Privacy Policy
Last updated: August 13, 2026
This is a static personal website, built to collect as little as possible about you. There is no advertising, no tracking cookies, no contact form, and no newsletter on this site, and fonts are self-hosted, so loading a page makes no request to Google Fonts or any other third-party font provider. This policy explains the little that is processed when you visit, and your rights under the GDPR.
Who is responsible (controller)
Stephan Christopher Kuehn
Achlada Maleviziou 157
715 00 Heraklion, Crete
Greece
Email: me [at] stevenkeen [dot] com
A Data Protection Officer is not required for a website of this nature and has not been appointed. You can contact the controller directly at the address above on any data-protection matter.
Hosting and server logs (Mittwald)
The website is hosted by Mittwald CM Service GmbH & Co. KG, Germany (EU). When you load a page, the hosting provider automatically processes standard technical data in its server logs—your IP address, the page requested, the date and time, and your browser and operating system. This is necessary to deliver the site securely and to detect abuse. Legal basis: our legitimate interest in the secure, stable operation of the website (Article 6(1)(f) GDPR). These logs are retained for 60 days and then deleted.
Delivery and security (Cloudflare)
DNS, content delivery, and basic security (bot and DDoS protection) run through Cloudflare, Inc. (United States) in front of the hosting. To route and protect requests, Cloudflare processes technical connection data such as your IP address and may set a single strictly necessary security cookie; it is not used for tracking or to build a profile. Cloudflare is certified under the EU–U.S. Data Privacy Framework, and transfers are additionally covered by the European Commission’s Standard Contractual Clauses. Legal basis: legitimate interest (Article 6(1)(f) GDPR). These security and delivery logs are generated and held by Cloudflare for abuse detection and attack mitigation, and then deleted. Cloudflare sets that period itself and publishes no fixed figure for it, stating only that it keeps such data for a limited period; we do not receive, export or store these logs, so we can neither shorten nor extend it.
Website analytics (Umami)
We use Umami, a privacy-friendly analytics tool we host ourselves on our own server in Germany, to see which pages are read, which sites link to us, and roughly where in the world readers are. It sets no cookies and stores no IP address, no name and no email address, and no third-party analytics company receives the data. To tell one visit from another it derives a short code from your IP address and browser that cannot be turned back into either. Legal basis: legitimate interest (Article 6(1)(f) GDPR). Analytics records are kept for as long as this website operates. They contain no name, no email address and no IP address. Nothing is stored on your device, so no cookie banner is required. To opt out, switch on Do Not Track or Global Privacy Control in your browser: we stop counting you immediately, here and on every other site we run.
Cookies
This site sets no cookies of its own and stores nothing on your device. Cloudflare, which routes and protects this site, may set a strictly necessary security cookie to separate trusted visitors from malicious traffic. This requires no consent, so there is no cookie banner. If you reach this site through a campaign link, its parameters (UTM tags) appear only in the page address as anonymous context and are never stored on your device. This site sets no tracking, advertising, or analytics cookies of any kind.
Contact by email
If you email me [at] stevenkeen [dot] com, your message and address are used only to reply to you, and are not added to any mailing list.
International data transfers
Our hosting and our analytics both run on Mittwald’s servers in Germany, with Cloudflare in front as our content-delivery and security layer. Cloudflare is a US company, so some technical connection data may be processed there; this is safeguarded by the EU–U.S. Data Privacy Framework and the Standard Contractual Clauses.
Your rights
Under the GDPR you have the right to:
- access the personal data held about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict processing in certain circumstances (Art. 18);
- receive your data in a portable format (Art. 20); and
- object to processing based on legitimate interests (Art. 21)—for analytics, switch on Do Not Track or Global Privacy Control and we stop counting you at once.
To exercise any of these, email me [at] stevenkeen [dot] com. Arts. 15–20 apply to data that identifies you, which our analytics counts do not—your right to object always applies.
Right to lodge a complaint
If you believe your data has been processed unlawfully, you may lodge a complaint with a supervisory authority—in particular in the EU country where you live or work, or with the Hellenic Data Protection Authority in Greece, where this site is based (Kifissias Avenue 1-3, 115 23 Athens; www.dpa.gr).
External links
This site links to external websites—including CRETAN®, Fisher of Kids, Responsible Tourism, LinkedIn, and Instagram. Once you leave this site, those sites’ own privacy policies apply.
Automated decision-making
Your data is not used for any automated decision-making or profiling within the meaning of Art. 22 GDPR.
Changes to this policy
This policy may be updated to reflect changes in practice or the law. The current version is identified by the date shown at the top.