Andrej Kisselev, Kisselev IT
Vallendarer Str. 6, 51105 Köln, Deutschland
E-Mail: [email protected]
Ein Datenschutzbeauftragter ist nicht zu benennen (§ 38 BDSG).
Über die Website werden Ausmalvorlagen bereitgestellt; ausgemalte Zeichnungen können abfotografiert und hochgeladen werden, und daraus entstehen Figuren in einem persönlichen Aquarium, das über eine Kurzadresse und ein eigenes Passwort geteilt werden kann.
Daten: IP-Adresse, Zeitpunkt, angeforderte Adresse, Statuscode, übertragene Datenmenge, Referrer, Browserkennung.
Zweck: Auslieferung, Betriebssicherheit, Fehleranalyse, Angriffsabwehr. Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO.
Speicherdauer der Protokolle von Webserver und vorgeschaltetem Netzwerkdienst: noch festzulegen.
Ohne Einwilligung gesetzt (§ 25 Abs. 2 Nr. 2 TDDDG), Rechtsgrundlage Art. 6 Abs. 1 lit. b bzw. lit. f DSGVO.
| Cookie | Zweck | Laufzeit |
|---|---|---|
pt_session |
Hält Sie angemeldet. Enthält ein Zufallstoken; serverseitig liegt nur dessen Hashwert. | 30 Tage |
pt_tank_<Kurz-ID> |
Nachweis, dass das Aquarium-Passwort eingegeben wurde. | 12 Stunden |
pt_console |
Anmeldung an der Betreiberkonsole. Nur bei Administratoren. | Sitzungsbezogen |
Wir betreiben eine eigene, schlanke Reichweitenmessung ohne Drittanbieter.
Im Cookie pt_visitor liegt eine rein zufällige Kennung mit zwei
Jahren Laufzeit. Je Seitenaufruf werden nur diese Kennung, der Pfad und die
Verweildauer übermittelt; bei angemeldetem Konto zusätzlich dessen Kennung.
Keine IP-Speicherung, keine Übermittlung an Dritte, kein Nachladen von
fremden Servern.
Rechtsgrundlage: Einwilligung nach § 25 Abs. 1 TDDDG und Art. 6 Abs. 1 lit. a DSGVO. Speicherdauer: 2 Jahre.
Hinweis: Dieser Abschnitt beschreibt den rechtlich gebotenen Zustand. Ein Einwilligungsdialog ist noch nicht umgesetzt; bis dahin trifft die Beschreibung nicht zu.
Daten: E-Mail-Adresse, Passwort (nur als scrypt-Hashwert, nie im Klartext), Sprache, Zeitpunkte von Registrierung und E-Mail-Bestätigung, gegebenenfalls einer Kontosperre.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO; Missbrauchsabwehr lit. f. Speicherdauer: bis zur Löschung des Kontos. Bestätigungs- und Zurücksetzungs-Token nur als Hashwert und nur bis zum Ablauf (48 Stunden) oder zur Verwendung.
Zu jeder Anmeldung speichern wir Hashwert des Sitzungstokens, Zeitpunkte und Browserkennung — damit Sitzungen gezielt beendet werden können.
Bei der Passwortvergabe prüfen wir gegen bekannte Datenlecks. Dazu bildet unser Server einen SHA-1-Hashwert und sendet nur dessen erste fünf Zeichen an „Have I Been Pwned"; der Abgleich passiert danach bei uns. Das Passwort verlässt den Server nicht, der Dienst erfährt nicht, wonach gesucht wurde, und Ihre IP-Adresse wird nicht übermittelt — die Anfrage stellt unser Server, nicht Ihr Browser.
Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO (Kontosicherheit).
Daten: Name und Kurzadresse des Aquariums, dessen Passwort (nur als Hashwert), hochgeladene Fotos und Hintergründe, daraus erzeugte Bilddateien und Vorschaubilder, Art und Titel der Figuren, Zeitstempel.
Bilddateien werden nicht frei ausgeliefert, sondern nur über eine Schnittstelle, die bei jedem Aufruf die Berechtigung prüft.
Zeichnungen von Kindern: Bitte laden Sie keine Fotos hoch, auf denen Personen abgebildet sind, und keine Zeichnungen mit Namen, Anschriften oder anderen identifizierenden Angaben. Für die Rechtmäßigkeit der Inhalte sind Sie verantwortlich.
Speicherdauer: bis zur Löschung durch Sie. Gelöschtes liegt 30 Tage im Papierkorb und ist so lange wiederherstellbar, danach ist es weg.
Wenn Sie Kurzadresse und Passwort weitergeben, können die Empfänger die Inhalte sehen. Wem Sie das geben, entscheiden allein Sie.
Fehlversuche am Aquarium-Passwort protokollieren wir je Aquarium mit Zeitpunkt, Ergebnis und einem Hashwert der IP-Adresse — nicht der Adresse selbst (Art. 6 Abs. 1 lit. f DSGVO).
Die Bezahlseite stellt Stripe bereit. Zahlungsdaten wie Kartennummern erreichen unseren Server zu keinem Zeitpunkt.
Anbieter: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Irland.
An Stripe: Betrag, Währung, Produktbezeichnung, Bestellnummer, interne Kennungen — dazu, was Sie selbst auf der Bezahlseite eingeben. Zurück an uns: Zahlungsstatus und Kennung der Bezahlsitzung.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO, für die Aufbewahrung lit. c. Speicherdauer: nach § 257 HGB und § 147 AO.
Einzelheiten: stripe.com/de/privacy
Bestätigungs-, Zurücksetzungs- und Kaufmails versenden wir über Resend, Inc. (Auftragsverarbeiter nach Art. 28 DSGVO). Übermittelt werden E-Mail-Adresse, Betreff und Inhalt. Rechtsgrundlage Art. 6 Abs. 1 lit. b DSGVO.
Der Server steht in einem deutschen Rechenzentrum. Davor liegt ein Netzwerkdienst, der die Verbindung entgegennimmt und dabei zwangsläufig Ihre IP-Adresse verarbeitet, um die Auslieferung zu beschleunigen und Angriffe abzuwehren (Art. 6 Abs. 1 lit. f DSGVO). Mit beiden bestehen Verträge zur Auftragsverarbeitung.
Unsere Seiten binden Schriftarten von fonts.googleapis.com
und fonts.gstatic.com ein. Dabei stellt Ihr Browser eine
Verbindung zu Google her; Ihre IP-Adresse wird dorthin übermittelt.
Anbieter: Google Ireland Limited, Dublin. Rechtsgrundlage: Einwilligung nach
§ 25 Abs. 1 TDDDG und Art. 6 Abs. 1 lit. a DSGVO.
Hinweis: Die Schriften werden derzeit ohne vorherige Einwilligung nachgeladen. Vorgesehen ist, sie lokal auszuliefern — dann entfällt dieser Abschnitt.
Einzelne Dienste sitzen in den Vereinigten Staaten oder setzen dort ansässige Unternehmen ein. Für die USA besteht seit dem 10. Juli 2023 ein Angemessenheitsbeschluss der Europäischen Kommission (EU-U.S. Data Privacy Framework), der für zertifizierte Unternehmen gilt. Ergänzend stützen wir Übermittlungen auf Standardvertragsklauseln nach Art. 46 Abs. 2 lit. c DSGVO.
Es lässt sich nicht vollständig ausschließen, dass Behörden im Drittland auf übermittelte Daten zugreifen und dass Ihnen dort nicht dieselben Rechtsbehelfe offenstehen wie in der Europäischen Union.
Eine formlose Nachricht an [email protected] genügt.
Die Bereitstellung von E-Mail-Adresse und Passwort ist für ein Konto erforderlich; alles Weitere ist freiwillig.
Sie können sich bei einer Aufsichtsbehörde beschweren (Art. 77 DSGVO), für uns zuständig ist:
Landesbeauftragte für Datenschutz und Informationsfreiheit
Nordrhein-Westfalen (LDI NRW)
Kavalleriestr. 2–4, 40213 Düsseldorf
www.ldi.nrw.de
Die Übertragung ist durchgängig verschlüsselt (TLS). Passwörter liegen nur als scrypt-Hashwerte vor, Sitzungs- und Bestätigungstoken ebenfalls nur als Hashwerte. Dazu kommen technische und organisatorische Maßnahmen nach Art. 32 DSGVO.
Stand: 31. August 2026
Andrej Kisselev, Kisselev IT
Vallendarer Str. 6, 51105 Köln, Germany
Email: [email protected]
No data protection officer needs to be appointed (§ 38 BDSG).
This site provides colouring templates; finished drawings can be photographed and uploaded, and the service turns them into figures in a personal aquarium that can be shared via a short address and its own password.
Data: IP address, time, requested address, status code, volume of data transferred, referrer, browser identification.
Purposes: delivery, operational security, error analysis, defence against attacks. Legal basis: Art. 6 (1) (f) GDPR.
Retention period for the logs of the web server and the upstream network service: still to be determined.
Set without consent (§ 25 (2) no. 2 TDDDG); legal basis Art. 6 (1) (b) or (f) GDPR.
| Cookie | Purpose | Lifetime |
|---|---|---|
pt_session |
Keeps you signed in. Holds a random token; only its hash value is stored on the server. | 30 days |
pt_tank_<short-ID> |
Proof that the aquarium password has been entered. | 12 hours |
pt_console |
Sign-in to the operator console. Administrators only. | Session |
We run our own lean audience measurement without third parties. The cookie
pt_visitor holds a purely random identifier with a lifetime of
two years. Per page view we transmit only that identifier, the path and the
time spent; if an account is signed in, its identifier as well. No IP address
is stored, nothing is passed to third parties, and nothing is loaded from
external servers.
Legal basis: consent under § 25 (1) TDDDG and Art. 6 (1) (a) GDPR. Retention: 2 years.
Note: This section describes the state required by law. A consent dialogue is not yet implemented; until then the description does not apply.
Data: email address, password (only as a scrypt hash value, never in plain text), language, times of registration and email confirmation, and of any account suspension.
Legal basis: Art. 6 (1) (b) GDPR; abuse prevention (f). Retention: until the account is deleted. Confirmation and reset tokens are stored only as hash values and only until they expire (48 hours) or are used.
For each sign-in we store the hash value of the session token, timestamps and the browser identification — so that sessions can be ended individually.
When a password is set we check it against known data breaches. To do so our server forms a SHA-1 hash and sends only its first five characters to “Have I Been Pwned”; the comparison then happens on our server. The password itself never leaves our server, the service does not learn what was searched for, and your IP address is not transmitted — the request comes from our server, not from your browser.
Legal basis: Art. 6 (1) (f) GDPR (account security).
Data: name and short address of the aquarium, its password (only as a hash value), uploaded photos and backgrounds, the image files and thumbnails derived from them, type and title of the figures, timestamps.
Image files are not served openly, but only through an interface that checks authorisation on every request.
Children's drawings: please do not upload photos showing people, and no drawings containing names, addresses or other identifying details. You are responsible for the lawfulness of the content.
Retention: until you delete it. Deleted items sit in a recycle bin for 30 days and can be restored during that time; afterwards they are gone.
If you pass on the short address and password, the recipients can see the content. Who receives them is your decision alone.
Failed attempts at an aquarium password are logged per aquarium with the time, the result and a hash value of the IP address — not the address itself (Art. 6 (1) (f) GDPR).
The payment page is provided by Stripe. Payment data such as card numbers never reach our server.
Provider: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.
To Stripe: amount, currency, product name, order number, internal identifiers — plus whatever you enter on the payment page yourself. Back to us: payment status and the identifier of the payment session.
Legal basis: Art. 6 (1) (b) GDPR, for retention (c). Retention: under § 257 HGB and § 147 AO (German commercial and tax law).
Details: stripe.com/privacy
Confirmation, reset and purchase emails are sent via Resend, Inc. (processor under Art. 28 GDPR). Email address, subject and content are transmitted. Legal basis Art. 6 (1) (b) GDPR.
The server is located in a German data centre. In front of it sits a network service that accepts the connection and necessarily processes your IP address in order to speed up delivery and defend against attacks (Art. 6 (1) (f) GDPR). Data processing agreements are in place with both.
Our pages embed fonts from fonts.googleapis.com and
fonts.gstatic.com. Your browser therefore connects to Google and
your IP address is transmitted there. Provider: Google Ireland Limited,
Dublin. Legal basis: consent under § 25 (1) TDDDG and Art. 6 (1) (a) GDPR.
Note: the fonts are currently loaded without prior consent. The plan is to serve them locally — this section will then no longer apply.
Some of the services are based in the United States or use companies established there. For the USA, an adequacy decision of the European Commission has been in place since 10 July 2023 (EU-U.S. Data Privacy Framework), which applies to certified companies. In addition we rely on standard contractual clauses under Art. 46 (2) (c) GDPR.
It cannot be entirely ruled out that authorities in the third country access transmitted data and that you do not have the same legal remedies there as within the European Union.
An informal message to [email protected] is enough.
Providing an email address and password is required for an account; everything else is voluntary.
You may lodge a complaint with a supervisory authority (Art. 77 GDPR); the one responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit
Nordrhein-Westfalen (LDI NRW)
Kavalleriestr. 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de
Transmission is encrypted throughout (TLS). Passwords are held only as scrypt hash values, session and confirmation tokens likewise only as hash values. On top of that come technical and organisational measures under Art. 32 GDPR.
Last updated: 31 August 2026