Skip to content
Malte Borggrewe PhD
About How I help Testimonials Projects FAQ Contact
Menu
About How I help Testimonials Projects FAQ Contact

Datenschutzerklärung

(English version below)

Stand: 25. August 2026

1. Verantwortlicher und Geltungsbereich

Verantwortlicher im Sinne der DSGVO ist:

Malte Borggrewe
Eppendorfer Weg 64
20259 Hamburg
Deutschland
E-Mail: hello@malteborggrewe.de

Diese Erklärung gilt für die Website malteborggrewe.de sowie für die Dienste app.malteborggrewe.de (Anwendungsportal) und auth.malteborggrewe.de (Registrierung und Anmeldung).

2. Hosting und Server-Logfiles

Die Website wird über GitHub Pages bereitgestellt, einen Dienst der GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. Die Dienste unter app.malteborggrewe.de und auth.malteborggrewe.de betreiben wir auf eigenen Servern bei der Hetzner Online GmbH in Deutschland; mit Hetzner besteht ein Vertrag zur Auftragsverarbeitung nach Art. 28 DSGVO.

Bei jedem Zugriff werden technisch notwendige Daten verarbeitet und in Server-Logfiles gespeichert: IP-Adresse, Datum und Uhrzeit des Zugriffs, die abgerufene Datei, übertragene Datenmenge, Referrer-URL sowie Browser und Betriebssystem. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO; unser berechtigtes Interesse liegt im sicheren und stabilen Betrieb und in der Abwehr von Angriffen. Die Logfiles werden gelöscht, sobald sie hierfür nicht mehr erforderlich sind, in der Regel innerhalb weniger Wochen.

Bei GitHub kann eine Übermittlung in die USA stattfinden; GitHub bzw. die Muttergesellschaft Microsoft ist unter dem EU-US Data Privacy Framework zertifiziert, ergänzend gelten die EU-Standardvertragsklauseln.

3. Nutzerkonto und Anwendungen

Für den Zugang zu den Anwendungen unter app.malteborggrewe.de ist ein Nutzerkonto erforderlich. Dabei verarbeiten wir Ihren Namen, Ihre E-Mail-Adresse, Ihr Passwort (ausschließlich als kryptografischer Hash gespeichert) sowie Zeitpunkt der Registrierung, Anmeldezeitpunkte und die dabei verwendete IP-Adresse. Registrierung und Anmeldung wickeln wir über die selbst betriebene Software Authentik auf unseren eigenen Servern ab.

Nach der Anmeldung werden die Anwendungen in einer für Ihre Sitzung erzeugten, isolierten Container-Umgebung bereitgestellt. Dabei verarbeiten wir technische Sitzungsdaten (Sitzungskennung, Start- und Endzeitpunkt, aufgerufene Anwendung). Dateien, die Sie in einer Sitzung hochladen, verbleiben ausschließlich in dieser Container-Umgebung und werden mit dem Ende der Sitzung gelöscht.

Für die Inhalte, die Sie hochladen, sind datenschutzrechtlich Sie verantwortlich. Enthalten diese personenbezogene Daten, verarbeiten wir sie ausschließlich weisungsgebunden für Sie als Auftragsverarbeiter auf Grundlage des Vertrags zur Auftragsverarbeitung, den Sie bei der Registrierung akzeptieren (Nutzungsbedingungen und Auftragsverarbeitung). Diese Datenschutzerklärung gilt insoweit nicht; maßgeblich ist die Datenschutzerklärung der von Ihnen vertretenen Stelle.

Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO (Bereitstellung des von Ihnen angeforderten Kontos und der Anwendungen); für die Protokollierung der Anmeldevorgänge Art. 6 Abs. 1 lit. f DSGVO i. V. m. Art. 32 DSGVO. Die Kontodaten speichern wir, solange das Nutzerkonto besteht. Sie können die Löschung Ihres Kontos jederzeit formlos per E-Mail verlangen.

4. Cookies

Wir setzen ausschließlich technisch notwendige Cookies ein, insbesondere zur Aufrechterhaltung Ihrer Anmeldung und zum Schutz vor Cross-Site-Request-Forgery. Eine Einwilligung ist nach § 25 Abs. 2 Nr. 2 TDDDG nicht erforderlich. Analyse-, Tracking- oder Marketing-Cookies setzen wir nicht ein.

5. Terminbuchung über Cal.com

Für die Vereinbarung von Terminen nutzen wir Cal.com der Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. Beim Aufruf unserer Seiten wird ein Skript von Cal.com geladen und dabei Ihre IP-Adresse an Cal.com übermittelt; Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an einer einfachen Terminvereinbarung). Buchen Sie einen Termin, verarbeitet Cal.com zusätzlich Ihre Angaben (Name, E-Mail-Adresse, gewählter Termin, optionale Angaben); Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO.

Mit Cal.com besteht ein Vertrag zur Auftragsverarbeitung nach Art. 28 DSGVO; für Übermittlungen in die USA gelten die EU-Standardvertragsklauseln.

6. Kontaktaufnahme und E-Mail-Versand

Wenn Sie uns per E-Mail kontaktieren, verarbeiten wir die von Ihnen mitgeteilten Daten zur Bearbeitung Ihrer Anfrage. Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO, sofern die Anfrage auf einen Vertrag gerichtet ist, andernfalls Art. 6 Abs. 1 lit. f DSGVO. Die Daten werden gelöscht, sobald die Anfrage abschließend bearbeitet ist und keine gesetzlichen Aufbewahrungspflichten bestehen.

Sämtliche E-Mails — persönliche Korrespondenz, System-E-Mails der Anwendungen (etwa Registrierungsbestätigung oder Zurücksetzen des Passworts) sowie E-Mails nach Ziffer 7 — versenden und empfangen wir über Google Workspace der Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland. Dabei werden Ihre E-Mail-Adresse und der Inhalt der Nachricht bei Google verarbeitet. Mit dem Anbieter besteht ein Vertrag zur Auftragsverarbeitung nach Art. 28 DSGVO; für Übermittlungen in die USA gelten die EU-Standardvertragsklauseln, ergänzend ist Google unter dem EU-US Data Privacy Framework zertifiziert.

7. Werbliche Ansprache

Die Anwendungen unter app.malteborggrewe.de stellen wir kostenfrei zur Verfügung. Im Gegenzug ist die Einwilligung in die werbliche Ansprache Bestandteil der Registrierung: Sie erteilen sie über ein gesondertes, nicht vorausgewähltes Kontrollkästchen, dessen Bestätigung für die Anlage eines Nutzerkontos erforderlich ist. Auf dieser Grundlage verwenden wir Ihren Namen und Ihre E-Mail-Adresse, um Sie zu unseren eigenen Leistungen und Angeboten zu kontaktieren — insbesondere zu neuen Tools auf der Plattform und zu einer möglichen Zusammenarbeit im Bereich Bioinformatik. Sollten wir künftig einen regelmäßigen Newsletter anbieten, erfolgt auch dessen Versand auf dieser Grundlage.

Rechtsgrundlage ist Art. 6 Abs. 1 lit. a DSGVO i. V. m. § 7 Abs. 2 Nr. 2 UWG. Eine Auswertung des Öffnungs- oder Klickverhaltens unserer E-Mails findet nicht statt.

Sie können die Einwilligung jederzeit mit Wirkung für die Zukunft widerrufen, formlos an hello@malteborggrewe.de oder durch eine Antwort auf jede unserer E-Mails; enthält eine E-Mail einen Abmeldelink, genügt auch dieser. Ihr Nutzerkonto und der Zugang zu den Anwendungen bleiben von einem Widerruf unberührt — die Nutzung der Anwendungen ist nach der Registrierung nicht davon abhängig, dass die Einwilligung fortbesteht. Nach dem Widerruf stellen wir den Versand unverzüglich ein. Zum Nachweis der Einwilligung speichern wir den Zeitpunkt der Erteilung sowie die dabei verwendete IP-Adresse und bewahren diesen Nachweis auch nach einem Widerruf für die Dauer der Verjährungsfristen auf (Art. 6 Abs. 1 lit. c DSGVO i. V. m. Art. 7 Abs. 1 DSGVO).

8. Empfänger und Datensicherheit

Eine Weitergabe erfolgt nur an die in dieser Erklärung genannten Auftragsverarbeiter sowie dann, wenn wir gesetzlich dazu verpflichtet sind. Eine Übermittlung zu Werbezwecken an Dritte findet nicht statt. Die Übertragung erfolgt durchgehend verschlüsselt über TLS, Passwörter werden ausschließlich als Hash gespeichert, und der Zugriff auf die Systeme ist auf die verantwortliche Person beschränkt. Eine automatisierte Entscheidungsfindung einschließlich Profiling nach Art. 22 DSGVO findet nicht statt.

9. Ihre Rechte

Sie haben das Recht auf Auskunft (Art. 15 DSGVO), Berichtigung (Art. 16 DSGVO), Löschung (Art. 17 DSGVO), Einschränkung der Verarbeitung (Art. 18 DSGVO), Datenübertragbarkeit (Art. 20 DSGVO) sowie auf Widerruf erteilter Einwilligungen mit Wirkung für die Zukunft (Art. 7 Abs. 3 DSGVO).

Widerspruchsrecht nach Art. 21 DSGVO: Soweit wir Daten auf Grundlage berechtigter Interessen nach Art. 6 Abs. 1 lit. f DSGVO verarbeiten, können Sie aus Gründen, die sich aus Ihrer besonderen Situation ergeben, jederzeit Widerspruch einlegen.

Zur Ausübung Ihrer Rechte genügt eine formlose Nachricht an hello@malteborggrewe.de. Ihnen steht zudem ein Beschwerderecht bei einer Aufsichtsbehörde zu; für uns zuständig ist:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22
20459 Hamburg
datenschutz-hamburg.de

Privacy Policy

Last updated: 25 August 2026

This is a translation for convenience. In case of discrepancies, the German version above prevails.

1. Controller and Scope

The controller within the meaning of the GDPR is:

Malte Borggrewe
Eppendorfer Weg 64
20259 Hamburg
Germany
Email: hello@malteborggrewe.de

This policy applies to the website malteborggrewe.de and to the services app.malteborggrewe.de (application portal) and auth.malteborggrewe.de (registration and sign-in).

2. Hosting and Server Log Files

The website is provided via GitHub Pages, a service of GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. The services at app.malteborggrewe.de and auth.malteborggrewe.de run on our own servers hosted by Hetzner Online GmbH in Germany; a data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.

Each access involves processing technically necessary data, which is stored in server log files: IP address, date and time of access, the file requested, the volume of data transferred, the referrer URL, and browser and operating system. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in secure and stable operation and in defending against attacks. Log files are deleted once they are no longer needed for this purpose, as a rule within a few weeks.

Data may be transferred to the USA in the case of GitHub; GitHub and its parent company Microsoft are certified under the EU-US Data Privacy Framework, supplemented by the EU Standard Contractual Clauses.

3. User Account and Applications

Access to the applications at app.malteborggrewe.de requires a user account. For this we process your name, email address, password (stored solely as a cryptographic hash), and the time of registration, sign-in times and the IP address used. Registration and sign-in are handled by Authentik, software we operate ourselves on our own servers.

After sign-in, the applications are provided in an isolated container environment created for your session. In doing so we process technical session data (session identifier, start and end time, application accessed). Files you upload during a session remain solely within that container environment and are deleted when the session ends.

For the content you upload, you are the controller under data protection law. Where it contains personal data, we process it solely on your instructions as your processor, on the basis of the data processing agreement you accept at registration (Terms of Use and Data Processing). This privacy policy does not apply to that content; the privacy notice of the organisation you represent governs it instead.

The legal basis is Art. 6(1)(b) GDPR (providing the account and applications you requested); for logging sign-in events it is Art. 6(1)(f) GDPR in conjunction with Art. 32 GDPR. Account data is stored for as long as the user account exists. You may request deletion of your account at any time by informal email.

4. Cookies

We use only technically necessary cookies, in particular to maintain your sign-in and to protect against cross-site request forgery. Consent is not required under § 25(2) no. 2 TDDDG. We do not use analytics, tracking or marketing cookies.

5. Appointment Booking via Cal.com

We use Cal.com, a service of Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA, for scheduling appointments. When you access our pages, a script is loaded from Cal.com and your IP address is transmitted to Cal.com; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in straightforward scheduling). If you book an appointment, Cal.com additionally processes the details you provide (name, email address, selected time, any optional information); the legal basis is Art. 6(1)(b) GDPR.

A data processing agreement pursuant to Art. 28 GDPR is in place with Cal.com; the EU Standard Contractual Clauses apply to transfers to the USA.

6. Contacting Us and Email Delivery

If you contact us by email, we process the data you provide in order to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a contract, otherwise Art. 6(1)(f) GDPR. The data is deleted once your enquiry has been conclusively dealt with and no statutory retention obligations apply.

All email — personal correspondence, system emails from the applications (such as registration confirmation or password reset) and the emails described in section 7 — is sent and received via Google Workspace, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Your email address and the content of the message are processed by Google in the course of this. A data processing agreement pursuant to Art. 28 GDPR is in place; the EU Standard Contractual Clauses apply to transfers to the USA, and Google is additionally certified under the EU-US Data Privacy Framework.

7. Marketing Contact

The applications at app.malteborggrewe.de are provided free of charge. In return, consent to marketing contact forms part of registration: you give it via a separate checkbox that is not pre-ticked and whose confirmation is required in order to create a user account. On this basis we use your name and email address to contact you about our own services and offers — in particular about new tools on the platform and about possible collaboration in bioinformatics. Should we offer a regular newsletter in future, it will also be sent on this basis.

The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with § 7(2) no. 2 UWG (German Act Against Unfair Competition). We do not analyse whether you open our emails or click links in them.

You may withdraw your consent at any time with effect for the future, by an informal message to hello@malteborggrewe.de or by replying to any of our emails; where an email contains an unsubscribe link, using that link is sufficient. Your user account and your access to the applications are unaffected by a withdrawal — once you have registered, use of the applications does not depend on the consent remaining in place. We stop sending immediately after a withdrawal. To demonstrate consent, we store the time it was given and the IP address used, and we retain this record after a withdrawal for the duration of the applicable limitation periods (Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR).

8. Recipients and Data Security

Your data is passed on only to the processors named in this policy and where we are legally obliged to do so. It is not transferred to third parties for advertising purposes. All transmission is encrypted via TLS, passwords are stored solely as hashes, and access to the systems is limited to the controller. Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.

9. Your Rights

You have the right of access (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR), to data portability (Art. 20 GDPR), and to withdraw consent with effect for the future (Art. 7(3) GDPR).

Right to object under Art. 21 GDPR: where we process data on the basis of legitimate interests under Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.

An informal message to hello@malteborggrewe.de is sufficient to exercise your rights. You also have the right to lodge a complaint with a supervisory authority; the authority responsible for us is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22
20459 Hamburg, Germany
datenschutz-hamburg.de

Navigation

About How I help Testimonials Projects FAQ Contact

More

Background Collaboration Expertise

Contact

Email LinkedIn

© 2026 Malte Borggrewe · Imprint · Privacy