Privacy notice
Last updated: 17 September 2026
Controller and contact
Patrick Proske, Schonenbachstrasse 1, 66989 Höhfröschen, Germany
Email: Patrick@h4nf.de
Further details: Legal notice.
Pulse: purpose and consent
Pulse helps H4NF understand which work is discovered and actively read. It is not used for advertising or profiling. Pulse starts only after your explicit choice in the privacy banner. You can withdraw or change that choice at any time through the fixed “Privacy” button.
Pulse relies on your consent under Article 6(1)(a) GDPR and, where terminal access is involved, section 25(1) TDDDG. Access to the site does not depend on consent.
Pulse data we process
- the predefined H4NF page and language version;
- server time of the page opening, qualified foreground time, and reading thresholds at 15, 30, 60, and 180 seconds;
- coarse scroll bucket and interaction-signal count;
- a random identifier for the current page opening only;
- a technical bot/quality classification;
- optionally, a country code resolved from the IP address on the H4NF server.
Pulse stores no full IP address, city, coordinates, search terms, full referrer, advertising ID, or persistent visitor identifier. Pulse uses no analytics cookies, local storage, or fingerprinting. Your banner choice is stored only as the h4nf_pulse_consent cookie in your browser for 180 days.
Recipients, geography, and transfers
Pulse is operated by H4NF. There is no external analytics provider and no disclosure for advertising. Country information is derived from a locally stored DB-IP Lite database; the IP address does not leave the H4NF server for this purpose. The required DB-IP attribution is displayed in the dashboard.
Retention
- technical Pulse events: 30 days;
- page-level Pulse visits: 180 days;
- daily aggregated Pulse statistics: 3 years;
- hashed Pulse-admin login-attempt security data: 7 days;
- your Pulse consent choice in the browser: 180 days or until changed/deleted.
Server logs
When the site is requested, the hosting provider processes technically necessary connection data, including the IP address, in server logs to deliver and secure the service. The Pulse endpoint must be configured with data-minimised logging and a maximum retention of 7 days; this server setting will be verified before production launch. Pulse itself does not store IP addresses.
Your rights
Subject to GDPR conditions, you have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent for the future. You may also complain to a data-protection supervisory authority. Contact us at the address above.