Skip to the Thing
Here’s The Thing

Privacy Policy.

Last updated: September 19, 2026

Controller

heresthething — Maik Hebel c/o Online-Impressum 11125 Europaring 90 53757 Sankt Augustin Germany

Email: maik@heresthethi.ng

This notice applies to heresthethi.ng and all its subdomains.

Hosting and security

The website uses Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, for hosting, delivery and security. Cloudflare processes IP addresses, request URLs and times, browser and device information, referring addresses where supplied, and connection, response and security data.

This processing provides the website, prevents abuse and supports fault diagnosis. The legal basis is Article 6(1)(f) GDPR; these are the operator’s legitimate interests. Certain technical data are necessary to deliver the requested pages and to maintain the security and availability of the service.

Cloudflare’s firewall, bot protection and browser checks may challenge or block requests. Cloudflare also provides traffic and performance statistics. The operator does not use advertising pixels, session recordings or browser analytics trackers, and does not offer visitor accounts or create visitor profiles or personal reading lists. Processing by external media providers after activation is described below.

Cloudflare acts as a processor for hosting under its Data Processing Addendum and uses contracted subprocessors. It also processes certain network data for its own purposes as described in its Privacy Policy.

Cookies

Cloudflare security cookies may include __cf_bm (30 minutes of inactivity) and cf_clearance (security-check results; Challenge Passage is set to 30 minutes, subject to Cloudflare’s validation allowances and renewal). See Cloudflare’s cookie information.

Access to restricted areas uses session cookies and a two-factor challenge cookie lasting up to ten minutes. Server sessions expire after eight hours unless renewed through activity. Browser session restoration may preserve session cookies.

Strictly necessary storage and access rely on section 25(2) TDDDG; associated security processing relies on Article 6(1)(f) GDPR. Optional YouTube and other external media activation relies on consent as described below.

YouTube videos

Some Things use an embedded YouTube player to display and play video content. The provider for users in the EEA is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Video titles and creator names are retrieved from YouTube by our server when a video is prepared for publication and stored with the Thing. This lookup does not connect your browser to YouTube.

The player loads only after you select “Agree and load YouTube video”. Before activation, this feature loads no YouTube player, script or thumbnail. Activation permits a connection to Google/YouTube, which receives your IP address, browser/device information, this website’s origin and interactions with the player. Google may store or access information on your device and, depending on your account and settings, associate data with your Google account.

The player uses YouTube’s privacy-enhanced mode. This does not prevent all data processing or device storage. The legal basis for activation is your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Activation is optional and is not remembered across page loads. Use “Unload video · withdraw consent” to remove the player and stop further requests from it. Withdrawal does not affect earlier lawful processing or erase data already held by Google.

Google determines its own retention periods according to the data and account settings involved. See Google’s Privacy Policy and YouTube’s embed information.

International transfers

Cloudflare and Google may process data outside the EEA, including in the United States. Cloudflare, Inc. and Google LLC participate in the EU–US Data Privacy Framework. Transfers covered by those certifications rely on the European Commission’s adequacy decision under Article 45 GDPR. For other transfers requiring safeguards, the providers use the Standard Contractual Clauses described in the documents linked below. Information on the safeguards is available in Cloudflare’s DPA and Google’s transfer information.

Operator accounts

There is no public registration. For authorised operators, the site stores contact and account details, password hashes, protected two-factor credentials, session information, login-attempt identifiers and security/editorial records. Drafts, attribution and media are stored for publication.

The legal basis is Article 6(1)(f) GDPR: securing accounts, controlling editorial access and recording changes.

Retention

On the current Cloudflare Free plans, Workers Logs are retained for up to three days, the Security Events view covers 24 hours, and D1 database recovery history covers up to seven days. These are separate product limits, not a deletion deadline for all Cloudflare data. Other Cloudflare network data are retained according to its stated operational, security and legal purposes.

Security and editorial audit events are retained for 30 days. Expired sessions, login challenges, rate-limit records and used-code markers are deleted by an hourly cleanup. Records become eligible for deletion when they expire or reach the retention limit; if a cleanup fails, deletion resumes on a subsequent successful run. Access and security checks enforce expiry independently of cleanup.

Account details and credentials are retained while operator access is required and removed through account administration when that access is permanently withdrawn. Drafts, published content and attribution remain stored while needed for editing and publication. Deleted database records may remain in recovery history until its retention window expires.

Contact

Email enquiries are processed to respond to the message: under Article 6(1)(f) GDPR for ordinary enquiries, Article 6(1)(b) for contractual enquiries, or Article 6(1)(c) for statutory requests. Correspondence is retained until the matter is resolved, subject to statutory retention duties or necessary preservation for legal claims.

The contact mailbox uses Zoho Mail, provided by Zoho Corporation GmbH, Germany. Zoho processes email addresses, message contents, attachments and technical delivery data on our behalf to provide the email service. Mailbox data is stored in Zoho’s EU data centres. Technical support may involve access from India; Zoho uses the European Commission’s Standard Contractual Clauses and supplementary safeguards for this access. See Zoho’s Privacy Policy and information on hosting and international transfers.

External media and links

External links lead to services governed by their own privacy notices.

Some Things use media from other external providers. Their names, media hosts, processing information and privacy links are shown with the Thing before activation. External media and related download-card images load only after you select “Agree and load external media”. The purpose is to display or play the selected content. The providers receive request data, including your IP address and browser information, and may store or access information on your device. Activation relies on Article 6(1)(a) GDPR and section 25(1) TDDDG. It is optional, is not remembered across page loads, and can be withdrawn using “Unload external media · withdraw consent”. Withdrawal stops further loading through this feature but does not erase information already received by a provider. Uploaded media are delivered through this website’s hosting.

Copying a permalink and generating a download card take place in your browser.

Your rights

Subject to the applicable conditions, you have rights of access, rectification, erasure, restriction and data portability under Articles 15–20 GDPR. You may withdraw consent at any time with effect for the future.

Right to object: under Article 21 GDPR, you may object to processing based on Article 6(1)(f) for reasons relating to your particular situation. Processing must then cease unless overriding compelling legitimate grounds or grounds relating to legal claims apply.

Contact the controller above. You may also complain to a supervisory authority, particularly in the member state of your residence, workplace or the alleged infringement (Article 77 GDPR). No decisions producing legal or similarly significant effects are made solely by automated processing within the meaning of Article 22 GDPR.

Legal NoticePrivacy Policy