Privacy Policy
Privacy notice for Heritage Canon
This notice explains what personal data is processed when you visit this site, click retailer links, use the consent controls, or contact us by email. It is intended to satisfy the information duties that apply when personal data is collected from you.
Last updated: March 20, 2026
1. Controller
2. What we process and on what basis
We process only the data needed to deliver the site, remember your consent choice, measure usage if you opt in, and respond if you contact us.
- Site delivery, technical stability, abuse prevention, and basic operational logging: Article 6(1)(f) GDPR (legitimate interests).
- Analytics: Article 6(1)(a) GDPR (consent).
- Handling direct email inquiries and keeping legally required records where necessary: Article 6(1)(f) GDPR and, where applicable, Article 6(1)(c) GDPR.
3. Hosting and server-side delivery
The site is hosted through GitHub Pages. When you visit the site, the hosting layer may process technical request data such as your IP address, requested URL, time of access, referrer, browser and device metadata, and transferred data volume.
We use this processing to deliver the website, maintain technical security, and defend against misuse. We do not use those hosting logs for reader profiling.
4. Consent management
The site uses a consent tool so analytics stays off until you opt in. The consent tool stores your choice in a necessary cookie named cc_cookie.
- Purpose: remember and document your consent choice
- Retention: up to 182 days, unless cleared earlier
- Legal basis: Article 6(1)(f) GDPR
You can change your choice at any time through the cookie preferences control in the footer.
5. Analytics
If you consent, the site loads Umami Cloud to measure how the catalog is used. We use this only to understand which pages and books readers visit, which referrals bring traffic, and how the site performs.
No analytics runs before consent. We do not use advertising trackers, cross-site profiling, or behavioral ad targeting on this site.
The site does not intentionally set separate advertising cookies for analytics. The necessary consent cookie described above is separate from analytics itself.
6. External retailer links
Book purchases do not take place on this site. If you click a buy link, your browser is sent to the relevant Amazon storefront. From that point onward, Amazon processes data under its own terms and privacy notice.
We do not receive your payment details or Amazon account data from those purchases.
7. Email contact
If you contact us by email, we process the information contained in your message in order to respond and handle the request. That will usually include your email address, the content of the message, and any information you choose to provide.
We keep correspondence only for as long as needed to handle the inquiry and any follow-up, unless a longer retention period is legally required.
8. Recipients and third-country transfers
Personal data may be processed by these categories of recipients:
- hosting and site-delivery providers, in particular GitHub Pages
- analytics provider Umami Cloud, but only after consent
- email infrastructure involved in sending and receiving messages
- Amazon, if you choose to follow an external retailer link
Some of these providers may process data outside the EU or EEA, especially in the United States. Where that happens, transfers rely on the provider's current legal transfer mechanism, such as an adequacy decision or contractual safeguards where applicable.
9. Retention
- Consent preferences: up to 182 days or until you clear them
- Analytics data: only as long as needed for aggregated traffic analysis within the analytics account
- Email correspondence: as long as needed to process the matter and comply with any legal retention duties
- Hosting and technical logs: according to the operational retention rules of the hosting provider
10. Your rights
Under the GDPR, you may have rights of access, rectification, erasure, restriction, objection, and data portability, depending on the circumstances of the processing.
If processing is based on consent, you can withdraw that consent at any time for the future. Withdrawal does not affect processing that took place before the withdrawal.
You also have the right to lodge a complaint with a supervisory authority. In Berlin, that is the Berlin Commissioner for Data Protection and Freedom of Information.
The current complaint path is available here: datenschutz-berlin.de
11. No automated decision-making
We do not use the site to make automated decisions about you that produce legal or similarly significant effects.
12. Related pages
For the site's formal identification details, see the Impressum / Imprint. For cookie-specific details, see Cookies / Consent.