1. Data protection at a glance
General information
This policy explains what happens to your personal data when you visit this website or contact me. Personal data is any data by which you can be personally identified.
This website loads no content from third-party servers: no external fonts, no maps, no embedded videos, no analytics or advertising services. There is no audience measurement and no profiling.
Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Dr. Martin Schalk, Schalk IP Consulting
Professor Angermair Ring 24, 85748 Garching, Germany
Phone: +49 89 50078701 · E-mail: [email protected]
A data protection officer does not have to be appointed under § 38 BDSG; please address enquiries directly to the contact details above.
2. Hosting
Hetzner Online GmbH (web server)
The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The infrastructure for this website is located in the ISO 27001 certified data centre in Nuremberg, Germany. For details see Hetzner’s privacy policy.
The legal basis is Art. 6 (1) lit. f GDPR; the legitimate interest lies in the reliable and secure operation of the website. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
3. Cloudflare (attack mitigation)
Traffic between your browser and the server passes through the network of Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare mitigates denial-of-service attacks and terminates the encrypted connection. In doing so, Cloudflare processes your IP address and technical details of the request.
- Legal basis: Art. 6 (1) lit. f GDPR – legitimate interest in defending the web presence against attacks.
- Processing agreement: an agreement pursuant to Art. 28 GDPR is in place, including the European Commission’s standard contractual clauses (Art. 46 (2) lit. c GDPR).
- Transfer to the USA: Cloudflare is certified under the EU-US Data Privacy Framework; the transfer is based on the European Commission’s adequacy decision of 10 July 2023 (Art. 45 GDPR). A residual risk of access by US authorities cannot be entirely ruled out.
- Cookies: to distinguish human visitors from automated requests, Cloudflare may set a strictly necessary cookie (
__cf_bm, lifetime 30 minutes). It serves attack mitigation only and does not require consent under § 25 (2) no. 2 TDDDG.
For details see Cloudflare’s privacy policy.
4. Server log files
Each time a page is requested, the web server automatically records:
- IP address of the requesting device
- date and time of the request
- the address requested, transfer protocol and status code
- volume of data transferred
- the previously visited page (referrer), where transmitted
- browser type, browser version and operating system
This information is required to operate the site and to investigate faults. The legal basis is Art. 6 (1) lit. f GDPR. The logs are deleted automatically after 14 days; they are retained longer only where a specific attack has to be investigated. The data is not combined with other sources and is not evaluated for advertising purposes.
5. Storage on your device
The website sets no cookies of its own. If you use the switch for the light or dark appearance, your choice is stored in your browser’s local storage under the name schalk-darstellung. This entry never leaves your device and is not transmitted to me. It is required to provide the service you have expressly requested and therefore does not require consent under § 25 (2) no. 2 TDDDG. You can delete it at any time via your browser settings.
6. Contacting me
I deliberately do not use web-based contact forms. If you write to me by e-mail, telephone or Threema, or via the contact card provided, I process your details in order to deal with your enquiry. The legal basis is Art. 6 (1) lit. b GDPR where your enquiry relates to entering into or performing a contract, and otherwise Art. 6 (1) lit. f GDPR – legitimate interest in responding to enquiries.
Threema
I offer Threema as an encrypted messaging channel. The provider is Threema GmbH, Pfäffikon SZ, Switzerland. Message content is end-to-end encrypted; the provider processes the connection data required for delivery. An adequacy decision of the European Commission is in place for Switzerland (Art. 45 GDPR). Use is voluntary – e-mail and telephone are available as equivalent alternatives. The privacy policy of Threema GmbH applies in addition.
E-mail, S/MIME and OpenPGP
You can reach me at [email protected] and [email protected]. My e-mails are digitally signed. For confidential messages you may use my S/MIME certificate (home page) or my OpenPGP key (see the security page). Encryption takes place solely between your mail program and mine; no third party is involved.
Your enquiry is retained until the purpose no longer applies – for example because your matter has been concluded – and you ask for it to be deleted. Mandatory statutory retention periods, in particular commercial and tax periods of six and ten years respectively, remain unaffected. Please note that unencrypted e-mail can be read in transit; for confidential documents I will provide encrypted access on request.
7. Collaboration and document exchange
The public website and client data are kept separate. For exchanging larger or confidential documents you can be given access to my private Nextcloud instance at cloud.schalk-ip.de, which does not run in a data centre but on my own hardware in Garching.
- Access: via an encrypted tunnel with no open ports (zero-trust principle).
- Backups: automated backups locally and additionally to a Storage Box provided by Hetzner Online GmbH; an agreement pursuant to Art. 28 GDPR is in place for this as well.
- Encryption: backups are encrypted on the local system before transmission. Neither the storage provider nor any third party can read them.
- Location: the productive system and the backups are located in Germany.
The legal basis is Art. 6 (1) lit. b GDPR (contract or pre-contractual measures), supplemented by Art. 6 (1) lit. f GDPR given the legitimate interest in confidentiality and resilience when handling intellectual property. The data is deleted once the engagement has ended and no statutory retention period applies.
8. Encrypted transmission
All pages are delivered exclusively over TLS (currently TLS 1.3) and secured with HTTP Strict Transport Security. You can recognise an encrypted connection by “https://” in the address bar and by the padlock symbol in your browser.
9. Your rights
Under the GDPR you have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). To exercise them, simply write to [email protected] or to the postal address given above.
Right to object under Art. 21 GDPR
Where processing is based on Art. 6 (1) lit. f GDPR, you may object to it on grounds relating to your particular situation. I will then no longer process the data concerned unless I can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims.
Withdrawal of consent
Where processing is based on your consent, you may withdraw it at any time with effect for the future (Art. 7 (3) GDPR). The lawfulness of processing carried out up to that point remains unaffected.
Complaint to a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
www.lda.bayern.de
Last updated: August 2026.