01Who is responsible?
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR, German: Datenschutz-Grundverordnung, DSGVO) is:
Tassilo Wolfin
Liebermannstraße 10
39108 Magdeburg
Email: kontakt@bnkz.de
You can also find all details in the legal notice (Impressum). No data protection officer has been appointed, because the legal requirements for one are not met.
02What happens to your files?
All tools run entirely in your browser. Files that you choose or drag in, and everything you type into the tools (text, password settings, Wi-Fi details, contact details for QR codes, numbers in the calculators), are processed only in the memory of this tab and are transmitted neither to me nor to third parties. When you close the tab, everything is gone.
This is not just a promise: The site sends a Content Security Policy with connect-src 'none'. With it, your browser does not allow the code of this site to make any connection via fetch, XMLHttpRequest, WebSocket, EventSource or sendBeacon, even to my own server. The site may load images and files only from this domain, and nothing at all from other servers. That is why the site cannot send anything to other servers by these routes. What such a policy by its nature does not cover, for example links that you follow yourself, is explained on the technical details page (German). To reach my own server, the code uses exactly one other route, an image request: the anonymous counting signal from section 04. It transmits only which page is open and for how long, never files and never what you enter. In addition, there is the “Suggest a tool” form (section 05), if you send it yourself. Since your files and what you enter do not leave your device, I do not process any personal data in this respect.
03Hosting & server logs
The site is hosted on a web server of checkdomain GmbH, Große Burgstraße 27/29, 23552 Lübeck, in Germany. checkdomain acts as a processor on my behalf (Art. 28 GDPR). When you open a page, the server processes technically necessary data in order to deliver the page: IP address, date and time, requested address, amount of data transferred, browser type and operating system, and the previously visited page, if your browser sends it.
The legal basis is my legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). In normal operation I do not analyze these logs and do not combine them with other data. They serve to estimate the use of server resources and to protect the site: If the site is attacked or misused, I look at the logs and pass the necessary details on to the competent authorities, for example the police or the German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI). How long the logs are kept depends on the rules of the hosting provider. Details are in the privacy policy of checkdomain (German).
04Cookies & anonymous statistics
Cookies. Visitors do not get any cookies from this site, and I do not embed any analytics, advertising or social media services from third parties. Fonts, icons and scripts come exclusively from this domain. Cookies exist only in the internal, password-protected operator area (for signing in, and so that the operator's own visits are not counted). Normal visitors never come into contact with them. Anyone who enters a wrong password there is counted for 15 minutes via an encrypted short code of their IP address, so that nobody can try out passwords one after another.
Local storage. That stays empty too. The site does not store anything in localStorage or sessionStorage and does not read anything from there. There is no setting that would need to be remembered.
Anonymous statistics. I only record visits and where they come from, and I do so for three reasons: to see whether the site is well received and which tools are needed, to estimate the use of server resources, and for security reasons, to notice attacks. For this I do the counting myself, without an outside service. When you open a page, your browser tells my server: which page, which other website you came from (only its name), the width of the window, and about every 15 seconds that the page is still open. From this, the server adds device, browser, operating system and language in broad categories and determines the country from your IP address. The IP address itself is not stored in the process. Nothing is stored on your device for this, and nothing is read from its storage. Apart from that, the script only looks at your browser setting “Do Not Track”.
Only totals per day are kept long-term, for example “12 visitors from Austria” or “Merge PDF: 40 views”. So that a visitor is not counted twice on the same day, the server forms a short code from the IP address, the browser identifier and a random value that is new every day. For this short code it remembers, for the current day, the country, the page opened last, the time of the last request and the number of requests, in order to calculate “online right now” and the time spent on the site. The IP address is not contained in the short code in plain text and cannot be read from it. The short code and the random value are deleted as soon as the first page request arrives on a following day. From that point at the latest, the data can no longer be traced back to you. Recognizing you across several days is therefore not possible. Files, what you enter, search terms and results of the tools are never reported.
The legal basis is my legitimate interest in improving the site (Art. 6(1)(f) GDPR). You do not want to be counted? Turn on “Do Not Track” or “Global Privacy Control” in your browser. Then the site sends nothing at all. The country detection uses the database IP Geolocation by DB-IP, which is stored on my server. No request is made to DB-IP.
05“Suggest a tool” form & email
The “Suggest a tool” form is the only place where this site transmits content, and only when you press “Send suggestion”. What is sent: your suggestion and, if you provide them, your name and your email address. All details except the suggestion itself are optional. The server turns this into an email to the operator. In addition, it stores your suggestion and the field “What do you need it for?”, together with the date, in a list of suggestions, without name, without email address and without IP address. The list is on the same server, cannot be accessed from outside and can only be seen in the password-protected operator area. It helps me collect suggestions and work through them. It holds at most the last 500 suggestions. Entries older than 12 months are deleted as soon as a new suggestion arrives or the operator opens or backs up the list. So please do not write any personal details into the fields for the suggestion. The mailbox, like the website, is with my hosting provider checkdomain in Germany. To prevent misuse, the server only counts how many suggestions arrive per hour, without recording IP addresses or content.
The legal basis is my legitimate interest in answering requests and improving the site (Art. 6(1)(f) GDPR). I use the details only for that and delete the email as soon as your request has been dealt with, after twelve months at the latest. I delete the entry in the list of suggestions after twelve months, when the next suggestion arrives or the next time the list is opened. The same applies if you write me an email directly.
06Recipients & storage periods
Apart from me, only the hosting provider checkdomain receives your data, as a technical service provider. I do not sell anything, do not pass anything on for advertising purposes and do not transfer any data to countries outside the EU. Data is passed on to authorities (for example the police or the BSI) only in the case of attacks or misuse (see section 03) or if I am legally obliged to do so. There is no automated decision-making and no profiling.
At a glance: server logs for the periods set by the hosting provider; daily short codes of the statistics until the first request on a following day; the anonymous daily totals of the statistics for 400 days (they no longer relate to a person); emails about suggestions until they have been dealt with, twelve months at the longest; the list of suggestions without name and email for twelve months (deleted when the next suggestion arrives or the list is opened) and at most 500 entries.
Voluntary support. The button “Buy me a coffee” is an ordinary link to the payment service Revolut. This site does not transmit anything when you see it. Only when you click the link does your browser open the Revolut page; the Revolut privacy notice applies there. If you pay something there, Revolut tells me your name, the amount and a message, if you write one.
07Your rights
Under the GDPR you have the right of access (Art. 15), the right to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20). An informal email to kontakt@bnkz.de is enough. Since I store hardly any personal data, there is usually nothing to hand over. Feel free to write to me anyway.
You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example where you live. The authority responsible for me is the State Commissioner for Data Protection of Saxony-Anhalt (Landesbeauftragter für den Datenschutz Sachsen-Anhalt), Otto-von-Guericke-Straße 34a, 39104 Magdeburg.
08Security & other matters
The site is delivered exclusively in encrypted form over HTTPS. You are not obliged by law or by contract to provide me with data. However, without the technically necessary connection data the site cannot be loaded. If the site or the legal situation changes, I will update this policy. The version published here at any given time applies.