Skip to content
Aszendra Deutsch
Privacy

What we process, and what we don't

As of September 2026

This is a translation for convenience. The German version is the authoritative one.

In short

This website sets no cookies and embeds nothing from third parties — which is why there is no consent banner either. The Aszendra browser sends exactly one thing outward: the question of whether a newer version exists. There are no accounts, no identifier and no telemetry.

1. Controller

David Baader, Heidkamp 1, 22399 Hamburg.
Email: hallo@aszendra.com

2. This website

Server logs

The website is hosted by Cloudflare Germany GmbH. Requests produce technical logs that may contain the IP address, timestamp, requested address, user agent and referrer. They serve secure operation and attack defence only.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in undisturbed, secure operation.
Retention: Cloudflare keeps these logs for a few days by default. We do not access them and do not combine them with anything.

Processing on our behalf

A data processing agreement under Art. 28 GDPR is in place with Cloudflare. Transfers to third countries are covered by the EU Commission's standard contractual clauses.

Cookies and analytics

None. This website sets no cookies, stores nothing in your browser, and embeds no fonts, maps, videos or scripts from third-party servers.

Download counting

When an installer is fetched, we count the event with the platform, version and date. No IP address, no user agent and no identifier is stored, and the numbers cannot be attributed to a person. We know there were 850 downloads on a given day, and never by whom.

Legal basis: Art. 6(1)(f) GDPR — interest in knowing whether and which versions are in use.

Email contact

If you write to us, we process what you send in order to answer. The legal basis is Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR for contractual matters. Messages are deleted once they are no longer needed and no retention obligation applies.

3. The Aszendra browser

What stays on your device

History, bookmarks, cookies, settings, open tabs, remembered site icons and the encrypted password vault are stored locally only. We have no access to them and there is no sync.

The update check

At most every four hours, Aszendra fetches a file from dl.aszendra.com stating which version is the newest. This transmits what every HTTPS request transmits — IP address and timestamp — plus the installed version, the platform and the chosen channel.

Not transmitted: any installation or device identifier, pages visited, settings, or any content whatsoever. Even the staged rollout of new versions works without an identifier: your machine rolls a number for it locally and never sends it.

Legal basis: Art. 6(1)(f) GDPR — distributing security updates. The check can be switched off entirely in settings.

Crash reports

Are not transmitted. They stay local, and you decide for each one whether to send it to us.

Connections you initiate yourself

Opening a website, a search query to the configured search engine and fetching the ad blocker's filter lists all go to the respective providers. Their privacy terms apply.

Why there is no consent banner here

A banner is not a courtesy ritual but a consequence of § 25 TDDDG (the German implementation of the ePrivacy rules): consent is required from whoever stores information on the terminal device or accesses information already stored there — cookies, but equally localStorage, identifiers in the browser, or embedded third-party scripts that do such things.

This site does none of that, and you can check: it ships no JavaScript, embeds nothing from foreign servers and writes nothing into your browser. Measured on the start, download and this page: no cookies, localStorage and sessionStorage empty, no database, no service worker, zero connections to other hosts.

Check rather than trust

Open the developer tools, tabs Network and Application. You will find the same list — an empty one.

What we do process is above: server logs at Cloudflare and a download count without IP address or identifier. Both happen on the server, not on your device, and rest on a legitimate interest — for which the GDPR provides a right to object, not a prior consent requirement.

A banner asking permission for something that never happens would not just be superfluous; it would be misleading.

A script we did not add

Cloudflare injects a bot-detection script of its own into every response (/cdn-cgi/challenge-platform/). We did not ask for it and it is not part of this site — but it does appear in the delivered source, and we would rather say so than leave it out.

It is blocked by our own security policy and therefore never executes; it sets no cookie and opens no connection. We are working on switching it off entirely.

4. Your rights

You have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Write to hallo@aszendra.com.

You may also lodge a complaint with a data protection supervisory authority, for example the one responsible for our location.

5. Changes

If the processing changes, this statement changes with it. The date above says when it last did.