1. Data controller
Mario V.W.B.R. Obst
Permanent residence: Erfurt, capital of the Free State of Thuringia, Germany.
Address for service:
Mario V.W.B.R. Obst
c/o JL Consulting Group GmbH
Zürcherstrasse 84 #1623
8852 Altendorf
Switzerland
The Swiss address is used solely as a rented public address for service. It does not establish a Swiss residential or business address for the controller.
Telephone: +49 1757 116303
Email: nachricht@stasihaft.de
2. Scope and legal bases
This privacy policy explains how personal data is processed when you visit this website. The principal applicable provisions are the European Union’s General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications and Digital Services Data Protection Act (TDDDG).
The website’s technical provision is based on Article 6(1)(f) GDPR. The legitimate interest is to provide this private contemporary history website securely, reliably and in a user-friendly way. Depending on its content, a contact enquiry is processed under Article 6(1)(b) or (f) GDPR.
3. Hosting and delivery through Cloudflare
This website is provided using Cloudflare Workers and Cloudflare Static Assets. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare operates a globally distributed network and processes technically necessary data.
When the website is accessed, technically necessary connection and log data is processed. This may include the IP address, date and time of access, requested address, volume of data transferred, referrer, browser and operating system information, and information relating to security and traffic routing. Processing serves to deliver the website, prevent attacks and maintain the service’s stability and security.
Processing may also take place outside the European Economic Area, particularly in the USA. Cloudflare provides contractual data protection safeguards for international transfers, including through its Data Processing Addendum and the standard contractual clauses incorporated into it. Further information is available in Cloudflare’s privacy policy and the Cloudflare Data Processing Addendum.
Cloudflare provides security functions to prevent automated and malicious access. A delivery setting prevents the automatic injection of the additional JavaScript-based bot check into this website’s pages. Other enabled protection functions may use cookies during a security check, such as cf_clearance to store a check result or __cf_bm for bot detection. These functions are not provided by the website’s own code. Cloudflare describes their purposes and lifetimes in its cookie documentation.
4. Cookies and local storage
This website uses no analytics, advertising or profiling cookies. It uses no audience measurement, Google Analytics or personalised advertising.
The website code sets no cookies of its own and uses neither Local Storage nor Session Storage. No cookie or consent banner is currently displayed. The hosting provider’s security checks are explained in Section 3. Under Section 25(2) TDDDG, consent is not required for storage or access serving solely to transmit a communication, or which is strictly necessary for the digital service expressly requested. Other storage or access requires prior consent; a statement in this privacy policy does not replace it.
The former cookie and privacy notice was removed on 23 September 2026. A notice cookie stored during an earlier visit is no longer read or renewed by the website code. It expires no later than 180 days after it was last stored and can be deleted at any time through your browser settings.
5. No externally loaded fonts or embedded platforms
Fonts, images, documents and videos are currently delivered directly through this website. No Google Fonts or embedded YouTube content is loaded. External websites are opened only when you select a corresponding link; their respective providers are responsible for data processing there.
6. Contact
If you contact me by email, telephone or post, the information you voluntarily provide is used to handle your enquiry. Post sent to the published address for service is received by JL Consulting Group GmbH in Switzerland and forwarded digitally or physically according to the controller’s instructions. The sender and postal information needed to receive and forward it is processed for this purpose. Data is deleted once the enquiry has been fully dealt with, unless statutory retention obligations or overriding legitimate interests prevent this.
7. Retention periods
Personal data is processed only for as long as necessary for the respective purpose or as required by law. Technical log data is processed according to the retention periods applicable to the Cloudflare service used and then deleted or anonymised.
8. Your rights
Under the GDPR, you can request access to, correction or deletion of your data. Subject to the applicable legal conditions, you may also have rights to restriction of processing, data portability, objection and withdrawal of consent previously given. To exercise your rights, send a message to the contact address above.
Under Article 77 GDPR, you have the right to complain to a data protection supervisory authority. The authority responsible for the controller based in Thuringia is:
Thuringian Commissioner for Data Protection and Freedom of Information (TLfDI)
Häßlerstraße 8
99096 Erfurt
Email: poststelle@datenschutz.thueringen.de
9. Security and updates
The website is transmitted in encrypted form over HTTPS. Appropriate technical and organisational measures protect the processed data against loss, misuse and unauthorised access. This policy is updated when functions, services or legal requirements change.
As at: 2 October 2026.