Privacy policy
Last updated: 7 October 2026
This page is a translation. The German version is legally binding.
This privacy policy explains which personal data is processed when visiting and using sandsteinlabs.de.
1. Controller
SandsteinLabs
Vinzenz Fuhrmann
Rosa-Menzer-Str. 19
01309 Dresden
Germany\
Email: mail@sandsteinlabs.de
2. Hosting and Server Logs
This website is operated on a server provided by WIIT AG (brand: webtropia), Joachim-Erwin-Platz 3, 40212 Düsseldorf, Germany, in a data center located in Germany. A data processing agreement pursuant to Art. 28 GDPR has been concluded with the provider.
When the website is accessed, the server processes technically necessary connection data. This includes, in particular, the IP address, date and time, requested URL, referrer, browser identifier (user agent), and HTTP status code.
This processing is necessary to deliver the website and to ensure stable and secure operation. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and reliable operation of this website.
Server logs are automatically deleted after no more than 15 days.
Protection Against Attacks Using CrowdSec
To protect against attacks and misuse, access logs are automatically analyzed using the CrowdSec security software.
If security-relevant behavior is detected, the relevant IP address may be temporarily blocked. Local security alerts are stored for no more than 7 days; local IP blocks generally remain in place for 4 hours.
For attacks detected by CrowdSec, information about the security incident may be transmitted to CrowdSec's central infrastructure. This may include, in particular, the IP address of the attacking system, the time and type or scenario of the attack, as well as technical metadata relating to the CrowdSec installation.
The provider is CrowdSec SAS, 20 rue Maurice Arnoux, 92120 Montrouge, France.
According to CrowdSec, CrowdSec and participants in the CrowdSec ecosystem treat the processing of attack data exchanged as part of the IP reputation system as joint processing. The purpose is to detect and defend against attacks on IT systems. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in protecting this website and the systems used to operate it against attacks and misuse.
According to CrowdSec, full attacker IP addresses are stored for no more than three months. Their precision is then gradually reduced.
CrowdSec uses additional service providers to operate its services. As a result, data may also be processed outside the European Economic Area. According to CrowdSec, transfers to countries without an adequate level of data protection are protected in particular by the European Commission's Standard Contractual Clauses.
Further information about processing by CrowdSec and the exercise of data subject rights is available in CrowdSec's own privacy policy.
3. Visiting the Website
This website does not use analytics or tracking services, advertising trackers, or marketing trackers. No externally hosted fonts or other third-party content are automatically embedded in the website.
Fonts, images, and other components directly belonging to the website are delivered through the website's own server infrastructure.
During normal website use, no data is therefore transmitted to external providers for analytics, advertising, or marketing purposes. The technical processing by hosting and security providers described in this Privacy Policy is excluded from this statement.
External websites are only accessed when you actively click a corresponding link.
4. Contact Form
If you use the contact form, your name, email address, and message, as well as the project to which your request relates where applicable, are processed.
The information is not permanently stored in a website database but is forwarded directly by email to the self-hosted mailbox.
Where your request relates to entering into or performing a contract, processing is based on Art. 6(1)(b) GDPR. For other requests, processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in processing and responding to inquiries.
To protect the form against automated misuse, the number of requests is limited. For this purpose, a pseudonymous value is generated from the IP address. This value is processed temporarily in memory only and is discarded after no more than 24 hours.
5. Email Communication
If you contact us by email, your email address, your name where applicable, the content of the message, and technical metadata relating to the message are processed.
The mailbox is operated on the server described in Section 2.
Where the communication concerns entering into or performing a contract, the legal basis is Art. 6(1)(b) GDPR. In all other cases, processing is based on Art. 6(1)(f) GDPR; the legitimate interest lies in processing and responding to communications.
6. Theme and Language Settings
If you manually switch the website between light and dark mode, your selection is stored in your browser's local storage (sl-theme).
If you manually change the language, the PARAGLIDE_LOCALE cookie is stored so that the website can be displayed in your selected language on subsequent visits.
The stored values contain only the selected setting and no unique user identifier. They are not used for analytics, tracking, or advertising purposes and are not transmitted to third parties.
Storage takes place solely as a result of your respective selection. The legal basis for accessing or storing information on your device is Section 25(2) No. 2 TDDDG.
You can delete the stored values at any time using your browser settings.
7. Content Management System
The content of this website is managed using the Directus content management system. Directus is operated on our own server infrastructure.
During normal use of this website, no personal data is transmitted to the provider of Directus as a result.
8. External Links
This website contains links to external services, for example GitHub, LinkedIn, and Instagram.
Simply viewing this website does not establish a connection to these providers. A connection to the respective provider is only established when you open an external link. The respective provider is responsible for the data processing that takes place there.
9. Backups
To ensure the availability and recoverability of the systems, encrypted backups are created and stored in the Object Storage service of Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany, within the European Union.
A data processing agreement pursuant to Art. 28 GDPR has been concluded with Contabo.
The backup data is encrypted on our own server before it is transmitted to Contabo. Contabo does not receive access to the unencrypted contents.
Backups are deleted or replaced by newer backups after no more than 12 months.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in ensuring the availability, integrity, and recoverability of the systems and data being operated.
10. Storage Periods
Unless a different storage period is specified in the individual sections, personal data is stored only for as long as necessary for the respective purpose.
In particular, the following retention periods currently apply:
- Server logs: no more than 15 days
- Local CrowdSec security alerts: no more than 7 days
- Local IP blocks: generally 4 hours
- Full attacker IP addresses transmitted to CrowdSec: according to CrowdSec, no more than 3 months
- Values used to limit misuse of the contact form: no more than 24 hours in memory
- Contact and email inquiries: until final processing has been completed and thereafter only where further storage is necessary due to legal obligations or for the establishment, exercise, or defense of legal claims
- Language setting: for the duration of the cookie or until manually deleted
- Theme setting: until manually deleted in the browser
- Encrypted backups: no more than 12 months
11. Recipients and Data Processors
As part of the processing described above, personal data may in particular be processed by the following recipients or service providers:
- WIIT AG (webtropia), Düsseldorf, Germany: hosting of the server infrastructure
- Contabo GmbH, Munich, Germany: storage of encrypted backups in Object Storage within the EU
- CrowdSec SAS, France, as well as, where applicable, its technical service providers and participants in the CrowdSec ecosystem: processing of security-relevant IP and attack data as part of attack detection and IP reputation services
Personal data is generally not transferred to third countries through our own hosting and backup infrastructure. In the case of CrowdSec, transfers to third countries may occur due to the service providers used by CrowdSec; further information is provided in Section 2.
12. Your Rights
Subject to the applicable legal requirements, you have in particular the following rights:
- Right of access pursuant to Art. 15 GDPR
- Right to rectification pursuant to Art. 16 GDPR
- Right to erasure pursuant to Art. 17 GDPR
- Right to restriction of processing pursuant to Art. 18 GDPR
- Right to data portability pursuant to Art. 20 GDPR
- Right to object to processing based on Art. 6(1)(f) GDPR pursuant to Art. 21 GDPR
To exercise your rights, you can contact us using the contact details provided in Section 1.
You also have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority. The Saxon Commissioner for Data Protection and Transparency is, in particular, the supervisory authority responsible for the data controller.
13. Status and Changes
This Privacy Policy will be updated if the services used, the processing of personal data, or the applicable legal requirements change.
The date of the current version is stated at the beginning of this Privacy Policy.