Privacy Policy
1. Controller
The controller responsible for the processing of personal data on this website is:
Sascha Heinze
Eckhoffplatz 34
22547 Hamburg
Germany
Email: kontakt.saschaheinze.de
2. General information about data processing
This website processes personal data only to the extent necessary to provide the website, user accounts, authentication, password reset functionality and video streaming features. Personal data is processed in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection laws.
3. Hosting and server log files
This website is hosted on servers operated by IONOS SE. When you access the website, technical data may be processed automatically by the server. This may include your IP address, date and time of access, requested URL, browser type, operating system, referrer URL and HTTP status codes.
This processing is necessary to deliver the website, ensure technical stability, detect errors and protect the service against misuse. The legal basis is Art. 6(1)(f) GDPR, based on the legitimate interest in providing a secure and functional website.
4. User account and registration
If you create an account, the following data may be processed:
- Email address
- Password in hashed form
- Account activation status
- Date of registration
- Authentication and refresh tokens stored in secure HTTP-only cookies
The data is used to create and manage your user account, provide login functionality, protect access to video content and enable account activation. The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary to provide the requested user account functionality.
5. Login, authentication cookies and logout
This website uses technically necessary HTTP-only cookies for authentication. These cookies store access and refresh tokens that allow you to stay logged in and access protected API endpoints.
These cookies are necessary for the operation of the service and are not used for advertising, tracking or analytics. The legal basis is Art. 6(1)(b) GDPR for account functionality and Art. 6(1)(f) GDPR for secure technical operation.
6. Account activation and password reset emails
When you register or request a password reset, your email address is used to send an account activation link or password reset link. Email delivery may be handled via an external email provider.
This processing is necessary to activate your account, protect your account from unauthorized access and allow you to reset your password. The legal basis is Art. 6(1)(b) GDPR.
7. Video streaming and media files
The website provides video streaming functionality. When videos are accessed, technical requests for video playlists, thumbnails and video segments may be processed by the server. This may include request metadata such as IP address, time of access, requested media file and HTTP status code.
This processing is necessary to provide the video streaming functionality and to ensure secure and stable delivery of media content. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
8. No analytics or advertising tracking
This website does not use advertising cookies, third-party analytics tools, tracking pixels or profiling technologies.
9. Recipients of personal data
Personal data may be processed by technical service providers where necessary to operate this website. This may include hosting providers, server infrastructure providers and email delivery providers.
Personal data is not sold and is not shared with third parties for advertising purposes.
10. Storage period
Personal data is stored only for as long as necessary for the purposes described in this Privacy Policy. Account data is generally stored for as long as the user account exists. Server logs are stored only for a limited period, unless longer storage is necessary for security reasons, error analysis or legal obligations.
11. Your rights
Under the GDPR, you have the right to request information about your personal data, access your data, request correction of inaccurate data, request deletion, request restriction of processing, object to processing and request data portability where applicable.
You also have the right to lodge a complaint with a competent data protection supervisory authority.
12. Right to object
Where personal data is processed on the basis of legitimate interests under Art. 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation.
13. Data security
Appropriate technical and organizational measures are used to protect personal data against loss, misuse, unauthorized access, alteration or disclosure. These measures include HTTPS encryption, password hashing and HTTP-only authentication cookies.
14. Changes to this Privacy Policy
This Privacy Policy may be updated if the website, technical infrastructure or legal requirements change. The current version is available on this page.
Last updated: May 2026