01
Website delivery and technical security
This statically generated website is delivered through Cloudflare Workers and static assets. Cloudflare processes technical connection data, including the IP address, access time, requested page, and browser or device information, to deliver the site and defend it against attacks. Cloudflare also provides the D1 database, queues, and the rate-limiting infrastructure used by the newsletter service.
This website uses no analytics, advertising, cross-site advertising, or social-media trackers. It stores only an explicit light or dark display choice in the browser.
For public write requests, the application derives a peppered cryptographic digest from the request IP address. The application does not store the raw IP address. The rate limiter sees only that digest and a window counter, and its state is deleted after the rate-limit window ends.
The basis for secure and stable website delivery and abuse prevention is the controller’s legitimate interest under Article 6(1)(f) GDPR.
03
Cloudflare and Brevo
Cloudflare D1 stores the newsletter subscription and consent record. Cloudflare Queues transfers messages for delivery. Brevo receives the recipient address and message content to deliver confirmation, subscription-status, newsletter, and unsubscribe-related messages, and returns technical delivery events such as delivery, deferral, bounce, block, complaint, or unsubscribe. No Brevo contact list is used as the subscription record.
Brevo open and click tracking is enabled, and Brevo may record those interactions in its own systems. schlieber.net does not import open or click events. Messages include HTML and plain-text versions. The HTML prepared by schlieber.net loads no remote content; Brevo may route links through its tracking domains.
Cloudflare may process data in the United States on the basis described in its privacy information, including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Brevo’s email processing for this service takes place within the EU. Data-processing agreements are in place with both providers.
04
Retention, unsubscribe, and suppression
A confirmation link expires after 48 hours. If a pending request is not confirmed, the raw email address is erased by the reconciliation process no later than 30 days after the request.
A confirmed address is used while consent remains active. Every newsletter contains an unsubscribe link. Unsubscribing takes effect immediately for future messages; queued newsletter mail is suppressed. The raw recipient address and stored newsletter message bodies are erased. A peppered email pseudonym, consent and withdrawal timestamps, and the minimal suppression state remain only to honour and evidence the withdrawal and prevent another delivery.
A hard bounce, complaint, block, or invalid-address event suppresses the recipient. In that case the raw address is erased from the subscriber and newsletter outbox records; a peppered pseudonym and the suppression reason remain so another send can be prevented.
The service does not use newsletter data for automated decision-making or profiling.
05
Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection under Articles 15–21 GDPR. You may withdraw consent at any time under Article 7(3) GDPR without affecting the lawfulness of processing before withdrawal.
An informal email to the controller is sufficient to exercise these rights. If you believe the processing of your data infringes data-protection law, you may lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.
06
Review and changes
This notice is updated when the newsletter architecture, providers, retention rules, or legal requirements change. The effective date above identifies the current notice.