Skip to content
SOVEREIGNTYBALANE
Legal

Privacy

This site sets no cookies and embeds no third-party services. Visits are counted on our own server, without an identifier. What is processed is set out here.

This site tells companies to know their dependencies and to handle data sparingly. It holds itself to that. Which is why this statement is shorter than you are used to.

Controller

BALANE GmbH, Balanstraße 84, 81541 Munich, Germany. Email: contact@balane.tech. Full details are in the legal notice.

What this site does not do

  • No cookies. No cookie is set, not even a technically necessary one. Which is why there is no consent banner either.
  • No third-party analytics. No Google Analytics, no advertising pixel, no service that recognises you across other sites. Page views we count ourselves, on our own server and without an identifier — the next section says exactly how.
  • No third-party embeds. Fonts, icons and scripts are served from the same origin as the page — the counting script included. Your browser opens no connection to Google Fonts, to a social network, or to anybody else's server; check it in the network tab, exactly one host appears. That is a statement about your browser: the counted page view is relayed onward by our server to our own Umami instance, and the network tab will not show you that. The next section sets out what is transmitted.
  • No accounts. There is no registration and no login.

The sovereignty check

Your answers in the check are stored exclusively in your browser's local storage (localStorage, key sovereignty-check-v1). They are not transmitted to any server — including ours. The score and the roadmap are computed in your browser.

You delete this data by choosing "Start over" in the check, or by clearing your browser's storage for this site. We never have access to it.

Reach measurement

We count page views with Umami, open-source analytics software we run ourselves. We do it to know which pieces get read — not to know who reads them. So:

  • No cookie, no identifier in the browser. No cookie is set and no visitor ID is stored on your device. Umami derives a visit's session key on the server from website ID, IP address and browser identification, salted with a rotating value. That key stays on our instance, is not permanently tied to your device, and permits no recognition on other sites.
  • What is recorded. The address requested, the referring page, screen size, browser, operating system, language, and the country derived from your IP address. The IP address itself is used for that derivation and not stored.
  • No third-party server for your browser. The counting script and the page-view report both run through sovereignty.balane.tech/stats, the same address as the page itself; your browser talks to no analytics vendor. Our server then relays the report to our Umami instance — where that instance runs is stated below.
  • "Do Not Track" is honoured. If your browser sends that signal, no view is counted. A content blocker that blocks /stats does the same, as does setting the key umami.disabled to 1 in this site's local storage — the one key the counting script reads.

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is knowing which content on this site is read. Nothing is stored on your device; the only thing read from it is the opt-out key named above. On that basis we consider the counting exempt from consent and set no banner. We put that down as our assessment rather than as settled fact: whether such a read, and the combination of the details recorded, fall under § 25 TDDDG is not conclusively decided. If you see it differently, switch the counting off by any of the three routes above — it takes effect immediately and we never learn of it.

The Umami instance runs on infrastructure from Railway Corporation, a company based in the United States; a data processing agreement under Art. 28 GDPR is in place. We name it for the same reason we name the host: a site that tells companies to ask this question has to answer it about itself. The counted data stays on that instance, is not combined with other sources, and is passed to nobody.

Server logs

When you request a page, the host processes technically necessary connection data: IP address, time, requested address, volume transferred, browser identification and, where sent, the referring page. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is the secure and stable operation of the site. This data is not combined with other sources and is deleted after a short period.

Hosting

This site is operated on Vercel Inc., a company based in the United States. A data processing agreement under Art. 28 GDPR is in place; the transfer relies on the adequacy decision for the EU–US Data Privacy Framework.

We state this explicitly, because this site tells companies to ask exactly that question of their own providers. What is processed there is connection data from requests for public content and nothing else — this site has no accounts, no forms and no database. Your answers in the sovereignty check are not transmitted there, because they never leave your browser.

An account of why we consider this a contradiction, and what we are doing about it, is on "About this site".

Contacting us

If you write to us by email, we process what you send in order to handle your enquiry. The legal basis is Art. 6(1)(b) or (f) GDPR. We delete the message once it has been dealt with and no retention obligation applies.

Booking a call

The "Talk to us" page carries a link to our booking calendar at Cal.eu, the European Union deployment of Cal.com. The calendar is not embedded in this site: until you follow the link, no connection to that provider is made and no data reaches it.

Following the link takes you off this site, and the provider's privacy notice applies from that point. What is processed there is what you enter into the booking form yourself — normally your name, email address, the slot you pick and your time zone — along with the technical connection data of the request. We receive those details in order to keep the appointment. The legal basis is Art. 6(1)(b) GDPR, or for purely informational calls Art. 6(1)(f) GDPR, the legitimate interest being the initiation of a business relationship.

The provider processes the data as a processor under Art. 28 GDPR, within the European Union. We delete your booking details once the appointment has been dealt with and no retention obligation applies. If you would rather not use an external service, send us an email instead — the outcome is the same.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection. Please write to the address above. You may also lodge a complaint with a data protection supervisory authority; ours is the Bayerisches Landesamt für Datenschutzaufsicht.