Privacy Policy
Privacy Policy
Last updated: 29 August 2026
This policy explains what this website does with personal data. It describes the site as it is actually configured — the log fields, retention periods and the one cookie below were read off the running server, not copied from a template.
Who is responsible
[YOUR LEGAL NAME] [Street address] [Postcode, City], [Country] Email: [contact address]
What is collected
Server access logs
Every request to this site is written to a log on the server. Each entry contains:
| Field | Example |
|---|---|
| IP address | 2a02:2479:55:5400::1 |
| Date and time | 29/Aug/2026:19:58:25 +0200 |
| Method, host and path | GET https www.sysadminheaven.com "/blog" |
| HTTP status and bytes sent | 200, 15546 |
| User agent | Mozilla/5.0 … |
| Referrer, where the browser sends one | - |
An IP address is personal data under the GDPR, so this section applies even though nothing here is tied to a name or an account.
- Purpose: operating the site, diagnosing faults, and detecting abuse. Automated scanners probe this server continuously; the logs are how that is spotted.
- Legal basis: legitimate interests, Art. 6(1)(f) GDPR — running a website securely, which cannot be done without knowing who is connecting to it.
- Retention: access logs rotate weekly and four are kept, so an entry is deleted after roughly five weeks. Error logs are kept for roughly ten weeks. Nothing is archived beyond that.
- Recipients: nobody. Logs stay on the server and are not sold, shared or sent to any analytics service.
Cookies
This site sets one cookie:
| Name | Purpose | Lifetime | Flags |
|---|---|---|---|
grav-site-… |
Session handling for the CMS that serves this site | 30 minutes | HttpOnly, SameSite=Lax, Secure over HTTPS |
It contains a random session identifier and nothing else. It does not track you, does not follow you to other sites, and is not shared with anyone.
This cookie is strictly necessary for the site to function — the CMS will not serve pages without session support — so under Article 5(3) of the ePrivacy Directive it is exempt from the consent requirement. That is why this site has no cookie banner. It has nothing to ask you about.
What this site does not do
- No analytics. No Google Analytics, Matomo, Plausible or anything comparable.
- No advertising, no tracking pixels, no fingerprinting.
- No social media buttons or embeds.
- No third-party fonts or scripts. Every asset — including the icon font — is served from this domain, so no third party ever sees your IP address.
- No accounts, no newsletter, no contact form. There is nothing here to sign up for.
- No automated decision-making or profiling (Art. 22 GDPR).
Where the data is
The server is a virtual machine hosted by [IONOS SE, Karlsruhe, Germany], inside the EU. No personal data is transferred outside the EEA. The hosting provider acts as a processor and has access to the underlying machine.
All traffic is encrypted with TLS; certificates are issued by Let's Encrypt.
Your rights
Under the GDPR you may request access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20), and you may object to processing based on legitimate interests (Art. 21). To exercise any of these, email the address at the top of this page.
Be aware of a practical limit: log entries are indexed only by IP address. If you ask about your data, the only way to find it is if you tell us the IP address you used and roughly when. Entries older than the retention period above are already gone.
You also have the right to lodge a complaint with a supervisory authority (Art. 77). In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
Changes
If this site's behaviour changes — an analytics tool, a comment system, a contact form — this page will be updated before that change goes live.