Privacy policy · Datenschutzerklärung

How this website
handles your data.

This website is deliberately minimal. It sets no cookies, loads no third-party fonts or embeds, and uses a privacy-friendly visitor counter that stores no personal data. The following information explains what is processed, and what your rights are under the General Data Protection Regulation (GDPR).

1. Controller

The controller responsible for data processing on this website within the meaning of Art. 4 (7) GDPR is:

Dr. Timo Strohmann
c/o University of Münster
European Research Center for Information Systems (ERCIS)
Leonardo-Campus 3
48149 Münster
Germany
Email: timo@strohmann.io

Since this is a private website without a legal obligation to appoint one, there is no data protection officer.

2. Hosting and server log files

This website is hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, United States (“Netlify”). When you access this website, the hosting provider’s servers automatically process technical information that your browser transmits, and store it temporarily in server log files. This typically includes:

  • the IP address of the requesting device,
  • date and time of the request,
  • the requested page or file and the amount of data transferred,
  • the HTTP status code,
  • the referring page (referrer), if transmitted by the browser, and
  • browser type, version, and operating system (user agent).

This data is processed to deliver the website reliably, to ensure the security and stability of the systems, and to detect and investigate misuse. The legal basis is Art. 6 (1) (f) GDPR. My legitimate interest lies in the secure and error-free operation of the website. Log data is not merged with other data sources and is not used to identify individual visitors. Netlify retains such log data only for as long as it is required for the secure and reliable operation of its platform and does not publish a fixed retention period; log data is not used by me to identify individual visitors and is deleted by Netlify once it is no longer needed, unless longer storage is required to investigate a specific security incident.

A data processing agreement in accordance with Art. 28 GDPR is in place with Netlify; it is incorporated in Netlify’s terms of service. Netlify is a company based in the United States, and data may therefore be processed outside the European Union. Netlify is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR), and additionally relies on the standard contractual clauses of the European Commission (Art. 46 (2) (c) GDPR). Further information is available in Netlify’s privacy policy at netlify.com/privacy.

3. Visitor statistics with GoatCounter

To understand how many people visit this website and which pages they read, I use GoatCounter, a privacy-friendly, open-source web statistics service operated by Martin Tournoij (GoatCounter, goatcounter.com) with servers in the European Union. GoatCounter is designed to work without cookies and without building profiles of individual visitors.

When you open a page, a small script loaded from GoatCounter’s servers sends the following to GoatCounter: the address of the page, the referring page if your browser transmits it, your browser type and operating system (user agent), your screen size, and the country derived from your IP address. To count how many different visitors a page has within a day, GoatCounter computes a hash from your IP address, user agent, and a random value that changes daily. The IP address itself is not stored, and the hash cannot be used to identify you or to recognize you on another day. No cookies or other identifiers are placed on your device.

On this site, GoatCounter additionally counts clicks on links to published papers and on the “Read the story behind the paper” links, so that I can see which publications attract interest. These counts are not tied to any person.

The legal basis is Art. 6 (1) (f) GDPR. My legitimate interest lies in understanding the reach of my academic work and in improving the website. Given the minimal and anonymous nature of the data, this processing does not require your consent. You can nevertheless prevent it by blocking scripts from gc.zgo.at in your browser or by using a content blocker. Statistics are kept in aggregated form for as long as the website exists. GoatCounter’s own privacy policy is available at goatcounter.com/help/privacy.

4. Cookies and embedded content

This website does not set cookies and does not use advertising or tracking services. Apart from the GoatCounter script described above, it does not load content from third-party servers: fonts, images, and stylesheets are delivered directly from the website’s own server. No social media plug-ins are used.

Your browser may use local storage for its own purposes, such as caching, but this website does not store any information on your device beyond what the browser does on its own.

5. External links

This website links to external websites, including Google Scholar, ORCID, publishers via DOI links, and other academic resources. When you follow such a link, you leave this website, and the privacy practices of the respective provider apply. I have no influence on the data processing there. Links are plain hyperlinks; no data is transmitted to the linked provider until you click.

6. Contact by email

If you contact me by email, I process the data you provide, such as your name, email address, and the content of your message, in order to handle your request and any follow-up questions. The legal basis is Art. 6 (1) (b) GDPR where the contact relates to a contract or pre-contractual measures, and otherwise Art. 6 (1) (f) GDPR, based on my legitimate interest in responding to inquiries. I delete the data when it is no longer needed for this purpose and no legal retention obligations apply. Emails are transmitted via the email provider’s servers; end-to-end encryption is not guaranteed unless we agree on it.

7. Recipients of data

Data is passed on only to the hosting provider named above and to GoatCounter for the anonymous visitor statistics described in section 3, and otherwise only if I am legally obliged to do so. Data is not sold or shared with third parties for their own purposes.

8. Your rights

Under the GDPR, you have the following rights with regard to your personal data:

  • the right of access (Art. 15 GDPR),
  • the right to rectification (Art. 16 GDPR),
  • the right to erasure (Art. 17 GDPR),
  • the right to restriction of processing (Art. 18 GDPR),
  • the right to data portability (Art. 20 GDPR),
  • the right to object to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR), and
  • where processing is based on consent, the right to withdraw that consent at any time with effect for the future (Art. 7 (3) GDPR).

To exercise these rights, contact me at the email address given above.

9. Right to lodge a complaint

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement. The supervisory authority responsible for me is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.

10. Automated decision-making

No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place on this website.

11. Changes to this policy

I may update this privacy policy to reflect changes to the website or to legal requirements. The current version is always available on this page.

Last updated: 7 September 2026.