-
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:CITY OF BAYREUTH
Neues Rathaus
Luitpoldplatz 13
95444 BayreuthP.O. Box 10 10 52
95410 Bayreuth
Tel.: +49 (0) 9 21 25 – 0
Fax: +49 (0) 9 21 25 – 13 05
E-mail: poststelle@stadt.bayreuth.deWhere this privacy notice refers to “we”, “us” or “our”, this shall mean the controller identified above.
-
Data Protection Officer
The following Data Protection Officer has been appointed for the controller:Data Protection Officer of the City of Bayreuth
Tel.: +49 (0) 9 21 25 – 13 55
E-mail: datenschutz@stadt.bayreuth.deYou may contact the Data Protection Officer at any time with any questions regarding data protection on this website.
-
General information on data processing
On this website, personal data are processed only to the extent that is technically necessary for the operation of a simple informational site.We do not carry out tracking for advertising or marketing purposes, do not create user profiles and do not use analytics tools such as Google Analytics or Matomo.
The processing of personal data is based exclusively on the GDPR, the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG) and the Telecommunications‑Digital Services Data Protection Act (Telekommunikation‑Digitale‑Dienste‑Datenschutz‑Gesetz – TDDDG).
-
Use of anti‑CSRF tokens (security cookies)
Nature and scope of processing
We use security tokens on our website to protect against so‑called cross‑site request forgery (CSRF) attacks.For this purpose, a randomly generated, unique identification key (token) is temporarily stored in a session cookie on your device or matched with your browser in order to ensure that form submissions or other state‑changing actions are actually initiated by you and not by a malicious third party.
Purpose of processing
The sole purpose of using these tokens is IT security and the protection of our website infrastructure as well as of your data against unauthorised access and misuse.Legal basis
The storage of the cookie and the access to information in your device are based on Section 25 (2) No. 2 TDDDG, as this measure is technically strictly necessary for the provision of the service expressly requested by you (secure submission of a form).The subsequent processing of data is based on Article 6 (1) (f) GDPR; our legitimate interest lies in ensuring data security and defending against cyber attacks.
Storage period
The CSRF token is bound to your current session and is automatically deleted as soon as you close your browser or the session expires (session cookie). -
Processing of access data and anonymised log files
Nature and scope of processing
When you access our website, the web server we use (NGINX) automatically records information in server log files.To protect your privacy as far as possible, we have configured the server so that all IP addresses (both the direct IP address and any proxy IP addresses) are automatically anonymised in the server’s working memory before being written to disk.
For IPv4 addresses, the last octet is removed (e.g. 192.168.1.XXX); for IPv6 addresses, the trailing part is truncated so that no link to an identified or identifiable person can be re‑established.
The following data are stored in this anonymised form:
-
Anonymised IP address of the requesting device and, where applicable, of the proxy
-
Date and time of access ($time_local)
-
Name of the requested file, HTTP method and protocol ($request)
-
HTTP status code of the server ($status) and of the internal application server ($upstream_status)
-
Volume of data transmitted in bytes ($body_bytes_sent and $upstream_response_length)
-
Website from which the access was made (referrer, $http_referer)
-
Browser type, version and operating system used ($http_user_agent)
-
Requested hostname ($host) and server name ($server_name)
-
Technical performance data such as total request time ($request_time), response time of the backend system ($upstream_response_time), internal routing address ($upstream_addr) and cache status ($upstream_cache_status).
-
The short‑term processing of the non‑anonymised IP address is performed solely in volatile memory for the technical handling of the request; the stored log data do not contain personal data once the masking has taken place.
Purpose of processing
The short‑term processing of the IP address and the subsequent storage of the anonymised data serve the purposes of technical administration, error diagnosis in interaction with our backend systems (upstream servers), performance optimisation and statistical evaluation of our website.Legal basis
The short‑term collection of the IP address at the moment of page access is based on Article 6 (1) (f) GDPR.Our legitimate interest is the error‑free provision and secure operation of our website infrastructure; because the data are anonymised immediately afterwards, your data protection interests are safeguarded.
Storage period
As the log files no longer contain personal data after automatic masking, they are not subject to strict deletion periods under the GDPR.We store these logs for 14 days for internal performance analysis and system monitoring, after which they are overwritten by more recent log data.
-
-
Performance and Web Analysis with Matomo
We use the open-source software tool Matomo on this website to analyze the surfing behavior of our users.Scope and Nature of ProcessingThis analysis is conducted exclusively in a privacy-friendly configuration:
-
No Cookies: No tracking cookies are stored on your device.
-
IP Anonymization: Your IP address is masked by removing the last two bytes immediately after collection and before storage (e.g., 192.168.xxx.xxx). This makes it impossible to trace the data back to you personally.
-
Local Hosting: The software runs exclusively on our website's servers. No data is transferred to Matomo or any other third parties.
Purpose of Data Processing
Processing this data allows us to analyze the use of our website. This helps us to continuously improve our platform and enhance its user-friendliness. By anonymizing the IP address, the interests of users regarding the protection of their personal data are sufficiently protected.Legal Basis
The legal basis for processing user data is our legitimate interest in optimizing and maintaining the economic operation of our online services pursuant to Art. 6 (1) (f) GDPR. -
-
Hosting and server provider (DigitalOcean)
Our website is hosted on servers of the following service provider:Parent company:
DigitalOcean, LLC
105 Edgeview Drive, Ste. 425
Broomfield, CO 80021
USAEuropean headquarters:
DigitalOcean EU B.V.
Zekeringstraat 17A
1014 BM Amsterdam
NetherlandsWe have concluded a data processing agreement with DigitalOcean pursuant to Article 28 GDPR, which in particular provides for appropriate safeguards for any international data transfers (e.g. EU standard contractual clauses).
The server locations we use are, according to our configuration, situated in a data centre within the European Union; should data be transferred to the USA in the course of the service, such transfers will be based on the aforementioned safeguards.
-
Rights of data subjects
Subject to the statutory requirements being met in the individual case, you have the following rights under the GDPR:-
Right of access to the personal data processed by us (Article 15 GDPR)
-
Right to rectification of inaccurate data (Article 16 GDPR)
-
Right to erasure (“right to be forgotten”, Article 17 GDPR), insofar as no statutory retention obligations apply
-
Right to restriction of processing (Article 18 GDPR)
-
Right to object to processing carried out on the basis of Article 6 (1) (f) GDPR (Article 21 GDPR)
-
Right to data portability (Article 20 GDPR), where applicable
-
Right to lodge a complaint with a supervisory authority (Article 77 GDPR).
-
You may exercise your rights at any time by contacting us or our Data Protection Officer.
The competent supervisory authority for the controller is the data protection authority responsible for the State of Bavaria; for municipal bodies in Bayreuth this is generally the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA).
-
-
External links
Our website may contain links to external websites over whose content and data protection practices we have no control.The processing of personal data by such third parties is governed exclusively by their own privacy notices.
-
Currency of this privacy notice
This privacy notice reflects the legal requirements of the GDPR and the TDDDG as applicable in 2026.
We reserve the right to amend this privacy notice if the scope of data processing on www.verstummte-stimmen.de or the underlying legal framework changes.