Privacy Policy

Data Controller

Kristof Lang,
c/o Block Services
Stuttgarter Str. 106
70736 Fellbach, Germany
E-Mail: xplore (at) klabx.com

Responsible within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection provisions.

Hosting

My website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes personal data (e.g., server log files) as part of hosting to ensure the operation of the website. A data processing agreement (DPA) according to Art. 28 GDPR has been concluded with Hetzner, ensuring that your data is only processed according to our instructions and in compliance with data protection regulations.

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in secure and stable website operation).

More information: https://www.hetzner.com/de/rechtliches/datenschutz

Server Log Files

When visiting my website, the hosting provider automatically collects the following data:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • IP address
  • Date and time of server request

This data serves exclusively to ensure trouble-free operation and IT security. Deletion occurs after 14 days at the latest.

Legal basis: Art. 6 para. 1 lit. f GDPR.

Comments

When you write comments on my website, the data entered in the comment form as well as the IP address and user agent string (for spam detection) are stored.

A hash can be generated from the email address and transmitted to the Gravatar service by Automattic Inc., USA. Privacy policy: https://automattic.com/privacy/

A third-country transfer (USA) only occurs with your consent according to Art. 6 para. 1 lit. a GDPR. By consenting to the use of Gravatar, you also agree to the transmission of your data (hash of your email address) to the USA. There is no adequacy decision by the EU Commission for the USA, and the level of data protection may not correspond to that of the EU. In particular, US authorities may under certain circumstances access your data without equivalent legal remedies being available to you.

Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of a usage contract) or Art. 6 para. 1 lit. f GDPR (legitimate interest in exchange).

Spam Protection

I use Antispam Bee. This plugin checks comments based on defined criteria without transferring data to third countries.

Legal basis: Art. 6 para. 1 lit. f GDPR (protection against spam).

Login Protection
I use the plugin Limit Login Attempts Reloaded to protect my website against brute force attacks and unauthorized access attempts.
For this purpose, login attempts are logged and the IP address of the user is temporarily stored if too many failed login attempts occur.
These data are not shared with third parties.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the security of the website).
More information: https://www.limitloginattempts.com/privacy-policy/

Cookies & Consent Management

For managing cookies and similar technologies, I use Real Cookie Banner.

Details: https://devowl.io/de/rcb/datenverarbeitung/

Legal bases: Art. 6 para. 1 lit. c GDPR (legal obligation) and Art. 6 para. 1 lit. f GDPR (management of consents).

Information about the cookies used can be found on my cookie information page.

Web Analytics with Matomo (self-hosted)

I use Matomo to analyze visitor traffic. The installation is on my own server without data transmission to third parties.

  • IP addresses are anonymized
  • Raw data (logs) are automatically deleted after 6 months
  • Aggregated reports are deleted after 24 months
  • Matomo may use cookies (only after consent according to Art. 6 para. 1 lit. a GDPR)
  • Without cookies, analysis is based on my legitimate interest in optimizing my offering (Art. 6 para. 1 lit. f GDPR)

You can revoke your consent at any time through the cookie settings.

Affiliate Programs & Links

I use affiliate links (partner links) on this website. If you click on such a link and purchase a product or book a service through it, I receive a commission from the provider. The price does not change for you.

Data processing (tracking of the click) takes place in order to settle the commissions.

Travelpayouts

I participate in the affiliate partner program of the Travelpayouts network (Go Travel Un Limited, Hong Kong). Affiliate links (advertising links) are integrated on my website for this purpose.

If you click on such an affiliate link, you will be redirected to the respective provider’s website (e.g., Booking.com, Agoda, GetYourGuide, etc.). The provider or the network may use tracking technologies (such as cookies or tracking pixels) to verify that you were referred from my website. This is technically necessary to calculate and process any applicable commission for the referral. I do not set any cookies or tracking technologies myself in this context.

Privacy policy of Travelpayouts: https://www.travelpayouts.com/en/privacy

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in fair remuneration for advertising services).

Multilingual Support

I use Polylang to offer content in multiple languages. A technically necessary cookie (pll_language) is set to store the selected language.

Legal basis: Art. 6 para. 1 lit. f GDPR.

Embedded Content

With your consent, I may embed content from third-party providers, e.g.:

When loading content from Google or Meta, data may be transferred to third countries (e.g., USA). An equivalent level of data protection cannot be guaranteed there. For the United Kingdom (location of the OpenStreetMap Foundation), an adequacy decision by the EU Commission is in place, which certifies an adequate level of data protection.

Legal basis: Art. 6 para. 1 lit. a GDPR (consent).

To protect your data, external content from third-party providers like YouTube, Instagram, and OpenStreetMap is blocked by default. When accessing the page, no connection is established to the servers of these providers.

Only when you give your consent – either through a targeted click on the respective content or through general consent in the cookie settings – the content will be loaded. With this consent, you agree to the associated data transmission to the third-party provider (in the case of OpenStreetMap, this specifically includes transmitting your IP address to request the map data) as described in the corresponding sections.

Storage Duration

Comments and metadata are stored indefinitely to automatically recognize follow-up comments. Server log files are deleted after 14 days at the latest.

In principle, personal data is only stored as long as necessary to achieve the respective purpose or as long as legal retention periods (e.g., from commercial or tax law) require storage. After the purpose ceases or the deadlines expire, the data is routinely deleted.

Your Rights

You have the right at any time to:

  • Information (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Revocation of given consents (Art. 7 para. 3 GDPR)

Right to complain: You can file a complaint with a supervisory authority, e.g., with the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate or, if you live in Japan, additionally with the Personal Information Protection Commission (PPC).

Contact

You can direct questions about data protection to my contact details mentioned above at any time.