Legal

Privacy

Last updated: April 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:

Daniel Nimz
Am Heergarten 145
38375 Räbke
Germany
Email: daniel@applein.blue

This website uses no tracking, no analytics tools and no cookies that would require a cookie banner or consent. Only strictly necessary session cookies are used (for example the operator's admin login), which are exempt from consent under Section 25 (2) No. 2 TTDSG (German Telecommunications and Digital Services Data Protection Act). As a visitor, you are not tracked by any scripts, third parties or analytics services.

2. General information on data processing

This privacy policy applies to the website https://applein.blue. The apps I publish in the app stores have their own privacy policies — an overview is available in the section below.

This website is built with WordPress (open source) and hosted on a server of netcup GmbH, Nuremberg/Germany.

I process personal data sparingly, for a specific purpose, and only for as long as necessary. On this website I use:

  • No analytics or tracking services (no Google Analytics, no Matomo, no Plausible, etc.)
  • No advertising cookies or advertising networks
  • No external fonts (no Google Fonts) — fonts are served entirely from my own server
  • No social media plugins, no embedded videos, no external embeds
  • Only strictly necessary cookies or session data (WordPress system)

A cookie banner is therefore not required, as only strictly necessary storage operations take place.

App-specific privacy policies

The following apps have separate privacy policies covering data processing, third-party services and retention periods:

  • LoliPopp — Game-night coordination app (iOS + Android)

Further apps will be linked here as they are released.

Where I obtain consent for the processing of personal data, Art. 6 (1) (a) GDPR serves as the legal basis.

For processing required to perform a contract or take pre-contractual steps, the legal basis is Art. 6 (1) (b) GDPR.

For processing required to fulfil a legal obligation, Art. 6 (1) (c) GDPR applies.

Processing necessary to pursue a legitimate interest is based on Art. 6 (1) (f) GDPR. My legitimate interest is in particular the technically error-free and secure provision of this website.

4. Hosting and server logs

The website is hosted on servers of netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. The servers are located in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with netcup.

When you visit the website, the server automatically collects data in server logs. This is technically necessary to deliver the site, ensure stability, and prevent abuse:

  • IP address (shortened/anonymised where technically possible)
  • Date and time of the request
  • Requested URL
  • Amount of data transferred
  • HTTP status code
  • Referrer (the previously visited page, if transmitted by the browser)
  • User agent (browser and operating system identifier)

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a secure, functioning website).

Retention: Logs are deleted or anonymised after a maximum of 14 days so that no personal reference remains. Exceptions apply only if there is evidence of a concrete attack and longer storage is required to investigate it.

5. SSL/TLS encryption

This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognise an encrypted connection by the "https://" in the address bar and the padlock icon of your browser.

6. Cookies and local storage

I only use strictly necessary cookies or local storage on this website. This concerns in particular:

  • WordPress session cookies required for the login area to work for me as operator. These cookies are only set if someone logs in — so not for regular visitors.

No other cookies (marketing, tracking, advertising) are used.

Legal basis: Section 25 (2) No. 2 TDDDG (technically necessary storage) in conjunction with Art. 6 (1) (f) GDPR.

7. Contact form

If you send me a message via the contact form, I process the following data:

  • Name (if provided)
  • Email address
  • Content of the message
  • Timestamp
  • Technical metadata (IP address, user agent) for spam protection

Purpose: Processing your request and communicating with you.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures), supplemented by Art. 6 (1) (f) GDPR (legitimate interest in proper handling of requests).

Spam protection: The form uses a honeypot mechanism (a field invisible to humans that automated bots would fill in). No external captcha services (e.g. Google reCAPTCHA) are used. Your data does not leave my hoster's server.

Storage: Messages are stored in the WordPress database and additionally sent by email to my address daniel@applein.blue.

Retention: Messages are deleted as soon as the purpose of communication has been fulfilled and no legal retention obligations apply — usually after 12 months at the latest.

8. Email communication

If you email me directly, I process the data contained in the email solely to handle your request. The legal basis is Art. 6 (1) (b) or (f) GDPR. Emails are deleted once the purpose has been fulfilled and no retention obligations apply.

9. Disclosure to third parties

Your personal data is not shared with third parties, except:

  • you have explicitly consented,
  • disclosure is necessary to fulfil a contract with you,
  • there is a legal obligation,
  • disclosure occurs as part of a processing agreement under Art. 28 GDPR (e.g. to my hoster netcup).

No data is transferred to third countries outside the EU/EEA through this website. (Separate rules apply to the apps — see the app-specific privacy policies.)

10. Your rights

You have the following rights at any time:

  • Access to your personal data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data, subject to statutory retention obligations (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing based on Art. 6 (1) (f) GDPR for reasons arising from your particular situation (Art. 21 GDPR)
  • Withdraw consent with effect for the future (Art. 7 (3) GDPR)

An informal message to daniel@applein.blue is sufficient to exercise these rights.

11. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates applicable data protection law (Art. 77 GDPR).

The competent authority for me is:

State Commissioner for Data Protection Lower Saxony (LfD Niedersachsen)
Prinzenstraße 5
30159 Hannover, Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: https://www.lfd.niedersachsen.de

12. No automated decision-making

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place on this website.

13. Changes to this privacy policy

I reserve the right to adapt this privacy policy if legal conditions or the processing on the website change. The version accessible at the time of your visit applies.