Privacy policy
Technical status: 11 September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP) and other applicable national data protection laws is:
Patrick Walter
Westerbachstraße 287
65936 Frankfurt am Main
Germany
Email: redaktion@pandorex.info
Pandorex is a project of nemonicon GmbH, c/o Daniel Walter, Zürcherstrasse 49b, 8104 Weiningen ZH, Switzerland (CHE-177.998.004).
2. General information on data processing
We take the protection of your personal data seriously. We process personal data in accordance with the GDPR, the German Federal Data Protection Act (BDSG), the German Telecommunications and Digital Services Data Protection Act (TDDDG) and the Swiss FADP.
This notice explains which personal data we collect, for which purposes and on which legal bases, and the rights you have in relation to that data.
3. Website delivery and hosting
3.1 Hosting provider
This website runs on a server we manage at netcup GmbH. The website and its database run on that server. Since the migration, Vercel no longer hosts the public website.
The server processes connection data required to deliver the website. The database and administration interface are not freely accessible from the internet; public functions use dedicated interfaces.
Provider information: netcup privacy policy.
3.2 Server logs
When you access the website, the server processes technical connection and request data. Depending on what your browser sends, these include:
- The requesting device’s IP address
- Date and time of access
- Name and URL of the requested resource
- Volume of data transferred
- HTTP status code
- Browser type and version
- Operating system
- Referrer URL, identifying the previously visited page
Not all connection data are retained in logs. The current configuration maintains operational and security logs, for example about errors and blocked connections. The upstream web server does not maintain a complete access log of every page view. Processing supports website delivery and security. Legal basis: Article 6(1)(f) GDPR and Article 31(1) FADP.
3.3 Language selection
For URLs without a language prefix, our server compares the IP address supplied by the upstream web server with a locally stored DB-IP country list. Connections recognised as originating in Germany, Austria or Switzerland initially receive German and a language selector. Elsewhere, or where the location is unknown, English is the default. Explicit URLs under /de/ and /en/ determine the language independently of location, making German content directly accessible worldwide. Country detection is approximate; VPNs, for example, can affect it.
No IP address is sent to DB-IP or another geolocation service for this comparison. The language feature stores neither IP addresses nor country histories. The locale cookie contains only de or en, for up to one year. An explicit language URL takes precedence; on an unprefixed URL, a saved German preference does not override the country rule. You can delete the cookie in your browser at any time. We do not use a cookie called user-country.
4. Cookies
4.1 General information
Cookies are small text files stored on your device and read by your browser when you return to our website. We distinguish between technically necessary and optional cookies.
4.2 Necessary cookies
Cookies necessary to operate the website include:
- Sign-in cookies (Auth.js): The software supports cookies for sessions, return addresses and protection of sign-in requests, including authjs.session-token with a security prefix over HTTPS. Google sign-in is enabled. These cookies secure sign-in and maintain your session; they are not used for audience measurement.
- Language cookie (locale): Stores de or en. Lifetime: one year, unless you delete or change it sooner.
- Privacy preferences (pandorex_consent_v1): Klaro stores your selection in a cookie on this website for 180 days. The previous cookie-consent localStorage setting is removed and is not treated as consent to Matomo.
4.3 Optional cookies
When audience measurement is configured and you have consented, Matomo uses first-party cookies on this website’s domain: _pk_id.* stores a randomly generated visitor identifier for 180 days, _pk_ses.* groups activity into a session for 30 minutes, and _pk_ref.* stores a sanitised referrer or campaign for 30 days. Browsers may shorten these periods. A brief cookie test after consent is deleted immediately. If cookies cannot be used, no substitute cookie-free measurement takes place.
4.4 Consent banner
Klaro is served directly by this website. You can select “Necessary only”, “Accept all” or customise your preferences. Matomo loads only after your consent has been saved; an unsaved selection does not activate measurement. You can disable audience measurement at any time using Privacy settings in the footer and saving your choice. This prevents further measurement requests and deletes Matomo cookies. Withdrawal does not retrospectively delete previously transmitted data. If the service is not configured or preferences cannot be loaded, measurement stays off.
5. User accounts and sign-in
5.1 Google and email sign-in
You can sign in with Google. The Google sign-in process starts only when you select that option. Apple and Facebook are not currently enabled. Sign-in through a single-use email link is prepared and offered only when email delivery is configured and enabled.
5.2 Account data
- Name or display name
- Verified email address
- Profile image URL or selected avatar
- Internal user ID and provider identifier required for sign-in
We store only profile data required for the account. We do not receive access to your Google password or your full Google profile. When email sign-in is enabled, a short-lived, single-use link is sent to your address; its hash is stored in the database instead of the complete token.
5.3 Purpose and legal basis
Account data enable sign-in, profiles, comments and ratings. Legal basis: Article 6(1)(b) GDPR, for performance of the requested service; Article 6(1)(a) GDPR where separate consent is given; and Article 31(1) FADP.
5.4 Google’s privacy information
Google processes data required for sign-in as a separate provider. Information on recipients, international processing and your settings is available in Google’s privacy policy. Simply visiting our sign-in page does not start a Google sign-in process.
6. Comments
6.1 Data processed
You must sign in to post comments and replies. The comment feature stores the following on our server:
- Your username
- Your profile image or avatar
- The content of your comment
- Date and time of the comment
- Your user ID, the related article and, for replies, the parent comment
6.2 Purpose and legal basis
Processing provides interactive discussion below articles. Legal basis: Article 6(1)(b) GDPR, performance of the requested service; Article 6(1)(f) GDPR, our legitimate interest in reader interaction; and Article 31(1) FADP.
6.3 Retention
Comments are retained until you or we delete them. You can request deletion of your comments at any time.
7. Ratings and profile activity
Rating articles and comments requires sign-in. We store your selected rating, user ID, article or comment ID and technical timestamps in our own database. You can change or remove your rating. Previous ratings stored only in a browser are not imported as genuine user votes.
Your profile calculates your comment count, number of articles commented on, positive ratings received and replies from other readers using stored comments and ratings. A list of your latest comments helps you find them again. This personal overview is available only to the signed-in account holder. No individual history of articles merely read is created for this purpose.
Processing provides the account and rating features you request. Legal basis: Article 6(1)(b) GDPR and Article 31(1) FADP.
8. Newsletter
8.1 Content and delivery
The weekly Pandorex Briefing contains up to five selected developments, short summaries and links to further reading. Automatic delivery is scheduled for Sundays at 09:00 in the Europe/Berlin time zone and uses the German or English language selected at signup. Delivery is restricted to confirmed addresses and requires a configured email service. Until email delivery is configured, the website offers RSS instead and does not accept newsletter signups.
8.2 Double opt-in
After you consent, we send a confirmation email. Your subscription becomes active only when you open the link and confirm on the confirmation page. The link is valid for 24 hours and can be used only once. Newsletter subscription is independent of a user account and of consent to audience measurement.
8.3 Stored data and retention
- Email address, internal subscription ID and chosen language
- Signup and confirmation timestamps
- Hashes of confirmation and unsubscribe tokens; complete tokens are not stored in the database
- Technical delivery status and the relevant issue, to prevent duplicate delivery and detect errors
Technical delivery records are removed after 90 days by the scheduled cleanup. Unconfirmed signups are deleted after seven days by the enabled mail delivery service’s cleanup. If that service is not running, this automatic cleanup does not run. Newsletters do not contain open-tracking pixels or personalised click redirects.
8.4 Legal basis
Legal basis: Article 6(1)(a) GDPR, consent, and Article 6(1) FADP. You can withdraw consent at any time with effect for the future.
8.5 Unsubscribing
Each issue includes an unsubscribe link. After opening it, you confirm on the page and your address is removed from the active mailing list. You can also contact redaktion@pandorex.info. Backup copies are subject to the applicable backup retention period.
9. RSS feed
You can subscribe to the latest articles through our RSS feeds. Feed requests process only the technical server data described in section 3.2. No additional processing takes place. We do not collect an email address or other subscription data.
10. Processors and third-party services
10.1 Self-hosted Supabase services
We use Supabase software for database, authentication and file storage functions on our own netcup server. The current website connects to this self-hosted installation. The database and administration interface are not freely accessible to the public.
Supabase Cloud is not used as the database service for this website’s current operation. Earlier cloud projects and any data still held there are a separate matter.
Software information: Supabase self-hosting documentation.
10.2 Matomo audience measurement
Optional audience measurement uses our own Matomo installation at analytics.pandorex.info on our managed server. The Vercel Analytics integration has been removed. After you consent, Matomo processes page views, timestamps, sessions, returning visits, screen resolution, selected clicks, known downloads and permitted campaign fields. Browser and operating system information may be derived from the browser identifier sent with a request. The network connection technically transmits your IP address; Matomo is configured to store a shortened address and use that shortened address for geographical classification.
No device fingerprint is created for recognition. Visitor identifiers are generated using cryptographic randomness and reused only through the first-party cookie. Search text, email addresses, form content, newsletter tokens and URL fragments are not sent as measurement data. Contact, account, sign-in, API and newsletter action pages are excluded. External referrer and link addresses are reduced to their origin, without path, query parameters or fragment. Campaign values are limited to a predefined list. Audience measurement is not linked to signed-in accounts. The separate heatmap and recording feature, requiring additional consent, is described in section 10.3.
Matomo is configured for automatic deletion of individual records after 90 days and aggregated reports after 24 months; backups have separate retention periods. Technical information is available in Matomo’s cookie documentation and the Klaro documentation.
10.3 Optional heatmaps and session recordings
With your separate consent, selected visits to our public overview, topic and article pages may be analysed as heatmaps and masked replays. Our own Matomo extension uses the locally served open-source rrweb library. It records click positions, mouse movement, scrolling, viewport information and the structure of the displayed page. Visible text is masked; forms, search, comments and account content are hidden. Contact, profile, sign-in and newsletter pages are excluded. Inputs, network traffic, console output, audio and video are not recorded.
Recording begins only after consent to Heatmaps and session recordings. Consent to audience measurement alone does not activate it. A random identifier is then stored in the current tab’s sessionStorage under pandorex_behavior_session_v1; it is no longer reused after 30 minutes of inactivity. It is not linked to the Matomo visitor identifier and no device fingerprint is used. If tab storage is unavailable, a random identifier applies only to the current page.
Recordings are stored exclusively on our server and accessible only to authorised Matomo users. We collect a limited sample, capped at three minutes per recorded page view. Live records are removed in the daily cleanup after the configured retention period of no more than 14 days. Backup copies have their own 14-day retention period. You can disable recording at any time through Privacy settings in the footer. This stops further recording, discards unsent data and removes the tab identifier; it does not retrospectively delete recordings already sent.
10.4 Contact and email delivery
The contact form sends your name, email address, subject and message to the editorial team to respond to your enquiry. Once enabled, delivery is intended to use the IONOS mailbox redaktion@pandorex.info; the mail provider processes the message and connection data needed for delivery. Without a configured delivery service, the form does not report a successful send. Message contents are not written to server logs as a substitute. Opening an email link uses your own email app and email provider. We process enquiries on the basis of Article 6(1)(b) or (f) GDPR. Provider information: IONOS privacy policy.
11. SSL/TLS encryption
This website uses SSL/TLS encryption for security. An encrypted connection is indicated by “https://” in your browser’s address bar and its connection-security indicator. Encryption protects data transmitted between your browser and this website from being read in transit by third parties.
12. Your data protection rights
Under the GDPR and FADP, you have the following rights in relation to your personal data:
- Access (Article 15 GDPR / Article 25 FADP): You may request confirmation of whether and which personal data we process about you, and a free copy of those data.
- Rectification (Article 16 GDPR / Article 32 FADP): You may request prompt correction of inaccurate data or completion of incomplete data.
- Erasure (Article 17 GDPR / Article 32 FADP): You may request deletion of your personal data unless a legal retention obligation applies.
- Restriction (Article 18 GDPR): You may request restriction of processing, for example while disputing the accuracy of data.
- Portability (Article 20 GDPR / Article 28 FADP): You may receive your data in a structured, commonly used and machine-readable format and transfer them to another controller.
- Objection (Article 21 GDPR / Article 32 FADP): You may object to processing based on Article 6(1)(f) GDPR.
- Withdrawal of consent (Article 7(3) GDPR): You may withdraw consent at any time with effect for the future.
- Complaint (Article 77 GDPR): You may lodge a complaint with a data protection supervisory authority.
To exercise your rights, contact redaktion@pandorex.info.
13. Account deletion
You may request deletion of your account and associated data at any time. Email redaktion@pandorex.info with the subject “Delete account”. We will delete your account within 30 days.
Account deletion permanently removes:
- Your profile: name, email address and profile image
- Your comments
- Your stored article and comment ratings
- The connection to the social sign-in provider
Your data cannot be restored after deletion.
14. International data transfers
The website and its database run on the server described in section 3. Vercel hosting and Supabase Cloud are not used for this deployment. If you choose Google sign-in, Google may process data outside the European Economic Area; the provider’s information and transfer grounds are described in the privacy policy linked in section 5.4. Optional Matomo measurement and our recording feature run on our server, as described in sections 10.2 and 10.3.
Before enabling additional external services, their actual processing, recipients and any necessary grounds for transfers to other countries are assessed separately. We do not assume that contractual safeguards from earlier hosting or sign-in configurations remain applicable to new services.
15. Disclosure to third parties
We disclose personal data only in the cases described in this notice or where legally required, for example following an order from a law-enforcement authority. We do not share data for advertising purposes.
16. Supervisory authorities
For users in Germany:
The Hessian Commissioner for Data Protection and Freedom of Information
Postfach 3163
65021 Wiesbaden, Germany
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: datenschutz.hessen.de
For users in Switzerland:
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern, Switzerland
Phone: +41 58 462 43 95
Website: edoeb.admin.ch
17. Changes to this privacy notice
We may update this notice to reflect legal requirements or changes to our services. The updated notice applies to subsequent visits. The current version is always available on this page.