Privacy Policy
Last updated: April 2026
1. Data Controller
The controller responsible for data processing on this website is:
Andreas John
Johann-Strauß-Straße 13
84494 Neumarkt-Sankt Veit
Germany
Email: andi-john-dev@gmx.net
2. Overview of Data Processing
This is a static website hosted on AWS (Amazon CloudFront + S3). It does not require user accounts, does not process form submissions, and does not use advertising or third-party tracking scripts. The only optional data processing is anonymous performance monitoring via AWS CloudWatch RUM, which is activated only after explicit user consent.
3. Hosting
This website is hosted on Amazon Web Services (AWS) using Amazon CloudFront (CDN) and Amazon S3 (storage). When you visit the site, your browser automatically transmits certain technical data to the server:
- IP address
- Date and time of access
- Requested URL / page
- HTTP status code
- Browser type and version
- Operating system
- Referrer URL
This data is processed to deliver the website to you and to ensure its security and stability. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). Server log data is stored for a limited period and then automatically deleted. AWS processes this data as a data processor on my behalf.
AWS infrastructure is located in the EU (Frankfurt, eu-central-1).
For more information, see the
AWS Privacy Notice
.
4. AWS CloudWatch RUM (Performance Monitoring)
This site optionally uses AWS CloudWatch RUM for anonymous performance monitoring. This service is only activated after you explicitly consent via the cookie consent banner.
What is collected
- Core Web Vitals (LCP, FID, CLS)
- Page load times and HTTP request performance
- JavaScript errors
- Page URLs visited during the session
- An anonymous, randomly generated session ID
What is NOT collected
- Names, email addresses, or any personally identifiable information
- IP addresses (not stored by CloudWatch RUM)
- Tracking cookies (cookies are explicitly disabled in the configuration)
Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time by clicking "Cookie Settings" in the footer.
Data location: All RUM data is processed and stored in the
EU (eu-central-1, Frankfurt).
5. Cookies and Local Storage
This website uses localStorage (not cookies) to remember your consent choice and your preferred colour theme. No data is sent to any server through these mechanisms.
| Key | Purpose | Duration |
|---|---|---|
rum_consent | Stores your cookie consent decision | Until manually cleared |
theme | Stores your preferred colour theme (light/dark) | Until manually cleared |
6. Data Transfers to Third Countries
AWS infrastructure used by this site is located in the EU
(eu-central-1). AWS Inc. is a US company; data processing
is governed by a Data Processing Addendum (DPA) and Standard Contractual
Clauses (SCCs) as required by GDPR Chapter V. The EU–US Data Privacy
Framework additionally provides an adequacy basis for AWS as a certified
participant.
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR)
To exercise any of these rights, please contact me at andi-john-dev@gmx.net.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). You may contact the supervisory authority in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement.
9. Changes to This Privacy Policy
I may update this privacy policy from time to time to reflect changes in data processing practices or legal requirements. The "Last updated" date at the top of this page indicates the most recent revision.