schlieber

Full site in preparation

DE

Privacy & consent

Newsletter privacy notice.

How schlieber.net handles an email address from newsletter signup through confirmation and unsubscribe.

Effective

01

Website delivery and technical security

This statically generated website is delivered through Cloudflare Workers and static assets. Cloudflare processes technical connection data, including the IP address, access time, requested page, and browser or device information, to deliver the site and defend it against attacks. Cloudflare also provides the D1 database, queues, and the rate-limiting infrastructure used by the newsletter service.

This website uses no analytics, advertising, cross-site advertising, or social-media trackers. It stores only an explicit light or dark display choice in the browser.

For public write requests, the application derives a peppered cryptographic digest from the request IP address. The application does not store the raw IP address. The rate limiter sees only that digest and a window counter, and its state is deleted after the rate-limit window ends.

The basis for secure and stable website delivery and abuse prevention is the controller’s legitimate interest under Article 6(1)(f) GDPR.

02

Newsletter and double opt-in

The newsletter form asks for an email address, language, and an explicit consent checkbox. It returns the same acknowledgement after every valid submission, so the response does not reveal whether an address is already subscribed. When confirmation is still required, the service creates or reuses a pending record and sends or reuses a confirmation message; a recent link remains valid for up to 48 hours. If the address is already confirmed, its consent record stays unchanged and an informational message explains that nothing else is required. Newsletter delivery is enabled only after confirmation.

The D1 record contains the email address, a pseudonymous email digest, language, subscription state, the applicable consent and privacy-notice versions, request and confirmation times, a pseudonymous request digest, token digests, and delivery or suppression state. This information is used to deliver the requested newsletter, prove consent, process withdrawal, and prevent delivery to suppressed addresses.

The basis for newsletter delivery is consent under Article 6(1)(a) GDPR in conjunction with section 174 TKG 2021. Consent can be withdrawn at any time with effect for the future.

03

Cloudflare and Brevo

Cloudflare D1 stores the newsletter subscription and consent record. Cloudflare Queues transfers messages for delivery. Brevo receives the recipient address and message content to deliver confirmation, subscription-status, newsletter, and unsubscribe-related messages, and returns technical delivery events such as delivery, deferral, bounce, block, complaint, or unsubscribe. No Brevo contact list is used as the subscription record.

Brevo open and click tracking is enabled, and Brevo may record those interactions in its own systems. schlieber.net does not import open or click events. Messages include HTML and plain-text versions. The HTML prepared by schlieber.net loads no remote content; Brevo may route links through its tracking domains.

Cloudflare may process data in the United States on the basis described in its privacy information, including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Brevo’s email processing for this service takes place within the EU. Data-processing agreements are in place with both providers.

04

Retention, unsubscribe, and suppression

A confirmation link expires after 48 hours. If a pending request is not confirmed, the raw email address is erased by the reconciliation process no later than 30 days after the request.

A confirmed address is used while consent remains active. Every newsletter contains an unsubscribe link. Unsubscribing takes effect immediately for future messages; queued newsletter mail is suppressed. The raw recipient address and stored newsletter message bodies are erased. A peppered email pseudonym, consent and withdrawal timestamps, and the minimal suppression state remain only to honour and evidence the withdrawal and prevent another delivery.

A hard bounce, complaint, block, or invalid-address event suppresses the recipient. In that case the raw address is erased from the subscriber and newsletter outbox records; a peppered pseudonym and the suppression reason remain so another send can be prevented.

The service does not use newsletter data for automated decision-making or profiling.

05

Your rights

You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection under Articles 15–21 GDPR. You may withdraw consent at any time under Article 7(3) GDPR without affecting the lawfulness of processing before withdrawal.

An informal email to the controller is sufficient to exercise these rights. If you believe the processing of your data infringes data-protection law, you may lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.

06

Review and changes

This notice is updated when the newsletter architecture, providers, retention rules, or legal requirements change. The effective date above identifies the current notice.