nordapps.Software from Upper Bavaria
EN

Legal

privacy policy

This website operates without third-party providers: no advertising networks, no fonts or scripts from other servers. I measure visits myself using my own technology. Everything collected is described here, and you can object at any time.

1 · Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):

Lukas Richter (NordApps)
Jahnstraße 3
85302 Gerolsbach
hello@nordapps.de

There is no legal requirement to appoint a data protection officer; for privacy questions, you can contact me at the address above.

2 · Overview

Activity Retention period
Page visitServer log with IP address approx. 6 weeks
Contact formStored as a case on my own server; no email sent no automatic deletion
Session cookieon the contact page and in the consent banner; technically necessary End of session
Response to the consent bannerna_consent cookie, decision and purpose version 180 days
Audience measurementown server; see section 8 no automatic deletion
Attempted attackswith full IP address; see section 9 no automatic deletion

3 · Hosting

This website runs on a server that I administer myself. The underlying infrastructure is provided by:

ZAP-Hosting GmbH & Co. KG
Krokusweg 9a
48165 Münster, Germany

The provider processes data on my behalf under a data processing agreement pursuant to Article 28 GDPR. The servers are in Germany; no data is transferred to third countries. The legal basis is Article 6(1)(f) GDPR: the legitimate interest in operating this website reliably and securely.

4 · Server logs

Each time a page is accessed, the web server automatically writes an entry to a log file. It records:

  • IP address of the requesting device
  • Date and time of access
  • Address requested and volume of data transferred
  • Server status message
  • Previously visited page, if transmitted
  • Browser and operating system identifier

This information is necessary for operation and is used for security and troubleshooting. It is not combined with other data or used to create usage profiles. Logs are rotated weekly and deleted after five rotations, resulting in a retention period of approximately six weeks. The legal basis is Article 6(1)(f) GDPR.

5 · Contact form

When you submit the form on the contact page, your information is stored as a case in a database on my own server. It is not sent by email; the server sends nothing externally. The information is not shared with third parties either. Your name, email address and project description are required; all other fields are optional.

In addition to your information, your browser identifier is stored: the string by which the browser identifies itself. This helps distinguish automated form submissions from genuine enquiries. New contact enquiries are not linked to audience measurement. Before the change on 7 September 2026, enquiries could be linked to visit records, including under the basic measurement used at that time. These existing links were not deleted by the change and can connect visit data with names and email addresses. Where consent was previously given, they may also contain full IP addresses and inferred locations.

The legal basis is your consent under Article 6(1)(a) GDPR, which you expressly give when submitting the form, and, for business enquiries, Article 6(1)(b) GDPR for steps taken before entering into a contract. You may withdraw your consent at any time without formal requirements. This does not affect the lawfulness of processing carried out before withdrawal.

Automatic deletion is not currently configured for enquiries; existing cases remain stored until specifically deleted. Any statutory retention obligations depend on the type and content of the individual case. This does not claim that all enquiries must legally be retained indefinitely. You will not be added to a mailing list or receive advertising. For access or deletion requests, please contact hello@nordapps.de. I will also check whether a statutory retention obligation prevents deletion of the particular case.

To protect against automated submissions, the number of submissions per IP address is limited. A checksum of the IP address and timestamps are processed on the server for this purpose. Only timestamps from the past hour are considered for the limit.

6 · Contact by email

If you email me directly, your information is stored to process the enquiry. The legal basis is Article 6(1)(b) GDPR for contract-related enquiries and Article 6(1)(f) GDPR otherwise. Email traffic runs through a mail server that I operate myself.

7 · Cookies

This website does not use cookies for advertising and does not embed third-party services. No analytics cookie is set for basic server-side measurement. No analytics cookie for recognition is set. The na_consent cookie stores your decision and the version of the described purposes for 180 days.

If there is no current decision, a consent banner appears for enhanced measurement: IP address, approximate location and browser measurements as described in section 8. The cookie na_consent contains your response and the purpose version, for example v2:ja or v2:nein. Consent to the previous version does not count as consent to these purposes, so you are asked again.

A technically necessary session cookie is set on the contact page and, while the consent banner is displayed, on the other pages as well. It protects forms from being triggered by other websites and contains only a random identifier. The cookie is deleted when the browser is closed. Storage is permitted without consent under section 25(2), point 2 TDDDG because it is strictly necessary for the service you have requested.

If you object to measurement, a cookie named na_optout is set. It contains only that one piece of information and is used solely to remember your objection on your next visit.

8 · Audience measurement

I measure how this website is used myself so that I can improve it. Analysis runs on my own server. Browser measurements are sent to this server only after current consent. No third-party analytics providers are involved. The following information distinguishes current collection from the existing historical data.

Measurement has two levels. Basic measurement applies unless you have objected. Enhanced measurement starts only after your explicit consent to the purposes currently described. Do Not Track and Global Privacy Control disable both levels.

Basic measurement without consent

The following is collected:

  • Pages visited and their order within a visit, each with a timestamp
  • Time between page requests, where there are multiple requests; this does not indicate actual reading time
  • Request source, such as a referring domain; any transmitted search terms and the campaign parameters utm_source, utm_medium and utm_campaign
  • Technical information from headers sent by the browser: device type, browser, operating system and language setting
  • Country and, within Germany, federal state. No locality or coordinates
  • Whether the visitor is automated, such as Googlebot

No measurement script is loaded in the browser for this purpose. Scroll depth, clicks, window size and form contents are not part of basic measurement.

Your IP address is not stored as part of this. The full IP address is not stored in basic measurement. A visit identifier that changes daily is generated from the IP address, browser identifier, date, operating mode and a secret server-side key. It groups page requests within a day; after 30 minutes without a request, a new visit begins. This is pseudonymous measurement, not a promise of complete anonymity. Server logs are described separately in section 4.

I base basic measurement on Article 6(1)(f) GDPR: my legitimate interest in understanding which content is needed and where the website has weaknesses. The incoming page requests received by the server are processed for this purpose. You may object to this measurement at any time.

With consent

The server-side information is supplemented by your full IP address, an approximate location with coordinates inferred from it, and browser measurements: time since a page loaded, scroll depth, window size and clicks on links or buttons outside forms. No form contents or selected values are measured. Link destinations are recorded without query parameters or fragments; visible link text, clicks within forms and selected values are not transmitted. Time measurement starts when the page loads and does not measure your actual attention. Switching from basic to enhanced measurement starts a separate visit record.

Your full IP address and an approximate location with coordinates inferred from it are stored in enhanced measurement only after your current explicit consent. The legal basis is your consent under Article 6(1)(a) GDPR; section 25(1) TDDDG also applies to measurement access in the browser. You can withdraw your consent at any time with future effect on the “Disable measurement” page. If you say no, the basic measurement described in the previous section continues. There is no disadvantage to you; the website continues to function unchanged.

No automatic deletion period is currently configured for analytics data. It remains stored until specifically deleted. This also applies to historical data; the technical setting does not mean that indefinite retention is legally required. The visit identifier changes daily. Nevertheless, stored full IP addresses may allow visits to be linked across multiple days. New contact enquiries are not linked to visit data.

Before the change on 7 September 2026, browser events were also recorded without consent; contact enquiries could be linked to visit records. Historical data may therefore contain personal links, selected values and, where earlier consent was given, full IP addresses and location information. This data was not automatically deleted. An objection stops future collection but does not delete historical data. For access, an objection or a deletion request, you can contact me at hello@nordapps.de.

You can turn this off

One click on this page is enough, and your visits will no longer be counted. If your browser sends Do Not Track or Global Privacy Control, this is respected automatically and you do not need to do anything else.

9 · Protection against attacks

Automated programs continually probe this website for known security vulnerabilities, such as WordPress login pages, database interfaces or stored access credentials. None of these are available on this server.

Such requests are rejected and logged. The information stored includes the time, the full IP address, the requested path, the request method, the browser identifier and the headers sent with it. If a request has a payload, this is also stored because it shows what was attempted.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest is in protecting this server and the data stored on it. Repeated attacks can only be traced and prevented when their source is known, which is why the full address is stored here, unlike in audience measurement. No automatic deletion period currently applies to these entries. This describes the current technical situation and is not a claim that indefinite retention is necessary. Data subjects may object to storage under Article 21 GDPR; I then assess individually whether the interest in protection takes precedence.

Visitors accessing a normal page of this website are not affected. This applies only to requests for paths that have never existed here. If you arrive there accidentally, for example through an outdated link, a short message is sufficient and the path will be excluded from the check.

10 · What does not take place on this website

  • No analytics by third-party providers, whether Google Analytics or a comparable solution
  • Fonts are loaded exclusively from my own server; no external font services are used.
  • No content from content delivery networks
  • No social network buttons or tracking pixels
  • No embedded maps, videos or font services
  • No sharing or selling of data to third parties
  • No recognition across other websites
  • No new links between contact enquiries and visit data
  • No automated decisions concerning visitors

11 · Your rights

You have the right at any time to access personal data stored about you (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection to processing (Article 21). You can withdraw consent at any time.

To do so, contact hello@nordapps.de.

Independently of this, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The competent authority is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27
91522 Ansbach

12 · Encrypted transmission

This website is served exclusively over encrypted HTTPS. You can recognise this by the address, which begins with https:// , and by the padlock symbol in your browser. When encryption is active, third parties cannot read the data you send to me.

This policy was last updated: 09/2026. The policy is updated when this website changes.