General Technical Information

GDPR, Analytics, Hosting, Cloudflare, Online-Calendar, Google-Fonts, Cookie-Policy

Guiding principles

  • Maximum DSGVO / GDPR compliance through self-hosting in Germany.
  • Maximum operational security in a 27001-certified data center.
  • Selection of secure open source solutions for Server-Platform and Operating Platform.
  • Maximizing Internet security in domain management.
  • Maximum security against unauthorized entry.


Hosting at Hetzner in Germany

This website with integrated business solution consisting of Server-Platform and Operating-Platform, is hosted by Hetzner in Germany (see also section Subdomains). 


Subdomains 

This website or business solution uses the following subdomains, with applications hosted by Hetzner itself:


GMail and Domains

  • The Swiss company Tolksdorf.digital GmbH uses Google Mail with the domain https://tolksdorf.digital. The DNS records of the domain are managed with Cloudflare without proxy functionality.
  • Deutsche Tolksdorf.digital UG uses Google Mail with the separate domain https://tolksdorf-de.digital. The website of the domain is redirected to the shared website https://tolksdorf.digital , provided by the Swiss company Tolksdorf.digital GmbH.


Google Fonts

This website uses Google fonts stored statically on its own servers, which are not reloaded online.

The following tool was used for the verification. https://www.ccm19.de/google-fonts-checker/


Cloudflare

The DNS records of the domain are managed with Cloudflare without proxy functionality.

More Information about Cloudflare Privacy Policy.


Appointment management with online calendar

To book appointments, a  self hosted Cal.com instance running in a container is used.


Website Analytics

For anonymous statistical evaluation, we use the standard Plausible Analytics and Matomo. These services are configured to be privacy-friendly and are activated by default. Services such as Google Tag Manager or the interactive AI assistant Samy are only loaded after explicit consent.


Matomo is a self-hosted web analysis platform that does not require any personal data and is operated in full compliance with the GDPR. Matomo is used on this website exclusively for anonymized reach measurement. Like Plausible Analytics, Matomo is a GDPR-compliant alternative to Google technologies. Both solutions can be obtained from the cloud or, as with Tolksdorf.digital, operated onpremise on your own servers. More information about Matomo and data protection:  https://matomo.org/privacy/?nav. Plausible is an intuitive, lightweight and open source web analytics solution. Plausible does not use cookies (See also section Cookie Policy) and is fully compliant with GDPR (DSGVO), CCPA and PECR. Created and hosted in-house by Hetzner (see above).

More information about GDPR-, CCPA- and Cookie-Laws-conform Website-Analytics using Plausible.

More information about the Privacy-Policy (Datenschutz) at Plausible.

Google Tag Manager (GTM) is a tag management system (TMS) that can be used to measure tracking codes and associated code fragments (commonly referred to as tags) on websites or in mobile apps.
We use Google Tag Manager exclusively for tests and demonstrations of how GTM can be used in compliance with the GDPR. It is deactivated in normal operation. The script is only loaded with express consent. Cookies may be set by Google and data may be transmitted to US servers. Use only takes place after active selection in the privacy settings. GTM is only available after explicit consent.


Artificial Intelligence (AI) on this website

An interactive AI assistant (“Samy”) is offered on this website, which only becomes active when requested by the user. The function is controlled in compliance with the GDPR via the Klaro! consent management system. No personal analysis or external processing takes place unless consent is given. The AI runs on its own infrastructure (subdomain samy.tolksdorfdigital.com) is free of third-party tracking and serves exclusively to provide professional support and voluntary information.


Cookie Policy

Cookie database that can be used to verify the data

At https://cookiedatabase.org/ you can view information about cookies, local storage, pixels and other tracking technologies. You can also read the Data Passports we have created about the services and organizations that create or use these technologies.


Cookie Banner, Cookie Analytics and Management

The open source solution Klaro! is used to manage cookies and external services. https://klaro.org/

Dabei handelt es sich um ein vollständig selbst gehostetes, leichtgewichtiges Consent-Management-Tool, das DSGVO-konform eine Einwilligung für technisch nicht notwendige Dienste (z. B. Analytics, eingebettete interaktive Komponenten) einholt und deren Ausführung unterbindet, solange keine Zustimmung vorliegt

The cookie decision can be adjusted at any time via the footer link “Privacy | Imprint | Cookies”. Then press F5 to reload the website.

Klaro! does not set any tracking cookies itself. Only a local, technically necessary cookie is used to save your selected settings.

Ein Cookie-Scan-Report is available on request.


Youtube related Cookies

To display videos on the website https://tolksdorf.digital wird Youtube genutzt. Videos are not played automatically, so users are free to use them while applying to and adhering the Google Privacy Controls .


Cookie VISITOR_INFO1_LIVE

This functionally important cookie is used by YouTube to determine bandwidth.

Source: https://cookiedatabase.org/cookie/youtube/visitor_info1_live/


Cookie YSC

This optional cookie is set by YouTube for marketing/tracking to track views of embedded videos.

Source: https://cookiedatabase.org/cookie/youtube/ysc/


Nextcloud

Nextcloud only stores cookies that are necessary for the proper functioning of Nextcloud. All cookies come directly from self-hosted Nextcloud servers, no third-party cookies are sent to your system. 

The cookies are used to determine how a request reaches the Nextcloud server and to prevent CSRF attacks. No identifiable information is stored in these cookies. The other cookies are used exclusively to identify users in the system. Cookies used:

Cookie

Stored data

Life time

Session cookie

  • session ID
  • secret token (used to decrypt the session on the server)

24 Minutes

Same-site cookies

No user-related data is stored, all same-site cookies cookies are identical for all users on all Nextcloud instances.

Forever

Remember-me cookie

  • user id
  • original session id
  • remember token

15 Days (configurable)

Source: https://docs.nextcloud.com/server/latest/admin_manual/gdpr/cookies.html


Cal (formerly Calendso)

As it is self-hosted, this module does not use cookies itself. For session management, information is stored in the local memory for technically necessary reasons to call up the appointment management https://cal.tolksdorf.digital used. The data is automatically deleted after the functionality is terminated. Further technical information can be found on Github: https://github.com/calcom/cal.com

  • __Secure-next-auth.callback-url
  • __Secure-next-auth.csrf-token
  • __clnds


Odoo related Scripts

csrf_token (Odoo)


The technically essential CSRF token (Cross-Site Request Forgery token) is a security mechanism that prevents malicious websites or attackers from performing actions on behalf of an authenticated user. When a user logs in to a website, they receive a CSRF token. This token is usually stored in the form of a cookie or a hidden input in the web form. The CSRF token must be sent with every action or request that the user sends to the website. The website then checks whether the token is correct to ensure that the request originates from a trustworthy sender.

Using the CSRF token ensures that only authorized actions can be performed by a user and that potential CSRF attacks are blocked. The token normally changes with each login or session to further increase security.

More informationen is available on Wikipedia .


__session_info__ (Odoo)

Technically essential for managing Odoo system users (not website users).


Odoo related Cookies

The following text was automatically generated and translated by Odoo. For technical reasons, only essential cookies are used for the use of this website.


Cookies are also used to help us understand your preferences based on previous or current activity on our site (the pages you have visited), your language and your country, which allows us to provide you with a better service. We also use cookies to collect aggregate data about website traffic and website interaction so that we can offer you better website experiences and tools in the future.

Here you will find an overview of the cookies that may be stored on your device when you visit our website:

Category of Cookies Purpose Examples

Session & Security
(essential)

This website is used by Tolksdorf.digital for demo purposes, which is why this cookie is technically necessary for session management.

Authenticate users, protect user data and enable the website to provide the services expected by users, such as maintaining the contents of their shopping cart or allowing file uploads.

The website will not function properly if you refuse or reject these cookies.

session_id (Odoo)


Preferences (essential)

Remember information about the preferred look or behavior of the website, such as your preferred language or region.

Your experience may be affected if you reject these cookies, but the website will continue to function.

frontend_lang (Odoo)
tz (Odoo)

Interaction history (optional)

Used to collect information about your interactions with the website, the pages you have visited, and specific marketing campaigns that led you to the website.

We may not be able to provide you with the best service if you reject these cookies, but the website will work.

im_livechat_vorheriger_Betreiber_pid (Odoo)
utm_campaign (Odoo)
utm_source (Odoo)
utm_medium (Odoo)

Advertisment & Marketing

 Not used.

Not used. 

Google Analytics
(optional, default is off

Understand how visitors use our website GDPR compliant after active consent, with Google Analytics. Learn more about Analytics-Cookies and Information about Daten Protection.

This also works if you actively agree to the use of these cookies.

_ga (Google)
_gat (Google)
_gid (Google)
_gac_* (Google)

You can choose whether you want your computer to warn you each time a cookie is sent or whether you want to disable all cookies. Every browser is a little different. So check your browser's help menu to find out how to change your cookies correctly.

We do not currently support Do Not Track signals as there is no industry standard for compliance.