Controller
Karl Philipp Nolte
Privacy
This page explains in a calm, readable form which data is processed across the website, contact flow, and join flow, and where external service boundaries begin.
Controller
Karl Philipp Nolte
Contact
hello@wateristheholygrail.com
Brevo
Used for signup and contact delivery
Controller
This privacy policy explains how personal data is processed in connection with this website. It is written with GDPR-oriented principles in mind and should be reviewed against the operator's actual hosting and legal setup before launch.
Karl Philipp Nolte
Email: hello@wateristheholygrail.com
Ostpreußenstr. 48, 45259 Essen, Germany
Hosting and Server Logs
This website is technically delivered via Vercel Inc.. When the website is accessed, technically necessary server log data may be processed, such as IP address, timestamp, requested resource, browser information, and referrer. This processing serves website delivery, stability, and security.
The legal basis is generally Art. 6(1)(f) GDPR insofar as processing is required for secure and functional website delivery.
Signup and EPUB Delivery
If you sign up through the join form, your email address, selected language, and signup source are processed to send a confirmation email, verify the signup via double opt-in, and then enable access to the EPUB plus future publication updates through the same channel.
Confirmation delivery and list management are handled technically through Brevo. The legal basis is your consent under Art. 6(1)(a) GDPR, which only becomes effective once the signup is actively confirmed. You can unsubscribe at any time through the respective email channel.
Contact Form
If you use the contact form, the data you enter is processed: first name, last name, email address, optional phone number, subject, and message. The submission is validated server-side, and an IP-based rate limit with short-lived in-memory storage is used for abuse protection.
To process your request, the form data is created or updated as a contact in Brevo. A confirmation email is sent to you, and an internal notification may also be triggered to the project address. Depending on the inquiry, the legal basis is Art. 6(1)(b) GDPR for pre-contractual or project-related requests, or Art. 6(1)(f) GDPR for other communication and abuse prevention.
Storage Duration
Contact inquiries are retained for as long as necessary to handle the request, any follow-up communication, and legitimate record-keeping needs. Join-signup data remains stored until you unsubscribe or the purpose no longer applies.
External Links and Platforms
This website contains links to external platforms such as Amazon, GitHub, and LinkedIn. When you follow those links, you leave this website. The privacy and content practices of those third parties are governed exclusively by their own notices and policies.
Analytics and Cookies
At the time of this version, no optional web analytics is enabled. This privacy-first default reduces compliance risk under GDPR/ePrivacy standards. If analytics or marketing tools are introduced later, legal basis, consent mechanism, and this policy must be updated before deployment.
Data Subject Rights
Subject to the applicable legal requirements, you may have rights of access, rectification, erasure, restriction of processing, data portability, and objection to certain processing activities. You may also have the right to lodge a complaint with a supervisory authority.
Updates to This Policy
This privacy policy may be updated if the site content, technical infrastructure, legal basis, or third-party services change. The version published on this website is authoritative.