Last updated: 4 August 2026

Privacy policy

Translation noticeThis page is an English translation provided for convenience. If this translation differs from the German Datenschutzerklärung, the German version is authoritative.

1. Controller

The controller under the General Data Protection Regulation is the person identified in the legal notice, which also provides contact details.

2. Technical delivery path

This website is delivered through Cloudflare Pages. Domain management and HTTPS delivery are handled by Cloudflare. Download files up to 25 MiB can be served directly through Cloudflare Pages; larger files (over 25 MiB) remain on self-hosted repository containers behind dedicated download hostnames.

3. Cloudflare (DNS and Pages hosting)

Cloudflare processes DNS requests and HTTP/HTTPS connections to the website because the static pages are delivered through Cloudflare Pages. The project-domain DNS records are configured with Cloudflare proxying enabled ("orange cloud"/proxied).

When the website is accessed, Cloudflare processes technically necessary connection and HTTP data, in particular the IP address, time, destination host, requested resource, HTTP methods, status codes, and headers transmitted by the browser. Cloudflare may also generate security-related metadata such as bot-detection characteristics, rate-limit indicators, and internal identification headers (for example, CF-Ray).

This processing supports encrypted transmission, secure HTTPS delivery, protection against abusive access, and website availability. Cloudflare stores technical log data according to its own retention periods, which are described in Cloudflare's Privacy Policy.

The providers are Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, and, for European contractual relationships, Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany. Cloudflare is used as a processor; the contractual basis is Cloudflare's Data Processing Addendum (DPA) under Article 28 GDPR.

The legal basis for technically necessary processing is Article 6(1)(f) GDPR (legitimate interest in secure, stable, and performant delivery) in conjunction with Article 28 GDPR.

Cloudflare operates a global network; data may therefore be processed outside the EU. Cloudflare's documentation describes the applicable transfer safeguards (including Standard Contractual Clauses and the Data Privacy Framework).

Further information: Cloudflare Privacy Policy, Cloudflare DPA, subprocessor list, and Cloudflare GDPR FAQ.

4. Self-hosted repository containers for large files

Files larger than 25 MiB continue to be delivered through self-hosted repository containers. This delivery path uses the project hosts deb.ralfhartmann.dev, macos.ralfhartmann.dev, and brew.ralfhartmann.dev.

External access to these hosts is routed through a Cloudflare Tunnel with Cloudflare proxying enabled.

For these downloads, the corresponding repository service processes technically necessary request data (for example time, host, path, HTTP method, and status) for delivery, troubleshooting, and security. These operational logs remain under self-hosted control and are processed only within self-hosted operations.

5. Package downloads

Depending on file size, download buttons and APT commands point either to the project domain (Cloudflare Pages) or to those repository hosts. Larger packages and installer files above 25 MiB are delivered through the repository hosts because of the Cloudflare Pages limit. No platform account is required for downloads.

6. Voluntary support through PayPal

The project website contains a clearly identified external link to PayPal.Me. No PayPal scripts, images, or other content are embedded. A connection to PayPal is therefore established only after the link has been actively followed.

Following the link opens PayPal in a new window or tab. PayPal then processes data including the visitor's IP address and technical browser, device, and request data. The rel="noreferrer" attribute prevents this project page's address from being sent as the referrer. If a payment is made, the entered account and payment data is processed by PayPal. The recipient receives the transaction data provided by PayPal for receiving and administering the payment; depending on the PayPal account, this may include the payer's name, email address, amount, and payment note.

For users in the European Economic Area, the provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. See PayPal's Privacy Statement for details. Support is voluntary and creates no additional rights, services, or benefits. Processing required to receive and administer voluntary payments relies on Article 6(1)(f) GDPR; statutory accounting and retention obligations rely on Article 6(1)(c) GDPR.

7. Contact by email

Project-related enquiries can be sent to scanworker@ralfhartmann.dev. Cloudflare Email Routing forwards incoming messages to a private GMX mailbox. The actual destination address is not published.

When an email is sent, the processed data includes the sender's name and address, recipient address, subject, message content, attachments, and technically necessary header and transport data. Cloudflare processes this data to receive and forward the message; GMX processes and stores it in the destination mailbox. Further information is available in Cloudflare's Privacy Policy and GMX's privacy and security information.

Processing is necessary to answer the enquiry and provide secure email communication. Pre-contractual or contractual enquiries rely on Article 6(1)(b) GDPR; other project-related messages rely on the legitimate interest in responding to them under Article 6(1)(f) GDPR. Statutory retention obligations rely on Article 6(1)(c) GDPR. Messages are deleted after the enquiry has been fully resolved unless statutory or other legitimate retention grounds apply.

8. No cookies or tracking

This website itself sets no cookies and uses no analytics, advertising, or tracking services. It contains no forms, external fonts, embedded videos, or third-party scripts. An external site is contacted only after a clearly identified link has been actively followed.

9. Legal basis

Technically necessary processing relies on Article 6(1)(f) GDPR. The legitimate interest is the secure, reliable, and data-minimizing operation of the project website and public package distribution.

10. Retention

Local operational and error logs are retained only as long as required for operation, security, and troubleshooting, then overwritten by the configured log rotation. Cloudflare determines its own retention periods; the provider's current published information applies.

11. Data subject rights

Where the legal requirements are met, rights of access, rectification, erasure, restriction, data portability, and objection apply. A complaint may also be lodged with a data protection supervisory authority. Requests can be sent to the email address in the legal notice.