Legal

Privacy Policy

Information on the processing of personal data when visiting this website, pursuant to the General Data Protection Regulation (GDPR).

1. Controller

The party responsible for data processing on this website is:

Roland Zaenger
Freiheit 1
38855 Wernigerode
Germany
Email: sicheres-smartphone@mailbox.org

You can find further details in the Imprint.

2. Nature of this website – no tracking, no cookies

What this is about: This website is a private hobby project with no commercial intent. It gathers information about a secure, privacy-friendly smartphone. It is deliberately built the way it recommends the topic itself: data-minimizing, without advertising, without tracking and without collecting data about its visitors. There is nothing to "monetize" – accordingly, there is no interest in collecting data about you.

This website is a private, non-commercial, purely static information resource. There is no contact form, no user account, no newsletter, no comment function. No web tracking takes place: no analytics tools (e.g. Google Analytics, Matomo), no advertising or tracking pixels, no profiling. No cookies are set. There is no content delivery network and no external third-party reverse proxy (e.g. Cloudflare) upstream – traffic runs directly between your browser and the server in Germany. Delivery is handled by the reverse proxy/web server Caddy running locally on that server itself; no third party is interposed.

3. Server, hosting & DNS (netcup, Germany)

The website runs on a dedicated virtual server (VPS) rented from the following provider; the name resolution (DNS) of the domains is also handled by this provider:

netcup GmbH
Daimlerstraße 25
76185 Karlsruhe, Germany

As a technical infrastructure service provider, netcup processes data on my behalf; the server location is in Germany/the EU. A data processing agreement pursuant to Art. 28 GDPR has been concluded with netcup (available in the netcup customer control panel). netcup is certified to ISO 27001 and ISO 27701.

Data minimization at the web server: The reverse proxy/web server Caddy on the VPS is configured to minimize data and stores no personal access logs permanently – in particular, no IP addresses are stored in server log files. A brief, technically essential processing of connection data takes place to deliver the pages, without permanent logging. The legal basis is the legitimate interest in secure and functional operation pursuant to Art. 6(1)(f) GDPR.

4. Encryption (HTTPS / TLS)

The site is delivered exclusively encrypted via HTTPS. The TLS certificates required for this are obtained and renewed automatically by the reverse proxy/web server Caddy through the certificate authority Let's Encrypt (ISRG). No personal visitor data is processed during certificate issuance. You can recognize an encrypted connection by https:// in the address bar of your browser.

5. No embedded third-party content, no external fonts

Fonts, scripts, stylesheets and images are served exclusively locally from the server of this website. No external content is loaded that would transmit your IP address to third parties – in particular no Google Fonts, no external CDNs for scripts, no embedded videos, maps or social media plugins. Only locally installed system fonts are used.

6. External links

This website links to external third-party offerings (e.g. grapheneos.org, dnsforge.de, kuketz-blog.de, imazing.com, actalis.com). When you click such a link, you leave this website; I have no influence over the data processing that takes place there. The privacy policies of the respective provider apply.

7. Your rights as a data subject

You have the following rights vis-à-vis the controller with regard to the personal data concerning you:

To exercise these rights, an informal message to the contact address given above is sufficient.

8. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement (Art. 77 GDPR). The supervisory authority responsible for the controller is the State Commissioner for Data Protection of Saxony-Anhalt.

9. Currency of this privacy policy

Last updated: June 2026. As the website is developed further or due to changed legal or regulatory requirements, it may become necessary to adapt this policy.