Privacy Policy

How your data is handled.

This privacy policy explains the nature, scope and purpose of the processing of personal data on this website in accordance with the EU General Data Protection Regulation (GDPR). This is a personal, non-commercial website: data is processed only where technically necessary, and never sold, rented or used for advertising.

Last updated August 2026

1. Controller

Name
David Blomeyer
Address
Address to be inserted

The controller within the meaning of Art. 4 (7) GDPR is the person named above. Due to the private nature and limited scope of this website, no data protection officer is required or appointed.

2. General principles

Personal data is any information relating to an identified or identifiable natural person. This website is designed to be data-minimal: no user accounts, no newsletters, no advertising networks, no profiling and no automated decision-making within the meaning of Art. 22 GDPR take place.

3. Hosting and server log files

This website is hosted by an external service provider. When you access the site, your browser automatically transmits technical information which the hosting provider stores in server log files:

  • IP address of the requesting device (shortened or stored briefly by the host)
  • Date and time of the request
  • Requested page or file, and amount of data transferred
  • Browser type, browser version and operating system
  • Referrer URL, i.e. the previously visited page

This data is required to deliver the website, to guarantee stability and security, and to defend against attacks. The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in the secure and reliable operation of the website. Log data is stored only for as long as necessary for these purposes and is deleted or anonymised thereafter. The data is not merged with other data sources and is not used to identify individual visitors.

Where the hosting provider acts on behalf of the controller, a data processing agreement pursuant to Art. 28 GDPR is in place.

4. Cookies and local storage

This website sets no tracking, marketing or analytics cookies. No consent banner is therefore required. Purely technical storage may be used in the browser to make interactive elements work - for example, the interactive self-assessment in the "Beyond Work" section saves your inputs in your browser's local storage so your results are still there when you return.

This information never leaves your device and is not transmitted to the controller or to any third party. You can delete it at any time via your browser settings. The legal basis for this strictly necessary storage is Section 25 (2) TDDDG in conjunction with Art. 6 (1) (f) GDPR.

5. Analytics and tracking

No web analytics, tracking pixels, heat maps, A/B testing tools, advertising networks or social media tracking plug-ins are used on this website. Your visit is not profiled.

6. Contact form and email contact

The contact form on this website does not store any data on a server. When you submit it, the information you entered is passed to your own email programme, which opens with a pre-filled message that you send yourself. No data is transmitted to the controller until you actively send that email.

If you contact the controller by email or via this route, the data you provide (name, email address, message content) is processed solely for the purpose of handling your enquiry and any follow-up questions. The legal basis is Art. 6 (1) (b) GDPR where the enquiry relates to pre-contractual or contractual matters, and otherwise Art. 6 (1) (f) GDPR based on the legitimate interest in responding to enquiries addressed to the controller.

Enquiries are deleted once they have been dealt with conclusively and no statutory retention obligations prevent deletion. Email transmission over the internet can have security gaps; complete protection against access by third parties cannot be guaranteed.

7. External links and embedded services

This website links to external platforms such as LinkedIn, ResearchGate and Spotify. These links are plain hyperlinks - no content is embedded and no data is transmitted to those providers while you browse this site. Data processing only begins once you click a link and leave this website, at which point the privacy policy of the respective provider applies.

Some of these providers are based outside the European Economic Area. Where personal data is transferred to third countries after you follow such a link, this takes place under the responsibility of the respective provider.

8. Documents and downloads

Academic documents made available for download (for example the research paper provided in the Research section) are served directly from this website. Accessing them generates only the server log data described in section 3.

9. Recipients of data

Personal data is not passed on to third parties, except to the hosting provider acting as a processor, or where disclosure is legally required or necessary to establish, exercise or defend legal claims. Data is never sold or made available for advertising purposes.

10. Storage duration

Personal data is stored only for as long as is necessary for the respective purpose, or as long as statutory retention periods require. Once the purpose ceases to apply, the data is deleted or anonymised.

11. Your rights

Under the GDPR you have the following rights at any time, free of charge:

  • Right of access to the personal data held about you (Art. 15 GDPR)
  • Right to rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability in a structured, machine-readable format (Art. 20 GDPR)
  • Right to object to processing based on legitimate interests (Art. 21 GDPR)
  • Right to withdraw consent at any time with effect for the future (Art. 7 (3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

To exercise these rights, simply write to david.blomeyer02@gmail.com. You may also lodge a complaint with the data protection supervisory authority of your usual place of residence, place of work or the place of the alleged infringement.

12. Right to object

Where data is processed on the basis of legitimate interests pursuant to Art. 6 (1) (f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation. In that case the data will no longer be processed unless compelling legitimate grounds for the processing can be demonstrated which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

13. Data security

This website uses TLS/SSL encryption (HTTPS) to protect the transmission of content between your browser and the server. You can recognise an encrypted connection by the "https://" prefix in the address bar of your browser. Appropriate technical and organisational measures pursuant to Art. 32 GDPR are in place to protect data against loss, manipulation and unauthorised access.

14. Changes to this policy

This privacy policy is adapted whenever changes to the website or to legal requirements make it necessary. The version published here at the time of your visit applies. Legal information about the provider can be found in the Imprint.