Privacy Policy
Last updated: September 23, 2026
1. The short version
This website is a small static site. It sets no cookies, uses no local storage, loads nothing from third parties and runs no analytics, tracking or advertising. The only personal data processed is what every web server needs to deliver a page, and the IP address in it is shortened before anything is written to disk.
2. Controller
ByteSide.io · Stefan Roßkopf Anemonenweg 789547 Gerstetten
Germany
hello [at] byteside.io
The controller is the natural person who decides on the purposes and means of processing personal data (Art. 4 No. 7 GDPR).
3. Hosting
This website runs on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place, so Hetzner processes data only on my instructions. Details: hetzner.com/legal/privacy-policy. Legal basis: Art. 6(1)(f) GDPR, my legitimate interest in delivering this website reliably.
4. Server log files
When you open this website, the server automatically records:
- the requested page and the time of the request
- the HTTP status code and the amount of data transferred
- the referrer URL
- browser type and version, and operating system (user agent)
- your IP address, shortened (see below)
IP addresses are shortened, and thereby anonymized, before the log entry is written: the last octet of an IPv4 address is removed, IPv6 addresses are cut to the /48 prefix. Cookie, authorization and language headers are not logged. Log files are deleted after 14 days at the latest, are not merged with other data and are used only to keep the website running and secure, including an aggregated, anonymous visitor count. Legal basis: Art. 6(1)(f) GDPR.
5. No cookies, no tracking
This website sets no cookies and writes nothing to your browser's local storage. There are no analytics, tracking or marketing tools, no social media plugins and no embedded third-party content. Fonts (Inter and JetBrains Mono) are served from this server, so no connection to Google Fonts or any other CDN is made.
Two small scripts run in your browser: one assembles the e-mail address on the legal pages (to keep it away from spam harvesters), the other uses your device's date to decide how many windows of the skyline on the start page are lit. Neither sends any data anywhere.
6. Contacting me
If you write to me by e-mail, I process your message and the data it contains (for example your name and address) to answer it. Incoming mail for hello@byteside.io is received and stored with Microsoft 365 (Exchange Online), provided by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Data may be processed in third countries, in particular the USA. The transfer is based on the European Commission's Standard Contractual Clauses, and Microsoft Corporation is certified under the EU-US Data Privacy Framework. Details: privacy.microsoft.com. Legal basis: Art. 6(1)(f) GDPR, and Art. 6(1)(b) GDPR where your message concerns a contract. Your message is deleted once it has been dealt with, unless statutory retention periods apply.
If you contact me via WhatsApp, the service is provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Messages are end-to-end encrypted, but WhatsApp has access to metadata such as sender, recipient and time, and states that it shares data with its US parent company Meta. Details: whatsapp.com/legal. Legal basis: Art. 6(1)(f) GDPR, my interest in fast and simple communication. Using WhatsApp is optional; you can always use e-mail instead.
7. Links to other websites
This page links to sevengrid.app, the website of my app SevenGrid, which is run by the same controller and has its own privacy policy, and to the SevenGrid listing on Google Play, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. No data is sent to these sites until you click a link. After that, the privacy policy of the site you visit applies, for Google Play: policies.google.com/privacy.
8. Encryption
This website is served exclusively over HTTPS (TLS), so data between your browser and the server cannot be read by third parties.
9. Your rights
Within the limits of the GDPR you have the right to:
- access the personal data I hold about you (Art. 15)
- have it rectified (Art. 16) or erased (Art. 17)
- restrict its processing (Art. 18)
- receive it in a portable format (Art. 20)
- withdraw any consent you gave, with effect for the future (Art. 7(3))
- lodge a complaint with a supervisory authority (Art. 77), for example the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW), Lautenschlagerstraße 20, 70173 Stuttgart
Right to object (Art. 21 GDPR): where processing is based on Art. 6(1)(f) GDPR, you may object to it at any time on grounds relating to your particular situation. I will then stop processing your data unless there are compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
To exercise any of these rights, an e-mail to the address above is enough. No automated decision-making or profiling takes place on this website.