Privacy / Datenschutz

Privacy information grounded in the live configuration.

This page reflects the public site code, live DNS and proxy path, origin server, email routing and logging configuration inspected on 19 August 2026. Facts that could not be verified are identified without naming an assumed provider.

Version0.6
Effective date2026-08-17
Last updated2026-08-19

Cloudflare proxies public web traffic to a Hetzner Cloud origin in Helsinki. Caddy HTTP access logging is disabled. Cloudflare Email Routing is active, and external inbound delivery to the public address has been confirmed.

Controller / Verantwortlicher

Current contact point.

The confirmed controller identity fields are shared with the imprint and maintained centrally.

ControllerPhilipp Pusch
Postal contact detailsThe controller's service address is listed in the Imprint.
Contact email[email protected]
Editorial responsibilityPhilipp Pusch

Implementation inventory

What the repository currently shows.

This inventory reflects the tracked website, the deployed origin and the public DNS and response path, plus Research Radar tooling present on the server.

Public site

Static public pages

  • The tracked website is a static HTML/CSS/JavaScript site under public/.
  • No public user accounts, portal logins or browser-side API calls were identified in the tracked site pages.
  • No embedded third-party videos, widgets or remote web-font calls were identified in the tracked public pages.
Contact and submissions

Email-first communication

  • The public submission route currently uses a mailto: link to [email protected].
  • No repository-backed public contact form database or CRM integration was identified.
  • The web server does not receive the message content. The sender's email provider will process the message and its metadata when the link is used.
  • Cloudflare Email Routing receives messages for the public address and forwards them to a private Gmail mailbox controlled by Philipp Pusch. The private forwarding address is not published.
Cookies / storage

No non-essential browser storage identified

  • The tracked public script toggles mobile navigation and fills year placeholders only.
  • No cookies, localStorage or sessionStorage calls were identified in the tracked public website files.
  • No first-party analytics or advertising tracker was identified. Cloudflare adds Network Error Logging response headers as part of the web-delivery infrastructure.
Research Radar tooling

Research scripts are not visitor analytics

  • Repository tooling under research-radar/ and scripts/research-radar/ fetches public literature and vendor web sources when run by the operator.
  • Those scripts can also call the OpenAI API if the operator supplies credentials, but that is a server-side or local research workflow, not a browser-side tracker on the public site.
  • No active systemd service, timer or cron schedule for Research Radar was identified during this inspection.
  • The current data model is mainly vendor, product, claim, evidence and bibliographic metadata, with paper author names retained as scientific citation metadata.

Categories of personal data

What may be processed and why.

Website delivery was checked against the live Cloudflare response path and the Caddy origin configuration. Voluntary email and research data remain separate data flows.

Repository-backed facts

Directly visible from the codebase

  • Email address, name, role and message content if you choose to contact VetAI Trust by email.
  • Any evidence files, study links or factual corrections you voluntarily submit by email.
  • Scientific metadata such as author names, publication identifiers and source URLs in Research Radar paper records.
Verified web delivery

Website delivery metadata

  • Cloudflare receives connection and request data needed to proxy the site, which may include IP address, request time, requested host and path, headers, user-agent, TLS and security-event data.
  • The Hetzner origin receives proxied connections. Caddy HTTP access logs are disabled, so ordinary page requests are not written to an origin access log by Caddy.
  • Caddy service, TLS, certificate and error events can include timestamps, domain names and remote network addresses. They are written to systemd-journald and forwarded to /var/log/syslog.
  • No first-party audience profiling, advertising measurement or browser analytics was identified.
Purposes

Processing purposes

  • Publishing and maintaining the VetAI Trust website.
  • Receiving, reviewing and responding to submissions, corrections, vendor responses and general enquiries.
  • Documenting editorial reasoning, evidence provenance and update history.
  • Running Research Radar literature or vendor-claim monitoring when the operator chooses to use that tooling.
Legal bases

Legal-basis map

  • Website delivery and security: usually legitimate interests under Art. 6(1)(f) GDPR.
  • Responding to direct enquiries and submissions: usually Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on the nature of the request.
  • Editorial record-keeping for corrections, evidence provenance and publication accountability: usually Art. 6(1)(f) GDPR.
  • Where correspondence is necessary to enter into or perform an agreement, Art. 6(1)(b) GDPR may apply; other correspondence is generally handled on the basis of legitimate interests.

Recipients / processors

Services used in the verified production path.

Origin hostingHetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, provides the Cloud vServer in the hel1-dc2 availability zone in Helsinki, Finland.
DNS, reverse proxy and network reportingCloudflare, Inc. provides authoritative DNS, reverse proxy/CDN, edge TLS and security services. Public web traffic passes through Cloudflare, and response headers enable Cloudflare Network Error Logging in supporting browsers.
Email handlingThe site opens the visitor's email application and stores no message in a website database. Cloudflare Email Routing receives mail for the public address and forwards it to a private mailbox provided by Google LLC (Gmail). The private destination address is not published.
Public page integrationsNo third-party analytics, ad tech, remote fonts, embedded media or browser-side AI API calls were identified.
Internal Research Radar boundaryResearch Radar is capable of calling OpenAI and public literature or vendor sources when an operator runs and configures it. No active schedule was found, and stored run metadata does not identify a model or provider. It is not included here as a processor of website visitor data.
Retention

Retention and deletion

  • No browser-side storage by cookies, localStorage or sessionStorage was identified in the tracked public pages.
  • No repository-backed public submission database was identified.
  • The production policy is to retain server and infrastructure logs for no more than 14 days where technically configurable. Longer retention is permitted only where specifically necessary to investigate a security incident.
  • Caddy HTTP access logging is disabled. Caddy service and TLS events remain in persistent journald storage, which enforces an explicit MaxRetentionSec=14day limit.
  • Those events are also forwarded to /var/log/syslog. The relevant system logs rotate daily with 14 archives and an explicit maximum age of 14 days; the system logrotate timer runs daily.
  • General enquiries and submissions are retained only while required for processing and legitimate follow-up. Unresolved or otherwise non-required correspondence is reviewed after 12 months. Statutory retention duties and requirements connected with legal claims override this schedule where applicable.
International transfers

Current infrastructure locations

  • No browser-side third-party tracking transfers were identified in the tracked public pages.
  • The Hetzner origin is located in Helsinki, Finland, within the European Union.
  • Cloudflare operates a global reverse-proxy network. The applicable transfer mechanism depends on the operator's Cloudflare agreement; account-level acceptance of a data processing agreement could not be verified on this server.
  • Cloudflare Email Routing and the private Gmail destination may involve processing outside the European Union under the respective provider terms. Optional Research Radar API calls are an internal editorial workflow and are not triggered by website visitors.
Your rights

Data-subject rights

  • You may request information about whether personal data concerning you is processed and seek access, rectification, erasure, restriction or objection as applicable.
  • Use the contact details on the contact page or the imprint to make a request.
  • You also have the right to lodge a complaint with the competent supervisory authority, in particular in the EU member state of your habitual residence, workplace or the operator's seat.
Updates

Policy changes

  • This page should be updated whenever the public site adds analytics, embedded third-party content, a contact form, accounts or materially different data flows.
  • The visible version metadata at the top of the page is part of the policy baseline.
  • Legal review is still recommended before this text is treated as final counsel-approved language.

Related trust pages

Connected policies.

Privacy covers personal data. Data Policy covers benchmark and evidence materials. Contact and Corrections explain how people can raise concerns and send information.