Legal
Privacy
A static site with one cookie, no advertising or analytics vendors, and measurement that will not run until you say so — it is served from my own infrastructure, not a tracking company. This page describes what the code does, not what a generator thinks a privacy policy should say.
Controller
Marius-Constantin Dinu, Wels, Austria
Email
Controller within the meaning of Art. 4(7) GDPR. Neither the measurement described here nor the booking form makes my core activities the regular and systematic monitoring of data subjects on a large scale under Art. 37(1)(b) GDPR, so there is no data protection officer to route this through: write to me directly.
Webfonts are served from here
Every font file is hosted on this domain. No request goes to Google Fonts or any other font CDN, so your IP address is never disclosed to a third party in order to render type. That is deliberate: the Munich Regional Court held that embedding Google Fonts remotely transmits the visitor's IP address without a legal basis and infringes the GDPR (LG München I, 20 January 2022, Az. 3 O 17493/20), and the Austrian data protection authority has reasoned along the same lines. The typefaces themselves — Newsreader and IBM Plex — are used under the SIL Open Font License and credited in the site's third-party notices.
Server logs
The web server that delivers these pages records the usual request data — IP address, timestamp, requested resource, HTTP status, referrer and user agent — for a short period in order to deliver the site, diagnose faults and defend against attacks. Legal basis: Art. 6(1)(f) GDPR, my legitimate interest in a functioning and secure website. These logs are not merged with the analytics described below, and they are not used to profile anyone.
Analytics, only after consent
I would like to know which parts of this site are actually read. The measurement is my own: a small script served from my own infrastructure, sending to my own endpoint. No Google Analytics, no Plausible, no Meta pixel, no advertising network, no cross-site tracking, and nothing is sold. One thing is shared, and it is described two paragraphs down.
Until you press Accept in the banner, the script is not on the page. It is injected only once consent is stored, so declining or ignoring the banner produces no analytics request at all — not a single beacon, not even a page view.
A notification reaches me over Telegram
This is the one place measurement leaves my own machines, so it belongs in plain sight rather than in a sub-clause. When a new session starts, and when someone sends the booking form, my server messages me through the Telegram Bot API. That notice carries the page you entered on, the referring site, your browser, device type and operating system, the country the connection came from, your language and time zone if you consented to measurement, and the rotating visitor identifier — and, for a booking enquiry, the details you typed into the form yourself.
Telegram therefore sees that message, in the same way an email provider would see an email. It never receives your IP address, because my server does not keep one to send. Decline measurement and no visit notice exists at all: the script that would report the visit is never put on the page, so there is nothing for my server to be told about and nothing for it to forward. Sending the booking form is a separate decision and still notifies me, because that is the point of sending it.
Your IP address is never stored
The receiving server sees your IP address, as every server must, and immediately turns it into a visitor identifier: a SHA-256 hash over a secret salt, your IP, your user agent and the site key, truncated to 64 bits. The address itself is never written to disk. Exactly two things are derived from it before it is discarded: whether the connection was IPv4 or IPv6, and the country it came from, looked up against a table stored on my own server so the address is never sent anywhere to resolve it. Country only — not a city, not a postcode, not a coordinate. When the lookup cannot place an address it records nothing rather than guessing.
The salt is random, lives in memory only, and is replaced whenever the UTC date changes. A new salt means yesterday's identifier and today's cannot be matched, by me or by anyone with the stored data. The identifier is therefore unlinkable across days, and it cannot be reversed into an address.
What is recorded
- The path and the page title. The query string is stripped before anything is written, apart from a campaign token if you arrived through a tagged link.
- The referring URL and its hostname, so I can tell a link from a search result.
- Browser family, operating system family, and desktop / mobile / tablet / bot.
- A two-letter code, and only if the edge proxy supplies one as a header. There is no GeoIP lookup, so usually there is no country at all.
- Time zone name, browser language, and viewport size in pixels.
- Scroll depth in quarters, dwell time per section, total time on the page, clicks on elements I marked for measurement together with the visible label of what was clicked, file downloads, and outbound link targets.
- A random string held in sessionStorage under cortex_sid, discarded when you close the tab.
No name, no email address, no account and no free text: measurement never asks for any of it, and there is no comment field, so there is nothing of that kind in an event. Stored events are deleted 90 days after they are recorded, and sooner once a volume ceiling is reached. Statistics are computed from the events that are still there, so once they are gone the history is gone with them.
The booking form, only if you send it
The teaching pages carry one form, for enquiring about a course. It is the single place on this site where I ask for your details, and nothing leaves the browser until you tick the consent box — it is not pre-ticked, and the form refuses to submit without it — and press send. It is a separate decision from the analytics banner: neither answer affects the other, and the request carries no cookie.
What you typed goes with it — name, email, company, role and the message, which carries the course and timeframe you selected. Three things you did not type are stored alongside it, and it would be easy to leave them out of this sentence: the same rotating visitor identifier the analytics uses, a session id derived from it, and your browser, operating system and device type. No page address, no referrer and no browsing history travel with it.
It goes to the same Cortex control plane that receives the analytics, and is stored there for one purpose: so that I can answer you. It is never merged with the analytics events, and it is kept as long as answering the enquiry warrants. The form is never the only route: you can write to Email instead, which reaches me as plain mail and touches none of the above, and that is all the form itself offers when scripting is off.
Cookies — there is exactly one
- cortex_consent, first-party, value granted or denied.
- To remember your answer so the banner stops asking, and so the analytics script knows whether it may run. Declining is stored too — that is what keeps the banner quiet.
- 180 days, or until you clear it below or in your browser.
- SameSite=Lax, so it is never attached to cross-site requests, and marked Secure over HTTPS. It is not sent to the analytics endpoint, which requests without credentials.
That is the complete list — no other cookie is set by this site or by anything it loads. Once analytics is running it additionally uses two sessionStorage entries, cortex_sid and cortex_k, for the session identifier and a campaign token from a ?k= link. Those are not cookies, are never sent to another site, and vanish when the tab closes.
Withdraw consent
Withdrawal must be as easy as giving consent (Art. 7(3) GDPR), so it is one button. It deletes the cookie and reloads the page; measurement stops immediately, and the banner will ask again on your next visit. Withdrawal does not affect the lawfulness of what was collected beforehand.
Legal bases
Analytics and the consent cookie: Art. 6(1)(a) GDPR, your consent, in conjunction with § 165(3) TKG 2021 for storing information on your device. Server logs and the security of the site: Art. 6(1)(f) GDPR, legitimate interest. The booking form: Art. 6(1)(a) GDPR, the consent you give by ticking the box before you send it. Email you send me: Art. 6(1)(b) or (f) GDPR, to answer you, kept as long as the correspondence warrants.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interest (Art. 21), plus the right to withdraw consent at any time (Art. 7(3)). One caveat, stated plainly: the analytics data holds no identifier I could tie to you. If you ask, I cannot single out your records from a salted hash, and Art. 11 GDPR does not require me to collect more data just to make that possible.
Write to Email and you get an answer. If you are not satisfied, you may lodge a complaint (Art. 77) with the Austrian supervisory authority:
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
dsb@dsb.gv.at ·
www.dsb.gv.at
Changes
This notice tracks the code. If what the site does changes, this page is edited in the same commit and the date at the top moves. There is no version buried in a footnote.