Privacy policy
Protecting your personal data matters to us. This website works without cookies, without tracking, without analytics services and without third-party content. Below we explain which data is nevertheless processed when you visit, what we use it for and which rights you have.
1. Controller
The controller for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Kontrollfeld GmbH
Gartenstraße 2
10115 Berlin
Germany
Represented by the managing directors Markus Bruns and Jakob Lipps
Commercial register: Amtsgericht Berlin, HRB 155693 B
Phone: +49 30 22908 585
Email: info@kontrollfeld.de
An informal message to this address is enough to request information or to exercise your rights under section 10.
2. Scope
This policy applies to the website www.kontrollfeld.de including the English section under /en/, and to requests arriving atkontrollfeld.de and kontrollfeld.com, which are permanently redirected to www.kontrollfeld.de.
3. Principles
We process personal data only where this is necessary to provide a functioning website and our services. We do not pass data on for advertising purposes, we do not build usage profiles, and we do not use any service that follows your behaviour beyond this website.
Personal data means any information relating to an identified or identifiable natural person — for example name, address, email address or IP address.
4. Hosting and server log data
This is a static website: the pages are generated in advance and delivered unchanged. There is no database and no application logic that processes visitor data.
The website is hosted via GitLab Pages, a service ofGitLab Inc., 268 Bush Street #350, San Francisco, CA 94104, USA. GitLab operates this service on infrastructure provided by Google LLC (Google Cloud); the delivering servers are located in the United States. Every page view therefore involves a transfer to a third country — see section 9 for details.
The processing is carried out on our behalf on the basis of the data processing agreement that forms part of GitLab's terms of service (Art. 28 GDPR).
When a page is requested, the web server processes technically necessary access data that your browser transmits automatically:
- IP address of the requesting device
- date and time of the request
- name and URL of the file requested, and the volume of data transferred
- notification of whether the request succeeded (HTTP status code)
- referring URL, if your browser sends one
- browser type and operating system (user agent)
This data is technically required in order to deliver the website, to ensure its stability and security and to fend off attacks. The legal basis is our legitimate interest in secure and trouble-free operation (Art. 6 (1) (f) GDPR). The retention period follows GitLab's own rules; we ourselves have no access to these access logs and can neither analyse them nor combine them with other data. No evaluation for marketing or analytics purposes takes place.
5. Encrypted transmission
This website is delivered exclusively over a TLS-encrypted connection (recognisable by https:// and the padlock symbol in your browser). The transfer between your device and the server is therefore protected against being read by third parties.
6. No cookies, no tracking, no third-party content
This website sets no cookies. We use no analytics, statistics or marketing tools, no tracking pixels, no social media plugins and no embedded third-party content such as maps, videos or font services. In particular we do not embed Google Fonts from external servers: every font in use is delivered from our own server. Loading a page therefore creates no connection to third-party servers.
For that reason no consent banner is required.
7. Local storage of your display preference
This website offers a switch between a light and a dark appearance. If you use it, your browser stores your choice in local storage (localStorage) under the key kf-theme with the value light or dark. This information stays on your device only, is not transmitted to us or to third parties, and contains no personal reference.
Accessing your device serves solely the function you explicitly requested and is strictly necessary for it; it therefore requires no consent under section 25 (2) no. 2 TDDDG. You can delete the entry at any time through your browser settings; the website then works exactly as before and starts again in the default appearance.
8. Contacting us
This website contains no contact form. You can reach us by email, phone or post.
If you contact us, we process the details you provide — such as name, email address, phone number and the content of your message — in order to handle and answer your enquiry. The legal basis is Art. 6 (1) (b) GDPR where your enquiry serves the performance of a contract or pre-contractual measures, and otherwise our legitimate interest in answering enquiries (Art. 6 (1) (f) GDPR).
Your details remain with us until you ask us to delete them, withdraw your consent, or the purpose of storage ceases to apply — for example once your matter has been dealt with. Mandatory statutory provisions, in particular retention periods under commercial and tax law of up to ten years, remain unaffected.
Note on email security: unencrypted email can be read by third parties in transit. For confidential content we are happy to offer you an encrypted channel — just ask.
9. Recipients and transfers to third countries
Your data is passed to third parties only where this is necessary to perform a contract, where we are legally obliged to do so, or where you have consented. Our hosting provider (section 4) is engaged as a processor within the meaning of Art. 28 GDPR; it processes data solely on our instructions.
Transfer to the USA. Because the website is delivered via GitLab Pages (section 4), the access data arising in the process — in particular your IP address — is transferred to servers in the United States. This happens with every page view and cannot be avoided technically for as long as the website is hosted there.
GitLab Inc. and Google LLC are certified under theEU-US Data Privacy Framework. For transfers to certified companies the European Commission established an adequate level of data protection by decision of 10 July 2023; the legal basis for the transfer is therefore Art. 45 (1) GDPR. The standard contractual clauses of the data processing agreement apply in addition.
We point out that US authorities can access data held by providers based there under certain conditions, and that you may not have the same legal remedies against this as you would within the EU. We therefore keep the processing limited to what is technically unavoidable: there is no tracking, there are no cookies and no content from further third parties, and beyond the access data named in section 4 no information about you reaches the host. Contacting us by email or phone (section 8) does not go through this route.
10. Your rights
You have the following rights towards us regarding your personal data:
- Access to whether and which data we process (Art. 15 GDPR)
- Rectification of inaccurate data or completion of incomplete data (Art. 16 GDPR)
- Erasure of your data, unless a retention obligation stands against it (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used format (Art. 20 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7 (3) GDPR)
Right to object: where we process data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you may object to that processing at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
A message to info@kontrollfeld.de is enough to exercise these rights. Doing so is free of charge for you.
11. Right to lodge a complaint with a supervisory authority
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your residence, your place of work or the place of the alleged infringement. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin, Germany
www.datenschutz-berlin.de
12. No automated decision-making
No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place in connection with this website. In particular, the access data named in section 4 is not used to draw conclusions about individuals or to automate decisions about them.
13. Whether providing data is required
Providing personal data is neither required by law nor by contract. You can use this website without telling us anything; the access data named in section 4 arises for technical reasons. If you contact us, we need the details necessary for that — without them we cannot answer your enquiry.
14. Links to external websites
Our content links in places to third-party websites, for example to legal texts or technical documentation. These links are only followed when you click them; no automatic connection is made. We have no influence over how the linked providers process data and accept no responsibility for it. Please refer to their privacy notices.
15. Changes to this privacy policy
We adjust this privacy policy as soon as the website or the legal situation changes — for example when new features are added. The version published here applies to your visit.
Status: September 2026
This is a translation for convenience. TheGerman version is the legally binding one.