Portrait of Dieter Szegedi

Dieter Szegedi

Clarity, structure, and decisions in the context of AI and complex systems

Privacy

English translation for convenience. The German version is authoritative.

This website uses no cookies, no tracking, and no embedded third-party services.

Controller

Dieter Szegedi, Wilhelm-Geyer-Weg 5, 89075 Ulm, Germany

Email: dieter@szegedi.info

Website and server logs

This website is hosted on a server operated by a hosting provider in Germany. The provider processes the server data on my behalf.

When you access the website, technical information transmitted by your browser is processed (e.g. IP address, date and time of access, requested page or file, referrer URL, and user agent). It is used to operate the website securely and reliably, in particular to analyse errors and to detect and defend against attacks. The legal basis is Article 6(1)(f) GDPR. My legitimate interest is the secure and reliable operation of this website.

Server logs are retained for 7 days. Analyses that contain individual requests or could be linked to a person are deleted no later than the corresponding logs. Only aggregated statistics without a link to individuals may be retained for longer.

Contact by email

If you email me, I process your email address and the content of your message so that I can reply. If your enquiry concerns a possible or existing working relationship, the legal basis is Article 6(1)(b) GDPR; for other enquiries it is Article 6(1)(f) GDPR. In the latter case, my legitimate interest is responding to incoming messages.

My email service provider and its subprocessors process messages on my behalf. This may involve processing outside the European Union or the European Economic Area. Such transfers are based on an adequacy decision or the EU Standard Contractual Clauses. You may request information about the safeguards used by contacting me at the email address above.

Emails are retained for as long as needed to handle the enquiry and any related communication. Statutory retention obligations remain unaffected.

Notifications about new content

If you ask to be informed about new content, I process the email address you provide, your selected language, the subscription status, the timestamps needed for delivery and evidence, and the stable identifier and language-specific route of the content page on which you submit the form. I use the page information to evaluate in aggregate which content leads to confirmed subscriptions. The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw that consent at any time with effect for the future, using the unsubscribe link in every message or by email.

The subscription is activated only after confirmation through a link that is valid for 48 hours (double opt-in). Until then, only a temporary confirmation request is stored; no account is created, no address is assigned to an account, and no notification permission is activated. Only opening the link creates an account in the background for a new address or uses the account that already belongs to that address. The address is confirmed and notifications about new content are enabled for it. Before confirmation, the destination page shows the email address entered so that you can identify the request. After confirmation, opening the same link again shows only that the address has already been confirmed and does not show the email address. Apart from the single page on which the form is submitted, I store no history of visited pages as subscription data. In particular, no referrer URL, device identifier, or user-agent data is stored for this purpose. Messages contain no tracking pixels and no recipient-specific content links. Individual opens and clicks are not measured.

After a requested email has been accepted for delivery and after confirmation, your browser stores a purely local completion state for the current session. It is used only to hide the sign-up option during that visit, including in tabs that are already open. The state contains neither the email address nor a device identifier and is not used for analysis. It disappears when the browser session ends.

If you enter an address that has already been confirmed, the website response is indistinguishable from a new request. Only the message sent to that address explains that notifications are already active. It may also contain a personal, long-lived access link. The link contains no email address and provides neither access to data nor the ability to make changes. Opening it merely establishes the local session state described above. Issuing a new access link or unsubscribing invalidates the previous link.

The address is stored in encrypted form. A separately generated hash is used solely to prevent duplicate subscriptions and to respect unsubscribe requests. Confirmation, access, and unsubscribe tokens are excluded from access and application logs. Access and confirmation tokens are stored on the server only as hashes. Delivery uses Google Workspace. The information above about commissioned email processing and possible transfers to third countries applies accordingly.

Uncompleted confirmation requests are deleted after no more than 7 days. Active data is processed until you unsubscribe. After an unsubscribe or permanent delivery failure, the recoverable address is removed within 30 days. The address hash, attribution to the sign-up page, and evidence of subscription and unsubscribe events may be retained for up to 3 years to establish or defend legal claims. Aggregate evaluations by content page contain no email address. Recipient-related delivery records are generally deleted after 90 days.

Sign-in and protected texts

A sign-in lasts at most eight hours. The browser keeps the access token and associated sign-in data in session storage. Open tabs of this website can share them locally; no cookies are set for this purpose. Explicit sign-out revokes the shared token on the server. Closing a tab does not guarantee server-side revocation. On expiry, the browser resets the sign-in display; a suspended tab does so when it resumes.

The sign-in display uses locally known state. Comment requests include an available token so the server can select accessible comments. This makes it technically possible to associate the requested page with the account. No individual reading history is stored; comment, account and protected-content requests are excluded from this website’s own access log.

Access grants for protected texts store the account ID, content ID and grant time, with an optional expiry time. Text, associated private files and comments are delivered only after permission is checked. Grants are included in the account report and removed when the account is deleted. Revocation cannot recall copies already retrieved. Comments on protected texts are shown only to readers authorised to access those texts; these discussions currently generate no comment emails and their text is not sent to the connected AI assessor.

Public comments

You may voluntarily leave a public comment below a published text. The comment text, timestamp, specific page, and a technical version reference for the text are stored. A pseudonym is optional and serves only as the publicly visible label for that statement; it makes no claim about identity, quality, or entitlement. Without a pseudonym, the comment appears as “Anonymous reader”.

If you also provide an email address, you may voluntarily link the chosen presentation to personal access. The address is stored in encrypted form; a secret-keyed hash is used to find the access again without publishing the address. The link sent by email confirms the access. Its token is stored on the server only as a hash and is excluded from this website’s own access log. After opening it, the browser keeps the link value only in session storage; no cookie is set for this purpose.

In the settings, you can change the pseudonym for this access; the new name then also appears on earlier comments linked to it. For each confirmed email address of the account, you can also separately choose whether it receives notifications about new content. Changing this setting removes neither the address nor the account. You can download a machine-readable report of the associated account, comment, access, passkey and, where applicable, notification data, or delete the access. Deletion removes the email address, access links, pseudonym association, configured passkeys and linked notification data. Comments already published remain under the last pseudonym used but are no longer associated with an access. Removal of a published comment can still be requested separately.

When you set up a passkey, I store its identifier, the associated public key, and technical security data: the setup date and, where applicable, last-use date, a security counter, available transport methods, and the authenticator’s indication of whether the passkey is synchronised or backed up. These data are used solely for secure sign-in and protection against misuse. The secret part of the passkey remains on your device or in the password manager you choose. Biometric data, your device PIN, and comparable unlocking data are not transmitted to me. A short-lived one-time challenge is used for every setup and sign-in. Signing in with a passkey is an optional account function; the legal basis is Article 6(1)(b) GDPR. The security processing used to protect access is also based on Article 6(1)(f) GDPR; my legitimate interest is protecting the account from unauthorised access.

You can remove each configured passkey individually in the settings. This stops its use for signing in to szegedi.info; it does not delete the key from your device or password manager. A synchronised passkey can represent the same means of access on several of your devices. Removing it here therefore stops sign-in with that means of access on all synchronised copies. Synchronisation itself may be carried out by your operating-system or password-manager provider under its own responsibility; I have no access to it. Passkey data are retained until you remove them or delete the account.

Submitting the form makes the comment public immediately. The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw it with effect for the future and request removal of a comment using the email address above. Comments are generally stored for as long as they are made public with the relevant text or until their removal is requested. Publication and visibility are stored separately so that a comment can later be hidden without overwriting its original content.

An AI system operated by me may assess comments on a helpfulness scale from 1 to 10. This assessment does not decide publication; it serves only as an optional visibility filter controlled by each reader. The score, assessment time, and versions of the rubric and system are stored. Reassessment does not overwrite earlier assessments. If a comment is hidden, all replies below it are also hidden in the presentation. This does not produce a legal or similarly significant automated decision.

The selected minimum score for comment display continues to be stored only in the browser’s session storage. It contains no identifier, is not part of personal access, and disappears with the browser session.

To limit automated submissions, a secret-keyed short-lived value is derived transiently from the IP address; neither the address nor that value is stored in the comment record. Comment reads and submissions are excluded from this website’s own access log. Technically necessary processing by the hosting provider remains unaffected.

Dieter receives an email containing each new public comment and a link. Replies to a comment are sent to the confirmed email addresses of its associated account. Reply emails can be turned off for each address in the account, independently of notifications about new content. Unconfirmed addresses receive no reply emails. The messages contain no tracking pixels; their comment links are public and contain no personal access token.

Your rights

You may request access to, rectification or erasure of your data, or restriction of its processing and, where the legal requirements are met, data portability. You may object to processing based on legitimate interests. To exercise these rights, contact me at the email address above.

You may also lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.

Providing data and automated decisions

Transmission of the technical server data is necessary to deliver the website. Contact by email, subscription to notifications, and publishing a comment are voluntary. I cannot reply without a sender address and a message, and I cannot send notifications without an email address. No automated decision-making or profiling takes place.

Get notified about new content

We use the email address only to notify you about new content. Notifications begin only after confirmation. More information under Privacy.