Privacy Policy

Privacy Policy

Last updated: 29 August 2026

This policy explains what this website does with personal data. It describes the site as it is actually configured — the log fields, retention periods and the one cookie below were read off the running server, not copied from a template.

Who is responsible

[YOUR LEGAL NAME] [Street address] [Postcode, City], [Country] Email: [contact address]

What is collected

Server access logs

Every request to this site is written to a log on the server. Each entry contains:

Field Example
IP address 2a02:2479:55:5400::1
Date and time 29/Aug/2026:19:58:25 +0200
Method, host and path GET https www.sysadminheaven.com "/blog"
HTTP status and bytes sent 200, 15546
User agent Mozilla/5.0 …
Referrer, where the browser sends one -

An IP address is personal data under the GDPR, so this section applies even though nothing here is tied to a name or an account.

  • Purpose: operating the site, diagnosing faults, and detecting abuse. Automated scanners probe this server continuously; the logs are how that is spotted.
  • Legal basis: legitimate interests, Art. 6(1)(f) GDPR — running a website securely, which cannot be done without knowing who is connecting to it.
  • Retention: access logs rotate weekly and four are kept, so an entry is deleted after roughly five weeks. Error logs are kept for roughly ten weeks. Nothing is archived beyond that.
  • Recipients: nobody. Logs stay on the server and are not sold, shared or sent to any analytics service.

Cookies

This site sets one cookie:

Name Purpose Lifetime Flags
grav-site-… Session handling for the CMS that serves this site 30 minutes HttpOnly, SameSite=Lax, Secure over HTTPS

It contains a random session identifier and nothing else. It does not track you, does not follow you to other sites, and is not shared with anyone.

This cookie is strictly necessary for the site to function — the CMS will not serve pages without session support — so under Article 5(3) of the ePrivacy Directive it is exempt from the consent requirement. That is why this site has no cookie banner. It has nothing to ask you about.

What this site does not do

  • No analytics. No Google Analytics, Matomo, Plausible or anything comparable.
  • No advertising, no tracking pixels, no fingerprinting.
  • No social media buttons or embeds.
  • No third-party fonts or scripts. Every asset — including the icon font — is served from this domain, so no third party ever sees your IP address.
  • No accounts, no newsletter, no contact form. There is nothing here to sign up for.
  • No automated decision-making or profiling (Art. 22 GDPR).

Where the data is

The server is a virtual machine hosted by [IONOS SE, Karlsruhe, Germany], inside the EU. No personal data is transferred outside the EEA. The hosting provider acts as a processor and has access to the underlying machine.

All traffic is encrypted with TLS; certificates are issued by Let's Encrypt.

Your rights

Under the GDPR you may request access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20), and you may object to processing based on legitimate interests (Art. 21). To exercise any of these, email the address at the top of this page.

Be aware of a practical limit: log entries are indexed only by IP address. If you ask about your data, the only way to find it is if you tell us the IP address you used and roughly when. Entries older than the retention period above are already gone.

You also have the right to lodge a complaint with a supervisory authority (Art. 77). In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Changes

If this site's behaviour changes — an analytics tool, a comment system, a contact form — this page will be updated before that change goes live.