Privacy Policy
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
upright UG (haftungsbeschränkt)
Represented by: Stefan Kutzner (Managing Director)
An den Bruchteichen 26, 04575 Neukieritzsch, Germany
Email: info@up-right.de
Phone: +49 341/98994189
2. Overview of data processing
We operate a free calculator website for informational purposes. We strive to process as little personal data as possible. In particular:
- We do not offer user accounts or registration.
- We do not collect email addresses.
- We do not use Google Analytics or any cookie-based analytics tool.
- Calculator inputs (e.g. age, weight, income) are processed entirely in your browser and are never transmitted to our servers.
The following sections describe each processing activity, its purpose, legal basis, and retention period.
3. Hosting and Content Delivery Network (Cloudflare)
Our website is hosted on Cloudflare Pages and delivered via the Cloudflare Content Delivery Network (CDN). The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (hereinafter "Cloudflare").
When you access our website, Cloudflare automatically processes the following technical data to deliver the requested page and to ensure the security and stability of the website:
- IP address (anonymised/truncated by Cloudflare)
- Date and time of the request
- URL of the requested page
- Referrer URL
- Browser type and version
- Operating system
- Amount of data transferred
Cloudflare acts as a data processor on our behalf. We have concluded a Data Processing Agreement (DPA) with Cloudflare pursuant to Art. 28 GDPR.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure,
efficient, and reliable delivery of our website).
Retention: Server log data is retained by Cloudflare for up to
30 days and then automatically deleted.
For more information, see Cloudflare's Privacy Policy.
4. Web Analytics (Cloudflare Web Analytics)
We use Cloudflare Web Analytics, a privacy-focused, cookieless analytics service provided by Cloudflare, Inc. This service collects only aggregated, anonymised usage data (such as page views, referrer, country, device type) and does not:
- Set any cookies or use browser storage
- Track individual users or create user profiles
- Collect or store IP addresses
- Use fingerprinting techniques
Because Cloudflare Web Analytics does not process personal data and does not store information on end-user devices, it does not require consent under the GDPR or TDDDG.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in understanding aggregate website usage to improve our service).
5. Advertising (Google AdSense)
We use Google AdSense, a service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), to display advertisements on our website.
Google Consent Mode v2: AdSense scripts and advertising cookies are loaded
only after you have given explicit consent via our cookie banner. Until
consent is granted, the consent parameters ad_storage,
ad_user_data, and ad_personalization remain set to
denied. No data is transmitted to Google for advertising purposes without
your consent.
Once you consent, Google may set cookies to serve, personalise, and measure advertisements. For a list of specific cookies, see our Cookie Policy. For more information, see Google's Privacy Policy.
Legal basis: Art. 6(1)(a) GDPR (consent).
Retention: Advertising cookies vary by type; typically 6 to 24 months.
See our Cookie Policy for details.
6. Cookies and consent management
Our website itself does not set any cookies. We use a single first-party
localStorage entry (cookie-consent-v1) to store your consent
choice. This entry is necessary to fulfil our legal obligation to document consent
(Art. 7(1) GDPR) and does not require separate consent under Section 25(2) TDDDG.
Third-party cookies may be set by Google services only after you provide consent via our cookie banner. You can change or withdraw your consent at any time by clicking "Cookie Settings" in the website footer or by clearing your browser data.
Legal basis for storing the consent record: Art. 6(1)(c) GDPR (legal obligation to document consent).
7. Legal bases for processing
We process personal data on the following legal bases:
- Art. 6(1)(a) GDPR — Consent: For advertising cookies and any personalisation by Google AdSense. You may withdraw consent at any time with effect for the future.
- Art. 6(1)(c) GDPR — Legal obligation: For storing the consent record as required by Art. 7(1) GDPR.
- Art. 6(1)(f) GDPR — Legitimate interest: For server log files, security, abuse prevention, and the technical delivery of the website via Cloudflare CDN.
8. Recipients of data
We do not sell personal data. We share data only with the following recipients, and only to the extent necessary:
- Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) — hosting, CDN, DDoS protection, and web analytics. Cloudflare acts as a data processor pursuant to Art. 28 GDPR.
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) — advertising (AdSense), only after consent is given.
- Public authorities — only if legally required.
9. International data transfers
Both Google LLC and Cloudflare, Inc. are certified under the EU-US Data Privacy Framework (DPF). The European Commission has recognised the DPF as providing an adequate level of data protection (adequacy decision of 10 July 2023). Transfers of personal data to these companies in the United States therefore take place on the basis of Art. 45 GDPR.
Where additional safeguards are required, we rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR).
10. Data retention
- Server logs (Cloudflare): up to 30 days, then automatically deleted.
- Advertising cookies (Google): vary by cookie; typically 6 to 24 months. See our Cookie Policy for details.
- Consent record (
cookie-consent-v1): stored in your browser's localStorage until you clear it or revoke consent. - Calculator inputs: not stored — processed in your browser only, never transmitted.
11. Your rights under the GDPR
You have the following rights with respect to your personal data:
- Right of access (Art. 15 GDPR) — You can request information about the personal data we process about you.
- Right to rectification (Art. 16 GDPR) — You can request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR) — You can request the deletion of your data, subject to legal retention obligations.
- Right to restriction of processing (Art. 18 GDPR) — You can request that we restrict the processing of your data.
- Right to data portability (Art. 20 GDPR) — You can request to receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR) — You can object to processing based on legitimate interest at any time. We will cease processing unless we can demonstrate compelling legitimate grounds.
To exercise any of these rights, please contact us at info@up-right.de.
12. Right to withdraw consent
Pursuant to Art. 7(3) GDPR, you have the right to withdraw any consent you have given at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. You can withdraw your cookie consent at any time by clicking "Cookie Settings" in the website footer or by clearing your browser data.
13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). You may contact the supervisory authority in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement.
The supervisory authority responsible for us is the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte), Devrientstraße 5, 01067 Dresden, Germany, www.datenschutz.sachsen.de.
If you are in Germany, the competent authority depends on the federal state where the controller is established. A list of authorities is available at www.bfdi.bund.de .
14. Automated decision-making
We do not use automated decision-making, including profiling, as referred to in Art. 22(1) and (4) GDPR that produces legal effects concerning you or similarly significantly affects you.
15. Obligation to provide data
You are not required to provide personal data to use our website. The website functions fully without consent to advertising cookies — you simply will not see personalised advertisements.
16. Children
This website is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe that a child has provided personal data to us, please contact us so that we can delete it.
17. Changes to this policy
We may update this privacy policy from time to time to reflect changes in legal requirements or our data practices. The current version is always available on this page.
18. Contact
upright UG (haftungsbeschränkt)
Stefan Kutzner
An den Bruchteichen 26, 04575 Neukieritzsch, Germany
Email: info@up-right.de
Phone: +49 341/98994189