Privacy policy

Last updated: September 2026

This is an English translation of the German privacy policy. Both say the same; if they ever differ, the German version applies.

1. Controller

Titus Hildebrand
Am Mühlbach 13, 93051 Regensburg, Germany
Phone: +49 176 83036085
Email: post@titus-hildebrand.de

2. Collection and storage of personal data

a) Visiting the website

The website runs on servers of STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. With every request, STRATO automatically stores log files containing your IP address, date and time, the address requested, the HTTP status code, the amount of data transferred, the page you came from, and your browser and operating system. This serves the secure and stable operation of the website, for example to detect attacks. The legal basis is my legitimate interest in this (Art. 6(1)(f) GDPR). STRATO stores the full IP address for no more than seven days; after that it is anonymised. I can only view the logs with anonymised IP addresses myself, and I only do so in the event of a fault or a suspected attack.

b) Contact by email or phone

If you email or call me, I process your contact details and the information in your message in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR if your enquiry aims at a contract, for example a quote for a website. For other enquiries, it is my legitimate interest in replying to you (Art. 6(1)(f) GDPR). The emails are kept in my mailbox at STRATO GmbH, and I retrieve them directly with the email program on my own devices; they are not forwarded to any other provider. I delete them once your enquiry has been dealt with, unless statutory retention obligations apply, for example to documents relating to an order.

c) Registration for and participation in the Delphi study

The Delphi study has been completed; registration is no longer possible. Participation was by invitation only. During registration and participation, the following data was collected and stored in a database on servers of STRATO GmbH:

The legal basis is the consent you gave when registering (Art. 6(1)(a) GDPR). The data is used exclusively for the scientific evaluation in my master’s thesis “Applying Artificial Intelligence to Process Optimization: A Delphi Study on Business Process Improvement Patterns” at the University of Regensburg. For the evaluation, I have transferred the answers to my computer. I will delete all data containing names on the server and on my computer as soon as the master’s thesis has been graded, and no later than 31 March 2027. In the thesis, answers appear only in aggregated form and without names. You can withdraw your consent at any time with effect for the future, most easily by deleting your account (menu under your name, “Delete account”) or by writing to me. I will then also delete your answers in my evaluation files. Results that have already been aggregated without names remain unaffected.

d) Example patterns from practice (round 5)

Round 5 is no longer part of the Delphi study but serves the same master’s thesis. Registered participants could voluntarily describe a case from their practice as an example pattern there. The entries for the attributes of the model are stored, linked to your account and the time of the last change, likewise in the database at STRATO GmbH. The entries are not supposed to contain specific figures, names of people or confidential details. An example pattern may appear in the thesis as an individual case example. Before it is used, the company concerned can review and approve it. The legal basis is your consent (Art. 6(1)(a) GDPR). I will delete the entries, like the other study data, as soon as the master’s thesis has been graded, and no later than 31 March 2027.

e) Client area for clients

For clients whose website I develop, there is a protected client area. An account is only created at my invitation: I enter the company and contact person and send an invitation link, valid for seven days, with which you set your own password. In the client area, I process the following, likewise in the database at STRATO GmbH:

As soon as you send the questionnaire or upload files, I receive an email. It names your company, the project, your name, the activity and the time, but no answers and no file names. The legal basis is the performance of our contract (Art. 6(1)(b) GDPR). I delete accounts, answers, uploaded files and the log no later than one year after the project has been completed. You can delete files and your account yourself at any time, and you can request the deletion of all data earlier at any time. I keep invoices for as long as tax law requires (section f).

f) Orders and invoices

For orders and invoices, I keep a client database, likewise on the server of STRATO GmbH. It stores the company or name, contact person, address, email address, phone number, whether you place the order as a business or as a private individual, my notes on the order, and the invoices. The legal basis is the performance of our contract (Art. 6(1)(b) GDPR) and, for invoices, additionally the statutory obligation to retain them (Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 14b of the German VAT Act (UStG)). I keep invoices for eight years, counted from the end of the year in which I issued them. Where tax law requires it, the tax office receives these documents. I delete the other client data as soon as I no longer need it for the order, queries or warranty claims and no statutory retention obligation applies any more, as a rule three years after the end of the year in which the order was completed.

g) Protection of logins

So that nobody can try out passwords or take over someone else’s account, I process the following when you log in, use “Forgot password” or change a password, likewise in the database at STRATO GmbH:

After every change of your password, you receive a short email so that you notice any misuse immediately. If wrong passwords pile up for an account or an account is locked, I receive an email with the address of that account so that I can step in. When you set a new password, I also check whether it is known from data breaches. For this, only the beginning of a checksum of the password (5 of 40 characters) is sent to the Pwned Passwords service of Have I Been Pwned, which is operated via Cloudflare. The password cannot be derived from this, and neither your email address, your name nor your network address is transmitted. The legal basis for all of this is my legitimate interest in protecting accounts against misuse and the obligation to process your data securely (Art. 6(1)(f) and Art. 32 GDPR).

3. Cookies and session

This website uses only technically necessary cookies. The session cookie (PHPSESSID) is only set when you open the login page or “Forgot password”, open a link to the client area or for a new password, or switch the language in the study or the client area. On all other pages, the language is part of the address (English pages start with /en/), which needs no cookie. The session cookie expires when you close the browser or log out; a login also ends by itself after 30 minutes without activity (study: 60 minutes). Anyone who only reads the other pages receives no cookie. The cookie contains nothing but a random identifier and serves only the login session, the language you chose and the protection of forms. After a successful login, the site sets a second cookie (__Host-device), which is valid for 180 days, even after logging out. It contains only a random identifier and shows that this browser has logged in with your account before: if someone else tries out passwords for your account, you can still log in from here without waiting (see section 2g). In the questionnaire of the client area, your browser additionally keeps entries that have not yet been saved in the memory of the open tab (sessionStorage) so that they are not lost after a login has expired; this copy never leaves your device and disappears when the tab is closed. All of this is permitted without consent under Section 25(2) no. 2 TDDDG, because it is strictly necessary for logging in, the security of accounts and the language you chose. The legal basis for the processing is the performance of your login and of our contract (Art. 6(1)(b) GDPR) and my legitimate interest in secure forms and accounts (Art. 6(1)(f) GDPR). I do not use cookies for tracking, analytics or advertising.

4. No content from other providers

The fonts, design and scripts of this website come exclusively from my own server. While you read the pages, your browser does not connect to any other provider. Only when you click a link to another website, for example to the App Store, Google Play or a press article, do the privacy notices of that provider apply.

5. Recipients of your data

I do not sell or rent out any data. The only recipients are:

When new passwords are checked, only the beginning of a checksum is sent to the Pwned Passwords service (section 2g); neither the password nor your identity can be determined from it. Your data is not transferred to countries outside the European Union.

6. Your rights

You have the right

Right to object under Art. 21 GDPR

Where I process data on the basis of my legitimate interest (Art. 6(1)(f) GDPR), for example the logs when you visit the website, emails outside an order and the data used to protect logins, you can object to this processing at any time on grounds relating to your particular situation. I will then no longer process this data unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. An informal message to post@titus-hildebrand.de is enough.

Do you have to provide data?

For an account, I need your name, your email address and a password; without them, I cannot set up an account. For an order, I need the information that must by law appear on an invoice; without it, I cannot accept the order. Participation in the study was voluntary. All other information is voluntary.

Automated decisions

I do not make automated decisions within the meaning of Art. 22 GDPR and do not create profiles. The waiting times after several wrong passwords are a technical protective measure, not a decision about you.

To exercise your rights, an email to post@titus-hildebrand.de is enough.

7. Data security

This website transmits all data in encrypted form (HTTPS); unencrypted requests are redirected. Passwords are stored exclusively as bcrypt hashes. Anyone who enters a password incorrectly several times has to wait increasingly long, and logins end after a period without activity (section 2g). Access to the database is restricted to the web server and is not publicly reachable.