At a glance
- MyFoodPath has no user accounts, no forms, no newsletter and no advertising.
- We set no cookies and embed no third-party content (no Google Fonts, no videos, no social media plugins, no external CDNs).
- For anonymous visitor statistics we use Plausible Analytics on our own server. It sets no cookies and builds no personal profiles.
- All data stays on servers in the European Union.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Julian Stricker, Italy – email: info@myfoodpath.com
No data protection officer has been appointed; none is required for this private project.
2. Hosting and server log files
MyFoodPath is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in data centres within the EU. A data processing agreement under Art. 28 GDPR is in place with Hetzner.
Whenever you open a page, the server processes technically necessary data sent by your browser:
- IP address
- date and time of access
- requested address (URL) and HTTP status code
- referrer (the page you came from), if sent
- browser type and operating system (user agent)
This data is needed to deliver the website and to keep it secure and stable, for example to fend off attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, reliable operation). Server log files are deleted after 14 days at the latest, unless they are needed longer to investigate a specific security incident.
3. Visitor statistics with Plausible Analytics
To understand which content is read, we use the open-source software Plausible Analytics (Community Edition). It runs on our own server at Hetzner; no data is passed to Plausible Insights OÜ or any other third party.
Plausible sets no cookies and stores nothing on your device. A pseudonymous identifier is computed from your IP address and user agent together with a secret value that changes daily, so that page views within one day can be counted. The IP address itself is not stored; the identifier is discarded daily, so you cannot be recognised across days or websites. Only aggregated values are stored, such as the page visited, referrer, country/region, browser, operating system and device type.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly audience measurement to improve the content). You can prevent tracking by disabling JavaScript or using a content blocker; the website keeps working.
4. Fonts and resources
All fonts, images and scripts are loaded directly from our server. Visiting MyFoodPath does not open connections to third-party servers.
5. Offline use (progressive web app)
MyFoodPath can be used as a web app. For this, a service worker stores pages, fonts and images in your browser's cache so they load faster and are available offline. This data stays on your device only and is never sent to us. You can delete it at any time in your browser settings ("clear site data").
6. Contact by email
If you email us, we process your email address and the content of your message to reply to you. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in answering enquiries). We delete the message once it has been dealt with, unless statutory retention obligations apply.
7. External links
Our content links to scientific sources and authorities (e.g. EFSA, EUR-Lex, PubMed). You only leave MyFoodPath when you click such a link; the operator of the linked website is responsible for its data processing.
8. Recipients and transfers to third countries
The only recipient of personal data is our hosting provider Hetzner, acting as a processor. No data is transferred to countries outside the EU/EEA.
9. Your rights
Under the GDPR you have the right to
- access the data stored about you (Art. 15),
- rectification (Art. 16) and erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20), and
- object to processing based on legitimate interest (Art. 21).
A short email to info@myfoodpath.com is enough. Please note that we cannot link pseudonymous statistics to any person.
You may also lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live. The authority responsible for us is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it.
10. Other information
Providing your data is not required by law or contract; without the technically necessary connection data, however, the website cannot be displayed. No automated decision-making or profiling takes place.
We update this privacy policy when the website or the law changes. The version published here applies.