Privacy Policy
As of 22 April 2026
This is a courtesy translation. The legally binding version is the German edition at /de/datenschutz; in case of doubt, the German wording prevails.
We take the protection of your personal data seriously and treat it confidentially in accordance with applicable data-protection law, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This policy explains which data we process when you visit our website and place a direct order, for what purpose, and on which legal basis.
1. Controller
Voss’scher Verlagc/o Vivian Voss
Hauptstr. 10
76872 Winden
Germany
E-mail: imprint@vossscher-verlag.com
Web: vossscher-verlag.com
2. Collection and processing of personal data
2.1 When you visit the website
When you load our website, your browser automatically transmits standard information to our server, as it does with any website request on the Internet. This consists exclusively of the technically unavoidable header data that every browser sends with every page request; none of it is publisher-specific or tracks your browsing behaviour.
The following data is transmitted without your active input by the browser and is briefly processed at the upstream reverse proxy (Caddy) for the purpose of repelling attacks (brute-force attempts, bot waves):
- Date and time of access
- Requested URL and HTTP status code
- Volume of data transferred
- Referrer URL (the previously visited page, if transmitted)
- Browser used and its version (User-Agent)
- Operating system used
Our server additionally operates an upstream packet-filter firewall (PF, the FreeBSD built-in). PF forwards legitimate traffic unchanged and records nothing; only when an attack pattern from a given IP address is detected within a short time-window (e. g. repeated login brute-force, port scans) is that IP added to a blocklist and blocked for a limited period. This blocklist contains exclusively attacking IPs and serves exclusively defensive purposes; the legal basis is the legitimate interest in the server's security (Art. 6 (1) (f) GDPR).
We do not store this data permanently. At the proxy level it is automatically deleted after at most 90 days. In the application-side logs of our publisher's web server ZERVO* your IP address is not captured to begin with. For operational diagnostics we measure only anonymised access counts, with no personal reference.
The remaining header data in our records is also not associated with any IP address or other identifier. At no point do we build a profile, a device fingerprint, or a session chain. We deliberately handle logging in a more data-frugal way than the law requires. The principle “what we do not store cannot be misused” is a matter of course for us.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the technical provision and security of the website).
* ZERVO is the proper name of our self-built publisher's web server (written in Rust), responsible for serving this website.
2.2 When you place a direct order
When you order a book directly via vossscher-verlag.com, we process the following data to perform the contract:
- First and last name
- Shipping address (street, number, optional address line 2, postal code, city, state/region, country)
- Optional: company, telephone number (for DHL customs handling outside the EU)
- E-mail address (for order confirmation and queries)
- Occasion: where you tell us about a gift occasion, the entry is used solely to choose a fitting hand-written dedication
- Ordered variant (hardcover or paperback) and payment details (see Section 4)
We use this data to fulfil your order, sign and ship the book, send an order confirmation, and respond to any questions you may have about your order.
Legal basis: Art. 6 (1) (b) GDPR (performance of a sales contract).
Retention period: ten years, where mandatory under German commercial and tax-record-retention obligations (§ 147 AO, § 257 HGB). Data not subject to these obligations is deleted as soon as the purpose of processing ceases.
3. Cookies and local storage
vossscher-verlag.com uses only technically necessary or preference-related first-party cookies and a corresponding local-storage entry. There is no reach measurement, no tracking and no profiling.
| Name | Purpose | Retention |
|---|---|---|
vvw-lang | Stores your selected language (English or German) so you land in the right language version on your next visit. | 12 months |
vvw-theme | Stores your brightness preference (light or dark) so the theme stays consistent across page views. | 12 months |
vvw-consent | Stores your cookie choice so the cookie notice does not reappear on every visit. | 12 months |
Because these cookies are either technically necessary or purely preference-related and do not enable any tracking, no consent under § 25 TTDSG is required. You may delete the cookies at any time via your browser’s settings.
Reset cookie consent → shows the cookie notice again if you wish to change your choice.
4. Payment processing via Stripe
Direct orders are processed through the payment service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Stripe processes your payment data (card number, IBAN, wallet token, etc.) on its own responsibility and according to its own privacy policy. We never store card or bank-account details. The only data visible to us is the Stripe transaction ID, the order amount and the success status.
Stripe complies with the PCI-DSS standard. For payments outside the EU, Stripe may transfer data to Stripe Inc. (USA); this transfer is based on EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Stripe’s privacy policy: stripe.com/en/privacy
Legal basis: Art. 6 (1) (b) GDPR (performance of a sales contract).
5. Shipping via DHL
To ship the book we transmit your shipping address and, where applicable, telephone number to DHL Group, Charles-de-Gaulle-Strasse 20, 53113 Bonn, Germany. DHL processes this data exclusively for the purpose of delivering your shipment and for tracking and (where applicable) customs notifications.
DHL’s privacy policy: dhl.com/global-en/home/footer/privacy-notice.html
Legal basis: Art. 6 (1) (b) GDPR (performance of a sales contract).
6. Hosting and technical operation
This website is hosted on infrastructure provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner acts as a processor within the meaning of Art. 28 GDPR; a corresponding agreement is in place. Hetzner has no access to content data but operates the underlying servers and data centre.
7. External links and sales channels
On the book pages we link to Amazon (sales platform for hardcover, paperback and Kindle). When you click an Amazon link you leave our website; from that point Amazon’s privacy terms apply. We do not use the Amazon affiliate programme and receive no tracking information about your click.
8. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses TLS encryption. You can recognise an encrypted connection by the lock icon in your browser’s address bar and the “https://” prefix in the URL.
9. Your rights as a data subject
Subject to statutory requirements, you have the following rights:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate or incomplete data (Art. 16 GDPR)
- Erasure of your data (“right to be forgotten”, Art. 17 GDPR), to the extent statutory retention obligations do not require continued storage
- Restriction of processing (Art. 18 GDPR)
- Data portability in a machine-readable format (Art. 20 GDPR)
- Objection to processing for reasons arising from your particular situation (Art. 21 GDPR)
- Withdrawal of consent once given, with effect for the future (Art. 7 (3) GDPR)
To exercise your rights, an informal e-mail to imprint@vossscher-verlag.com is sufficient.
10. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data-protection supervisory authority if you believe the processing of your data infringes applicable data-protection law. The competent authority for us as a controller based in Rhineland-Palatinate is:
The State Commissioner for Data Protection and Freedom of Information of Rhineland-PalatinateHintere Bleiche 34
55116 Mainz, Germany
datenschutz.rlp.de
11. Currency of this policy
This privacy policy applies in the version dated above. Further development of the website or amended legal requirements may necessitate updates. The latest version is always available at vossscher-verlag.com/en/privacy.