Privacy
Privacy
Policy
intelligent piXel GmbH, Enzianstraße 4a, 82319 Starnberg, Germany. Managing Director George A. Rauscher. Contact my@intelligent-pixel.com. The complete provider information, including the court of registration, the commercial register number, and the VAT identification number, is set out in the imprint.
We have not appointed a data protection officer. We assessed the requirements of Art. 37(1) GDPR and section 38(1) BDSG and concluded that no obligation to appoint one arises. We review that assessment whenever our activities change materially. Any data protection question sent to the address above reaches the managing director directly.
This website consists of static pages and a contact form. There are no visitor accounts, no comment function, no newsletter, no storage of form submissions in a database, and no behavioral profiles. Which connection data your browser sends automatically while you read, and how long it stays, are set out under Server logs.
We process this data in order to deliver this website. We operate the server in a German data center run by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. Hetzner acts as a processor under Art. 28 GDPR on the basis of a data processing agreement and processes data solely on our instructions. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the reliable and secure operation of this website.
intelligent piXel GmbH designed and built the digital infrastructure behind this website and also operates it. Hetzner supplies the hardware and the certified security around it: alarm systems, video surveillance, and access control. The machine is a dedicated server used exclusively for these purposes. The operating system and every service running on it are administered solely by intelligent piXel GmbH, and no other customer shares this system. As the operator of the data center, Hetzner has physical access to the hardware and has technical access to the system through the remote management interface, which is why Hetzner is bound as a processor under Art. 28 GDPR.
IPServerSec is the core of the protection on this server, a hardening and early-warning system we built in-house. It is not a purchased plugin, not a subscription, and not a third-party service. It grew over years out of real attacks on real servers. IPServerSec places traps on paths no legitimate visitor ever requests. If such a path is requested, the system blocks the source immediately and notifies the administrator by email and SMS. That message carries only the trigger and the time, no IP address and no data relating to you. The system checks this server every 12 hours for reachability, error responses, and anomalies in access behavior. It consolidates the findings of every protective layer into a single alert chain and documents each incident so it can be reconstructed later. IP addresses are processed for attack detection, trap evaluation, and automatic blocking decisions. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the early detection and prevention of attacks on this server and the protection of the data processed on it. We review every block by hand on request. See Automated decisions below.
A web application firewall built on the OWASP Core Rule Set inspects every incoming request in real time. It is designed to reject requests matching SQL injection, cross-site scripting, remote code execution, and path traversal including local file inclusion before they reach the application. For that matching, the firewall processes the request path, the method, the headers, and the source IP address. No security measure can guarantee complete protection against every conceivable attack. We log blocked requests with a timestamp, the source IP address, the rule that matched, and the request metadata, so an incident can be reconstructed afterward. These entries are deleted automatically after a maximum of 14 days. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is defending against attacks at the application layer and keeping security incidents traceable.
CrowdSec runs as an intrusion prevention system. It evaluates the access and error logs of this website, recognizes attack patterns, and blocks attacking IP addresses automatically. On this server the blocks escalate in stages: 12 hours, then 72 hours, then indefinitely. IP addresses, access patterns, and attack signatures are processed for this purpose. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is defending against repeated automated attacks and keeping this website available. This server participates in the shared threat intelligence network of CrowdSec SAS, Paris, France. When an IP address is blocked on this server, we transmit to CrowdSec the IP address, the timestamp, and the label of the detected attack pattern. We transmit no content, no form data, and no identifiers relating to your person. CrowdSec processes this information as a controller in its own right for the purpose of building and operating the threat network, and the CrowdSec SAS privacy policy sets out the details and your rights against CrowdSec. The processing takes place within the European Union.
Not all data that can lead to a block originates on this server. Through the CrowdSec SAS threat intelligence network we obtain lists of IP addresses that have shown attack behavior on other participating servers. The categories of data are IP addresses, timestamps, and the label of the attack pattern detected. The source is CrowdSec SAS and, through it, the server operators participating in the network. We use no other sources. The purpose is defending against attacks we would otherwise only detect after the first hit. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protecting this server against attackers already identified elsewhere. A block issued on this basis lasts for as long as the address remains on the list and is re-evaluated with every update. If you consider a block unjustified, write to my@intelligent-pixel.com, and we will review it by hand and restore access where appropriate. Your rights under Art. 15 to 21 GDPR apply to this data in the same way.
AIDE, the Advanced Intrusion Detection Environment, verifies the integrity of the monitored system files every 12 hours. If one of those files changes, the system detects the deviation at the next scheduled run and reports it. The check covers the operating system, the web server configuration, the application code, and security-critical root configuration files including SSH authorized_keys and shell profiles. The reference database sits off the server, so an attacker with full privileges cannot quietly update it along with the file he altered. AIDE does not evaluate visitor data. It compares checksums of the monitored files against a protected reference. The purpose is early detection of unauthorized system changes. AIDE is a technical measure under Art. 32 GDPR.
At the network layer we block ranges from which, over an extended period, we have observed almost exclusively automated attacks and no legitimate traffic. No EU or EEA state is blocked. The block is based solely on the technical origin of the connection, not on nationality, residence, or place of establishment, and the ranges change continuously. To map an IP address to a region we use a lookup database held locally on the server, so your IP address is not transmitted to any third party for this. If you are a legitimate visitor and a block catches you, for instance while traveling or through a provider using addresses from a blocked range, write to my@intelligent-pixel.com and we will restore access. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is reducing the attack load from ranges where we observe almost nothing but automated attacks.
Every connection runs over TLS 1.2 or TLS 1.3 with certificates from Let’s Encrypt. Certificates renew automatically, and we monitor every renewal, so an expiring certificate does not go unnoticed. This is a technical measure under Art. 32 GDPR.
Every response sets Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. These headers tell your browser to enforce encryption, prevent clickjacking, block MIME sniffing, limit what leaks through the referrer, and switch off device permissions this site does not use. These are technical measures under Art. 32 GDPR.
This website runs under its own Unix account with strictly limited file access, an open_basedir restriction, and dangerous system functions disabled in the PHP runtime: shell execution, process spawning, and writes outside the permitted paths. A web shell dropped through an application flaw cannot invoke system commands through the PHP runtime as long as those functions remain disabled. The separation is designed to contain the effects of a compromise within this account. AppArmor runs with enforced profiles for all services. These are technical and organizational measures under Art. 32 GDPR.
This website is not administered through a browser-based login. It has no content management system, no admin panel, and no login form. That removes the login surface attackers target most often and leaves no web credentials to guess. Maintenance, updates, and every system change are carried out over the server command line, reachable only through a secure administrative connection. Requests to common admin login paths are therefore never legitimate. Anyone probing them is looking for a way in and gets blocked. IP addresses are processed to evaluate such attempts. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is detecting targeted reconnaissance against administrative interfaces.
Messages from the contact form are handed to Proton Mail SMTP over an encrypted connection and are DKIM-signed when they are sent. Mail sent directly from our own server is signed by our OpenDKIM installation. Receiving servers that verify the signature and evaluate our published policies are able to identify a forged message claiming to come from this domain. Email metadata is processed for that verification. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protecting our domain against misuse as a forged sender address and protecting recipients against phishing.
Security updates for the operating system and installed packages arrive automatically through unattended-upgrades and Ubuntu Pro Extended Security Maintenance. Canonical Livepatch applies kernel security fixes without a reboot, so we can close critical holes without taking the site down. These are technical measures under Art. 32 GDPR.
When you visit, the web server automatically processes the connection data required to deliver the page and to keep the system secure: IP address, date and time, requested URL, HTTP status code, referrer, and browser information. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure, stable, abuse-resistant operation of this site, which covers error analysis, attack detection, and system integrity. We never use server log data for profiling or marketing. It is stored for a maximum of 14 days and then deleted automatically.
This site sets no cookies. No analytics cookies, no advertising cookies, no session cookies. There is no Google Analytics, no Matomo, no Meta Pixel, no remarketing tool, and no behavioral tracking. No cross-site tracking, no advertising profiles. We sell no data. We build no profile of you, neither when you read the public pages nor when you use the contact form.
We set no cookies, and beyond that we neither access your device nor store information on it. This website uses no local storage, no session storage, no IndexedDB, no Cache Storage API, no service worker, no web beacons, and no device recognition techniques such as browser or canvas fingerprinting. The fonts are files on our own server and are delivered like any other page resource. If you hover over a link in the language switcher, your browser prefetches that page of this website, and only from this server. Your browser caches such files as it normally would. That operation is strictly necessary to provide the service you requested and is therefore exempt from the consent requirement under section 25(2) no. 2 TDDDG. We accordingly need no consent under section 25(1) TDDDG and deliberately do not show a consent banner.
If you use the contact form, we process what you enter: your name, your email address, the topic you select, the message itself, your consent, and technical anti-abuse data such as IP address and submission time. We write none of it to a database.
The form hands your message to Proton Mail SMTP over an encrypted TLS connection, and from there it goes to the mailbox that handles it. The provider of the mail delivery service and of that mailbox is Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland. Proton AG acts as our processor in this respect. The data processing agreement under Art. 28(3) GDPR forms part of its terms of service and therefore governs the processing of personal data over this channel. Switzerland is covered by Commission adequacy decision 2000/518/EC of July 26, 2000, which remains in force under Art. 45(9) GDPR, so a transfer under Art. 46 or Art. 49 GDPR is not required for this channel.
For abuse protection the system logs the event type, the IP address, and the sender’s email address in a separate security log. That log sits outside the website files, is not part of any backup, and is deleted automatically after 14 days. We do not permanently store the content of your message on this web server. It is handed straight to the mail service and is not written to any file or database of the website afterward. Technically unavoidable transient buffering in memory or in the mail queue exists only for the duration of the handover. In the mailbox we keep your message for as long as handling the matter and the applicable statutory retention periods require.
Legal bases in detail: we process your name, email address, selected topic, and message content under Art. 6(1)(b) GDPR where your inquiry serves the initiation or performance of a contract, and otherwise under Art. 6(1)(f) GDPR, our legitimate interest being to answer the inquiry addressed to us. Voluntary additional information you choose to include is processed on the basis of your consent under Art. 6(1)(a) GDPR. You may withdraw that consent at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal. Logging for abuse protection rests on Art. 6(1)(f) GDPR, our legitimate interest being to prevent automated abuse of the form and the sending of unsolicited messages through our infrastructure.
At /en/leak-check/ you can check whether a password has appeared in known data breaches. The check happens only when you trigger it yourself and have explicitly consented to the transfer beforehand. Without that consent no request is made; the button stays disabled, and nothing is preconnected or pre-resolved either.
What is transmitted
Your input is hashed inside your browser into a 40 character SHA‑1 value. Only the first five characters of that value are sent to the service. Around 2,000 different passwords share those five characters, and which one was meant cannot be derived from them. Your password itself and the remaining 35 characters do not leave your device. The request also transmits your IP address, because it originates from your browser and does not pass through our server. The approach is called k‑anonymity.
Recipient
Superlative Enterprises Pty Ltd, Australia, operator of the Have I Been Pwned service, served via the network of Cloudflare, Inc., United States. No adequacy decision of the European Commission exists for Australia. The transfer therefore relies on your explicit consent under Art. 49(1)(a) GDPR. You are aware that this transfer is made without an adequacy decision and without appropriate safeguards.
Legal basis
Art. 6(1)(a) GDPR, your consent. It is voluntary. Without it you can use this website unchanged; only the check is unavailable.
Storage
We store neither your input nor the hash nor the result. No log entry is created on our server, because the request is made by your browser. For the recipient's handling of the request we refer you to their own privacy policy.
Withdrawal
You can withdraw your consent at any time by not triggering a further check and by clearing the checkbox. Data already transmitted cannot be recalled.
You are under no statutory or contractual obligation to provide us with personal data. Retrieving the public pages technically requires your browser to transmit the connection data listed under Server logs, and without that transmission the pages cannot be delivered. Using the contact form is voluntary. We need your name, your email address, and your message in order to reply, and without them we cannot handle your inquiry. The topic is optional, and leaving it out puts you at no disadvantage. You do not have to use the form at all. Email reaches us just as well.
You may contact us via Telegram at @intelligentpixel. Telegram is operated by Telegram FZ-LLC, Dubai, United Arab Emirates. There is no adequacy decision for the United Arab Emirates under Art. 45 GDPR, and no appropriate safeguards under Art. 46 GDPR are in place for this channel. We therefore offer Telegram only as an additional, voluntary channel. Please do not use it for inquiries containing personal or confidential information. If you choose it anyway, you transfer your message data to a third country on the basis of your explicit consent under Art. 49(1)(a) GDPR, and you are informed of the following risks: the United Arab Emirates offers no level of protection comparable to the GDPR, there is no effective legal remedy against state access, we cannot enforce your data subject rights against Telegram on your behalf, and Telegram processes your usage data and metadata for its own purposes outside our control. You may withdraw that consent at any time with effect for the future. For any inquiry that should not go to a third country without an adequacy decision, use the contact form or email.
Insofar as we operate servers, security monitoring, mail hosting, or remote support for a client, we act as a processor under Art. 28 GDPR on the basis of a data processing agreement. The details of that processing are governed by that agreement, not by this website notice.
Remote support runs over RustDesk on our own relay and server hardware inside the EU, not through a third-party cloud. Session data is processed solely to provide the support you requested. The legal basis is Art. 6(1)(b) GDPR. We delete it no later than 30 days after the case is closed, unless it is still needed to document a security incident or to comply with statutory retention obligations. Where a session gives us access to third-party data, for instance data of our clients’ staff or customers, we process it exclusively on behalf of the relevant controller under Art. 28 GDPR, and the duty to inform those individuals lies with that client.
Our protective systems make blocking decisions automatically. In our assessment a block does not reach the threshold of a legal effect or a similarly significant effect under Art. 22(1) GDPR, because it only prevents access to this website, creates no record used for any other purpose, and leaves contact by email untouched. Independently of that assessment we voluntarily grant you the safeguards of Art. 22(3) GDPR: you may at any time write to my@intelligent-pixel.com to obtain human intervention, express your point of view, and contest the decision. We then review the block by hand and reply within 10 business days. As to the logic: an IP address is blocked when it requests a path that exists only as a trap, when a web application firewall rule matches, when the intrusion prevention system recognizes a known attack pattern, or when the address appears on a threat network block list. Only technical connection and request data are used, no content, no special categories of data under Art. 9 GDPR, and no characteristics of your person. We also review every permanent block on our own initiative at least once a year and lift it where there is no longer a reason for it. Profiling within the meaning of Art. 4(4) GDPR for any other purpose, in particular evaluation, advertising, or creditworthiness, does not take place.
Beyond the server log we store no inquiry data on this web server. The log itself is kept for a maximum of 14 days. The contact form hands your message straight to the mailbox that handles it and keeps no copy on the web server. For abuse protection the security log retains the event type, the IP address, and the sender’s email address for a maximum of 14 days, then deletes them automatically. Firewall entries for blocked requests follow the same 14-day limit. Where a business or case-related relationship exists, correspondence in the mailbox may be kept for the duration of that relationship and for the statutory retention periods that apply to it. Blocked IP addresses stay stored for as long as the block lasts. Time-limited blocks are deleted by the system when they expire. We review permanent blocks at least once a year and delete the entry where 12 months have passed since the last incident and no other reason exists. In any event we delete it after 24 months at the latest, unless the address has been involved in a new incident. Independently of this we review any block by hand at your request.
Fonts are hosted locally as part of this site’s own assets. Your browser does not contact any font provider, and no request goes to Google Fonts or any comparable service. Apart from the mail relay that is technically necessary when you use the contact form, the threat intelligence exchange described under Intrusion prevention, the service described under Password check when you explicitly trigger the leak test, and the optional channels you can choose yourself, we transmit no visitor data to third parties for marketing or analytics.
The only recipients of personal data are: Hetzner Online GmbH, Germany, as processor for hosting; Proton AG, Switzerland, as processor for mail dispatch and the mailbox; CrowdSec SAS, France, as an independent controller for the threat network; and Telegram FZ-LLC, United Arab Emirates, if you expressly choose that channel, and Superlative Enterprises Pty Ltd, Australia, served via Cloudflare, Inc., United States, if you explicitly trigger the leak test. Beyond this we disclose personal data only where we are legally obliged to, in particular to public authorities and courts, or where it is necessary for the establishment, exercise, or defense of legal claims, for instance to our lawyers. We disclose no data for advertising or analytics purposes, and we sell no data.
Under the GDPR you have the right to request access to the personal data we hold about you, to have it corrected if it is inaccurate, to have it deleted where there is no longer a legitimate reason to hold it, to restrict how we process it, and to receive it in a structured, commonly used, machine-readable format. Where processing rests on your consent, you may withdraw it at any time with effect for the future, and the lawfulness of processing carried out before the withdrawal remains unaffected. Independently of this you have the separately presented right to object under Art. 21 GDPR, see the next section. An email to my@intelligent-pixel.com is enough for any of these requests.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Art. 6(1)(f) GDPR, which covers the security processing described on this page. If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims. Art. 21(1) GDPR.
If you believe your rights under data protection law have not been respected, you have the right to lodge a complaint with the competent supervisory authority. For intelligent piXel GmbH, based in Starnberg, Bavaria, that authority is the Bayerisches Landesamt für Datenschutzaufsicht, BayLDA, Promenade 18, 91522 Ansbach, Germany.
We update this policy when the technical setup or the legal situation changes. This version is dated August 8, 2026.