Privacy Policy
Effective Date: August 5, 2026
This Privacy Policy explains how Hauke Jung ("we," "us," or "our") collects, uses and protects personal information when you use https://bollwark.eu, the Bollwark dashboard, and the hosted CAPTCHA service at api.bollwark.eu.
It is written for customers — people with a Bollwark account. If you arrived here because you saw a Bollwark check on somebody else's website, the document you want is the Visitor Privacy Notice.
We handle data under the General Data Protection Regulation (GDPR) and applicable German law.
Table of Contents
- Introduction
- The Two Roles We Play
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- Cookies and Tracking
- Data Security
- Data Retention
- Your Rights and Choices
- International Data Transfers
- Children's Privacy
- Third-Party Links
- Changes to This Policy
- Contact Information
1. Introduction
Hauke Jung, operating from Hauptstr. 41, 79199 Kirchzarten, Germany, provides Bollwark: a proof-of-work CAPTCHA that distinguishes humans from automated traffic without setting a single cookie.
The software is open source under the MIT licence and can be run by anyone on their own servers. If you self-host, we process nothing — no telemetry, no phone-home, no licence check. This policy covers the hosted service and this website.
2. The Two Roles We Play
This distinction runs through everything below, so it is worth stating plainly.
| Whose data | Our role | Governed by | |
|---|---|---|---|
| Your account — email, org, plan, billing, dashboard usage | Yours | Controller | This policy |
| Traffic hitting your site's checks — visitor IPs, headers, interaction counts | Your visitors' | Processor, acting on your instructions | Your privacy notice + our Visitor Privacy Notice |
For the second row you are the controller. You decide to put a check on your page, you need a lawful basis for it, and you are the one your visitors will contact about their rights. What we process on your behalf, and the minimisation applied to it, is documented in full in the Visitor Privacy Notice.
3. Information We Collect
a. Information you provide directly
- Account details — name, email address and authentication data
- Organisation details — organisation name, members, plan
- Site configuration — the domains and origins you register for a site key
- Billing information — processed by Polar; we never see or store your card number
- Support and communication — emails, GitHub issues, and anything you tell us in them
b. Information collected automatically
-
Server logs — request paths, timestamps, response codes and errors from bollwark.eu and the dashboard, kept for operations and security
-
Session data — a signed session cookie so you stay logged in (see Cookies)
-
Bot-protection signals on our own forms — we run Bollwark on our own signup and contact forms. It processes your IP address and basic interaction data exactly as described in the Visitor Privacy Notice: truncated before storage, no cookies, no fingerprint. Legal basis: Article 6(1)(f) GDPR.
-
Analytics — we use Umami, self-hosted on our own servers, to count page views and referrers. It sets no cookies and stores no persistent identifier: a visit is counted via a hash of IP address, user agent and a salt that rotates daily, so the same person is not recognisable across days and never across sites. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in understanding how the site is used.
There is no Google Analytics, no tag manager, no advertising pixel and no session-recording tool on this site, and no data from it is shared with an advertising network. Should that ever change, this policy will say so before it does.
c. Data we process on your behalf
Traffic data from checks running on your sites. We are the processor; see Section 2. It is stored with the visitor's IP address already truncated, and it is scoped to your organisation — no other customer can see your traffic, and you cannot see theirs.
4. How We Use Your Information
We use your information to:
- Provide the service — authenticate you, issue and rotate site keys, run checks, show you your dashboard
- Bill you and manage your subscription
- Keep the service secure — detect and prevent abuse of our own infrastructure
- Support you and respond to what you send us
- Improve the service — understand which features are used and where things break
- Comply with legal obligations under EU and German law, including tax and accounting retention
- Send you product updates or newsletters, only where you have explicitly consented; every one has an unsubscribe link
Operational messages about your account — a failed payment, a key rotation, an incident, a change to these terms — are contractually necessary and are not marketing. You cannot unsubscribe from those without closing your account.
5. How We Share Your Information
We do not sell personal information. We share it only as follows.
Sub-processors
| Sub-processor | Purpose | Location | Policy |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting and infrastructure | Germany (EU) | Privacy |
| Contabo GmbH | Server hosting and infrastructure | Germany (EU) | Privacy |
| FerrisKey (self-hosted) | Authentication and login | Our own servers (EU) | ferriskey.rs |
| Polar Software Inc. | Subscription billing and payments | EU/EEA processing | Privacy |
| Scaleway SAS | Transactional email delivery | France (EU) | Privacy |
Each acts as a processor under a data processing agreement and processes data within the EU or under appropriate safeguards.
Other disclosures
- Legal requirements — where compelled by law or a competent authority
- Business transfers — in a merger, acquisition or asset sale, with notice to you
- With your consent — where you explicitly authorise it
- Aggregated or anonymised data — for statistics and research, with no way to identify anyone
6. Cookies and Tracking
Bollwark's whole design premise is not needing them. In practice:
- The CAPTCHA widget sets no cookies at all — not on your site, not on ours. It also writes nothing to
localStorage,sessionStorageor IndexedDB. - The dashboard sets exactly one cookie, a signed session cookie, so you stay logged in. It is strictly necessary and expires after 7 days of inactivity.
- No analytics or marketing cookies exist on this site.
Because we store nothing on your device beyond that strictly necessary session cookie, no consent banner is required under § 25 TDDDG. The full detail is in the Cookie Policy.
7. Data Security
- HTTPS (TLS 1.2+) for all traffic, with the public certificate chain monitored externally every 15 minutes
- Encrypted storage and access-controlled infrastructure
- Administrative endpoints are unreachable from any browser — the dashboard talks to a server, and only the server holds credentials for the CAPTCHA service. A cross-origin call from a browser is refused by design.
- Tenant isolation is enforced server-side, on the result, before anything reaches a page. A session that cannot be resolved to an organisation sees nothing rather than everything.
- Data minimisation as a control — visitor IP addresses are truncated in the code path that writes them, so no configuration exists under which a full address is stored.
- Regular dependency and security updates
No system is 100% secure, and we do not claim absolute security.
8. Data Retention
| Data | Retention |
|---|---|
| Account and organisation data | For the life of the account, then deleted or anonymised |
| Traffic decision logs (your visitors) | Per your plan: 7, 30 or 365 days, then swept automatically. Default in the open-source software: 72 hours |
| Session data | 7 days of inactivity |
| Invoices and accounting records | 10 years, as required by German law (§ 147 AO, § 257 HGB) |
| Support correspondence | Up to 3 years |
| Server logs | Up to 90 days |
Closing your account deletes your account, your organisation and its traffic history from production systems; backups age out within 30 days. Records we are legally required to keep — chiefly invoices — are retained for the statutory period and used for nothing else.
You may request deletion at any time; see Your Rights.
9. Your Rights and Choices
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you
- Rectification — correct anything inaccurate or incomplete
- Erasure — have your data deleted ("right to be forgotten")
- Restriction — limit how we use it
- Portability — receive it in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — at any time, without affecting processing that already lawfully happened
Write to info@bollwark.eu. We respond within one month, as Article 12(3) requires.
Marketing communications
If you subscribe to our newsletter we process your email address to send it. The legal basis is your consent (Article 6(1)(a) GDPR), and you can withdraw it via the unsubscribe link in every message or by emailing us. Delivery is by Scaleway, a French provider processing exclusively within the EU. We keep your address only while you are subscribed.
Do Not Track
We do not track you, so there is nothing for a "Do Not Track" signal to switch off.
California (CCPA/CPRA)
California residents have comparable rights to know, delete, correct and opt out. We do not sell or share personal information. Use the contact details below.
10. International Data Transfers
Your data is stored and processed within the European Union, primarily in Germany. Where a sub-processor requires a transfer outside the EU, we ensure appropriate safeguards — Standard Contractual Clauses or an adequacy decision under Article 45 GDPR — are in place first.
11. Children's Privacy
The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal data from minors. If you believe a child has given us personal data, write to info@bollwark.eu and we will delete it.
12. Third-Party Links
This site and our documentation link to third-party sites such as GitHub. We are not responsible for their content or privacy practices. Read their policies before sharing personal data with them.
13. Changes to This Policy
We may update this policy as the service or the law changes. Material changes are announced by email or a prominent notice on this site, with a new effective date. Please review it periodically.
14. Contact Information
Data Controller:
Hauke Jung
Hauptstr. 41
79199 Kirchzarten, Germany
Email: info@bollwark.eu
We have not appointed a Data Protection Officer; we are not required to under Article 37 GDPR or § 38 BDSG.
If you believe your data has been handled improperly, you may lodge a complaint with your local supervisory authority. Ours is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI): baden-wuerttemberg.datenschutz.de.
© 2026 Hauke Jung. All rights reserved.