Privacy Policy
Responsible for this website within the meaning of Art. 4 No. 7 GDPR is intelligent piXel GmbH, International Institute of Forensic Expertise (IIFE), Enzianstrasse 4a, 82319 Starnberg, Germany. Managing Director: George A. Rauscher. You can reach us at george@rauscher.xyz and, for data protection matters, also at my@intelligent-pixel.com.
This website is deliberately minimal from a data protection perspective. We do not use analytics, marketing pixels, profiling, advertising cookies, embedded social widgets, or consent banners for third-party tracking, because we do not run that kind of stack here.
The website itself consists exclusively of published pages and blog articles. We do not collect, store, or process any visitor data beyond the technically necessary server communication described below. There are no user accounts, no comment sections, no newsletter lists, no form submissions stored on our servers, and no behavioral profiles of any kind.
When you browse the public pages, the only data processed is the connection data your browser automatically sends to the server (IP address, request time, requested URL, browser type) for the duration of the request. This data is logged for security purposes and deleted automatically after 14 days. No permanent record of your visit is created.
This website is hosted on server infrastructure operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in Germany, so hosting and the associated connection data are processed within the European Union. Hetzner acts as a processor under Art. 28 GDPR on the basis of a data processing agreement. The legal basis for hosting is our legitimate interest in the secure and efficient provision of this website under Art. 6(1)(f) GDPR.
This website is delivered through the BunnyCDN content delivery network operated by BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia. BunnyCDN is a processor under Art. 28 GDPR on the basis of a data processing agreement. When you access this website, your browser connects to the nearest BunnyCDN edge server first, not to our origin server. The edge server processes your IP address, the requested URL, the referrer, and standard HTTP headers to deliver cached content and to forward dynamic requests to the origin.
The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in the fast, reliable, and globally available delivery of this website. BunnyCDN operates edge servers in multiple regions worldwide. The company is based in Slovenia, an EU member state. Some sub-processors used by BunnyCDN for account management and support operate in the United States. BunnyCDN does not store the content of your requests beyond what is technically necessary for caching and forwarding.
The entire digital infrastructure of this website was designed, built, and is operated by intelligent piXel GmbH, Enzianstrasse 4a, 82319 Starnberg, Germany, a company specialized in server hardening and attack prevention. The physical hardware is provided by Hetzner Online GmbH in German data centers with certified physical security including alarm systems, video surveillance, and access control.
intelligent piXel GmbH is responsible for all layers above the hardware: the operating system, the web server, the application runtime, the security stack, and the website itself. This is not a hosted plan on a shared platform. It is a dedicated, single-tenant server under exclusive administrative control.
The core of the protection is IPServerSec, a hardening and early warning system developed in-house by intelligent piXel GmbH and operated across its entire server fleet. It is not a purchased plugin, not a subscription, and not a third-party service. It has grown over years from real attack patterns observed on production systems.
IPServerSec deploys traps for automated attack scanners. These are paths that a legitimate visitor never requests. The moment such a path is accessed, the source is permanently blocked, without a second chance and without prior warning. In parallel, an alert is sent by SMS and email to the administration within seconds.
The system also monitors every protected server twice daily for reachability, erroneous responses, and anomalies in access behavior. It consolidates the alerts of all protection layers into a single alarm chain and documents every incident in a traceable manner. Not as a report that someone reads eventually, but as a message that arrives on the phone within seconds.
For the operation of IPServerSec, your IP address is processed for attack detection, trap evaluation, and automatic blocking decisions. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in the protection of our systems and the data of our users against automated and manual attacks.
An AI-based web application firewall (CrowdSec AppSec) based on the OWASP Core Rule Set inspects every incoming request in real time. SQL injection, cross-site scripting, remote code execution, and local file inclusion attempts are stopped before they reach the application, not inside it.
The firewall processes the request path, request method, headers, and the source IP address for pattern matching and rule evaluation. Blocked requests are logged with timestamp, source IP, matched rule, and request metadata for forensic analysis. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in the integrity and availability of the website.
CrowdSec, an intrusion prevention system, evaluates all access and error logs, recognizes attack patterns, and blocks attacking IP addresses automatically. Global threat intelligence lists are incorporated into the local block decisions. Blocks escalate in tiers: twelve hours, then seventy-two hours, then permanent.
The processing of IP addresses, access patterns, and attack signatures is based on Art. 6(1)(f) GDPR. The legitimate interest is the defense against automated and manual attacks on the server infrastructure. Blocked IP addresses are stored for the duration of the respective block and are deleted automatically when the block expires.
AIDE (Advanced Intrusion Detection Environment) checks the integrity of all system files daily. If someone changes a single file that they are not authorized to change, this is detected and reported. The check covers the operating system, the web server configuration, the application code, and the security-critical root configuration files including SSH authorized keys and shell profiles.
AIDE does not process personal data directly. It compares file hashes against a trusted baseline. The purpose is the early detection of unauthorized system changes as a technical and organizational measure under Art. 32 GDPR.
Access from high-risk regions is blocked at the network level before it reaches the application. Country-based block lists for China, Russia, North Korea, Kazakhstan, and Bulgaria supplement the dynamic blocks of the intrusion prevention system. The processing of IP addresses for geo-IP evaluation is based on Art. 6(1)(f) GDPR, our legitimate interest in the prevention of attacks from regions with documented high attack activity.
Every connection to this website runs over TLS 1.2 or TLS 1.3 with certificates from the Let's Encrypt initiative. The certificates renew automatically. Expired encryption cannot occur as a result. The legal basis for the processing of connection metadata for the encrypted transport is Art. 6(1)(f) GDPR.
Every response from this website sets the following security headers: HTTP Strict Transport Security (HSTS), Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. These headers instruct your browser to enforce transport encryption, prevent clickjacking, block MIME-type confusion, restrict referrer leakage, and disable unused device permissions. The processing is based on Art. 6(1)(f) GDPR, our legitimate interest in the protection of the communication channel against manipulation.
This website runs under its own Unix user with strictly restricted file access and disabled system functions. A compromise remains isolated and cannot spread to other parts of the infrastructure. This is a technical and organizational measure under Art. 32 GDPR.
AppArmor enforces fine-grained access rules for all system services. Each process may do exactly what it is designed to do and nothing beyond that. The web server, the PHP runtime, the database, and the mail transport are each confined to their own AppArmor profile.
The PHP runtime runs with disabled functions for shell execution, process spawning, and file writes outside the designated upload paths. This prevents web shells from executing system commands even if an application vulnerability is exploited.
This website is not administered through a login area in the browser. All maintenance, all updates, and every system-level change run through the command line of the server, accessible only through a secured administrative connection. The WordPress administration areas are blocked for public access and effectively do not exist for internet visitors. There is no login form that could be attacked and no credentials that could be guessed. Anyone who calls these paths at all has thereby demonstrated that they do not belong there and is blocked immediately.
The processing of IP addresses for the evaluation of access attempts to blocked administration paths is based on Art. 6(1)(f) GDPR, our legitimate interest in the prevention of unauthorized access to the administration interface.
Outgoing emails are signed with DKIM (DomainKeys Identified Mail). Anyone who attempts to write in the name of this domain fails the signature check. The processing of email metadata for DKIM verification is based on Art. 6(1)(f) GDPR, our legitimate interest in the prevention of email spoofing and phishing in our name.
Through unattended-upgrades and Ubuntu Pro Extended Security Maintenance (ESM), the system receives security updates automatically, for the operating system as well as for the deployed applications. Canonical Livepatch applies security updates to the Linux kernel without a reboot. Critical vulnerabilities close while the website remains continuously available. These are technical and organizational measures under Art. 32 GDPR.
When you visit this website, the web server automatically processes connection data required to deliver the site and maintain operational security. This typically includes your IP address, date and time of access, the requested URL, the HTTP status code, the referrer, browser information, and similar technical metadata.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and abuse-resistant operation of the website, including error analysis, attack detection, and system integrity. Server log data is not used for profiling or marketing and is kept for a maximum of 14 days, after which the system deletes the log files automatically.
This public website does not use non-essential cookies. We do not use Google Analytics, Matomo, Meta Pixel, remarketing tools, behavioral tracking, or comparable visitor-analysis services.
No cross-site tracking takes place. No advertising profiles are created. No data is sold. If you simply browse the public pages, we do not build a dossier about you.
If you use the contact form, we process the information you enter there: your name, email address, optional subject selection, message content, consent confirmation, and technical anti-abuse data such as IP address and submission time.
The form data is not stored in a database. It is relayed directly via Proton Mail SMTP to the responsible mailbox and processed solely for the purpose of your inquiry. The mail transport provider is Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland. Switzerland benefits from an adequacy decision of the European Commission under Art. 45 GDPR. A data processing agreement under Art. 28 GDPR is in place with Proton AG.
For abuse protection, the system logs the event type, your IP address, and the sender email address in a security log. This log is kept separate from the website files, is not part of any backup, and is deleted automatically after 14 days. The message content itself is never stored on our servers.
The processing serves the handling of your inquiry, pre-contractual communication, and the protection of the form against abuse. The legal basis is Art. 6(1)(b) GDPR where your request relates to pre-contractual or contractual communication, and otherwise Art. 6(1)(f) GDPR, based on our legitimate interest in responding to serious inquiries and defending the contact channel against spam and misuse.
You may also contact us directly via Telegram at @intelligentpiXel. If you choose this channel, the content of your messages, your Telegram username, and any information you voluntarily share are processed through the Telegram messaging service. Anonymous contact is supported.
Telegram is operated by Telegram FZ-LLC and associated Telegram entities based in Dubai, United Arab Emirates, with server infrastructure in several jurisdictions. The United Arab Emirates is not covered by a European Commission adequacy decision under Art. 45 GDPR. When you initiate contact through Telegram, you do so on your own initiative and knowingly transfer your message data to this service. The transfer is based on your explicit request under Art. 49(1)(a) GDPR and on our legitimate interest under Art. 6(1)(f) GDPR in offering a low-friction, optionally anonymous contact channel.
Telegram applies its own privacy policy and terms to the transport and storage of your messages, and we have no control over that processing. If you prefer to keep your inquiry inside the European Union, please use the contact form or email instead.
For documents, evidence packages, or media files that need handling outside normal email, we offer an optional secure upload through a MEGA file-request link. This channel is operated by MEGA Limited, Auckland, New Zealand. New Zealand benefits from a European Commission adequacy decision under Art. 45 GDPR. A data processing agreement under Art. 28 GDPR is in place with MEGA Limited. Files are encrypted in your browser before upload.
Use of this channel is entirely voluntary and only relevant if you actively choose to send us files through it. Depending on the nature of your submission, the legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR. Uploaded material is retrieved and then removed from the upload area once it is no longer needed for the matter it relates to.
If you use one of our RustDesk remote-support clients, the remote session connects only to our own relay and server infrastructure in Germany. No third-party remote-support cloud is involved. Session data is processed solely to provide the support you requested, on the basis of Art. 6(1)(b) GDPR, and is not retained beyond what that support requires.
Article pages may offer voluntary share options for email, copying the article link, browser or operating-system sharing, and selected external platforms such as Facebook, X, LinkedIn, WhatsApp, Telegram, and Reddit. These are implemented as local controls or ordinary outbound links, not as embedded social widgets.
No connection to those external platforms is made when the article page loads. Data may be transmitted to the selected provider only if you actively click the corresponding share link. The provider then processes the request under its own responsibility and privacy policy. Email sharing opens your local mail application with a prepared subject and message text.
Inquiry data is not stored on our servers. The contact form relays your message directly to the responsible mailbox and keeps no copy of the message content. For abuse protection, the security log retains event type, IP address, and sender email address for a maximum of 14 days, after which it is deleted automatically.
If a business or case-related relationship results from the inquiry, communication records may be retained for the duration of that relationship and for any statutory retention periods that apply under commercial or tax law. Messages you send through Telegram remain subject to Telegram's own storage. Files you send through the secure upload are removed from the upload area when they are no longer needed. Server logs are retained for a maximum of 14 days. Blocked IP addresses are retained for the duration of the respective block.
No automated decision-making under Art. 22 GDPR takes place on this website. IP-based blocking decisions made by IPServerSec and CrowdSec serve exclusively the protection of the server infrastructure against automated and manual attacks. These decisions do not produce legal effects concerning you and do not significantly affect you in a similarly significant way. A block prevents access to this website only and does not have consequences beyond that access restriction.
If you believe that you have been blocked in error, you can contact us at my@intelligent-pixel.com and we will review the block manually.
The fonts used by this website are hosted locally as part of the theme assets. Your browser does not need to contact Google Fonts or other external font providers to render the public pages.
Aside from the technically necessary mail relay described above when you actively use the contact form, and the optional channels you may deliberately choose, we do not intentionally transfer visitor data to third-party marketing or analytics providers.
Under the GDPR, you have the right to request information about personal data concerning you, to request rectification of inaccurate data, erasure, restriction of processing, and data portability where the statutory requirements are met. You also have the right to object to processing based on Art. 6(1)(f) GDPR.
If processing is based on consent, you may withdraw that consent with effect for the future. To exercise your rights, send a message to my@intelligent-pixel.com or george@rauscher.xyz.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. The authority competent for intelligent piXel GmbH in Bavaria is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
We may update this privacy policy to reflect changes to our website, our contact channels, or the applicable legal requirements. The version published here is always the current one.
Last updated: 7 August 2026.