Privacy Policy
This is a translation for convenience.
The German version is the operative
one and shall prevail in case of any discrepancy.
1. Controller
The controller for the processing of personal data on simpler.website and
de.simpler.website, within the meaning of Art. 4 Nr. 7 DSGVO (Article 4(7)
GDPR), is:
Marvin Thiel
Weinbergstraße 2
04179 Leipzig
Germany
Email: mail@marvinthiel.com
No data protection officer has been appointed; the conditions of
§ 38 BDSG are not met.
2. Principles
We process as little personal data as possible. We use no analytics,
statistics or tracking services, we embed no third-party content (no
fonts, no maps, no videos, no tracking pixels), and we do not sell data.
We disclose personal data to third parties only as described in this
policy or where we are legally obliged to.
3. Your account
When you register we process your email address and a cryptographic hash
of your password. We do not store the password itself. Your email address
is also your sign-in name; we collect no separate username, no name and no
postal address.
The account also carries the time of registration, the time of the last
sign-in, the interface language you chose, whether your email address has
been confirmed, and time-limited tokens for confirming the address and for
resetting the password. While a change of your email address is waiting to
be confirmed, the new address belongs to the token issued for it; on
confirmation it becomes your account's address, and otherwise the token
expires after 24 hours.
Purpose: providing and administering the account, signing in, confirming
the email address, resetting the password.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Article 6(1)(b) GDPR).
4. The content of your website
We store what you write into your website, the images you upload, the
website's title, the subdomain you chose and, if you use one, your own
domain. Legal basis: Art. 6 Abs. 1 lit. b DSGVO. Published content is
publicly accessible; that is the purpose of the service.
Where that content contains personal data (your own website's imprint,
for instance), we process it on your behalf; see section 7.
We remove all metadata from uploaded images. An image is re-created from
decoded pixel data; EXIF data including GPS coordinates, camera identity
and capture time never reaches our disks. Only the orientation is applied
before the metadata block is discarded; without that, every portrait
photograph would publish sideways.
5. Cookies
We set exactly three cookies, all three strictly necessary:
sw_session: keeps you signed in after you sign in.
-
sw_csrf: protects the service's forms from being submitted
from other websites.
-
sw_lang: remembers whether you want the service in German
or in English. It is set only when you have chosen that language
yourself, in your account settings or by following a link from our
German home page, and it contains nothing but "de" or "en". It is kept for a year, because
otherwise your choice would be lost every time you close your browser.
We set no analytics or tracking cookies. We set no third-party cookies. We
use no comparable techniques such as Local Storage or tracking pixels to
recognise you.
The legal basis for storing them on your device is
§ 25 Abs. 2 Nr. 2 TDDDG: all three cookies are strictly necessary for the
service you have expressly requested. That includes sw_lang,
which does nothing but carry out your own choice of language and does not
recognise you. The subsequent processing is covered
by Art. 6 Abs. 1 lit. b DSGVO. A consent banner is therefore not required,
and we show none.
Visitors to published customer websites receive no cookies at all.
6. Server logs and IP addresses
We store no IP addresses. Access logging is switched off in both the web
server and the application server; no logfiles are produced that record
who requested which page and when.
Your IP address is unavoidably processed for the duration of the
connection itself (without it the response cannot reach you) and is not
stored afterwards. It is not analysed, not combined with other data and
not passed on.
7. Visitors to the websites we host
Our customers' published websites are delivered as static HTML. They
contain no JavaScript, no cookies, no tracking pixels, no analytics
services and no resources loaded from third parties. The stylesheet and
the images come exclusively from our own servers.
About visitors to those pages we collect and store no personal data, and
in particular no IP addresses.
Where a customer places a link to another website, that is a link and not
an embed: your browser contacts the other site only once you click it.
What happens there is governed by that website's own privacy policy.
The customer is responsible for the content of a hosted website. In
relation to us it is a processing relationship under Art. 28 DSGVO.
8. Payment processing
Payments are handled by Mollie B.V., Keizersgracht 126,
1015 CW Amsterdam, Netherlands. Mollie is registered with the Dutch
Chamber of Commerce under number 302.04.462 and is a payment service
provider licensed and supervised by the Dutch central bank
(De Nederlandsche Bank).
Mollie processes payment data as an independent controller
(eigenständig Verantwortliche) within the meaning
of the GDPR, and not as our processor. Mollie's own privacy statement
applies to that processing, and your data subject rights in respect of it
are exercised against Mollie.
We transmit to Mollie: your email address (which also serves as the
customer name there), the amount payable in euros, and a description of
the plan you booked.
Your payment details (card number, IBAN, or your bank's credentials)
are entered exclusively on Mollie's own pages. Those details never reach
our servers and are neither collected nor stored by us.
From Mollie we receive and store: the customer, mandate, subscription and
payment identifiers, the amount, the status and the time of a payment, and
the invoice number generated from it.
The legal basis is Art. 6 Abs. 1 lit. b DSGVO. The Netherlands is a member
state of the European Union; no transfer to a third country takes place.
9. Processors
We use the following processors under Art. 28 DSGVO. A data processing
agreement is in place with both.
-
netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany:
operation of the servers. All servers are located in Germany.
-
Heinlein Hosting GmbH, Schwedter Straße 8/9A, 10119 Berlin, Germany:
operator of mailbox.org, sending and receiving our email. Its servers
are located in Germany.
We use no other processors.
10. The emails we send
To your email address we send only the following emails:
- the link confirming your email address,
- the link resetting your password,
-
the link confirming a new email address, when you want to change the
address on your account; it goes to the new address, and only when it
is opened does that address become your account's,
-
a notice to your previous address that such a change was asked for,
naming the address it would move to (so that you find out if it was
not you),
-
a notice that somebody tried to move an account to your address
although an account for it already exists (again so that you find out,
without the person asking learning anything about your account),
-
a notice that somebody tried to register with your address although an
account for it already exists (so that you find out, without a second
account being created),
-
notice of a failed payment, and the warning that your website will
otherwise go offline,
-
the confirmation of the contract required by § 312f Abs. 2 BGB, once
your subscription becomes active, carrying your order, the total
price and the withdrawal notice.
-
the confirmation of a cancellation required by § 312k Abs. 4 BGB, once
somebody has cancelled through the cancellation button, carrying the
content of the declaration, the date and time it reached us, and the
date the contract is to end. It goes to the address given with the
cancellation.
-
notices the contract or a statute obliges us to send: the announcement
of a substantial change to this policy or to our terms (section 15 of
this policy, § 17 of the terms), the announcement
of a change of our processors (§ 16 of the terms), the acknowledgement
of and the reply to a report under Art. 16 DSA (§ 13 of the terms),
and notice of a suspension of your content or of a termination by us
(§ 14 of the terms). These go to the address of your account.
We send no advertising and no newsletter. These emails are part of the
contract and cannot be unsubscribed from while an account exists.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO; for the notices a statute
prescribes, Art. 6 Abs. 1 lit. c DSGVO in addition.
11. Cancellations made through the cancellation button
Section 312k of the German Civil Code requires a cancellation button that
works without logging in. Anyone cancelling there gives us the details
that provision lists: the kind of termination and, where it is an
extraordinary one, the grounds; an email address and optionally a name so
that you can be identified; the designation of the contract; the date on
which the contract should end; and the address the cancellation
confirmation should go to.
We store those details together with the time they reached us. That is
partly performance of the contract and of your cancellation
(Art. 6(1)(b) GDPR) and partly a legal obligation: section 312k(3) and (4)
require the content and the time of the declaration to be evidenced and
confirmed to you (Art. 6(1)(c) GDPR).
We do not store an IP address with it, not even the
sender's. Because the page works without logging in, we also do not check
on submission whether the address given has an account with us; the
page's answer is the same either way.
A declaration of cancellation is part of the contract file and is kept
like the rest of it; see the next section.
12. Retention and deletion
We delete account data when you ask for your account to be deleted;
content and images are deleted together with the website. Confirmation
tokens expire after 24 hours.
Invoice and payment data must be kept for ten years under § 147 AO and
§ 14b UStG. The right to erasure yields to that obligation under
Art. 17 Abs. 3 lit. b DSGVO. Where your account has a payment history we
therefore delete the account data and anonymise the remaining invoice
records rather than removing them: afterwards they carry no reference to
you, but they still carry the amount, the date and the invoice number,
because that is precisely what has to be kept.
Send a deletion request informally to
mail@marvinthiel.com. We act on
it within one month (Art. 12 Abs. 3 DSGVO).
13. Your rights
You have the following rights against the controller:
- access to the data we process about you (Art. 15 DSGVO),
- rectification of inaccurate data (Art. 16 DSGVO),
- erasure (Art. 17 DSGVO, subject to the limit in section 12),
- restriction of processing (Art. 18 DSGVO),
- data portability (Art. 20 DSGVO),
- objection to processing (Art. 21 DSGVO).
To exercise them, write informally to
mail@marvinthiel.com.
14. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority about
the processing of your personal data, in particular in the member state of
your habitual residence, your place of work or the place of the alleged
infringement (Art. 77 DSGVO).
The authority competent for the controller named above is:
Die Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17
01067 Dresden, Germany
15. Changes to this policy
We update this policy when the service or the law changes. The version in
force carries the date given below. We inform you by email about
substantial changes.
17. Language versions
This privacy policy exists in German and in English. The German version is
the operative one; the English version is a translation provided for
convenience. In the event of any discrepancy the German version shall
prevail.
Last updated:
2026-09-02
Deutsche Version