Skip to content

Privacy

Privacy Policy

This page explains in a calm, readable form which data is processed across the website, contact flow, and join flow, and where external service boundaries begin.

Controller

Karl Philipp Nolte

Contact

hello@wateristheholygrail.com

Brevo

Used for signup and contact delivery

01

Controller

This privacy policy explains how personal data is processed in connection with this website. It is written with GDPR-oriented principles in mind and should be reviewed against the operator's actual hosting and legal setup before launch.

Karl Philipp Nolte

Email: hello@wateristheholygrail.com

Ostpreußenstr. 48, 45259 Essen, Germany

02

Hosting and Server Logs

This website is technically delivered via Vercel Inc.. When the website is accessed, technically necessary server log data may be processed, such as IP address, timestamp, requested resource, browser information, and referrer. This processing serves website delivery, stability, and security.

The legal basis is generally Art. 6(1)(f) GDPR insofar as processing is required for secure and functional website delivery.

03

Signup and EPUB Delivery

If you sign up through the join form, your email address, selected language, and signup source are processed to send a confirmation email, verify the signup via double opt-in, and then enable access to the EPUB plus future publication updates through the same channel.

Confirmation delivery and list management are handled technically through Brevo. The legal basis is your consent under Art. 6(1)(a) GDPR, which only becomes effective once the signup is actively confirmed. You can unsubscribe at any time through the respective email channel.

04

Contact Form

If you use the contact form, the data you enter is processed: first name, last name, email address, optional phone number, subject, and message. The submission is validated server-side, and an IP-based rate limit with short-lived in-memory storage is used for abuse protection.

To process your request, the form data is created or updated as a contact in Brevo. A confirmation email is sent to you, and an internal notification may also be triggered to the project address. Depending on the inquiry, the legal basis is Art. 6(1)(b) GDPR for pre-contractual or project-related requests, or Art. 6(1)(f) GDPR for other communication and abuse prevention.

05

Storage Duration

Contact inquiries are retained for as long as necessary to handle the request, any follow-up communication, and legitimate record-keeping needs. Join-signup data remains stored until you unsubscribe or the purpose no longer applies.

06

External Links and Platforms

This website contains links to external platforms such as Amazon, GitHub, and LinkedIn. When you follow those links, you leave this website. The privacy and content practices of those third parties are governed exclusively by their own notices and policies.

07

Analytics and Cookies

At the time of this version, no optional web analytics is enabled. This privacy-first default reduces compliance risk under GDPR/ePrivacy standards. If analytics or marketing tools are introduced later, legal basis, consent mechanism, and this policy must be updated before deployment.

08

Data Subject Rights

Subject to the applicable legal requirements, you may have rights of access, rectification, erasure, restriction of processing, data portability, and objection to certain processing activities. You may also have the right to lodge a complaint with a supervisory authority.

09

Updates to This Policy

This privacy policy may be updated if the site content, technical infrastructure, legal basis, or third-party services change. The version published on this website is authoritative.