Who Is Responsible
This is my personal blog at https://www.patorikku.net (‘Blog’). I, Patrick Dahm, am responsible for the processing of personal data on the Blog (controller within the meaning of the EU General Data Protection Regulation, ‘GDPR’). You can reach me at patrick@dahm.sg. This policy is intended to meet the requirements of the GDPR and, where it applies, Singapore’s Personal Data Protection Act 2012 (‘PDPA’).
In Brief
The Blog uses no analytics, no advertising and no tracking of any kind, and it loads nothing from other websites except as described below. If you only read, your browser receives no cookies. Personal data is processed only to deliver the Blog, to keep it secure, to answer your messages, to publish your comments, and to play videos you choose to watch.
Hosting and Server Log Files
The Blog is hosted by a hosting provider on servers in Singapore. Whenever you open a page, your browser transmits technical data that the server records in log files: your IP address, the date and time, the page requested, the referring page, and information about your browser and operating system. This data is needed to deliver the Blog, to keep it stable and secure, and to investigate faults and attacks. It is kept only as long as needed for these purposes. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure website).
Security
The Blog is protected by the security plugin Wordfence, provided by Defiant, Inc., USA. Wordfence checks every request against firewall rules and records the IP address and details of blocked requests and of login attempts. To help protect other websites, the IP addresses of attackers are shared with Defiant, and Wordfence may look up where an IP address is located using Defiant’s servers. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the Blog and its readers against attacks).
Contact Form
If you write to me using the contact form, your name, e‑mail address and message are sent to me by e‑mail so that I can reply. The Blog does not store them. I keep our correspondence as long as needed to deal with your enquiry, and longer only where the law requires it. Legal basis: Art. 6(1)(b) GDPR where your message concerns a contract or steps towards one, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
The contact form is protected against spam by Cloudflare Turnstile, a service of Cloudflare, Inc., USA. When you open the contact page, your browser transmits technical data, such as your IP address and information about your browser, to Cloudflare, which uses it to distinguish people from automated programs and to improve its bot detection. Cloudflare’s privacy notice for Turnstile is available at https://www.cloudflare.com/turnstile-privacy-policy/. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the form against spam).
Comments
If you leave a comment, the Blog stores your name, e‑mail address, website (if given) and comment, together with your IP address, information about your browser, and the time. Your name, website and comment are published; your e‑mail address is not. Comments remain until they are deleted, and you can ask me to delete yours at any time. Legal basis: Art. 6(1)(a) GDPR for publishing your comment, and Art. 6(1)(f) GDPR for the IP address and browser information (legitimate interest in tracing abuse).
Before a comment is published, it is checked for spam by Akismet, a service of Automattic Inc., USA. For this purpose, your name, e‑mail address, website, comment, IP address and information about your browser are sent to Akismet. Akismet keeps most spam-related data for between two weeks and 90 days. More information is available at https://akismet.com/privacy/. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in keeping spam off the Blog).
If you tick ‘Save my name, e‑mail, and website in this browser for the next time I comment’, your name, e‑mail address and website are stored in three cookies in your browser for almost a year, so that the comment form is filled in for you next time. You can delete them in your browser at any time. Legal basis: your consent, Art. 6(1)(a) GDPR and, where German law applies, § 25(1) TDDDG.
Embedded Videos
YouTube videos appear as a still image with a play button; the image is stored on the Blog. Nothing is loaded from YouTube until you click play. When you do, the video is loaded from youtube-nocookie.com, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. YouTube then receives your IP address and information about your browser, may store cookies or similar data on your device, and may process this data in the USA. Google’s privacy policy is available at https://policies.google.com/privacy. Legal basis: your consent, given by clicking play, Art. 6(1)(a) GDPR and, where German law applies, § 25(1) TDDDG.
Links to Other Websites
Links to other websites, such as LinkedIn, are plain links. Nothing is transmitted to those websites until you follow a link; their own privacy policies then apply.
Transfers outside Singapore and the EU
I run the Blog from Singapore, where it is also hosted. Singapore is not covered by an adequacy decision of the European Commission. Cloudflare, Automattic, Defiant and Google may process data in the USA. For Cloudflare, Automattic and Google, the transfer relies on the European Commission’s adequacy decision for the EU – US Data Privacy Framework (Art. 45 GDPR), under which they are certified; for Defiant, which is not certified, it relies on standard contractual clauses (Art. 46(2)(c) GDPR). Where personal data is transferred out of Singapore, I take appropriate steps to ensure a standard of protection comparable to that under the PDPA.
Your Rights
You have the right to access your personal data (Art. 15 GDPR), to have it corrected (Art. 16 GDPR) or erased (Art. 17 GDPR), to restrict its processing (Art. 18 GDPR), and to receive it in a portable format (Art. 20 GDPR). Under the PDPA, you may request access to and correction of your personal data. Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR; section 16 PDPA).
Right to object: where processing is based on Art. 6(1)(f) GDPR, you may object to it at any time on grounds relating to your particular situation (Art. 21 GDPR).
To exercise your rights, write to patrick@dahm.sg. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work (Art. 77 GDPR). Readers in Singapore may contact the Personal Data Protection Commission.
Providing Data
You are not obliged to provide personal data. Without an e‑mail address, however, I cannot reply to your message, and comments require a name and an e‑mail address. No automated decision-making, including profiling, takes place.
Changes
I update this policy when changes in how personal data is processed on the Blog, or in the law, require it. The current version is always available on this page.
Last updated: 11 October 2026