Legal
Last updated: 2 August 2026
This is a translation for convenience. The German version is the legally binding one.
Sebastian Selig
Birkenweg 15
25436 Moorrege
Germany
Email: hello@it-selig.de
No data protection officer has been appointed. The thresholds of Art. 37 GDPR and § 38 BDSG are not met.
Pushlog is a service for publishing changelogs. We process personal data only where it is necessary to run the service. We use no analytics, tracking or advertising services, and we do not sell data.
Pushlog runs on servers operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner.
The web server keeps no access log. Visitors' IP addresses, requested URLs, referrers and browser identifications are not stored persistently.
The web server and the application write operational and error messages to the server's system log. In individual cases these messages can contain personal data, such as an email address inside an error message. The purpose is technical operation, troubleshooting and abuse prevention. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is stable and secure operation.
Entries in the system log are deleted after 7 days.
We use strictly necessary cookies only:
These cookies are strictly necessary for the service you explicitly requested, so they are stored without consent under § 25(2)(2) TDDDG. There is no cookie banner because we set no cookies that require consent. No audience measurement and no cross-device tracking take place.
For an account we process:
The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary to perform the user agreement. Data is stored until the account is deleted. You can request deletion at any time by emailing hello@it-selig.de.
The registration form is protected by Cloudflare Turnstile, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Your IP address and technical browser characteristics are transmitted to Cloudflare in order to detect automated sign-ups.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is preventing spam and abusive registrations. Turnstile sets no cookies for tracking purposes. Transfer to the USA is based on the EU-U.S. Data Privacy Framework and supplementary standard contractual clauses. A data processing agreement under Art. 28 GDPR is in place with Cloudflare.
We use Resend to send email, a service of Resend, Inc., San Francisco, California, USA. The recipient address and the content of the message are transmitted.
We send confirmation and password reset messages (Art. 6(1)(b) GDPR) and changelog digests to confirmed subscribers (Art. 6(1)(a) GDPR). Transfer to the USA is based on standard contractual clauses under Art. 46 GDPR. A data processing agreement under Art. 28 GDPR is in place with Resend.
Paid plans are processed through Stripe, a service of Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
Payment details such as card numbers are processed exclusively by Stripe and are not transmitted to us or stored by us. Our database holds only a Stripe customer identifier linking your account to the subscription held there.
The legal basis is Art. 6(1)(b) GDPR. Invoice and accounting data is retained for 10 years under § 147 AO and § 257 HGB.
If you use the AI improvement feature for changelog entries, the bullet points you enter are transmitted to OpenAI, a service of OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland.
Transmission happens only when you actively trigger the feature. The legal basis is Art. 6(1)(b) GDPR, as this is a contractually promised feature. Under OpenAI's API terms the transmitted content is not used for training models and is retained only temporarily for abuse detection. A data processing agreement under Art. 28 GDPR is in place with OpenAI.
Please do not enter personal data about third parties or confidential information into this field.
Visitors to a changelog can sign up for email updates. For this we process the email address, the requested frequency, and the time of sign-up and confirmation.
Sign-up uses double opt-in: an address is only enabled for delivery after the confirmation link is clicked. The legal basis is Art. 6(1)(a) GDPR. Consent can be withdrawn at any time via the unsubscribe link in every email, after which the address is deleted.
For subscriber data belonging to a changelog we act on behalf of the operator of that changelog. That operator is responsible for their own processing.
Operators can publish their changelog under their own domain. The domain name is transmitted to Let's Encrypt, a service of the Internet Security Research Group, USA, in order to issue a TLS certificate. The legal basis is Art. 6(1)(b) GDPR. No personal data beyond the domain name is transmitted.
Through the contact form we process your name, email address and the content of your message. The details are forwarded to us by email only and are not stored in our database. The form is protected by Cloudflare Turnstile (see section 6).
The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR with our legitimate interest in responding. The resulting email correspondence is deleted once it is no longer required and no retention obligations apply.
The fonts DM Sans and Space Mono are downloaded at build time and served from our own server. No connection to Google is made when you load the page.
Transfers to the USA occur with Cloudflare, Resend and Let's Encrypt. They are safeguarded by the EU-U.S. Data Privacy Framework or by standard contractual clauses under Art. 46(2)(c) GDPR. Stripe and OpenAI are engaged through their Irish entities within the EU.
| Data | Retention |
|---|---|
| System log | 7 days |
| Account data | until the account is deleted |
| Subscriber data | until unsubscribed |
| Invoice and accounting data | 10 years (§ 147 AO, § 257 HGB) |
| Contact enquiries | until resolved |
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR).
You may object at any time to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR). Consent you have given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR).
To do so, simply write to hello@it-selig.de.
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
Holstenstraße 98
24103 Kiel
Germany
No automated decision-making, including profiling, under Art. 22 GDPR takes place.
We update this policy when the service or the legal situation changes. The version published on this page applies.