Who Is Responsible

This is my per­son­al blog at https://www.patorikku.net (‘Blog’). I, Patrick Dahm, am respons­ible for the pro­cessing of per­son­al data on the Blog (con­trol­ler with­in the mean­ing of the EU Gen­er­al Data Pro­tec­tion Reg­u­la­tion, ‘GDPR’). You can reach me at patrick@dahm.sg. This policy is inten­ded to meet the require­ments of the GDPR and, where it applies, Singapore’s Per­son­al Data Pro­tec­tion Act 2012 (‘PDPA’).

In Brief

The Blog uses no ana­lyt­ics, no advert­ising and no track­ing of any kind, and it loads noth­ing from oth­er web­sites except as described below. If you only read, your browser receives no cook­ies. Per­son­al data is pro­cessed only to deliv­er the Blog, to keep it secure, to answer your mes­sages, to pub­lish your com­ments, and to play videos you choose to watch.

Hosting and Server Log Files

The Blog is hos­ted by a host­ing pro­vider on serv­ers in Singa­pore. Whenev­er you open a page, your browser trans­mits tech­nic­al data that the serv­er records in log files: your IP address, the date and time, the page reques­ted, the refer­ring page, and inform­a­tion about your browser and oper­at­ing sys­tem. This data is needed to deliv­er the Blog, to keep it stable and secure, and to invest­ig­ate faults and attacks. It is kept only as long as needed for these pur­poses. Leg­al basis: Art. 6(1)(f) GDPR (legit­im­ate interest in oper­at­ing a secure website).

Security

The Blog is pro­tec­ted by the secur­ity plu­gin Word­fence, provided by Defi­ant, Inc., USA. Word­fence checks every request against fire­wall rules and records the IP address and details of blocked requests and of login attempts. To help pro­tect oth­er web­sites, the IP addresses of attack­ers are shared with Defi­ant, and Word­fence may look up where an IP address is loc­ated using Defiant’s serv­ers. Leg­al basis: Art. 6(1)(f) GDPR (legit­im­ate interest in pro­tect­ing the Blog and its read­ers against attacks).

Contact Form

If you write to me using the con­tact form, your name, e‑mail address and mes­sage are sent to me by e‑mail so that I can reply. The Blog does not store them. I keep our cor­res­pond­ence as long as needed to deal with your enquiry, and longer only where the law requires it. Leg­al basis: Art. 6(1)(b) GDPR where your mes­sage con­cerns a con­tract or steps towards one, oth­er­wise Art. 6(1)(f) GDPR (legit­im­ate interest in answer­ing enquiries).

The con­tact form is pro­tec­ted against spam by Cloud­flare Turn­stile, a ser­vice of Cloud­flare, Inc., USA. When you open the con­tact page, your browser trans­mits tech­nic­al data, such as your IP address and inform­a­tion about your browser, to Cloud­flare, which uses it to dis­tin­guish people from auto­mated pro­grams and to improve its bot detec­tion. Cloudflare’s pri­vacy notice for Turn­stile is avail­able at https://www.cloudflare.com/turnstile-privacy-policy/. Leg­al basis: Art. 6(1)(f) GDPR (legit­im­ate interest in pro­tect­ing the form against spam).

Comments

If you leave a com­ment, the Blog stores your name, e‑mail address, web­site (if giv­en) and com­ment, togeth­er with your IP address, inform­a­tion about your browser, and the time. Your name, web­site and com­ment are pub­lished; your e‑mail address is not. Com­ments remain until they are deleted, and you can ask me to delete yours at any time. Leg­al basis: Art. 6(1)(a) GDPR for pub­lish­ing your com­ment, and Art. 6(1)(f) GDPR for the IP address and browser inform­a­tion (legit­im­ate interest in tra­cing abuse).

Before a com­ment is pub­lished, it is checked for spam by Akismet, a ser­vice of Auto­mat­tic Inc., USA. For this pur­pose, your name, e‑mail address, web­site, com­ment, IP address and inform­a­tion about your browser are sent to Akismet. Akismet keeps most spam-related data for between two weeks and 90 days. More inform­a­tion is avail­able at https://akismet.com/privacy/. Leg­al basis: Art. 6(1)(f) GDPR (legit­im­ate interest in keep­ing spam off the Blog).

If you tick ‘Save my name, e‑mail, and web­site in this browser for the next time I com­ment’, your name, e‑mail address and web­site are stored in three cook­ies in your browser for almost a year, so that the com­ment form is filled in for you next time. You can delete them in your browser at any time. Leg­al basis: your con­sent, Art. 6(1)(a) GDPR and, where Ger­man law applies, § 25(1) TDDDG.

Embedded Videos

You­Tube videos appear as a still image with a play but­ton; the image is stored on the Blog. Noth­ing is loaded from You­Tube until you click play. When you do, the video is loaded from youtube-nocookie.com, oper­ated by Google Ire­land Lim­ited, Gor­don House, Bar­row Street, Dub­lin 4, Ire­land. You­Tube then receives your IP address and inform­a­tion about your browser, may store cook­ies or sim­il­ar data on your device, and may pro­cess this data in the USA. Google’s pri­vacy policy is avail­able at https://policies.google.com/privacy. Leg­al basis: your con­sent, giv­en by click­ing play, Art. 6(1)(a) GDPR and, where Ger­man law applies, § 25(1) TDDDG.

Links to Other Websites

Links to oth­er web­sites, such as Linked­In, are plain links. Noth­ing is trans­mit­ted to those web­sites until you fol­low a link; their own pri­vacy policies then apply.

Transfers outside Singapore and the EU

I run the Blog from Singa­pore, where it is also hos­ted. Singa­pore is not covered by an adequacy decision of the European Com­mis­sion. Cloud­flare, Auto­mat­tic, Defi­ant and Google may pro­cess data in the USA. For Cloud­flare, Auto­mat­tic and Google, the trans­fer relies on the European Commission’s adequacy decision for the EU – US Data Pri­vacy Frame­work (Art. 45 GDPR), under which they are cer­ti­fied; for Defi­ant, which is not cer­ti­fied, it relies on stand­ard con­trac­tu­al clauses (Art. 46(2)(c) GDPR). Where per­son­al data is trans­ferred out of Singa­pore, I take appro­pri­ate steps to ensure a stand­ard of pro­tec­tion com­par­able to that under the PDPA.

Your Rights

You have the right to access your per­son­al data (Art. 15 GDPR), to have it cor­rec­ted (Art. 16 GDPR) or erased (Art. 17 GDPR), to restrict its pro­cessing (Art. 18 GDPR), and to receive it in a port­able format (Art. 20 GDPR). Under the PDPA, you may request access to and cor­rec­tion of your per­son­al data. Where pro­cessing is based on your con­sent, you can with­draw it at any time with effect for the future (Art. 7(3) GDPR; sec­tion 16 PDPA).

Right to object: where pro­cessing is based on Art. 6(1)(f) GDPR, you may object to it at any time on grounds relat­ing to your par­tic­u­lar situ­ation (Art. 21 GDPR).

To exer­cise your rights, write to patrick@dahm.sg. You also have the right to lodge a com­plaint with a data pro­tec­tion super­vis­ory author­ity, in par­tic­u­lar in the EU mem­ber state where you live or work (Art. 77 GDPR). Read­ers in Singa­pore may con­tact the Per­son­al Data Pro­tec­tion Commission.

Providing Data

You are not obliged to provide per­son­al data. Without an e‑mail address, how­ever, I can­not reply to your mes­sage, and com­ments require a name and an e‑mail address. No auto­mated decision-mak­ing, includ­ing pro­fil­ing, takes place.

Changes

I update this policy when changes in how per­son­al data is pro­cessed on the Blog, or in the law, require it. The cur­rent ver­sion is always avail­able on this page.

Last updated: 11 Octo­ber 2026