Privacy policy
Last updated: September 2026
This is an English translation of the German privacy policy. Both say the same; if they ever differ, the German version applies.
1. Controller
Titus Hildebrand
Am Mühlbach 13, 93051 Regensburg, Germany
Phone: +49 176 83036085
Email: post@titus-hildebrand.de
2. Collection and storage of personal data
a) Visiting the website
The website runs on servers of STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. With every request, STRATO automatically stores log files containing your IP address, date and time, the address requested, the HTTP status code, the amount of data transferred, the page you came from, and your browser and operating system. This serves the secure and stable operation of the website, for example to detect attacks. The legal basis is my legitimate interest in this (Art. 6(1)(f) GDPR). STRATO stores the full IP address for no more than seven days; after that it is anonymised. I can only view the logs with anonymised IP addresses myself, and I only do so in the event of a fault or a suspected attack.
b) Contact by email or phone
If you email or call me, I process your contact details and the information in your message in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR if your enquiry aims at a contract, for example a quote for a website. For other enquiries, it is my legitimate interest in replying to you (Art. 6(1)(f) GDPR). The emails are kept in my mailbox at STRATO GmbH, and I retrieve them directly with the email program on my own devices; they are not forwarded to any other provider. I delete them once your enquiry has been dealt with, unless statutory retention obligations apply, for example to documents relating to an order.
c) Registration for and participation in the Delphi study
The Delphi study has been completed; registration is no longer possible. Participation was by invitation only. During registration and participation, the following data was collected and stored in a database on servers of STRATO GmbH:
- Full name
- Email address
- Password, stored only as a bcrypt hash (not reversible); the password itself is not stored
- Ratings of the metamodel elements (retain, adapt or remove) and the reasons given
- Self-assessment of knowledge and confidence in the rating (scale from 1 to 5)
- Where applicable, suggestions for additional metamodel classes and answers to questions about names
- Information on professional background (round 4): industry, role in the company, professional experience, age group, size of the organisation, and experience with business process management and with artificial intelligence. In the thesis, this information appears only in aggregated form, for example as a distribution across industries and roles.
- Time stamps of submission
The legal basis is the consent you gave when registering (Art. 6(1)(a) GDPR). The data is used exclusively for the scientific evaluation in my master’s thesis “Applying Artificial Intelligence to Process Optimization: A Delphi Study on Business Process Improvement Patterns” at the University of Regensburg. For the evaluation, I have transferred the answers to my computer. I will delete all data containing names on the server and on my computer as soon as the master’s thesis has been graded, and no later than 31 March 2027. In the thesis, answers appear only in aggregated form and without names. You can withdraw your consent at any time with effect for the future, most easily by deleting your account (menu under your name, “Delete account”) or by writing to me. I will then also delete your answers in my evaluation files. Results that have already been aggregated without names remain unaffected.
d) Example patterns from practice (round 5)
Round 5 is no longer part of the Delphi study but serves the same master’s thesis. Registered participants could voluntarily describe a case from their practice as an example pattern there. The entries for the attributes of the model are stored, linked to your account and the time of the last change, likewise in the database at STRATO GmbH. The entries are not supposed to contain specific figures, names of people or confidential details. An example pattern may appear in the thesis as an individual case example. Before it is used, the company concerned can review and approve it. The legal basis is your consent (Art. 6(1)(a) GDPR). I will delete the entries, like the other study data, as soon as the master’s thesis has been graded, and no later than 31 March 2027.
e) Client area for clients
For clients whose website I develop, there is a protected client area. An account is only created at my invitation: I enter the company and contact person and send an invitation link, valid for seven days, with which you set your own password. In the client area, I process the following, likewise in the database at STRATO GmbH:
- Name, email address and password of your account (the password only as a bcrypt hash)
- Your answers in the project questionnaire, with the time of saving and of sending
- Files you upload, such as photos, logos and documents, with the original file name, size and time. For photos, you confirm before uploading that any recognisable persons agree to the publication; this confirmation is stored as well.
- Invoices I make available to you there
- a log of activities, for example when an account was set up, the questionnaire was sent or a file was uploaded, without file names and without email addresses
As soon as you send the questionnaire or upload files, I receive an email. It names your company, the project, your name, the activity and the time, but no answers and no file names. The legal basis is the performance of our contract (Art. 6(1)(b) GDPR). I delete accounts, answers, uploaded files and the log no later than one year after the project has been completed. You can delete files and your account yourself at any time, and you can request the deletion of all data earlier at any time. I keep invoices for as long as tax law requires (section f).
f) Orders and invoices
For orders and invoices, I keep a client database, likewise on the server of STRATO GmbH. It stores the company or name, contact person, address, email address, phone number, whether you place the order as a business or as a private individual, my notes on the order, and the invoices. The legal basis is the performance of our contract (Art. 6(1)(b) GDPR) and, for invoices, additionally the statutory obligation to retain them (Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 14b of the German VAT Act (UStG)). I keep invoices for eight years, counted from the end of the year in which I issued them. Where tax law requires it, the tax office receives these documents. I delete the other client data as soon as I no longer need it for the order, queries or warranty claims and no statutory retention obligation applies any more, as a rule three years after the end of the year in which the order was completed.
g) Protection of logins
So that nobody can try out passwords or take over someone else’s account, I process the following when you log in, use “Forgot password” or change a password, likewise in the database at STRATO GmbH:
- Counters of wrong passwords, per account and per network address. For this, I store the network address and login names for which no account exists only as a checksum formed with a secret key. I delete counters for network addresses after 24 hours and counters for accounts 30 days after the last failed attempt; if an account is locked after a very large number of failed attempts, its counter remains until a new password is set.
- a security log with the time and type of event (such as login, wrong password, password changed, account deleted), the account concerned, the shortened network address (without its last part) and a short form of browser and operating system. Passwords and links are never included, and login names without an account only as a checksum. I delete the log after 90 days; this also applies to entries about a deleted account.
- Links for setting a new password, only as a checksum; they are valid for 60 minutes and only once.
- Browsers you have already logged in with: a random identifier from the cookie (see section 3), stored in the database only as a checksum, together with the time of the last login. I delete it 180 days after it was last used.
After every change of your password, you receive a short email so that you notice any misuse immediately. If wrong passwords pile up for an account or an account is locked, I receive an email with the address of that account so that I can step in. When you set a new password, I also check whether it is known from data breaches. For this, only the beginning of a checksum of the password (5 of 40 characters) is sent to the Pwned Passwords service of Have I Been Pwned, which is operated via Cloudflare. The password cannot be derived from this, and neither your email address, your name nor your network address is transmitted. The legal basis for all of this is my legitimate interest in protecting accounts against misuse and the obligation to process your data securely (Art. 6(1)(f) and Art. 32 GDPR).
3. Cookies and session
This website uses only technically necessary cookies. The session cookie (PHPSESSID) is only
set when you open the login page or “Forgot password”, open a link to the client area or for a new
password, or switch the language in the study or the client area. On all other pages, the language is part
of the address
(English pages start with /en/), which needs no cookie. The session cookie expires when you close the
browser or log out; a login also ends by itself after 30 minutes without activity (study: 60 minutes).
Anyone who only reads the other pages receives no cookie. The cookie contains nothing but a random
identifier and serves only the login session, the language you chose and the protection of forms. After a
successful login, the site sets a second cookie (__Host-device), which is valid for 180 days,
even after logging out. It contains only a random identifier and shows that this browser has logged in with
your account before: if someone else tries out passwords for your account, you can still log in from here
without waiting (see section 2g). In the questionnaire of the client area, your browser additionally keeps
entries that have not yet been saved in the memory of the open tab (sessionStorage) so that
they are not lost after a login has expired; this copy never leaves your device and disappears when the tab
is closed. All of this is permitted without consent under Section 25(2) no. 2 TDDDG, because it is strictly
necessary for logging in, the security of accounts and the language you chose. The legal basis for the
processing is the performance of your login and of our contract (Art. 6(1)(b) GDPR) and my legitimate
interest in secure forms and accounts (Art. 6(1)(f) GDPR). I do not use cookies for tracking, analytics or
advertising.
4. No content from other providers
The fonts, design and scripts of this website come exclusively from my own server. While you read the pages, your browser does not connect to any other provider. Only when you click a link to another website, for example to the App Store, Google Play or a press article, do the privacy notices of that provider apply.
5. Recipients of your data
I do not sell or rent out any data. The only recipients are:
- STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. It operates the server, database and email mailbox of this website in data centres in Germany and processes the data only on my behalf, on the basis of a data processing agreement (Art. 28 GDPR).
- Authorities to which I must pass on data by law, for example the tax office for invoices.
When new passwords are checked, only the beginning of a checksum is sent to the Pwned Passwords service (section 2g); neither the password nor your identity can be determined from it. Your data is not transferred to countries outside the European Union.
6. Your rights
You have the right
- to request information about the data stored about you (Art. 15 GDPR),
- to have incorrect data corrected (Art. 16 GDPR),
- to have your data deleted, unless a statutory retention obligation prevents this (Art. 17 GDPR). You can also delete an account on this site yourself; you will then receive a confirmation by email,
- to have the processing restricted (Art. 18 GDPR),
- to receive data you have provided to me, and which I process automatically on the basis of your consent or our contract, in a common, machine-readable format, or to have it transmitted to another controller (Art. 20 GDPR),
- to withdraw consent at any time with effect for the future (Art. 7(3) GDPR); processing carried out until then remains lawful,
- to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for me is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de (new tab).
Right to object under Art. 21 GDPR
Where I process data on the basis of my legitimate interest (Art. 6(1)(f) GDPR), for example the logs when you visit the website, emails outside an order and the data used to protect logins, you can object to this processing at any time on grounds relating to your particular situation. I will then no longer process this data unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. An informal message to post@titus-hildebrand.de is enough.
Do you have to provide data?
For an account, I need your name, your email address and a password; without them, I cannot set up an account. For an order, I need the information that must by law appear on an invoice; without it, I cannot accept the order. Participation in the study was voluntary. All other information is voluntary.
Automated decisions
I do not make automated decisions within the meaning of Art. 22 GDPR and do not create profiles. The waiting times after several wrong passwords are a technical protective measure, not a decision about you.
To exercise your rights, an email to post@titus-hildebrand.de is enough.
7. Data security
This website transmits all data in encrypted form (HTTPS); unencrypted requests are redirected. Passwords are stored exclusively as bcrypt hashes. Anyone who enters a password incorrectly several times has to wait increasingly long, and logins end after a period without activity (section 2g). Access to the database is restricted to the web server and is not publicly reachable.