This is a translation for convenience. The German version is the authoritative one.
In short
This website sets no cookies and embeds nothing from third parties — which is why there is no consent banner either. The Aszendra browser sends exactly one thing outward: the question of whether a newer version exists. There are no accounts, no identifier and no telemetry.
1. Controller
David Baader, Heidkamp 1, 22399 Hamburg.
Email: hallo@aszendra.com
2. This website
Server logs
The website is hosted by Cloudflare Germany GmbH. Requests produce technical logs that may contain the IP address, timestamp, requested address, user agent and referrer. They serve secure operation and attack defence only.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in
undisturbed, secure operation.
Retention: Cloudflare keeps these logs for a few days by
default. We do not access them and do not combine them with anything.
Processing on our behalf
A data processing agreement under Art. 28 GDPR is in place with Cloudflare. Transfers to third countries are covered by the EU Commission's standard contractual clauses.
Cookies and analytics
None. This website sets no cookies, stores nothing in your browser, and embeds no fonts, maps, videos or scripts from third-party servers.
Download counting
When an installer is fetched, we count the event with the platform, version and date. No IP address, no user agent and no identifier is stored, and the numbers cannot be attributed to a person. We know there were 850 downloads on a given day, and never by whom.
Legal basis: Art. 6(1)(f) GDPR — interest in knowing whether and which versions are in use.
Email contact
If you write to us, we process what you send in order to answer. The legal basis is Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR for contractual matters. Messages are deleted once they are no longer needed and no retention obligation applies.
3. The Aszendra browser
What stays on your device
History, bookmarks, cookies, settings, open tabs, remembered site icons and the encrypted password vault are stored locally only. We have no access to them and there is no sync.
The update check
At most every four hours, Aszendra fetches a file from
dl.aszendra.com stating which version is the newest. This
transmits what every HTTPS request transmits — IP address and timestamp —
plus the installed version, the platform and the chosen channel.
Not transmitted: any installation or device identifier, pages visited, settings, or any content whatsoever. Even the staged rollout of new versions works without an identifier: your machine rolls a number for it locally and never sends it.
Legal basis: Art. 6(1)(f) GDPR — distributing security updates. The check can be switched off entirely in settings.
Crash reports
Are not transmitted. They stay local, and you decide for each one whether to send it to us.
Connections you initiate yourself
Opening a website, a search query to the configured search engine and fetching the ad blocker's filter lists all go to the respective providers. Their privacy terms apply.
Why there is no consent banner here
A banner is not a courtesy ritual but a consequence of
§ 25 TDDDG (the German implementation of the ePrivacy
rules): consent is required from whoever stores information on
the terminal device or accesses information already stored
there — cookies, but equally localStorage, identifiers in
the browser, or embedded third-party scripts that do such things.
This site does none of that, and you can check: it ships no JavaScript,
embeds nothing from foreign servers and writes nothing into your
browser. Measured on the start, download and this page: no cookies,
localStorage and sessionStorage empty, no
database, no service worker, zero connections to other
hosts.
Check rather than trust
Open the developer tools, tabs Network and Application. You will find the same list — an empty one.
What we do process is above: server logs at Cloudflare and a download count without IP address or identifier. Both happen on the server, not on your device, and rest on a legitimate interest — for which the GDPR provides a right to object, not a prior consent requirement.
A banner asking permission for something that never happens would not just be superfluous; it would be misleading.
A script we did not add
Cloudflare injects a bot-detection script of its own into every response
(/cdn-cgi/challenge-platform/). We did not ask for it and it
is not part of this site — but it does appear in the delivered source,
and we would rather say so than leave it out.
It is blocked by our own security policy and therefore never executes; it sets no cookie and opens no connection. We are working on switching it off entirely.
4. Your rights
You have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Write to hallo@aszendra.com.
You may also lodge a complaint with a data protection supervisory authority, for example the one responsible for our location.
5. Changes
If the processing changes, this statement changes with it. The date above says when it last did.