1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Arthur Schmidt-Pabst
Jacobsohnstr. 50A
13086 Berlin
Germany
Email: theveil@schmidtpabst.com
2. General information
This Privacy Policy explains which personal data is processed when you visit and use
The Veil website.
Personal data is any information relating to an identified or identifiable natural person.
This can include IP addresses, email addresses, technical connection data, and the content
of communications.
We process personal data only to the extent necessary to operate the website, provide free
memberships, send the newsletter, communicate with users, or comply with legal obligations.
3. Hosting and delivery of the website
The website and its Ghost installation run on a virtual server provided by:
IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany
When the website is accessed, technically necessary data is transmitted to the server. This may include:
- IP address,
- date and time of access,
- the requested page or file,
- the amount of data transferred,
- referrer URL,
- browser type and version,
- operating system,
- HTTP status code, and
- other technical connection data.
This processing is necessary to deliver the website, maintain its stability and security,
identify errors, and prevent misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable
operation of the website.
Server and security logs are deleted or anonymised once they are no longer required for
operations, error analysis, and the prevention of misuse, unless statutory retention duties
or a specific security incident require longer storage.
4. Ghost
We use the open-source Ghost software to publish content and manage free memberships.
Ghost runs on our own server hosted by IONOS. Merely using the self-hosted Ghost software
does not cause member data to be transferred to the Ghost Foundation or Ghost(Pro).
When a free membership is created, Ghost processes in particular:
- the email address provided,
- the signup and confirmation status,
- the time of signup,
- technical information about the signup where applicable,
- membership and newsletter status, and
- data required to provide passwordless sign-in.
Memberships do not use a conventional password. Instead, a time-limited sign-in link is
sent by email when required.
The legal basis for processing data to create and provide a free membership is Article 6(1)(b) GDPR.
Member data is generally stored for as long as the membership exists. Following a deletion
request, it is deleted unless legal duties or legitimate reasons require limited further storage.
Unsubscribing from the newsletter does not automatically terminate the free membership.
You can request complete deletion of your membership at
theveil@schmidtpabst.com.
5. Registration, confirmation, and sign-in emails through Proton Mail
We use Proton Mail for registration confirmations, newsletter confirmation messages, and
passwordless sign-in emails.
The provider is:
Proton AG
Route de la Galaise 32
1228 Plan-les-Ouates
Geneva
Switzerland
The data processed includes the recipient address, sender and recipient information, subject
line, message content, and the technical data required to transmit the message.
Registration and sign-in emails are used to create and provide the free membership. The legal
basis is Article 6(1)(b) GDPR.
Where Proton Mail is used to confirm consent to the newsletter, the processing is based on
Article 6(1)(a) GDPR.
The European Commission has recognised Switzerland as providing an adequate level of data
protection. Further information is available in
Proton’s Privacy Policy.
6. Newsletter and double opt-in
The Veil newsletter is sent only following an express subscription.
The subscription uses a double opt-in process:
- The interested person enters their email address in the signup form.
- The signup is initially stored as unconfirmed.
- A confirmation email is sent to the address through Proton Mail.
- The newsletter subscription is activated only after the confirmation link is used.
- Subsequent newsletters are sent through Sinch Mailgun.
To document consent, we may retain the time of signup, the time of confirmation, the consent
status, and technically necessary evidence of the confirmation.
The legal basis for sending the newsletter is Article 6(1)(a) GDPR.
Consent may be withdrawn at any time with effect for the future. You can use the unsubscribe
link at the end of each newsletter or email
theveil@schmidtpabst.com.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
After unsubscribing, the email address may remain on a suppression or unsubscribe list where
this is necessary to reliably prevent further messages and document the unsubscribe request.
7. Newsletter delivery through Sinch Mailgun
We use Sinch Mailgun to deliver the newsletter. The service is offered within the Sinch group
of companies. The US company Mailgun Technologies, Inc. may in particular provide Mailgun services.
Sinch Mailgun processes data on our behalf as a service provider for newsletter delivery.
The data processed may include:
- email address,
- sender and recipient information,
- the subject and content of the newsletter,
- time and technical status of delivery,
- bounce and error messages,
- spam complaints,
- unsubscribe information, and
- technical log data required for delivery, security, and the prevention of misuse.
Our Mailgun domain and message delivery are configured to use Mailgun’s EU sending region.
Message and recipient data intended for delivery is therefore processed through Mailgun’s
European endpoints.
Sinch is, however, an international group of companies. Limited account, support, security,
or administrative data may therefore also be processed outside the European Economic Area.
According to Sinch, transfers to the United States or other third countries are protected in
particular through the EU-US Data Privacy Framework or the European Commission’s Standard
Contractual Clauses, as applicable.
The legal basis for using Mailgun is the consent to receive the newsletter under Article 6(1)(a)
GDPR. Mailgun is used to carry out this processing technically.
We do not create personal opening or click profiles. Ghost’s measurement of newsletter opens
and clicks is disabled. Technical delivery information, error messages, unsubscribes, and spam
complaints continue to be processed where required for reliable delivery, security, and
newsletter administration.
Delivery data processed by Mailgun is deleted once it is no longer required for delivery,
error analysis, security, and the prevention of misuse, and no statutory or contractually
necessary retention reasons apply.
Further information is available in the
Sinch Mailgun Privacy Policy.
8. External files delivered through jsDelivr
The website loads certain technically necessary JavaScript and CSS files for Ghost membership
and search functions through the jsDelivr content delivery network.
The provider is:
Volentio JSD Limited
Suite 2a1, Northside House
Mount Pleasant
Barnet, England EN4 9EB
United Kingdom
When these files are retrieved, the delivering CDN technically receives the IP address, date
and time of the request, requested file, and browser and connection information.
This processing provides the website’s membership and search functions reliably and efficiently.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and technically
efficient delivery of the website.
The European Commission has adopted an adequacy decision for the United Kingdom. jsDelivr may
use additional infrastructure and CDN providers for global delivery.
9. Cookies and local storage
The website uses only technically necessary cookies or similar storage mechanisms, in
particular when a member signs in through a passwordless sign-in link.
These technologies are necessary to store the sign-in status, provide membership functions,
and maintain the security of the website.
The legal basis for the associated processing of personal data is Article 6(1)(b) GDPR and,
for security and operational purposes, Article 6(1)(f) GDPR.
No advertising or marketing cookies are used.
Ghost’s web analytics, newsletter-open measurement, newsletter-click measurement, member-source
tracking, and outbound-link tagging functions are disabled.
10. Contacting us
If you contact us by email, we process the data you send, in particular your email address,
message content, and your name where provided.
The data is processed to handle and respond to your enquiry.
The legal basis is Article 6(1)(b) GDPR where the communication relates to preparing or
performing a contractual or membership relationship. In other cases, processing is based on
Article 6(1)(f) GDPR. Our legitimate interest is the appropriate handling of incoming enquiries.
The data is deleted once the enquiry has been finally resolved and no statutory retention duty
or legitimate reason requires further storage.
11. Recipients and processors
To the extent required for the relevant purpose, personal data may be transferred in particular to:
- IONOS SE for server operation and hosting,
- Proton AG for registration, confirmation, and sign-in emails,
- Sinch Mailgun or Mailgun Technologies, Inc. for newsletter delivery,
- infrastructure partners of the content delivery network used,
- technical service providers where required for maintenance, security, or troubleshooting, and
- public authorities or other bodies where disclosure is required by law.
Where legally required, we enter into agreements with processors in accordance with Article 28 GDPR.
12. Retention periods
Where this Privacy Policy does not specify a particular retention period, we store personal
data only for as long as it is required for the relevant processing purpose.
The data is then deleted or anonymised unless statutory retention duties, documentation of
consent, the establishment, exercise or defence of legal claims, or specific security interests
require further storage.
13. Your rights
Subject to the statutory requirements, you have in particular the following rights:
- the right of access under Article 15 GDPR,
- the right to rectification under Article 16 GDPR,
- the right to erasure under Article 17 GDPR,
- the right to restriction of processing under Article 18 GDPR,
- the right to data portability under Article 20 GDPR,
- the right to object under Article 21 GDPR, and
- the right to withdraw consent under Article 7(3) GDPR.
A withdrawal applies only for the future. It does not affect the lawfulness of processing carried
out before the withdrawal.
To exercise these rights, email
theveil@schmidtpabst.com.
14. Objection to processing based on legitimate interests
Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object to that
processing at any time on grounds relating to your particular situation.
We will then no longer process the data unless we demonstrate compelling legitimate grounds
that override your interests, rights, and freedoms, or the processing is required for the
establishment, exercise, or defence of legal claims.
15. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority.
The authority responsible for the controller’s place of establishment is in particular:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
www.datenschutz-berlin.de
16. Security
We implement appropriate technical and organisational measures to protect personal data from
loss, misuse, unauthorised access, and unlawful alteration.
The website is transmitted over encrypted HTTPS connections. Despite the protective measures
used, email communication can generally involve security risks.
17. Changes to this Privacy Policy
We may amend this Privacy Policy if the website, services used, or legal requirements change.
The current version will be published on this website.
1. Provider
Arthur Schmidt-Pabst
Jacobsohnstr. 50A
13086 Berlin
Germany
Email: theveil@schmidtpabst.com
“The Veil” is a project name and not a separate legal entity.
2. Scope
These Terms of Use apply to the use of The Veil website, its published content, free memberships,
and the free email newsletter.
There are currently no membership or subscription fees. The website does not currently offer
paid memberships, donations, or other paid digital services.
3. Fictional nature
The Veil is a work of speculative fiction.
Transmissions, artifacts, future events, institutions, research bodies, technical systems,
analyses, and persons shown on the website may form part of the fictional narrative.
Such content does not claim that the described events, transmissions, or institutions exist in the real world.
The project may deliberately refer to real ideas, technologies, persons, institutions,
or events. Those references serve the narrative and do not make its fictional transmissions
or future events real.
Where individual pieces refer to real sources, events, or scientific concepts, that does not
turn them into real predictions, warnings, or statements of fact.
4. Free membership
Certain functions or content may require a free membership.
A valid email address is required to sign up. Registration and subsequent sign-in use time-limited
confirmation or sign-in links. Users are responsible for protecting access to their email account
and the sign-in links they receive from unauthorised use.
There is no entitlement to the creation or permanent availability of a membership.
Users may request deletion of their membership at any time by emailing
theveil@schmidtpabst.com.
5. Newsletter
The newsletter is sent only following a confirmed subscription through a double opt-in process.
Subscription is voluntary and free. It may be withdrawn at any time through the unsubscribe link
in each newsletter or by emailing
theveil@schmidtpabst.com.
Unsubscribing from the newsletter does not automatically delete the free membership. Complete
deletion may be requested separately.
6. Permitted use
The website may be used only in accordance with applicable law and these Terms of Use.
In particular, users must not:
- attempt to gain unauthorised access to accounts, servers, or non-public areas,
- circumvent technical access restrictions,
- use automated access in a way that interferes with the operation of the website,
- introduce malicious software or manipulated requests,
- use the website to deceive, harass, or harm others,
- misuse sign-in or confirmation links, or
- use content in violation of copyright, trademark, or personality rights.
7. Copyright and rights of use
The texts, images, audio, video, graphics, designs, and other content published on The Veil are
protected by copyright or other rights unless expressly stated otherwise.
The content may be accessed and viewed for personal, non-commercial use.
Reproduction, publication, adaptation, making available to the public, commercial exploitation,
or distribution beyond uses permitted by law requires the prior consent of the respective rights holder.
Legally permitted quotation and other statutory copyright exceptions remain unaffected.
8. Availability and changes
We endeavour to operate the website reliably but cannot guarantee uninterrupted or error-free availability.
Content, functions, and access arrangements may be developed, changed, or discontinued. This applies
in particular to experimental areas or parts of the project that are still under development.
Material changes affecting existing free memberships will be announced in an appropriate manner.
9. Suspension and termination
Access to individual functions or a membership may be temporarily suspended or terminated where
there are specific indications of misuse, a threat to technical security, or a material breach of
these Terms of Use.
A membership may also be terminated if the relevant service is discontinued altogether.
10. Liability
We have unlimited liability for intent and gross negligence and for damage arising from injury to
life, body, or health.
In the event of a slightly negligent breach of an essential contractual obligation, liability is
limited to the foreseeable damage typical of the contract. Essential contractual obligations are
obligations whose performance is necessary to make proper use of the service possible and on whose
performance users may normally rely.
Otherwise, liability for slight negligence is excluded to the extent permitted by law.
Liability under the German Product Liability Act and for expressly assumed guarantees remains unaffected.
External links are reviewed when they are added. The respective external provider is responsible for
later changes to linked services and for content over which we have no control.
11. Data protection
Information about the processing of personal data is available in the Privacy Policy.
12. Applicable law
The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods.
For consumers, this choice of law applies only to the extent that it does not deprive them of mandatory
protection afforded by the law of the country in which they have their habitual residence.
13. Changes to these Terms of Use
These Terms of Use may be amended if the service, technical systems, or legal requirements change.
The current version will be published on the website. Material changes affecting existing memberships
will be communicated in an appropriate manner.