Legal · Privacy
Privacy notice:
short, because there is little to declare.
This website works without cookies, without tracking services and without third-party servers. What is processed anyway is set out here — in full and in plain language.
No cookies, no external tracking, no content from third-party servers. Traffic measurement runs on my own server log files with a shortened IP address. Personal data only arises if you give it to me yourself — via the contact form or by signing up for the letter.
Version of this notice: 17 July 2026
1. Controller
Matthias Eger — Matthias Eger Design Studio
Pfarräckerstraße 14
92637 Weiden in der Oberpfalz, Germany
Email: mail@matthiaseger.de
Phone: 0961 – 634 32 61
No data protection officer has been appointed, as there is no legal obligation to do so. I am your point of contact for all data protection matters myself.
2. Hosting
This website is hosted by Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin. When you access the site, the host processes technically necessary connection data (in particular the IP address of your device) in order to deliver the pages. A data processing agreement under Article 28 GDPR (General Data Protection Regulation, German: DSGVO) is in place with the host — it processes data only on my instructions. The legal basis is my legitimate interest in providing the website securely and reliably (Article 6(1)(f) GDPR).
3. Server log files and traffic measurement — without cookies
I measure the use of this website myself, without tracking services and without cookies. On every page view, the website writes one line to its own log file (JSON format) on the server. The following is stored:
- Shortened IP address: the last octet is replaced by a zero (203.0.113.87 becomes 203.0.113.0); IPv6 addresses are shortened accordingly. The full address is not stored.
- Daily identifier: a truncated hash value derived from the IP address and the browser identifier, which changes every day. Its only purpose is to count views on the same day as “one visitor”. Neither the IP address nor your identity can be reconstructed from the hash; recognition across day boundaries is impossible.
- Page visited, date and time, HTTP status code.
- Referrer (the page visited before, if the browser transmits it) and user agent (browser/device identifier).
The legal basis is Article 6(1)(f) GDPR. The legitimate interest: trouble-free operation, detection of misuse and attacks, and simple traffic measurement — deliberately without external tracking services. Retention period: the log files are deleted after 14 months; this period is configurable and can be shortened. The data is not combined with any other data.
4. Screen resolution (once per session)
To improve how the website is displayed on common screen sizes, your browser transmits the screen resolution (width × height) to the server once per session. So that this happens only once, the browser sets a marker in sessionStorage — a purely local note that is deleted automatically when the browser tab is closed. It is not a cookie, no identifier is stored and no information is transmitted to third parties. The legal basis is Article 6(1)(f) GDPR (interest in a properly working display); storing the marker is also technically necessary within the meaning of § 25 Abs. 2 Nr. 2 TDDDG (Section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act).
5. Contact form and contact by email
If you use the contact form, I process the details you enter there (name, email address, optionally phone number and subject, and your message) solely in order to deal with your enquiry. The enquiry is stored as a file on my server — together with a timestamp and a shortened IP address — and sent to me by email. The legal basis is Article 6(1)(b) GDPR (initiation or performance of a contract or pre-contractual measures). The same applies if you write to me directly by email. The data is not passed on to third parties and is deleted as soon as the enquiry has been dealt with conclusively and no statutory retention obligations stand in the way.
6. Newsletter “Klartext KI” (double opt-in)
My letter “Klartext KI” uses the double opt-in procedure: after signing up you receive an email containing a confirmation link. The subscription only takes effect once you click that link — so nobody can sign up someone else's address.
The following is stored: your email address, the status of the subscription (requested / confirmed), the times of sign-up and confirmation, and the shortened IP address used at sign-up — as evidence of your consent. The legal basis is your consent (Article 6(1)(a) GDPR). The addresses are used solely for sending the letter, are not passed on and are not combined with any other data.
Withdrawal: you can withdraw your consent at any time — via the unsubscribe link in every issue or informally by email to mail@matthiaseger.de. After you unsubscribe, your address is deleted from the distribution list. The lawfulness of processing carried out up to the withdrawal remains unaffected.
7. No cookies, no tracking, no third-party resources
This website sets no cookies, uses no external tracking or analytics services (no Google Analytics, no Matomo, no advertising pixels) and loads no content from third-party servers — no CDN scripts, no external fonts, no embedded maps or videos. The fonts, too, are self-hosted and delivered from my own server. When you visit this website, your browser therefore connects to my server only. That is also why there is no cookie banner here: there is nothing for you to consent to.
8. External links
This website contains links to external services, for example to LinkedIn, Xing or Google (reviews). These are pure references: simply visiting this website transmits no data to those providers. Only when you click such a link do you leave this website — from that point on the privacy notice of the respective provider applies, and I have no influence over their data processing.
9. Your rights
You have the following rights against me as the controller with regard to personal data concerning you:
- access (Article 15 GDPR),
- rectification (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- objection to processing based on Article 6(1)(f) GDPR (Article 21 GDPR), and
- withdrawal of consent given, with effect for the future (Article 7(3) GDPR).
An informal email to mail@matthiaseger.de is enough. You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for me is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
10. Encryption (TLS)
This website uses TLS encryption (recognisable by “https://” and the padlock symbol in your browser's address bar). All data you transmit — for example via the contact form or the newsletter sign-up — is transmitted in encrypted form and cannot be read by third parties in transit.
11. Changes to this notice
I update this notice when the technology behind this website or the legal requirements change. The version published here at the time applies (version: 17 July 2026).
Questions about data protection?
One email is enough — you get a clear answer, not a boilerplate paragraph.
