Skip to content
Ranil RanasingheGraphic Designer · Artist · Teacher

Privacy policy

This website sets no cookies, counts no visits and embeds no third-party services in its pages. What is processed is what running a web server technically entails — and whatever you yourself write into the enquiry form. Both are described here exactly as they actually happen.

Controller

Ranil Ranasinghe
Querstraße 6
90489 Nürnberg
Germany

No data protection officer has been appointed; the conditions of § 38 (1) BDSG are not met.

Visiting the website

Each time a page is requested, your browser transmits data to the server, where it is recorded in a log file:

  • the IP address of the requesting device
  • date and time of the request
  • the requested address and the protocol used
  • the response status code and the amount of data transferred
  • the previously visited page, if your browser sends it
  • the browser and operating system identifier

This data is needed to deliver the site, keep it running reliably and detect attacks. It is not combined with any other data and is not used to identify individuals.

Log files are rotated daily and automatically deleted after fourteen days.

Legal basisArt. 6 (1) (f) GDPR — legitimate interest in the secure and reliable operation of the website.

Hosting

The website is hosted on a server operated in Germany by netcup GmbH, Daimlerstrasse 25, 76185 Karlsruhe. netcup processes the data listed above solely in order to make the site available, and on our instructions.

Legal basisArt. 6 (1) (f) GDPR — legitimate interest in operating the website.

Defence against attacks

The server runs CrowdSec, software that detects automated attacks. It reads the same log files and temporarily blocks an IP address when a known attack pattern comes from it — for example the mass probing of addresses or credentials.

If an IP address triggers such a pattern, that address and the detected pattern are reported to the central service of CrowdSec SAS in France, which builds a shared blocklist from them. An ordinary page request does not trigger this: the IP addresses of normal visitors never leave the server.

Legal basisArt. 6 (1) (f) GDPR — legitimate interest in defending the server against attacks.

Enquiry form

You can send an enquiry from the contact page. What is transmitted is:

  • your name
  • your email address
  • your message
  • the work the enquiry refers to, if you came from a work page
  • the language in which you are using the site

This information is not stored in a database. It is forwarded immediately by email to Ranil Ranasinghe's mailbox and kept there until your enquiry has been answered and the matter is closed.

Three measures guard against form spam, none of them a captcha: a field invisible to humans, a minimum time spent on the form, and a limit on requests per IP address. For that limit your IP address is counted in memory for ten minutes and then discarded.

Legal basisArt. 6 (1) (b) GDPR where the enquiry serves to prepare a contract, otherwise Art. 6 (1) (f) GDPR — legitimate interest in answering your request.

Email and telephone

If you write or call directly, the details in your message or your telephone number are processed in order to answer your request. The mailbox is hosted by GMX (1&1 Mail & Media GmbH); incoming messages are stored there.

Legal basisArt. 6 (1) (b) or (f) GDPR.

What this website does not do

The following points are not a statement of intent but the verified state of the code that is served:

  • It sets no cookies and stores nothing in your browser.
  • It counts no visits and embeds no analytics or audience measurement tool.
  • The two typefaces used are served as files from the same server as the site. No connection to Google Fonts is made when a page loads.
  • It embeds no maps, videos, social network buttons or third-party content, and links to no external website.
  • There is no automated decision-making and no profiling.

Encryption

The site is served exclusively over encrypted HTTPS; requests over HTTP are redirected to HTTPS. The certificate is issued by Let's Encrypt.

Your rights

You have the right at any time to information about the data processed about you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20).

You may object under Art. 21 GDPR to any processing based above on Art. 6 (1) (f) GDPR. An informal note to the address or email address given above is sufficient.

Right to lodge a complaint

Independently of this, you may lodge a complaint with a data protection supervisory authority. The competent authority is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.

This statement describes the state as of 1 September 2026. If what the website does changes, this text is changed with it. This English version is a translation for convenience. In case of doubt the German version is authoritative.