Legal · Compliance
プライバシーポリシー
European Union · Germany · GDPR · DSGVO · BFSG · TDDDG.
This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data within our online offering and the websites, functions, and content connected with it (collectively, the "Service"). With regard to the terminology used (such as "processing" or "controller"), we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR / Regulation (EU) 2016/679) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, "BDSG").
1. Scope
This Privacy Policy applies to our public editorial / fan-promotional sites for the books listed above. The sites are non-commercial, contain no advertising, no analytics, no first-party cookies, and no third-party tracking.
2. Data Controller and Contact
The data controller pursuant to Art. 4 (7) GDPR is:
Graham Miranda UG (haftungsbeschränkt)
Hasselfelder Str. 23
38889 Blankenburg (Harz)
Germany
Telefon: +49 156 78397267
E-Mail: privacy@grahammiranda.network
Commercial Register: HRB 36794 (Amtsgericht Stendal) · D-U-N-S® 317 036 323 · USt-IdNr: DE459781189
3. Data Protection Officer
Pursuant to Art. 37 GDPR, the appointment of a Data Protection Officer is mandatory if the controller's core activities consist of processing on a large scale of special categories of data or of monitoring data subjects on a large scale. Neither applies to this Service. We have nevertheless voluntarily designated a contact point for privacy questions:
Data Protection Contact: dpo@grahammiranda.network
4. Categories of Personal Data
We process the following categories of personal data strictly to the extent described:
| Category | Description | Source |
|---|---|---|
| Server logs | IP address (truncated where possible), request URL, HTTP method, response status, user-agent string, referrer, timestamp | Automatically generated by the hosting provider when you visit the Site |
| Correspondence data | Name, e-mail address, message body, any attached files | You, when you contact us voluntarily |
| Local-storage preferences | UI language preference and cookie-banner acknowledgement | Your browser (localStorage, not a cookie) |
We do not process special categories of data within the meaning of Art. 9 (1) GDPR.
5. Legal Basis for Processing (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Provision of the website, technical security, defence against attacks | Art. 6 (1) (f) GDPR — legitimate interest |
| Handling of your enquiries (e-mail, contact form) | Art. 6 (1) (f) GDPR or Art. 6 (1) (b) GDPR — pre-contractual measures |
| Compliance with legal obligations (e.g. retention of commercial correspondence) | Art. 6 (1) (c) GDPR — legal obligation (e.g. § 257 HGB, § 147 AO) |
6. Recipients of Personal Data
Personal data is shared with:
- The hosting/CDN/DNS provider named below (Cloudflare, Inc.) necessary for technical operation.
- Public authorities, courts, or external advisors where we are legally obliged to do so (Art. 6 (1) (c) GDPR).
- Professional advisors (tax advisor, legal counsel) insofar as necessary for the operation of our business and bound by professional confidentiality.
7. Sub-Processors (Art. 28 GDPR)
We use the following sub-processor under a written Art. 28 GDPR processing agreement:
| Provider | Service | Data | Safeguard |
|---|---|---|---|
| Cloudflare, Inc. 101 Townsend Street, San Francisco, CA 94107, United States | Hosting, CDN, edge-cache, DDoS protection, DNS | Server logs (IP address, request URL, user agent, referrer, timestamp); encrypted in transit. | EU–US Data Privacy Framework (certified July 2023), Standard Contractual Clauses (SCCs) |
Current sub-processor list: https://www.cloudflare.com/cloudflare-customer-subprocessors/
8. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), we use the following safeguards:
- EU–US Data Privacy Framework (where the recipient is certified, valid from July 2023);
- Standard Contractual Clauses (SCCs) adopted by the European Commission (implementing decision (EU) 2021/914 of 4 June 2021);
- Where applicable, derogations under Art. 49 GDPR.
9. Retention Periods
| Data | Retention |
|---|---|
| Server logs | Typically 30 days; longer only where required for the investigation of specific incidents |
| Correspondence (e-mail) | For the duration of the enquiry and any follow-up; up to 6 years thereafter per § 257 HGB / § 147 AO |
| Cookies / localStorage | None — by design |
10. Your Rights (GDPR Arts. 12–22)
You have the right to:
- Access (Art. 15 GDPR);
- Rectification (Art. 16 GDPR);
- Erasure (Art. 17 GDPR);
- Restriction of processing (Art. 18 GDPR);
- Data portability (Art. 20 GDPR);
- Objection (Art. 21 GDPR) — in particular to processing based on Art. 6 (1) (f) GDPR;
- Withdrawal of consent (Art. 7 (3) GDPR);
- Lodging a complaint with a supervisory authority (Art. 77 GDPR).
To exercise these rights, contact us at privacy@grahammiranda.network. We will respond without undue delay, in any event within one month (Art. 12 (3) GDPR).
11. Changes to this Policy
We update this Privacy Policy to reflect changes in our processing or to legal requirements.
12. Valid from
15 December 2025
13. Right to Lodge a Complaint
The competent supervisory authority for our company is:
Landesbeauftragte für den Datenschutz und die Informationsfreiheit Sachsen-Anhalt
Leiterstraße 9, 39104 Magdeburg, Germany
Telefon: +49 391 81803-0 · E-Mail: poststelle@lfd.sachsen-anhalt.de
https://datenschutz.sachsen-anhalt.de