01
Website delivery and technical security
This statically generated website is delivered through Cloudflare Workers and static assets. Cloudflare processes technical connection data, including the IP address, access time, requested page, and browser or device information, to deliver the site and defend it against attacks. Cloudflare also provides the D1 database, queues, and the rate-limiting infrastructure used by the newsletter service.
The published sites use no analytics, advertising, cross-site advertising, or social-media trackers. They store only an explicit light or dark display choice in the browser.
For public write requests, the application derives a peppered cryptographic digest from the request IP address. The application does not store the raw IP address. The rate limiter sees only that digest and a window counter, and its state is deleted after the rate-limit window ends.
The basis for secure and stable website delivery and abuse prevention is the controller’s legitimate interest under Article 6(1)(f) GDPR.
03
Source of truth, queues, and email transport
Cloudflare D1 is the sole subscriber and consent source of truth. Cloudflare Queues carries durable work instructions to a separate jobs Worker. D1 stores the message body with an action-link placeholder, not a raw action token. The jobs Worker derives the link only immediately before transmission and then passes the completed message to Brevo for delivery.
Brevo is used only as transient email transport. Brevo receives the recipient address and message content and returns technical delivery events such as delivery, deferral, bounce, block, complaint, or unsubscribe. No contact list is synchronized to Brevo. Brevo open and click tracking is enabled, and Brevo may record those interactions in its own systems. This service does not ingest open or click events. Double-opt-in mail is sent as a branded HTML message with a complete plain-text alternative. The authored HTML loads no remote resources, and the confirmation capability remains in the URL fragment. The provider-held-body check rejects every resource-bearing or active-content element and permits only one-for-one link routing through the small, separately approved list of exact Brevo tracking origins plus a fixed inert compatibility-comment profile. This check concerns the body returned by Brevo; it is not proof of raw delivered MIME or that a delivered message contains no open-tracking resource. Public signup on schlieber.net and dev.schlieber.net sends only the double-opt-in and lifecycle messages described here. Newsletter campaign delivery remains separately release-gated.
Cloudflare may process data in the United States on the basis described in its privacy information, including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Brevo’s email processing for this service takes place within the EU. Data-processing agreements are in place with both providers.
04
Retention, unsubscribe, and suppression
A confirmation link expires after 48 hours. If a pending request is not confirmed, the raw email address is erased by the reconciliation process no later than 30 days after the request.
A confirmed address is used while consent remains active. Every newsletter contains an unsubscribe link. Unsubscribing takes effect immediately for future messages; queued newsletter mail is suppressed. The raw recipient address and stored newsletter message bodies are erased. A peppered email pseudonym, consent and withdrawal timestamps, and the minimal suppression state remain only to honour and evidence the withdrawal and prevent another delivery.
A hard bounce, complaint, block, or invalid-address event suppresses the recipient. In that case the raw address is erased from the subscriber and newsletter outbox records; a peppered pseudonym and the suppression reason remain so another send can be prevented.
The service does not use newsletter data for automated decision-making or profiling.
05
Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection under Articles 15–21 GDPR. You may withdraw consent at any time under Article 7(3) GDPR without affecting the lawfulness of processing before withdrawal.
An informal email to the controller is sufficient to exercise these rights. If you believe the processing of your data infringes data-protection law, you may lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.
06
Review and changes
This notice is reviewed whenever the newsletter architecture, providers, retention rules, published domains, or legal requirements change. Any content change requires a new bilingual version and immutable snapshot.