PRIVACY POLICY
This privacy policy applies to all websites and online services of the sole proprietor Armin Kunkel, in particular to the following domains:
- https://www.dev-journey.de
- https://www.avensio.de
- https://books.avensio.de
The services offered include in particular:
- information and blog offerings
- software products and developer tools
- digital content (e.g. eBooks, audiobooks)
- subscription-based online services
If deviating or supplementary privacy information is provided on individual websites, that information takes precedence over the general provisions of this privacy policy.
Personal data (hereinafter “data”) is processed by us only to the extent necessary to provide a functional and user-friendly website and the content and services offered there.
This website uses TLS encryption for security reasons to protect the transmission of confidential content.
With the following privacy policy, we inform you in particular about the type, scope, purpose, duration and legal bases of the processing of personal data, insofar as we alone or jointly with others determine the purposes and means of processing.
Our privacy policy is structured as follows:
I. Information about us as controller
II. Rights of users and data subjects
III. Information on data processing
I. Information about us as controller
The controller within the meaning of data protection laws is:
Armin Kunkel
Ludwigshafener Str. 17
76187 Karlsruhe
Germany
Phone: +49 (0) 176 7698 3011
Website: https://www.dev-journey.de
Email: datenschutz@dev-journey.de
II. Rights of users and data subjects
With regard to the data processing described in more detail below, users and data subjects have the right
- to obtain confirmation as to whether data concerning them is being processed, to obtain access to the processed data, further information about the data processing and copies of the data (Art. 15 GDPR);
- to obtain rectification or completion of inaccurate or incomplete data (Art. 16 GDPR);
- to obtain immediate erasure of data concerning them (Art. 17 GDPR) or – where further processing is required pursuant to Art. 17(3) GDPR – restriction of processing in accordance with Art. 18 GDPR;
- to receive the data concerning them and provided by them and to transmit this data to other controllers (Art. 20 GDPR);
- to lodge a complaint with a supervisory authority if they believe that the processing of personal data concerning them infringes data protection provisions (Art. 77 GDPR).
III. Information on data processing
Data processed when using our website will be deleted as soon as the purpose of storage ceases to apply and no statutory retention obligations prevent deletion, unless different information is provided below for individual processing operations.
Server logs
For technical reasons, in particular to ensure a secure and stable website and to defend against automated attacks, access logs are stored by our webspace provider (Manitu) in so-called server log files.
These log entries typically contain the date and time of access, the requested URL, the HTTP status, the referrer and information about the browser used. The IP address is stored in fully anonymized form.
Further information on data processing by our hosting provider can be found at: Privacy at Manitu.
This data is stored for security reasons, for example to investigate misuse or fraudulent acts. The log data is stored for approximately 30 days with anonymized IP addresses and then deleted, unless further storage is required.
Cookies
We use cookies on our website. Cookies are small text files that are placed and stored on your device by the internet browser you use. They are used to store certain information, for example your language preference or settings.
We currently use the following technically required cookies:
- i18n_redirected: stores the language selected by you so that the website is displayed in the desired language version on subsequent visits.
- PHPSESSID: technically required session cookie for providing a server session, in particular for CSRF protection functions and secure form and order processes.
i18n_redirected is used exclusively to technically store your selected language preference in the browser. PHPSESSID is used to provide secure session and form functions in the ordering and contact process.
The legal basis for processing in connection with PHPSESSID is Art. 6(1)(b) GDPR, insofar as the session is required for contract initiation or contract performance. Otherwise, processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in the technically error-free and secure provision of our website.
Storage duration: PHPSESSID is a session cookie in a double sense: it serves the server-side session and expires at the end of the session, usually when the browser is closed. i18n_redirected remains stored until you delete the cookie or until the validity period stored by the browser (1 year) expires.
Contact requests / contact option
If you contact us via contact form or email, the data you provide will be used to process your request. Providing the data is necessary to process and answer your request – without providing it, we cannot answer your request, or can do so only to a limited extent.
The legal basis for this processing is Art. 6(1)(b) GDPR, insofar as your request is aimed at concluding a contract or is related to an existing contractual relationship. Otherwise, processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in processing your request.
Your data will be deleted as soon as your request has been finally processed and no statutory retention obligations prevent deletion, for example in the event of subsequent contract processing.
Rate limiting
To protect our website against misuse and attacks (e.g. automated requests or brute-force attacks), we use rate-limiting procedures. In doing so, request-related identifiers are technically recorded in order to limit the number of requests within certain time windows.
Depending on the function, different identifiers are used for this purpose. The identifiers are stored exclusively in hashed form, so that no direct tracing back to the original values is possible.
Processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the security, integrity and functionality of our website as well as protecting against misuse of our services.
The data stored as part of rate limiting is stored only for the duration of the respective rate-limiting time window (maximum one hour) and then automatically deleted, unless security-relevant incidents require longer retention.
Newsletter
If you subscribe to our free newsletter, we store your email address and the language selected by you. In addition, we record the date of registration and confirmation as part of the double opt-in procedure as well as the IP addresses used in that process in order to document and prove your consent. We also process technical confirmation, unsubscribe and language-change tokens so that newsletter registration can be confirmed, the newsletter can be unsubscribed from and the newsletter language can be changed. Confirmation, unsubscribe and language-change links each contain the associated token as a URL parameter. This data is stored to prove consent pursuant to Art. 7 GDPR.
Registration, confirmation and administration of the newsletter are carried out via our own backend. The actual sending of emails is carried out via the mail infrastructure provided by our hosting provider. Data is not passed on to third parties for their own purposes.
The legal basis for processing is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future. To do so, you can use the unsubscribe link contained in every newsletter or contact us at datenschutz@dev-journey.de.
Your data will be deleted after unsubscribing from the newsletter, unless statutory retention obligations prevent deletion. The data stored to prove consent may also be retained until the expiry of statutory limitation periods. The tokens used in the context of newsletter administration remain stored for as long as they are required for confirmation, unsubscribe, language change, proof of consent or administration of the subscription status.
Product-specific data processing
In addition to the general use of our website, we offer specific online services and products. Depending on the use of these offerings, additional personal data may be processed. The following sections describe data processing in connection with our online shop as well as with developer products and software licenses.
Online shop (digital content)
If you purchase digital content (usage licenses; e.g. eBooks, audiobooks) or software licenses (e.g. software modules) via our website, we process the data transmitted by you for the performance and processing of the contract. Without this data, conclusion of the contract and provision of the digital content is not possible. The data may be transmitted both by consumers and by entrepreneurs in the context of contract conclusions.
The legal basis for processing is Art. 6(1)(b) GDPR (contract performance).
We delete the data collected in the context of contract processing after the contract has been fully processed, insofar as no statutory retention obligations prevent deletion. Tax and commercial-law retention periods remain unaffected.
Payment provider
To process payments, we use the external payment provider Stripe. Payment data is entered directly with the payment provider. As a rule, we receive only confirmation that the payment has been successfully completed as well as billing-relevant information. Depending on the checkout and payment process, customer, contact, invoice and location data may also be processed insofar as this is necessary for payment processing, invoicing and tax classification.
Payment provider:
- Stripe Payments Europe Ltd., Ireland
Stripe Privacy Policy
The transfer of the data required for payment processing is carried out on the basis of Art. 6(1)(b) GDPR (contract processing). Insofar as tax-relevant location data or abuse indicators are processed, this is additionally carried out on the basis of Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. Further information on data processing by Stripe can be found in the provider’s privacy policy.
Provision of digital content and usage licenses
After successful payment, we provide you with the purchased digital content or usage licenses (e.g. eBooks, audiobooks or software modules) for download or use.
For this purpose, we process the data required for provision, in particular order information, license identifiers and technical access or download tokens. This data is used exclusively for providing the purchased content, preventing misuse (e.g. protection against unauthorized downloads) and ensuring the technical functionality of our services.
Technical identifiers or tokens may be used to secure the download and access functions. These are processed exclusively to the technically necessary extent and are partly stored in hashed form.
The legal basis for this processing is Art. 6(1)(b) GDPR (contract performance).
The data is deleted as soon as it is no longer required for providing the digital content and for statutory retention periods.
Geolocation (GeoIP) for determining tax-relevant location data
For the correct tax treatment of digital services, we process the IP address or geolocation information derived from it (e.g. country or federal state) during payment processes. This data is used to determine tax-relevant location data and to plausibilize location information. The IP address is not stored permanently, but is used exclusively to derive location information.
Processed data
- IP address or geolocation information derived from it
- country and, where applicable, region/federal state
- technical metadata for traceability (e.g. time, evidence source)
Purpose of processing
- determination of tax-relevant location data (e.g. VAT or sales tax)
- documentation of tax evidence for audits
- prevention of misuse in digital delivery
Legal basis
- Art. 6(1)(c) GDPR (fulfilment of tax-law obligations)
- Art. 6(1)(f) GDPR (legitimate interest in correct taxation and prevention of misuse)
Data source
To determine geolocation data, we use GeoLite2 data from MaxMind Inc. The data is processed locally. The IP address is not transmitted to MaxMind.
Depending on the payment method, additional location information may also come from payment data or from information provided by the user. We do not make tax location decisions solely on the basis of IP-based geolocation, but – where available – take several pieces of evidence into account to plausibilize location data.
Storage duration
Location and evidence data is stored only for as long as this is necessary for tax documentation purposes and statutory retention periods.
Objection
Insofar as processing is based on Art. 6(1)(f) GDPR, you may object to the processing on grounds relating to your particular situation. Correct tax treatment may, however, remain necessary.
Product reviews
On our website, it is possible to review digital content or software products. Reviews can in particular be submitted after a purchase via review links provided.
The following data is processed:
- review (star rating)
- optionally entered pseudonym
- optionally entered review text
- product reference
- time of the review
- technical identifier for verifying eligibility to review (order reference and review token)
Processing is carried out for the purpose of displaying user reviews for products and improving transparency for other users.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in displaying authentic product reviews and improving our offering.
Published reviews may be displayed on the website and presented in aggregated form (e.g. average star rating). Reviews may also be provided in structured form (e.g. JSON-LD) in order to enable search engines to display review information.
Reviews are stored for as long as they are relevant for displaying the product or until the reviewer requests deletion, unless statutory retention obligations prevent deletion.
Developer products (Nuxt module)
We offer software products and developer tools, in particular software modules for web development projects (e.g. a Nuxt module). The purchase is made via our online shop and an external payment provider.
In the context of purchasing and using these developer products, the following data may be processed:
- invoice and customer data (e.g. name, company name, billing address)
- email address
- where applicable, VAT identification number (VAT ID) for business customers
- license information (e.g. license key)
- access data to the private npm registry, insofar as this is required for authentication of package access
- technical metadata for license validation (e.g. timestamps and technical verification features)
Processing is carried out for the purpose of contract processing, license administration and provision and updating of the purchased software products.
A technical license check may be carried out for the use of the software. This checks whether a valid license exists for the respective product. This check is carried out against our own infrastructure in Germany. It serves exclusively to ensure proper use of the software license, authentication for package access and prevention of unauthorized use.
The legal basis for processing is Art. 6(1)(b) GDPR (contract performance). Insofar as data is processed for the prevention of misuse or for securing our software products, this is carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
The data is stored only for as long as this is required for contract processing, license administration and compliance with statutory retention obligations. Access data to the private npm registry and the possibility of using license-based software components generally exist only during an active license term.
Affiliate links
We use so-called affiliate links on our website. These are links to offers from third-party providers. If you follow such a link and subsequently carry out a transaction with the respective provider, we may receive a commission. This does not result in any additional costs for you.
On our website itself, no cookies are set in connection with affiliate links. Only when you follow an affiliate link may the respective provider use its own cookies or similar technologies to allocate commissions.
No own additional processing of personal data takes place on our website in this connection. Only after clicking an affiliate link do the privacy notices of the respective third-party provider apply.
Search function
This website offers a search function that can be used to search blog posts.
The search functions operate entirely locally in the visitor’s browser. This means:
- The search index is stored and processed exclusively on your device.
- No search queries or results are transmitted to our server or to third parties.
Links to social networks
Our website contains links to profiles on social networks. These links are implemented as normal links or graphics. When merely accessing our website, no data is transmitted to the respective providers via these links.
Only when you click such a link are you redirected to the respective platform. From that point onward, any processing of personal data is carried out by the respective provider under its own responsibility.
Please note the privacy notices of the respective providers when you visit their platforms.
