSense)
This blog is a side project and is partly financed by ads – the income pays for hosting, domains and test devices. For this I use Google AdSense from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Ads appear within the article text, below the article and in the sidebar and are labelled “Advertisement”. There are no ads on the contact, support, privacy and cookie pages, in search results or in the feeds.
Before Google serves ads that require cookies or similar technologies, Google asks for your consent in its own consent dialog. The dialog comes from Google (certified consent management under the IAB Transparency & Consent Framework); I receive no data about you through it. You can accept, reject or choose individual purposes and vendors there. You can change your choice at any time: via the link “Change ad consent” in the page footer or in the cookie policy.
When loading ads, Google processes – depending on your choice – among other things your IP address, information about your browser and device, the page visited and cookie or device identifiers. For personalised ads, Google may create interest profiles on its own responsibility; I have no influence on this. Data may be transferred to the USA; Google LLC is certified under the EU-US Data Privacy Framework. Google’s privacy policy also applies; you can find your ad settings at adssettings.google.com.
The legal basis for cookies and for processing personal data for personalised advertising is your consent (Art. 6(1)(a) GDPR in conjunction with section 25(1) TDDDG). You can withdraw it at any time with effect for the future (see above). Without consent, no personalised ads are served according to Google’s requirements.
11. Embedded videos (YouTube/Vimeo)
Some articles embed videos from YouTube or Vimeo. The actual video is not loaded automatically when you open the article; only a preview image is shown. Only clicking on it loads the real video player – before that, your browser has no contact with YouTube or Vimeo.
I embed YouTube videos via the privacy-enhanced domain youtube-nocookie.com, which according to YouTube means no personalisation cookies are set before playback. After the click, or at the latest when the video plays, Google Ireland Limited still processes technical data such as your IP address. Vimeo videos are embedded via player.vimeo.com from Vimeo.com, Inc. (555 West 18th Street, New York, NY, USA); Vimeo does not offer a comparable “no-cookie” mode.
The legal basis is your consent through actively clicking the preview image (Art. 6(1)(a) GDPR). More information: Google/YouTube privacy policy, Vimeo privacy policy.
12. Legal basis of processing
Where I ask for your consent for a processing operation, the legal basis is Art. 6(1)(a) GDPR (for example when submitting the contact form, when loading an embedded video or in the consent dialog for ads, see section 10). Where the processing is necessary to answer your request or provide a feature you asked for, I rely on Art. 6(1)(f) GDPR (legitimate interest). Where I am subject to a legal obligation that requires processing, the legal basis is Art. 6(1)(c) GDPR.
13. Legitimate interests
Where processing is based on Art. 6(1)(f) GDPR, my legitimate interests are: the secure and stable technical operation of this website, protection against spam and abuse (for example in comments) and a basic understanding of which articles are read (anonymous view counts) in order to plan future content.
14. Storage period
Personal data is only stored for as long as necessary for the respective purpose or while a statutory retention period runs. It is then deleted. Google determines the lifetime of the cookies it sets (see section 3).
15. Automated decision-making
I do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. For personalised advertising, Google may create usage profiles on its own responsibility (see section 10); I have no influence on this.
Last updated: October 2026