Skip to content
openplate

Privacy

This notice covers the website openplate.de. The app at app.openplate.de has its own privacy notice.

The German version of this page is the binding one. This English text is a translation, provided for information only.

Who is responsible

The controller under the General Data Protection Regulation (GDPR) is:

SPARQ VENTURES UG (haftungsbeschränkt)
Straße 73 49
13125 Berlin
Deutschland

The company is represented by its managing director, Altan Sarisin. The imprint lists all our details. For every privacy question, write to info@openplate.de.

What happens when you visit

The website runs on our own server at Hetzner Online GmbH, in the data centre in Nuremberg, Germany. It has no accounts, no forms and no newsletter sign-up. It sets no cookies. It loads no content from other companies: its fonts and images come from our own server. The only thing it stores in your browser is your choice of a light or dark theme, if you make one.

The website counts visits with Matomo, a program we run on our own server at Hetzner in Germany. The tracker script also comes from this server. The tracker runs with cookies switched off, so it writes nothing to your browser. For each page you open, Matomo records the page, its title, the page that linked you here, your IP address with its last two parts set to zero (for example 192.168.0.0), an approximate location derived from it, and technical data of your browser and device, such as browser, operating system, device type, screen size and language. It also records when you click a link that leads to another website or starts a file download. To group the pages of one visit, Matomo computes an identifier from these technical data on its server. The site sends no user identifier and no free text. No analytics company receives the data, and we do not sell or share it. Matomo keeps the record of each visit and the reports built from these records. Nothing deletes them automatically today.

For each request, our server writes a line to two logs: your IP address, the time, the requested address, the result, the size, the page that linked to it, and the name and version of your browser. Our reverse proxy, the program that receives every request, keeps its log for at most 15 days. The web server of the site keeps its own log until we install a new version of the site, or until the log reaches its size limit. CrowdSec, a security program on our server, reads the first log. When requests from an IP address match a known attack pattern, CrowdSec blocks the address and reports it to the CrowdSec network of CrowdSec SAS in France, with the pattern and the time.

Self-hosted openplate servers ask openplate.de for the newest version every six hours. We count how many IP addresses asked per day and keep only the daily totals.

Cloudflare, Inc. in the USA runs the name servers of our domains. It answers which server a name belongs to, and does not see the content of your visit.

Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in delivering the website, keeping it secure and knowing which pages people read. To object to the counting of visits (Art. 21 GDPR), write to us.

When you write to us

The site lists our addresses, for example research@openplate.de for questions about research. When you write to one of them, your message reaches our mailbox at Google Workspace, a service of Google. Google may process the data in the USA. For such transfers, we rely on the adequacy decision of the European Commission for the EU-US Data Privacy Framework, where the recipient is certified under it, and otherwise on the standard contractual clauses of the European Commission. Nothing deletes messages in this mailbox automatically today.

Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in answering you, or Art. 6(1)(b) GDPR when you write about a contract.

Your rights

Under the GDPR, you have the right to access your data, to have it corrected or deleted, to restrict its processing, to receive a copy in a machine-readable format, and to object to processing based on our legitimate interest. Write to info@openplate.de.

You also have the right to complain to a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information). You can also complain to the authority in the EU member state where you live or work.