§ 1 — purpose and structure of this document
This document constitutes the information required to be provided to data subjects under Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "General Data Protection Regulation" or "GDPR"), together with the information required under the German Federal Data Protection Act (Bundesdatenschutzgesetz, "BDSG") and the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, "TDDDG").
It is structured as follows. Sections 1 to 3 establish scope, definitions and the identity of the controller. Section 4 provides a consolidated overview of every processing operation. Sections 5 to 12 describe each operation individually. Sections 13 to 16 address the legal bases relied upon, including the assessments carried out where processing rests on legitimate interests. Sections 17 to 21 address recipients, processors and transfers to third countries. Sections 22 to 26 address retention, security and related organisational matters. Sections 27 to 33 address the rights of data subjects and the means of exercising them. Sections 34 to 38 address residual matters including minors, the relationship to other services operated by the same person, and amendment of this document.
Where this document states that a processing operation does not take place, that statement is made deliberately and is intended to be relied upon. A privacy policy that enumerates only what is done leaves the reader unable to distinguish between an operation that was considered and rejected and one that was never contemplated. Section 15 accordingly sets out the operations that do not occur.
§ 2 — scope
This policy applies to the processing of personal data in connection with the website available at the hostname samsam.lol, including all pages served under that hostname and the server-side endpoints those pages invoke.
This policy does not apply to the cryptocurrency exchange comparison service operated at the hostname swap.samsam.lol. Although that service is operated by the same person and is served from the same infrastructure, it carries out materially different processing operations: it transmits order-related data to third-party exchange providers, retrieves pricing information from an external source, and stores order records on the user's terminal equipment subject to a choice presented to the user. A separate privacy policy governs that service and is published at /swap/privacy/. Where a data subject has used both services, each policy applies independently to the processing it describes.
This policy does not apply to websites operated by third parties which may be reached by following links published on samsam.lol. Responsibility for the processing carried out on those websites lies with their respective operators. This policy governs the processing that occurs up to and including the moment a link is followed; it does not govern what occurs thereafter.
This policy does not apply to communications conducted outside the website. Where a data subject corresponds with the controller by electronic mail using the address published in this document or in the legal notice, that correspondence is processed for the purpose of responding to it, on the basis set out in § 9, but the technical description in that section relates specifically to the contact form and not to direct correspondence.
§ 3 — definitions
Terms defined in Article 4 GDPR carry the meanings given there. The following terms are used in this document and are defined here for the assistance of the reader. These definitions are descriptive and do not modify the statutory definitions.
Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
Processing means any operation performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, restriction, erasure and destruction.
Controller means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor means a natural or legal person which processes personal data on behalf of the controller and under the controller's instructions.
Third party means a person other than the data subject, the controller, the processor and persons authorised to process personal data under their direct authority.
IP address means the numerical identifier assigned to a device or network connection for the purpose of routing traffic on the internet. An IP address transmitted by a visitor's connection is treated throughout this document as personal data, consistent with the judgment of the Court of Justice of the European Union of 19 October 2016 in Case C-582/14 (Breyer), in which a dynamic IP address retained by an online media services provider was held to constitute personal data in relation to that provider where it has the legal means to identify the data subject with the assistance of additional information held by a third party.
User agent means the string transmitted by a browser in the course of an HTTP request which describes the browser software and, ordinarily, the operating system on which it is running.
Hash function means a function which maps input of arbitrary length to output of fixed length in a manner which is deterministic, in that the same input always produces the same output, and one-directional, in that the input cannot feasibly be derived from the output. SHA-256, referred to in § 8, is a hash function producing a 256-bit output.
Salt means a secret value combined with an input before hashing. Its function is to prevent the reconstruction of the input by exhaustive search of the input space. Without a salt, an actor holding a stored digest and knowledge of the input format could compute candidate digests until one matched. With a salt held only by the controller, that attack requires the salt.
Terminal equipment means the device used by the data subject to access the website, in the sense used by § 25 TDDDG.
sessionStorage means a storage mechanism provided by the browser in which values are accessible only to pages served from the same origin and are deleted when the browsing context is closed.
Third country means a country outside the European Economic Area.
§ 4 — consolidated overview of processing operations
The following list enumerates every processing operation carried out in connection with this website. Each entry states the operation, the categories of data concerned, the purpose, the legal basis and the section in which the operation is described in full.
- Delivery of the website. Connection data including IP address, timestamp, requested path, response status, transferred volume, user agent, language header and referrer where transmitted. Purpose: delivery of requested content, transport security, service stability, attack mitigation. Legal basis: Article 6(1)(f) GDPR. See § 5.
- Bot mitigation. Browser environment signals evaluated by the mitigation provider. Purpose: distinguishing automated from human requests in order to protect the endpoints described in §§ 8 and 9. Legal basis: Article 6(1)(f) GDPR. See § 6.
- Transport security. Connection metadata necessary to negotiate an encrypted channel. Purpose: confidentiality and integrity of data in transit. Legal basis: Article 6(1)(f) GDPR, and Article 32 GDPR as an obligation. See § 7.
- Visit counting. IP address, user agent and language header, processed transiently into a salted digest which alone is stored. Purpose: establishing the approximate number of distinct visits. Legal basis: Article 6(1)(f) GDPR. See § 8.
- Contact form. Name and electronic mail address where provided, and message content. Purpose: receiving and responding to enquiries. Legal bases: Article 6(1)(b) GDPR where the enquiry concerns a contractual or pre-contractual matter, otherwise Article 6(1)(f) GDPR. See § 9.
- Rate limiting of the contact endpoint. IP address, processed into a short-lived record. Purpose: prevention of automated and repetitive submissions. Legal basis: Article 6(1)(f) GDPR. See § 9.
- Automated submission filtering. The content of a form field not presented to human users. Purpose: identification and discarding of automated submissions. Legal basis: Article 6(1)(f) GDPR. See § 9.
- Storage on terminal equipment. One flag in sessionStorage containing no identifier. Purpose: suppression of a repeated animation within a browsing session. Legal basis: § 25(2) TDDDG; no processing of personal data arises. See § 10.
- Retrieval of embedded third-party content. Connection data disclosed to the third party by the data subject's browser in the course of retrieval. Purpose: presentation of the website as designed. Legal basis: Article 6(1)(f) GDPR. See § 11.
- Correspondence by electronic mail. The content of correspondence and the sender's address. Purpose: responding to the correspondence. Legal bases: Article 6(1)(b) or (f) GDPR according to subject matter. See § 12.
No processing operation other than those enumerated above is carried out in connection with this website.
§ 5 — delivery of the website
The website is hosted on Cloudflare Pages, a service provided by Cloudflare, Inc. Server-side functionality is executed as Cloudflare Pages Functions on the same infrastructure. Cloudflare acts as a processor within the meaning of Article 28 GDPR pursuant to a data processing agreement concluded between the parties, and processes personal data solely on documented instructions from the controller save where required to do otherwise by law.
A request for any resource on this website necessarily transmits the following categories of data to the hosting infrastructure. These categories are inherent in the Hypertext Transfer Protocol and are not collected by choice:
- the IP address of the requesting system, without which a response cannot be routed;
- the date and time of the request;
- the path of the requested resource and the HTTP method employed;
- the HTTP status code of the response;
- the volume of data transferred in response;
- the user agent string transmitted by the browser;
- the Accept-Language header reflecting the language preferences configured in the browser;
- the referring uniform resource locator, where the browser transmits one, which it does not do in all configurations;
- protocol version, cipher suite and related connection metadata used for transport security;
- routing and security metadata added by the hosting provider's network in the course of delivery and attack mitigation.
The purposes of this processing are the delivery of the requested content to the requesting system, the maintenance of the confidentiality and integrity of the connection, the operational stability of the service, and the detection and mitigation of attacks directed at the infrastructure, including volumetric attacks and automated abuse.
The legal basis is Article 6(1)(f) GDPR. The assessment carried out in accordance with that provision is set out in § 14.
The controller does not receive, retain, or have technical access to the infrastructure logs generated by the hosting provider in the course of delivery. The controller is therefore not in a position to retrieve, search, filter or export connection data relating to any individual visit, and cannot answer a request for access framed in those terms other than by stating the foregoing. Retention of those logs, and any processing of them for the provider's own security purposes, is governed by the provider's own policies and by the data processing agreement.
The website is served from a distributed network of servers. The server responding to a given request is ordinarily the one geographically closest to the requesting system, with the consequence that the physical location of processing varies according to the location of the data subject. Where that location is outside the European Economic Area, § 21 applies.
§ 6 — bot mitigation
A bot mitigation mechanism, Cloudflare Turnstile, is executed during the loading of the front page. Its purpose is to distinguish requests originating from human visitors from requests generated by automated systems, and thereby to protect the contact endpoint described in § 9 and the visit counter described in § 8 from automated abuse.
The mechanism evaluates signals exposed by the browser environment in order to form an assessment. In the ordinary case it resolves without any interaction by the data subject and without presenting a challenge. Where the assessment is inconclusive, an interactive challenge may be presented, the completion of which is necessary in order to proceed.
Where an interactive challenge is presented, the provider may store a value on the terminal equipment for the duration of that challenge in order to carry its state between requests. That storage is strictly necessary in order to provide a service expressly requested by the user within the meaning of § 25(2) No. 2 TDDDG and accordingly does not require consent.
The legal basis for the processing is Article 6(1)(f) GDPR. The legitimate interest pursued is the protection of the website's endpoints against automated abuse, unsolicited bulk submissions, and the artificial inflation of the aggregate figure described in § 8.
The mechanism is configured to fail open. Where it is unavailable, is blocked by a network filter or extension, or does not return an assessment within a defined period, access to the website proceeds without a completed assessment. This is a deliberate configuration decision which prioritises the availability of the website to human visitors, including those using privacy-enhancing tools which interfere with such mechanisms, over the completeness of the mitigation. A data subject is accordingly never excluded from the website by reason of the mechanism failing to complete.
§ 7 — transport security
All content is delivered exclusively over connections secured by Transport Layer Security. Requests received over unencrypted connections are redirected to the encrypted equivalent. The negotiation of an encrypted channel entails the processing of connection metadata including the protocol version and the cipher suite agreed between the client and the server.
The purpose of this processing is to protect the confidentiality and integrity of data transmitted between the data subject's browser and the server, including any content submitted through the contact form. The legal basis is Article 6(1)(f) GDPR, and the processing additionally gives effect to the obligation in Article 32(1)(a) GDPR to implement measures including, as appropriate, the encryption of personal data.
§ 8 — visit counter
The website displays an aggregate count of visits. The technical construction of that figure is described here in full, because the construction is material to the assessment of the processing and to the response that can be given to a request under Article 15 GDPR.
Upon loading of the front page, the browser transmits a request to the endpoint/api/views. The server takes three values transmitted with that request — the IP address of the requesting system, the user agent string and the Accept-Language header — concatenates them together with a secret value held exclusively on the server, and computes the SHA-256 digest of the resulting string.
Only the resulting digest is written to storage, together with an expiry of six hours. The IP address is used as an input to the computation and is not written to storage at any point in the operation. Where a digest equal to the computed value is already present in storage, the aggregate figure is returned unchanged and no increment occurs. Where it is not present, the aggregate figure is incremented by one and the digest is written with the expiry stated.
Three properties of this construction are material. First, the hash function is one-directional: it is not computationally feasible to derive the input from the digest. Second, the inclusion of a secret salt prevents reconstruction of the input by exhaustive search, which would otherwise be feasible given the limited size of the IPv4 address space; without knowledge of the salt, candidate inputs cannot be tested against a stored digest. Third, the expiry means that the linkage between any two visits by the same data subject cannot persist beyond six hours, since the digest supporting that linkage ceases to exist.
The value retained beyond the expiry period is the aggregate figure alone. That figure is a single integer. It contains no information relating to any individual, records no timestamps, no geographic information, no referrer and no sequence of visits, and cannot be decomposed into the events which produced it.
The purpose of the processing is to establish the approximate number of distinct visits to the website. The legal basis is Article 6(1)(f) GDPR and the assessment carried out is set out in § 14.
A previous implementation of this mechanism additionally set a cookie containing a randomly generated identifier with a validity of one year, which served the same de-duplication purpose in parallel with the digest. That cookie has been removed. The storage of an identifier on terminal equipment for the purpose of counting visits is not strictly necessary for the provision of a service expressly requested by the user within the meaning of § 25(2) TDDDG, and would accordingly have required consent under § 25(1). The digest mechanism achieves the same purpose without any storage on terminal equipment, and was retained for that reason.
The consequence of this design for the rights of the data subject is addressed in § 31.
§ 9 — contact form
The website provides a form by which a message may be sent to the controller. Its use is entirely voluntary and no function of the website is conditional upon it.
The form transmits three values to the server: a name, an electronic mail address, and a message. The name and the address are optional and may be submitted empty; the message is required and a submission containing fewer than two characters of message content is rejected. Where an electronic mail address is supplied, it is validated for format before any further processing occurs. The length of each field is limited on the server, and content exceeding those limits is truncated before processing.
The server forwards the submitted content to a webhook endpoint operated by Discord Inc., with the consequence that the message is delivered into a private channel on that platform which is read by the controller.
The IP address of the submitting system is not included in the data transmitted to that platform. It is processed on the server exclusively for the purpose of enforcing a rate limit of one submission per sixty seconds per address. The record supporting that limit expires sixty seconds after creation, is not associated with the content of any submission, and is not retained thereafter.
The form contains an additional field which is not presented to human users. Automated submission systems commonly populate every field present in a form. Where that field is received containing a value, the submission is discarded, no forwarding takes place, and no data from the submission is retained. The measure serves exclusively to reduce automated unsolicited submissions and involves no assessment of the data subject.
The legal basis for processing the content of a submission is Article 6(1)(b) GDPR where the enquiry relates to a contract or to steps taken at the request of the data subject prior to entering into a contract. Where the enquiry does not relate to such a matter, the legal basis is Article 6(1)(f) GDPR, the legitimate interest being the handling of communications addressed to the controller. The legal basis for the rate limit and for the filtering measure described above is Article 6(1)(f) GDPR, the legitimate interest being the maintenance of a functional contact channel.
Data subjects are informed that content submitted through the form is stored on infrastructure operated by Discord Inc. and is subject to that provider's own processing and retention. Submissions remain in the destination channel until deleted. Where a data subject prefers that the platform not be involved in the transmission, correspondence sent directly tosam@samsam.lol reaches the same recipient without passing through it, and is processed as described in § 12.
Submissions are retained for as long as is necessary to deal with the matter raised, and are erased upon request. Where a statutory retention obligation applies to particular correspondence, retention is limited to the period prescribed and processing of the data concerned is restricted to the purpose giving rise to the obligation.
§ 10 — storage on terminal equipment
Two items may be stored on the terminal equipment in connection with the use of this website. Both fall within the exemption in § 25(2) TDDDG and accordingly do not require consent.
The first is a single flag written to sessionStorage recording that the opening animation of the front page has been displayed, in order that it is not repeated upon subsequent navigation within the same browsing session. The stored value contains no identifier and no information relating to the data subject. It is accessible only to pages served from this origin, is never transmitted to any server, and is deleted by the browser when the browsing context is closed. Because it contains no information relating to an identified or identifiable natural person, no processing of personal data arises from it; it is disclosed here because § 25 TDDDG governs storage on terminal equipment irrespective of whether the stored information is personal data.
The second arises only where the bot mitigation mechanism described in § 6 presents an interactive challenge, in which case the provider of that mechanism may store a value carrying the state of that challenge for its duration.
No other information is stored on the terminal equipment by this website. In particular, no use is made of cookies set by this website, of localStorage, of IndexedDB, of the Cache API for the purpose of identification, of ETag or other cache-validation headers for the purpose of identification, or of any other mechanism capable of persisting an identifier.
Information stored on terminal equipment may be deleted at any time using the functions provided by the browser. The sole consequence of deleting the flag described above is that the opening animation is displayed again upon the next visit.
§ 11 — content retrieved from third parties
Typefaces and icon assets used by this website are served from this domain and form part of the website's own distribution. No request is made to any external font service and no data is transmitted to the provider of any such service.
This configuration was adopted deliberately. The retrieval of typefaces from an external provider necessarily transmits the IP address of every visitor to that provider. In its judgment of 20 January 2022 in case 3 O 17493/20, the Regional Court of Munich I held that the transmission of a visitor's IP address to such a provider without consent constituted an infringement of the general right of personality. Incorporating the assets into the site's own distribution eliminates the transmission and the question together.
Certain other elements of the front page are hosted by third parties and are retrieved directly by the data subject's browser when the page loads. Such a retrieval constitutes a direct connection between the browser and the third party. It necessarily discloses to that party the IP address of the requesting system together with the request headers described in § 5. The controller does not transmit that data; it arises from the browser's own request. The third parties concerned are:
- files.catbox.moe, from which the profile image displayed on the front page is retrieved.
- Spotify AB, which provides an embedded audio player. This provider sets cookies on its own domain when the player loads. Those cookies include a value which differs between browsers and which persists for approximately one year, and a value recording the page from which the player was loaded. They are set by Spotify, on Spotify's domain, under Spotify's own privacy policy, and are disclosed in this document because they are stored on the data subject's terminal equipment as a consequence of the player being embedded on this page. Configuring the browser to block third-party cookies prevents them from being set. No other function of the website depends upon the player.
- api.lanyard.rest, from which the operator's status on a messaging platform is retrieved. The request transmits an identifier belonging to the operator, which is not data relating to the visitor; the request itself discloses the visitor's IP address in the manner common to all requests.
- api.thecatapi.com, from which the photographic images displayed in the gallery are retrieved.
- cdn.simpleicons.org, from which two icons used in the social links section are retrieved.
- em-content.zobj.net, from which image files are retrieved in order to render certain emoji consistently across platforms.
- Giphy, from which a single 88 by 31 pixel link graphic in the footer is retrieved.
The legal basis for the integration of this content is Article 6(1)(f) GDPR, and the assessment is set out in § 14. Data subjects who do not wish these connections to be established may prevent them by means of browser configuration or content-blocking software. The website has been implemented so as to degrade without error where such content is unavailable, and the omission of any of the above does not prevent the remainder of the website from functioning.
The controller has considered whether the integration of embedded content gives rise to joint controllership within the meaning of Article 26 GDPR, having regard to the judgment of the Court of Justice of the European Union of 29 July 2019 in Case C-40/17 (Fashion ID). The controller's assessment is that responsibility extends to the decision to embed the content and thereby to cause the transmission of connection data to the third party, and that this document discloses that decision and its consequences accordingly. Processing carried out by the third party for its own purposes after receipt is determined by that party alone and is governed by its own policy.
The enumeration above is complete as at the date stated at the head of this document. The page currently being displayed retrieves no third-party content of any kind and executes no scripts.
§ 12 — correspondence by electronic mail
Where a data subject corresponds with the controller using the electronic mail address published in this document or in the legal notice, the content of that correspondence and the sender's address are processed for the purpose of responding to it.
The legal basis is Article 6(1)(b) GDPR where the correspondence relates to a contract or to steps taken at the request of the data subject prior to entering into a contract, and otherwise Article 6(1)(f) GDPR, the legitimate interest being the handling of communications addressed to the controller.
Correspondence is retained for as long as is necessary to deal with the matter raised and is erased thereafter upon request. Data subjects are informed that electronic mail is not necessarily transmitted in encrypted form end to end, and that the confidentiality of a message in transit cannot be guaranteed by the recipient.
§ 13 — legal bases relied upon
The following provisions of Article 6(1) GDPR are relied upon in connection with this website.
Article 6(1)(b) — processing necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. Relied upon in respect of the handling of an enquiry submitted through the contact form or by electronic mail where the enquiry concerns such a matter.
Article 6(1)(f) — processing necessary for the purposes of the legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Relied upon in respect of the operations identified in § 4 and assessed in § 14.
Article 6(1)(c) — processing necessary for compliance with a legal obligation. Relied upon only where a specific obligation arises, for example an obligation to retain particular correspondence or to respond to a lawful order. No such obligation applies to the ordinary operation of the website.
No processing is currently based on consent within the meaning of Article 6(1)(a) GDPR. Where this changes, this document will be amended and consent will be sought before the processing concerned begins.
In addition to Article 6, § 25 TDDDG governs the storage of information on, and access to information stored on, the terminal equipment of the data subject. The position under that provision is set out in §§ 10 and 16.
§ 14 — assessment of legitimate interests
Where processing is based on Article 6(1)(f) GDPR, that provision requires that the legitimate interest pursued be identified, that the processing be necessary for that interest, and that the interest not be overridden by the interests or fundamental rights and freedoms of the data subject. The assessments carried out are recorded below.
Delivery of the website (§ 5). The interest is the operation of a functioning and secure website. The processing is necessary because the categories of data concerned are inherent in the protocol by which a resource is requested and returned; a website which processed less would not be reachable. In the balancing exercise it is material that the data is not combined with other sources, is not used to identify the individual, is not enriched, and that a data subject requesting a resource from a server must objectively expect that server to process the connection data required to serve it. The interests of the data subject are not considered to override the interest in delivery.
Bot mitigation (§ 6). The interest is the protection of the endpoints described in §§ 8 and 9 against automated abuse. The processing is necessary because those endpoints are publicly reachable and would otherwise be subject to automated submission and to artificial inflation of the aggregate figure. In the balancing exercise it is material that the assessment is transient, that no profile is created, and that the mechanism is configured to fail open so that a data subject is never denied access by its operation.
Visit counting (§ 8). The interest is the controller's interest in understanding the approximate reach of their own website. That interest is modest. The processing is necessary in the limited sense that some means of distinguishing repeat requests is required for the figure to carry any meaning at all. In the balancing exercise it is material that the implementation was selected specifically to minimise identifiability, that the raw IP address is never stored, that the salt prevents reconstruction, that the retention period is six hours, that no behavioural data is recorded, and that the resulting figure contains no personal data. Considered against a modest interest, the intrusion is correspondingly slight and the interests of the data subject are not considered to override it.
Rate limiting and submission filtering (§ 9). The interest is the maintenance of a functional contact channel. The processing is necessary because an unprotected endpoint is subject to automated submission at a volume which renders it unusable. In the balancing exercise it is material that the record supporting the rate limit expires after sixty seconds, is not associated with submission content, and that the filtering measure involves no assessment of the data subject.
Embedded content (§ 11). The interest is the presentation of the website with the content it is designed to display. The processing is necessary in the sense that content hosted by a third party cannot be displayed without a request to that party. In the balancing exercise it is material that the number of such parties has been deliberately reduced, that the most significant of them by volume of transmitted data was eliminated by incorporating typefaces into the site's own distribution, that each remaining party is disclosed by name in § 11, that the cookies set by one of them are disclosed specifically, and that the website has been implemented to function without any of them. Data subjects retain effective control through browser configuration.
A data subject may object to any processing based on Article 6(1)(f) in accordance with Article 21 GDPR. The effect of such an objection is described in § 29.
§ 15 — processing which does not take place
For the avoidance of doubt, none of the following is carried out in connection with this website. These statements are made deliberately and are intended to be relied upon.
- No web analytics service is used, whether provided by a third party or self-hosted. No page views, sessions, scroll behaviour, click behaviour, pointer movement, form interaction, heat maps or session replays are recorded. The aggregate figure described in § 8 is the only measurement taken, and it records nothing beyond a count.
- No advertising of any kind is served. No advertising identifiers are set or read, and no remarketing, retargeting, audience building or conversion measurement is performed.
- No tracking of data subjects across websites is performed, and no cookies are set by this website for that or any other purpose.
- No device fingerprinting is performed. The animated background is rendered using WebGL and the banner using the Canvas API. Both are used exclusively to display graphics. Neither enumerates device characteristics, queries rendering capabilities for the purpose of distinguishing devices, nor transmits any information concerning the rendering environment.
- No automated decision-making, including profiling, within the meaning of Article 22(1) GDPR is carried out. No decision producing legal effects concerning a data subject or similarly significantly affecting them is taken by automated means.
- No special categories of personal data within the meaning of Article 9(1) GDPR are processed, and no personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR is processed. Such data is neither requested nor inferred.
- No user accounts, authentication mechanisms, credentials, newsletters or mailing lists are operated.
- No payment data is processed, as no payment is accepted through this website.
- No personal data is sold, licensed or otherwise made available to data brokers or to any party for consideration.
- No location data beyond that which may be inferred from an IP address by a recipient is processed. No geolocation interface is invoked.
§ 16 — position under § 25 TDDDG
Section 25(1) TDDDG provides that the storage of information in the terminal equipment of an end user, and access to information already stored in that terminal equipment, are permitted only where the end user has consented on the basis of clear and comprehensive information. Section 25(2) provides exceptions, including where the sole purpose of the storage or access is to carry out the transmission of a communication, and where the storage or access is strictly necessary in order for the provider to provide a digital service expressly requested by the user.
This website relies upon the exception in § 25(2) No. 2 in respect of the two items described in § 10. No other storage or access occurs. Accordingly no consent is required and no consent interface is presented.
The controller draws attention to the fact that the absence of a consent interface on this website is a consequence of the absence of anything requiring consent, and not a decision to dispense with a required interface. The identifier previously used for the purpose described in § 8 was removed in order to reach that position, rather than retained behind a consent request.
§ 17 — recipients
Personal data processed in connection with this website is disclosed to the following recipients and categories of recipient, and to no others.
Cloudflare, Inc., as a processor within the meaning of Article 28 GDPR, in respect of all connection data described in § 5, the operation of the endpoints described in §§ 8 and 9, and the bot mitigation described in § 6.
Discord Inc., in respect of the content of submissions made through the contact form described in § 9, upon delivery to the destination channel.
The providers of embedded content enumerated in § 11, in respect of the connection data arising from the retrieval of that content by the data subject's browser.
Disclosure to public authorities occurs only where there is a legal obligation to disclose, or where disclosure is necessary for the establishment, exercise or defence of legal claims. No such disclosure has occurred as at the date of this document, and none is anticipated in the ordinary operation of the website.
No personal data is disclosed to any recipient for the purposes of advertising, market research, audience measurement or profiling. No analytics provider, tag management system, consent management platform or customer data platform is engaged.
§ 18 — processors
Where a third party processes personal data on behalf of the controller, that processing is carried out on the basis of a contract meeting the requirements of Article 28(3) GDPR, under which the processor is bound to process personal data only on documented instructions, to ensure that persons authorised to process the data are subject to an obligation of confidentiality, to implement the measures required by Article 32, to assist the controller in responding to requests from data subjects, and to delete or return the data at the end of the provision of services.
In selecting processors, the controller has regard to the guarantees offered in respect of technical and organisational measures, the terms on which sub-processors may be engaged, the transparency of the provider's own documentation, and the transfer mechanisms available where processing occurs outside the European Economic Area.
§ 19 — sub-processors
Processors engaged by the controller may engage sub-processors in accordance with Article 28(2) and (4) GDPR. Where they do so, the processor remains fully liable to the controller for the performance of the sub-processor's obligations. Current sub-processor lists are maintained and published by the processors concerned.
§ 20 — sources of data
All personal data processed in connection with this website is obtained from the data subject, either by transmission from the data subject's browser in the course of requesting a resource, or by the data subject's voluntary submission of the contact form or correspondence by electronic mail. No personal data is obtained from third-party sources, from publicly accessible registers, or from data enrichment services. Article 14 GDPR, which concerns data not obtained from the data subject, is accordingly not engaged.
§ 21 — transfers to third countries
Several of the recipients identified in § 17 are established in the United States of America or process personal data on infrastructure located there. Processing therefore takes place outside the European Economic Area.
Such transfers are effected on the basis of the safeguards published by the recipients concerned. These comprise, according to the recipient, the standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR, and certification under the EU-U.S. Data Privacy Framework, in respect of which the European Commission adopted an adequacy decision on 10 July 2023 pursuant to Article 45 GDPR.
Data subjects are informed of the following matters in the interests of accuracy. The adequacy of protection afforded in a third country may be affected by the legal framework of that country, in particular by the powers of access available to its public authorities. Adequacy decisions concerning the United States have twice been annulled by the Court of Justice of the European Union, in Case C-362/14 (Schrems) by judgment of 6 October 2015 and in Case C-311/18 (Schrems II) by judgment of 16 July 2020. The controller is a private individual and is not in a position to audit the practices of the recipients concerned or to verify their compliance with the safeguards they publish.
The measures within the controller's control are the minimisation of the data transmitted and the reduction in the number of recipients. Those measures have been applied: typefaces were incorporated into the site's own distribution in order to eliminate transmission to a font provider, and the IP address was removed from the data forwarded under § 9.
§ 22 — retention
Personal data is retained only for as long as is necessary for the purposes for which it is processed, or for as long as a statutory retention obligation requires. The following periods apply.
- The digest described in § 8 — six hours from creation, upon which it expires automatically.
- The rate-limiting record described in § 9 — sixty seconds from creation.
- The aggregate visit figure — retained indefinitely as a single integer containing no personal data.
- Contact form submissions and correspondence — until the matter raised has been dealt with, and thereafter until erasure, which is carried out upon request.
- The flag described in § 10 — until the browsing session is ended by the data subject.
- Connection data held by the hosting provider — in accordance with that provider's retention policy, which the controller neither determines nor has access to.
Where data must be retained in order to comply with a statutory obligation, or in order to establish, exercise or defend legal claims, processing of that data is restricted to those purposes for the duration of the period concerned in accordance with Article 18(2) GDPR.
§ 23 — technical and organisational measures
Measures are implemented in accordance with Article 32 GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks of varying likelihood and severity to the rights and freedoms of natural persons. The measures in place include:
- transmission exclusively over connections secured by Transport Layer Security, with unencrypted requests redirected;
- storage of values required for server-side operation, including the webhook address referred to in § 9 and the salt referred to in § 8, as server-side secrets which are not transmitted to the browser and are not present in any client-side asset;
- validation and length limitation of all input accepted by the contact endpoint prior to processing;
- rate limiting of the contact endpoint as described in § 9;
- automated submission filtering as described in § 9;
- bot mitigation as described in § 6;
- data minimisation by design in accordance with Article 25 GDPR, including the removal of the identifier described in § 8 and the removal of the IP address from the data forwarded under § 9;
- elimination of external dependencies where the same result is achievable locally, as described in § 11;
- restriction of access to the destination channel described in § 9 to the controller.
It is noted that the transmission of data over the internet cannot be guaranteed to be free from security gaps and that complete protection against access by third parties is not achievable. The most significant protective measure applied to this website is the decision not to collect data which is not required, since data which is not collected cannot be disclosed.
§ 24 — data protection by design and by default
Article 25 GDPR requires the implementation of appropriate measures designed to implement data protection principles in an effective manner and to integrate the necessary safeguards into the processing, and requires that by default only personal data necessary for each specific purpose is processed.
The following decisions were taken in the design of this website in order to give effect to those requirements: the identifier previously used for visit de-duplication was removed and replaced by an expiring salted digest; the IP address was removed from the data forwarded to the messaging platform; typefaces and icon assets were incorporated into the site's own distribution in order to eliminate transmission to external providers; no analytics facility was implemented at any stage; and the pages comprising this policy and the legal notice execute no scripts and retrieve no third-party content.
§ 25 — records of processing activities
Article 30(5) GDPR exempts an enterprise employing fewer than 250 persons from the obligation to maintain a record of processing activities unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special categories of data. The processing described in this document is carried out by a single individual and does not involve special categories of data. Notwithstanding the exemption, this document itself constitutes a description of every processing operation, its purpose, its legal basis, its recipients and its retention period.
§ 26 — personal data breaches
In the event of a personal data breach within the meaning of Article 4(12) GDPR, the controller will notify the competent supervisory authority in accordance with Article 33 GDPR without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller will communicate the breach to the data subjects concerned in accordance with Article 34 GDPR, subject to the exceptions in Article 34(3). Given that no contact details are retained for the majority of data subjects, such communication would where necessary be effected by publication on this website.
§ 27 — rights of the data subject: introduction
Chapter III GDPR confers the rights set out in §§ 28 to 32 upon data subjects. Those rights are exercisable against the controller identified in § 33 and are exercised free of charge, subject to Article 12(5).
Section 31 addresses a matter which materially affects the practical exercise of several of these rights in relation to this website, and should be read together with §§ 28 to 30.
§ 28 — right of access, rectification and erasure
Access (Article 15 GDPR). The data subject has the right to obtain confirmation as to whether personal data concerning them is being processed and, where that is the case, access to that data together with information as to the purposes of processing, the categories of data concerned, the recipients or categories of recipient, the envisaged retention period or the criteria used to determine it, the existence of the rights described in this document, the right to lodge a complaint with a supervisory authority, the source of the data where not collected from the data subject, and the existence of automated decision-making.
Rectification (Article 16 GDPR). The data subject has the right to obtain without undue delay the rectification of inaccurate personal data concerning them and, taking into account the purposes of the processing, the right to have incomplete personal data completed.
Erasure (Article 17 GDPR). The data subject has the right to obtain the erasure of personal data concerning them without undue delay where one of the grounds in Article 17(1) applies, including where the data is no longer necessary for the purposes for which it was collected, where the data subject objects under Article 21(1) and there are no overriding legitimate grounds, or where the data has been unlawfully processed. That right is subject to the exceptions in Article 17(3), including where processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
§ 29 — right to restriction, portability and objection
Restriction (Article 18 GDPR). The data subject has the right to obtain the restriction of processing where the accuracy of the data is contested, for a period enabling verification; where processing is unlawful and the data subject opposes erasure and requests restriction instead; where the controller no longer needs the data but the data subject requires it for legal claims; or where an objection under Article 21(1) is pending verification.
Portability (Article 20 GDPR). The data subject has the right to receive personal data concerning them which they have provided to the controller, in a structured, commonly used and machine-readable format, and to transmit that data to another controller, where the processing is based on consent or on a contract and is carried out by automated means.
Objection (Article 21 GDPR). The data subject has the right to object at any time, on grounds relating to their particular situation, to processing based on Article 6(1)(f). Upon such an objection the controller shall no longer process the data unless compelling legitimate grounds are demonstrated which override the interests, rights and freedoms of the data subject, or the processing serves the establishment, exercise or defence of legal claims. The processing described in §§ 5, 6, 8 and 11 is based on Article 6(1)(f) and is subject to this right. Where an objection is upheld in respect of the processing in § 5, the practical consequence is that the website cannot be delivered to the objecting data subject.
Withdrawal of consent (Article 7(3) GDPR). Where processing is based on consent, that consent may be withdrawn at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal. No processing described in this document is presently based on consent.
§ 30 — exercising these rights
Requests should be addressed tosam@samsam.lol. No particular form is prescribed and no reason need be given, save in the case of an objection under Article 21(1), which requires grounds relating to the data subject's particular situation.
A response is provided without undue delay and in any event within one month of receipt in accordance with Article 12(3) GDPR. That period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case the data subject is informed within one month of receipt together with the reasons for the delay.
Where reasonable doubts exist concerning the identity of the person making a request, additional information necessary to confirm identity may be requested in accordance with Article 12(6) GDPR. Any information so provided is used exclusively for that purpose and is erased once the request has been dealt with.
Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, a reasonable fee may be charged taking into account the administrative costs of providing the information, or the request may be refused, in accordance with Article 12(5) GDPR. The burden of demonstrating the manifestly unfounded or excessive character of a request lies with the controller.
§ 31 — limits arising from the design of the visit counter
Article 11(1) GDPR provides that where the purposes for which a controller processes personal data do not or do no longer require the identification of a data subject, the controller is not obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with the Regulation. Article 11(2) provides that where the controller is able to demonstrate that it is not in a position to identify the data subject, Articles 15 to 20 do not apply except where the data subject provides additional information enabling their identification.
The mechanism described in § 8 is constructed so that the controller cannot identify a data subject from what is stored. The stored value is a one-directional digest incorporating a secret salt, and no other record links it to any individual. It follows that a request under Articles 15 to 20 which relates solely to that processing cannot be answered by retrieving data, because no data capable of being retrieved by reference to the data subject exists.
Where such a request is received, the controller will state the foregoing rather than provide a nil response without explanation. This limitation does not extend to any other processing described in this document. In particular, a submission made through the contact form or correspondence sent by electronic mail contains information supplied by the data subject and is capable of being located, provided and erased, and will be upon request.
§ 32 — right to lodge a complaint
Without prejudice to any other administrative or judicial remedy, every data subject has the right under Article 77(1) GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if they consider that the processing of personal data relating to them infringes the Regulation.
In the Federal Republic of Germany, supervisory competence in respect of non-public bodies lies with the data protection authority of the federal state in which the controller is established. A complaint may be lodged irrespective of whether the matter has first been raised with the controller, and the exercise of that right is not conditional upon any prior step.
Article 78 GDPR additionally confers the right to an effective judicial remedy against a legally binding decision of a supervisory authority, and Article 79 the right to an effective judicial remedy against a controller or processor.
§ 33 — controller and contact
The controller within the meaning of Article 4(7) GDPR is the operator of samsam.lol, a private individual resident in the Federal Republic of Germany.
Contact for all matters relating to this document, including the exercise of the rights described in §§ 27 to 32:sam@samsam.lol.
The identification details required under § 5 DDG are published in thelegal notice. That notice forms part of the information provided under Article 13 GDPR and should be read together with this document.
No data protection officer has been designated. Article 37(1) GDPR requires designation where processing is carried out by a public authority or body, where the core activities consist of processing operations which by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of processing on a large scale of special categories of data or data relating to criminal convictions. None of those conditions is met. Section 38(1) BDSG additionally requires designation where at least twenty persons are constantly engaged in the automated processing of personal data; the website is operated by one person. The absence of a designated officer does not affect any right described in this document.
§ 34 — obligation to provide personal data
There is no statutory or contractual obligation to provide personal data in order to access this website, and the provision of personal data is not a requirement necessary to enter into a contract.
The connection data described in § 5 is transmitted automatically by the browser as a technical consequence of requesting a resource and cannot be withheld without preventing the request from completing. The data described in § 9 is provided voluntarily, and the sole consequence of not providing it is that no message is transmitted and no response can be given.
§ 35 — minors
The website is not directed at children, does not offer information society services to children within the meaning of Article 8 GDPR, and does not knowingly process personal data relating to children. No age declaration is requested because no offer requiring one is made.
The only means by which a child could provide personal data through this website is the voluntary submission of the contact form described in § 9 or correspondence as described in § 12. Where the controller becomes aware that personal data relating to a child has been provided, that data is erased.
§ 36 — relationship to the exchange comparison service
The service operated at swap.samsam.lol is a separate offering. It transmits order-related data to third-party exchange providers, retrieves pricing information from an external source, and stores order records on the data subject's terminal equipment subject to a choice presented to the data subject. None of that processing occurs in connection with samsam.lol and none of it is governed by this document.
The privacy policy applicable to that service is published at/swap/privacy/, and its legal notice at/swap/legal/. Data subjects who have used that service should consult those documents, which describe processing operations not described here.
§ 37 — applicable law
Processing described in this document is subject to Regulation (EU) 2016/679, to the German Federal Data Protection Act, and to the German Telecommunications Digital Services Data Protection Act. Nothing in this document limits any right conferred by those instruments, and any provision of this document which is inconsistent with them is to be read as modified to the extent necessary to give effect to them.
§ 38 — amendment
This document is amended where changes to the website, to the processing operations described, or to the applicable legal framework make amendment necessary. The date stated at the head of this document indicates the version currently in force, and the version published at this address is the version which applies.
No mechanism exists for notifying data subjects individually of amendments, since no contact details are retained for that purpose. Data subjects wishing to remain aware of changes should consult this page. Where an amendment materially alters the processing described, the amendment will be reflected in the date at the head of the document.