Airic Lenz

Privacy

Last updated 3 Sept 2026

This is a personal, non-commercial site. It sets no cookies and embeds nothing from third parties — no external fonts, no tracking pixels, no social widgets. It does keep a small set of visitor statistics, described below, gathered by software I run on the same server; beyond that, the only data it processes is what a web server unavoidably records when it answers a request.

Who is responsible

Airic Lenz. You can reach me at airic@airiclenz.com. I am the controller for the processing described here within the meaning of the GDPR (Regulation (EU) 2016/679).

Visitor statistics

I count visits to see which pages are read and how they are used. The software doing it is my own, running on the same server that serves this site: nothing is sent to a third party, no analytics service is embedded, and no data leaves the server. It sets no cookie and writes nothing to your browser's storage.

Your IP address is never stored. It is folded together with your browser's user agent into a keyed hash, using a secret salt that is regenerated every day and written over the old one. That gives a short, meaningless identifier that lets me tell two page views on the same day apart from two different visitors — and once the salt is replaced, yesterday's visitors can no longer be recomputed, not by me and not by anyone who obtains the database.

What a page view records:

If your browser sends the Do Not Track signal, or Global Privacy Control, nothing is collected at all — the measurement does not start, rather than starting and being discarded.

These detail rows are deleted after 90 days. What is kept beyond that is only the per-day, per-page totals — how many views and how many visitors a page had on a given day — which are no longer tied to anything about an individual visit. The legal basis is my legitimate interest in understanding how the site is used and in keeping it working well, Art. 6(1)(f) GDPR. You may object to this processing at any time under Art. 21 GDPR; the browser signals above are the fastest way to do so, and you can also just write to me.

Hosting and server logs

This site is hosted by Domainfactory GmbH, Neuturmstrasse 5, 80331 Munich, Germany, which acts as my processor within the meaning of Art. 28 GDPR and handles the data described here only on my instructions. Each request to the site is written to an access log containing:

These logs exist to deliver the site, to keep the server secure, and to let me diagnose faults. The legal basis is my legitimate interest in operating a functioning and secure website, Art. 6(1)(f) GDPR. They are kept only for as long as those purposes require and are then deleted by the hosting provider. They are not combined with any other data, not used to build profiles, and not passed on to anyone beyond the hosting provider named above.

If you email me

Whatever you put in the message is processed so I can reply, on the basis of Art. 6(1)(f) GDPR, and kept for as long as the exchange is meaningful. I do not add correspondents to any mailing list.

Links to other sites

Pages here link out to places like GitHub. Following such a link hands you over to that operator, whose own privacy practices apply from that point on. Nothing is sent to them while you stay on this site.

Your rights

Under the GDPR you may request access to your personal data (Art. 15), its rectification (Art. 16) or erasure (Art. 17), a restriction of processing (Art. 18), portability (Art. 20), and you may object to processing based on legitimate interest (Art. 21). Write to the address above and I will answer.

In practice the records that could relate to you are a server log line, findable solely by IP address, and the visitor-statistics rows for the day of your visit — those hold no IP address, but within that same day the hash can still be recomputed from your IP and user agent, so they are findable too. After the day's salt is replaced they are not. So please include the approximate date, the IP and, if you can, the user agent if you want me to look something up.

You also have the right to complain to a supervisory authority. Mine is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY).