Artur Susdorf, Franz-Sigrist-Str. 6, 79206 Breisach am Rhein, Germany. Data-protection contact: privacy@zetlyn.com.
/route endpoint takes an
optional have= list of URLs so it can plan a reading order that does not repeat what
you have. That is a reading history, and it is treated like the query: used to answer the request,
then gone. It is not stored and not logged. The website does not send it; only an API client that
chooses to./report-edge), the report is appended to a log file. It contains the two page
identifiers, the relation kind, the note you submit, a timestamp and your IP
address, kept to make abuse of that endpoint traceable (Art. 6 (1) (f) GDPR). No account
is required. If you would rather report a relation without sending one, write to
privacy@zetlyn.com instead. This is the only place where an
address is written down, and it happens only if you press that button.The site is served by Caddy on a server rented from Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany), acting as processor. A move to netcup GmbH is planned; this page will name whoever holds the server.
There is no access log. Caddy does not write one unless it is asked to, and it is not asked to: its journal holds only service events — start, reload, TLS certificate renewal — a few hundred lines in total. No request line is recorded, so no IP address, requested path, query string, user agent or referrer is retained by the web layer. This is why the query record described above contains no address: the web layer never sees one that could be written next to it, and the application is not given one. The query text is recorded by the application deliberately and by itself; everything the web layer could have added is absent because it is never collected.
The machine runs other, unrelated services whose own logs sit in the same system journal. Those are not part of this service and no Zetlyn request data is among them.
Separately, Zetlyn's crawler fetches public pages to build the index. What it stores and how to block it is described on the crawler page. Operators of crawled sites can request removal via the contact there.
On the query records, we have to tell you what we cannot do. They carry no
identifier, so there is no way to find the entries that came from you — not for us either. We cannot
produce them on request, correct them or delete them individually, because nothing connects them to a
person (Art. 11 (2) GDPR). That is a consequence of collecting less, not a refusal: the alternative
would be to store something identifying so that it could later be searched for. Reported relations
(/report-edge) DO contain your address and can be found and erased — write to the
contact below.
Under the GDPR you have the right to access, rectification, erasure, restriction, objection and data portability, and to lodge a complaint with a supervisory authority. The competent authority here is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg — the state data-protection commissioner for Baden-Württemberg. Contact us at privacy@zetlyn.com.