Privacy

Last updated

I want this site to be simple, and that includes your data. In short: no cookies, nothing saved on your device, nothing loaded from other companies. What’s left is explained below: the log of the web server, a cookieless visit count that checks one opt-out setting in your browser, and the emails you send me.

Who is responsible

The controller (Verantwortlicher) under the GDPR (DSGVO) is:

Daniel Kurdoghlian, Pushing Pixels
Malmögasse 16, 1100 Vienna, Austria
office@pushingpixels.at

More details are in the imprint.

Hosting

This site runs on a server that I rent from Hetzner and run myself. It’s the same server that hosts pushingpixels.at. The pages are plain files; there is no database and no user account behind them.

Server logs

When you open a page, your browser sends a request to the server. The web server (nginx) writes a line about it to its access log:

  • your IP address
  • date and time of the request
  • the address of the page or file you asked for
  • the response status and the amount of data sent
  • the page you came from, if your browser sends it
  • your browser and operating system (the user agent)

I need these logs to run the site, to find errors and to spot and stop attacks. The legal basis is my legitimate interest in a working and secure website (Art. 6(1)(f) GDPR). I only look at them for these reasons. The server rotates its logs automatically and deletes old ones; I don’t keep them any longer than that, unless an attack has to be investigated.

Visitor statistics

To know which pages people read and how many follow the link to Pushing Pixels, I count visits with Umami. I run it myself at stats.pushingpixels.at; it isn’t a service of another company. It doesn’t use cookies.

Every page loads a small script from stats.pushingpixels.at. It sends a count when you open a page and when you click a link to Pushing Pixels. Before it sends anything, it removes everything after a “?” or “#” from the page address and from the address of the page you came from. From the count, Umami records:

  • the page address (shortened as above) and the page title
  • the website you came from, if your browser tells it (shortened as above)
  • browser, operating system, device type and screen size
  • language setting
  • approximate location (country, region, city)
  • for a Pushing Pixels link: where on the page you clicked it

Umami works out the location from your IP address. It doesn’t save the IP address. To tell visits apart, it calculates an ID from your IP address, your browser’s user agent and a secret value that changes regularly. Nothing it saves identifies you by name. Loading the script and sending a count are ordinary requests to the statistics server, so the section on server logs applies to them too.

The opt-out check

Umami has a switch for turning the statistics off in your browser: an entry called “umami.disabled” in your browser’s local storage. The script looks for this entry when it starts and again before each count. If it’s there, nothing is sent. This is the only thing the site reads from your browser’s storage. The script never writes the entry; only you can set it. To do that, open your browser’s developer console on this site and enter localStorage.setItem("umami.disabled", "1"). It then stays in this browser until you clear the site’s data.

If your browser sends a “Do Not Track” signal, the script still loads and checks the entry once, then sends nothing. Blocking stats.pushingpixels.at, for example with a content blocker, also stops the script. The site works the same either way.

The legal basis for the statistics is my legitimate interest in knowing which content is useful and whether the link to my business is used (Art. 6(1)(f) GDPR). You can turn the statistics off for your browser as described above.

The Austrian Telecommunications Act (Telekommunikationsgesetz 2021, TKG 2021), section 165(3), has rules for storing information on your device and for reading it from there. The opt-out check reads from your device. The site doesn’t ask for your consent before it does. The check reads only the one entry, only to find out whether you have turned the statistics off, and stores nothing.

Cookies and your device

This site sets no cookies. It doesn’t write to local storage, session storage or any other place in your browser. The only thing it reads from there is the statistics opt-out entry described above. Light or dark mode follows the setting of your device, so there’s nothing to remember.

To decide what to show, the site also checks, in your browser, some settings of your device while you’re on a page: light or dark mode, and whether you prefer reduced motion or forced colours (high contrast). For the animated particle scenes on the home page and in the lab, it also checks roughly how much memory and how many processor cores the device has, whether data saving is on or the connection is slow, whether the browser can draw 3D graphics and how smoothly it does, the name of the graphics chip and the screen’s pixel density. That way a slow device, or one set to reduced motion or forced colours, gets a still picture instead. While a scene runs, it follows your mouse and, on phones and tablets that allow it without asking, the tilt of the device, so the particles move with it. Scenes and videos also notice whether they’re on screen, so they can pause when they’re not. These checks happen in your browser only; the site doesn’t send their results anywhere or keep them, and the same goes for mouse and tilt. The statistics script sends screen size and language setting, as listed above.

No third parties

Apart from the statistics script above, which comes from my own Umami server, everything this site needs comes from its own server: fonts, scripts, images and videos. There are no embedded videos, maps, social media buttons or ads, and no content delivery network.

Links to other websites, such as LinkedIn, GitHub or pushingpixels.at, are plain links. Nothing is sent to them until you click one. Their own privacy policies apply once you’re there. Links to pushingpixels.at carry a short note in the address (utm_source=derblub.com and where on the page the link was), so Pushing Pixels can see that you came from this site.

Email

If you write to me, I use your email address and what you write to answer you. Emails to my address arrive at the mail server that runs on the same server as this site. The legal basis is steps before a possible contract, if you ask about working together (Art. 6(1)(b) GDPR), and otherwise my legitimate interest in answering messages (Art. 6(1)(f) GDPR).

I delete emails when they’re no longer needed. If an email becomes part of a business relationship, I keep it for as long as Austrian tax and business law require.

Your rights

Under the GDPR you have the right to

  • know which data about you I process (Art. 15)
  • have incorrect data corrected (Art. 16)
  • have your data deleted (Art. 17)
  • have processing restricted (Art. 18)
  • receive your data in a common format (Art. 20)
  • object to processing that is based on my legitimate interest (Art. 21)

Just email me at office@pushingpixels.at. If you think I’m handling your data unlawfully, you can also complain to a data protection authority. In Austria that’s the Data Protection Authority (Datenschutzbehörde), dsb.gv.at.

You don’t have to give me any data to read this site. I don’t use your data for automated decisions or profiling.