Data protection privacy statement in accordance with the requirements of the General Data Protection Regulation (GDPR) of the European Union
Ok, folks, according to EU law I have to put this onto my webpage. The lawyers among you should go to the details further down with all that technical explanations, just to see that I comply with the EU rules and there is no reason to file a cease and desist order against me. Parts of the statement were generated by AdSimple's Data Protection Generator and automatically translated from German into English with DeepL.
You, however, who are just really interested in what I'm doing with your data, stay here with me for a short explanation.
I do not intentionally collect any data from you here on this webpage. I don't need to know who you are and where your kids are playing. I know why you are here, because this page is widely dedicated to paper modeling and the Apollo space program, so you are probably interested into these topics. I don't need cookies or other creepy stuff to find that out.
In general, this was it. However, as things are not that simple, you find here further information about my webpage and its use of your data.
The template I use is manufactured by JoomlaShine, a premium vendor for Joomla templates and development tools. I'm quite sure that their products do callbacks to mother ship when the webpage is browsed, however they are more interested in me to ensure that I paid for the template, than in you as a random visitor.
The template uses Google fonts. You might know who Google is and what Google does. In return, be assured Google definitely knows who you are, maybe better than your family or your bank, and regardless whether you are visiting my website or not. However, to fully comply with the GDPR, the fonts are kept locally on my server. Lawyers go home.
I plan to come up with a possibility to leave comments on certain articles. To avoid spam from robots, reCAPTCHA technology will be implemented so that you can leave comments without registering. This technique is provided by Google as well, and you can be sure that Google will read you comment faster than me.
When you place an order, you are doing this via email, not through a web form here. Following data is stored locally in a data base on my desktop computer and on a local backup storage:
- your email address
- your shipping details including full name and full address
- your assigned serial number of the kit
- Date of order
- Date of purchase
- Price of the kit
- Shipping costs
- Information if your kit has been ordered at the printing company by me. This also indicates that your payment has been received
- and - if you send me a feedback - if the kit has arrived well
- type of payment (Paypal or bank account)
Your address details are also forwarded to the printing company Jentzsch in Vienna, because the kits are stored there for delivery and they cannot send the kit to you otherwise - hope this makes some sense.
Local data base
The local data base is necessary to keep track, which serial numbers of the kit are still available, and eventually, to tell me when the kit is sold out.
It's also used to send you an order confirmation email, generate the PayPal invoice and my order at the printing company, and is needed when something goes wrong with shipping.
Furthermore, it's needed to pay my taxes. I'm obliged to keep these data for 7 years, so that the tax authorities are able to check that you purchased kit #N for price X and shipping cost Y on date Z. Your data is kept secure and offline, and not used for any other purpose. Frankly, I would not even have the time and knowledge for any data abuse.
My web server is hosted by an ISP, who provides web tools to do some basic statistics like from which country my visitors come from and what your favorite pages are on my website (definitely not this one, I guess) and so on. Most visitors come from USA, followed by Germany and UK. Now you know the secret ;)
There are also tools to block visitors when they try to abuse the webpage like embedding web viri or DDOS attacks. All the necessary data is stored in a web log file, that is kept for 14 days; then it is deleted automatically. I do not actively use Google Analytics or similar stuff.
Social media and ad free zone
No ads (well - aside from my own products, of course), no Facebook, WhatsApp, InstaGram, Twitter, LinkedIn, whatsoever. There is a small exception for YouTube, because there is fantastic footage available about the Apollo Space Program, but also building instructions for the Crawler Transporter model, and some articles here will refer to these videos.
For the lawyers
This privacy statement explains to you, in accordance with the requirements of the General Data Protection Regulation (GDPR) 2016/679 and the Data Protection Act (DPA), what information are collected, how this data is used, and what choices you have as a visitor on this website.
Automatic data storage
When you visit websites today, specific information are automatically generated and stored; this also applies to my website.
The data stored in the web server log file include:
- the address (URL) of the called web page
- Browser and browser version
- the operating system
- the address (URL) of the previously visited page (referrer URL)
- the host name and IP address of the device from which it is accessed
- Date and time
Web server log files are usually stored for two weeks and then automatically deleted. I have no intention to pass on these data, but I cannot rule out completely that these log files might be accessed without my knowledge by authorities of the government.
Our website uses HTTP cookies to store user-specific data.
Below we explain what cookies are and why they are used to help you better understand the following privacy statement.
What exactly are cookies?
Whenever you surf the Internet, use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most Web pages store small text files in your browser. These files are called cookies.
Cookies store certain user data from you, such as language or personal page settings. When you return to our site, your browser sends the "user-related" information back to our site. Thanks to cookies, our website knows who you are and offers you your usual standard settings. In some browsers, each cookie has its own file, in others, such as Firefox, all cookies are stored in a single file.
There are both first-party and third-party cookies. First-party cookies are created directly by our site, third-party cookies are created by partner sites (such as Google Analytics). Each cookie is unique because each cookie stores different information. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans or other "pests". Cookies also cannot access information on your PC.
For example, cookie data may look like this:
Expiry time: 2 years
Use: Differentiation of website visitors
Example value: GA1.2.1326744211.152111168934
A cookie should contain at least 4096 bytes.
At least 50 cookies should be stored per domain.
A total of at least 3000 cookies should be stored.
What types of cookies are there?
There are 4 types of cookies:
Absolutely necessary cookies
These cookies are necessary to ensure the basic functionality of the website. For example, these cookies are needed when a user places a product in the shopping cart, then continues surfing on other pages and later only proceeds to checkout. These cookies do not delete the shopping cart, even if the user closes his browser window.
These cookies collect information about the user behavior and whether the user gets any error messages. In addition, these cookies are used to measure the loading time and the behavior of the website with different browsers.
These cookies ensure better user friendliness. For example, entered locations, font sizes or form data are stored.
These cookies are also called targeting cookies. They are used to deliver individually tailored advertising to the user. This can be very practical, but also very annoying.
Usually, when you first visit a website, you are asked which of these cookie types you want to allow. And of course this decision is also stored in a cookie.
How can I delete cookies?
If you want to determine which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:
Chrome: Delete, enable and manage cookies in Chrome
Safari: Managing cookies and website data with Safari
Firefox: Deleting cookies to remove data that websites have stored on your computer
Internet Explorer: Deleting and managing cookies
Microsoft Edge: Deleting and managing cookies
If you do not want cookies, you can set your browser so that it always informs you when a cookie is to be set. In this way, you can decide for each individual cookie whether to allow the cookie or not. The procedure varies depending on the browser. It is best to search for the instructions in Google using the search term "Delete cookies Chrome" or "Deactivate cookies Chrome" in the case of a Chrome browser or exchange the word "Chrome" for the name of your browser, e.g. Edge, Firefox, Safari.
Since 2009 there are the so-called "cookie guidelines". These guidelines state that the storage of cookies requires the consent of the website visitor (i.e. you). Within the EU countries, however, there are still very different reactions to these guidelines. In Austria, however, this directive was implemented in § 96 (3) of the Telecommunications Act (TKG).
If you want to know more about cookies and do not shy away from technical documentation, we recommend https://tools.ietf.org/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called "HTTP State Management Mechanism".
Rights under the Basic Data Protection Ordinance
According to the provisions of the DSGVO and the Austrian Data Protection Act (DSG), you have in principle the following rights:
- Right to rectification (Article 16 DSGVO)
- Right to cancellation ("right to be forgotten") (Article 17 DSGVO)
- Right to limitation of processing (Article 18 DSGVO)
- Right of notification - notification obligation in relation to rectification or erasure of personal data or limitation of processing (Article 19 DSGVO)
- Right to data transferability (Article 20 DSGVO)
- Right of objection (Article 21 DSGVO)
- Right not to be subject to a decision based exclusively on automated processing, including profiling (Article 22 DS Block Exemption Regulation)
If you believe that the processing of your data violates the data protection law or your data protection claims have otherwise been violated in any way, you can complain to the supervisory authority, which in Austria is the data protection authority, whose website you can find at https://www.dsb.gv.at/ .
We use Google Fonts of the company Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA) on our website.
You do not need to login or provide a password to use Google fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google Account, don't worry that your Google Account information will be transmitted to Google while using Google Fonts. Google collects and stores information about your use of CSS (Cascading Style Sheets) and fonts. What the data storage looks like exactly, we will
What are Google Fonts?
Google Fonts (formerly Google Web Fonts) is an interactive directory of more than 800 fonts provided by Google LLC for free use.
Many of these fonts are released under the SIL Open Font License, while others are released under the Apache License. Both are free software licenses. So we can use them freely without paying royalties.
Why do we use Google Fonts on our website?
With Google Fonts, we can use fonts on our own website, and don't have to upload them to our own server. Google Fonts is an important building block to keep the quality of our website high. All Google fonts are automatically optimized for the web and this saves data volume and is a great advantage especially for use on mobile devices. When you visit our site, the small file size ensures fast loading time. Google Fonts are also known as secure web fonts. Different image synthesis systems (rendering) in different browsers, operating systems and mobile devices can lead to errors. Such errors can partially distort texts or entire web pages optically. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform problems with Google Fonts. Google Fonts supports all popular browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). So we use Google Fonts to make our entire online service as beautiful and consistent as possible.
What data does Google store?
When you visit our website, fonts are downloaded from a Google server. This external call transmits data to the Google server. In this way, Google also recognises that you or your IP address is visiting our website. The Google Fonts API was developed to reduce the collection, storage and use of end-user information to what is necessary for the efficient delivery of fonts. API also stands for "Application Programming Interface" and serves, among other things, as a data transmitter in the software sector.
Google Fonts securely stores CSS and font requests at Google and is therefore protected. Google can determine the popularity of the fonts through the collected usage figures. Google publishes the results on internal analysis pages such as Google Analytics. Google also uses data from its own web crawler to determine which web pages use Google fonts. This data is published in Google Fonts' BigQuery database. BigQuery is a Google web service for companies that want to move and analyze large amounts of data.
However, it should also be remembered that each Google Font Request also automatically transmits information such as IP address, language settings, browser screen resolution, browser version and browser name to the Google servers. It is not clear whether this data is also stored or not, and Google does not communicate this information unambiguously.
How long and where is the data stored?
Google stores requests for CSS assets for one day on your servers, which are mainly located outside the EU. This allows us to use the fonts using a Google stylesheet. A stylesheet is a style sheet that can be used to quickly and easily change the design or font of a website, for example.
The font files are stored on Google for one year. Google's goal is to improve the loading time of websites. If millions of websites refer to the same fonts, they are cached after the first visit and appear immediately on all other websites visited later. Sometimes, Google updates font files to reduce file size, increase language coverage, and improve design.
How can I delete my data or prevent data storage?
The data that Google stores for a day or a year cannot simply be deleted. The data is automatically transmitted to Google when the page is viewed. To delete this data early, you need to contact Google support at https://support.google.com/?hl=de&tid=111168934 In this case, you will only prevent data storage if you do not visit our site.
Unlike other web fonts, Google allows us unrestricted access to all fonts. So we have unlimited access to a plethora of fonts and can get the most out of our website. You can find out more about Google Fonts and other questions at https://developers.google.com/fonts/faq?tid=11116893
While Google addresses privacy related issues, it does not provide truly detailed information about data retention. It's relatively difficult (almost impossible) to get truly accurate information about stored data from Google.
You can also find out which data is basically collected by Google and for what purpose this data is used at https://www.google.com/intl/de/policies/privacy/ .
We might use Google Maps of the company Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA) on our website.
By using the functions of this map, data is transferred to Google. You can find out which data is collected by Google and what this data is used for at https://www.google.com/intl/de/policies/privacy/ .
Our primary goal is to ensure that our website is protected and secure for you and for us in the best possible way. In order to guarantee this, we use Google reCAPTCHA from Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA). With reCAPTCHA, we can determine if you are a flesh and blood person and not a robot or other spam software. By spam we mean any unsolicited information that we receive electronically.
With the classic CAPTCHAS, you usually had to solve text or image puzzles to check them. With reCAPTCHA from Google, we usually don't have to bother you with such puzzles. In most cases it is enough to simply tick the box and confirm that you are not a bot. With the new Invisible reCAPTCHA version you don't even have to set a check mark anymore. You can find out exactly how this works and, above all, which data is used for it in the course of this data protection declaration.
What is reCAPTCHA?
reCAPTCHA is a free captcha service from Google that protects websites from spam software and abuse by non-human visitors. This service is most commonly used when you fill out forms on the Internet. A captcha service is an automatic Turing test designed to ensure that an action on the Internet is performed by a human and not by a bot. In the classic Turing test (named after the computer scientist Alan Turing), a human being makes a distinction between a bot and a human being. With Captchas, this is also done by the computer or a software program.
From these user actions, the software calculates a so-called captcha score. Google uses this score to calculate how high the probability is that you are a human being even before captcha input. ReCAPTCHA or captchas in general are always used when bots could manipulate or abuse certain actions (e.g. registrations, surveys, etc.).
Why do we use reCAPTCHA on our website?
We only want to welcome people of flesh and blood on our site. Bots or spam software of all kinds can stay at home. That's why we do everything we can to protect ourselves and offer you the best possible usability. That's why we use Google reCAPTCHA from Google. So we can be pretty sure that we will remain a "bot-free" website.
By using reCAPTCHA, data is transmitted to Google, which uses Google to determine whether you are really a human being. reCAPTCHA therefore serves the security of our website and consequently also your security. For example, without reCAPTCHA it could happen that during registration a bot registers as many e-mail addresses as possible in order to subsequently "spam" forums or blogs with unwanted advertising content. With reCAPTCHA we can avoid such bot attacks.
Which data is stored by reCAPTCHA?
ReCAPTCHA collects personal data from users in order to determine whether the actions on our website actually originate from humans. The IP address and other data required by Google for the reCAPTCHA service can therefore be sent to Google. IP addresses are almost always truncated before they are sent to a server in the U.S. within the member states of the EU or other signatory states to the Agreement on the European Economic Area.
The IP address will not be combined with any other data held by Google unless you are signed in to your Google Account while using reCAPTCHA. First, the reCAPTCHA algorithm checks whether Google cookies from other Google services (YouTube, Gmail, etc.) have already been placed on your browser. Then reCAPTCHA places an additional cookie in your browser and captures a snapshot of your browser window.
The following list of collected browser and user data is not exhaustive. Rather, they are examples of data which, according to our knowledge, are processed by Google.
- Referrer URL (the address of the page from which the visitor comes)
- IP address (e.g. 2188.8.131.52)
- Information about the operating system (the software that allows you to run your computer). Known operating systems are Windows, Mac OS X or Linux.)
Cookies (small text files that store data in your browser)
- Mouse and keyboard behavior (every action you perform with the mouse or keyboard is saved)
- Date and language settings (which language or which date you have preset on your PC is saved)
- Screen resolution (shows how many pixels the image consists of)
There's no doubt that Google uses and analyzes this data before you click the "I'm not a robot" check mark. With the Invisible reCAPTCHA version even the ticking is omitted and the whole recognition process runs in the background. How much and which data Google stores exactly, you don't get to know from Google in detail.
The following cookies are used by reCAPTCHA: Here we refer to the reCAPTCHA demo version of Google at https://www.google.com/recaptcha/api2/demo. All these cookies require a unique identifier for tracking purposes. Here is a list of cookies that Google has set on the reCAPTCHA demo version:
Expiry time: after one year
Use: This cookie is used by the company DoubleClick (also owned by Google) to register and report a user's actions on the website in connection with advertisements. In this way, the advertising effectiveness can be measured and appropriate optimization measures can be taken. IDE is stored in browsers under the domain doubleclick.net.
Example value: WqTUmlnmv_qXyi_DGNPLESKnRNrpgXoy1K-pAZtAkMbHI-111168934
Expiry time: after one month
Use: This cookie collects website usage statistics and measures conversions. A conversion occurs, for example, when a user becomes a buyer. The cookie is also used to display relevant advertisements to users. The cookie can also be used to prevent a user from seeing the same ad more than once.
Example value: 2019-5-14-12
Expiry time: after 9 months
Example value: U7j1v3dZa11689340xgZFmiqWppRWKOr
Expiry time: after 19 years
Use: The cookie stores the status of a user's consent to the use of different Google services. CONSENT also provides security to help verify users, prevent fraudulent logon information, and protect user information from unauthorized attacks.
Example value: YES+AT.de+20150628-20-0
Expiry time: after 6 months
Use: NID is used by Google to match ads to your Google search. The cookie helps Google "remember" your most frequently-entered searches or your past interaction with ads. You'll always get customized ads. The cookie contains a unique ID that Google uses to collect the user's personal preferences for advertising purposes.
Example value: 0WmuWqy1168934zILzqV_nmt3sDXwPeM5Q
Expiration time: after 10 minutes
Use: Once you have checked the "I am not a robot" box, this cookie will be set. The cookie is used by Google Analytics for personalized advertising. DV collects information in anonymous form and is also used to make user choices.
Example value: gEAABBCjJMXcI0dSAAAANbqc111168934
Note: This enumeration cannot claim to be complete, as experience has shown that Google changes the selection of its cookies time and again.
How long and where is the data stored?
By inserting reCAPTCHA, data is transferred from you to the Google server. Where exactly this data is stored, Google, even after the data has been restored to its original state, will not be able to provide any information.
Without having received a confirmation from Google, it can be assumed that data such as mouse interaction, time spent on the website or language settings are stored on the European or American Google servers. The IP address that your browser transmits to Google is generally not merged with other Google data from other Google services. However, if you are logged into your Google Account while using the reCAPTCHA plug-in, the data will be merged. This is subject to Google's different data protection regulations.
How can I delete my data or prevent data storage?
If you do not want data about you and your behavior to be transmitted to Google, you must completely log out of Google and delete all Google cookies before visiting our website or using the reCAPTCHA software. In principle, the data is automatically transmitted to Google as soon as you call up our site. In order to delete this data, you must contact Google support at https://support.google.com/?hl=de&tid=111168934 .
So when you use our website, you consent to Google LLC and its agents automatically collecting, processing and using information.