Convenience translation
Website privacy
Complete English translation of the information about personal-data processing on the public cavetown.de and kyouma.uk websites. The German notice remains authoritative if wording differs.
01
02
Scope
This notice applies to the public landing page at cavetown.de and
www.cavetown.de, as well as the gradually introduced secondary web
addresses kyouma.uk and www.kyouma.uk. The secondary addresses do
not serve a separate copy of the site. They discard URL paths and
query strings and redirect to the cavetown.de home page. The only
path-specific exception is the standard security contact at
/.well-known/security.txt, which redirects to its
canonical counterpart. Other
services on subdomains that are shared only
with intended users are covered by the supplementary
privacy notice for private services.
03
Hosting
The server infrastructure is provided by:
netcup GmbHEmmy-Noether-Straße 10
76131 Karlsruhe
Germany
The hosting provider processes technical data where required to provide and secure the server infrastructure. Further information is available in the netcup privacy notice.
04
Server logs
The web server necessarily processes the following data for each request:
- the requesting system’s IP address,
- date and time of access,
- HTTP method and requested URL path,
- HTTP protocol version,
- response status and amount of data transferred, and
- the supplied browser or User-Agent header.
Query strings and Referer values are deliberately omitted from the Apache access log. Processing supports secure delivery, troubleshooting and defence against abuse. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is stable and secure operation of the website.
Local Apache logs rotate by size. At most five files of up to 20 MB each are retained before the oldest is overwritten, so there is no fixed retention period. Security events may be retained separately for as long as needed to investigate and prevent abuse.
05
Abuse detection with CrowdSec
CrowdSec analyses access logs locally to identify automated scans, attacks and other abusive requests. When a security event is found, the attacking IP address, time and event type, together with limited request context such as the target path and User-Agent, may be sent to:
CrowdSec SAS20 rue Maurice Arnoux
92120 Montrouge
France
Processing supports immediate attack defence and shared IP-reputation data and is based on Article 6(1)(f) GDPR. CrowdSec describes this ecosystem processing as joint controllership. According to CrowdSec, concrete attacking IP addresses are normally kept unchanged for no more than three months and are then progressively aggregated or anonymised. Its privacy policy contains current details and data-subject contacts.
CrowdSec names AWS, GCP, Firebase, Slack and ClickUp, among others, as possible processors. Processing may therefore take place outside the European Economic Area. CrowdSec states that, depending on the recipient, it relies on European Commission adequacy decisions or standard contractual clauses for those transfers.
Addresses assessed as abusive may be blocked temporarily. If access was blocked incorrectly, use the controller contact above to request a review.
06
Cookies and local storage
The landing page sets no cookies and uses neither Local Storage, Session Storage nor comparable techniques. It uses no analytics, advertising or profiling services. All styles, graphics and the small worldline-console script are served by CaveTown. That script controls only the local countdown and randomized display; it sends no requests and stores no data. Motion is reduced when the browser requests it.
Because the landing page does not store or read information on the visitor’s device that requires consent, it does not display a consent banner.
07
Contact by email
When you contact CaveTown by email, your email address, message, technical mail metadata and voluntarily supplied information are processed to answer the request. The legal basis is Article 6(1)(f) GDPR. Data is deleted once the matter is concluded unless legal retention duties or legitimate documentation needs require otherwise.
08
Recipients and international transfers
Technical-data recipients may include netcup as hosting provider and CrowdSec as security service. Both organisations are established in the European Economic Area, but CrowdSec may use the processors and international-transfer safeguards described above. Apart from this security processing, the landing page does not deliberately initiate a third-country transfer. Other disclosures occur only where required by law, necessary for legal claims or covered by another applicable legal basis.
09
Data-subject rights
Subject to the conditions of the GDPR, rights include:
- access to personal data (Article 15),
- rectification of inaccurate data (Article 16),
- erasure (Article 17),
- restriction of processing (Article 18),
- data portability where applicable (Article 20), and
- objection to processing under Article 6(1)(f) (Article 21).
Send requests to support@cavetown.de.
10
Right to complain
Under Article 77 GDPR, data subjects may complain to a supervisory authority. The authority generally responsible for the controller’s location is:
The State Commissioner for Data Protection and Freedom of Information Baden-WürttembergHeilbronner Straße 35
70191 Stuttgart
Germany
Email: poststelle@lfdi.bwl.de
www.baden-wuerttemberg.datenschutz.de
11
Updates and authoritative version
Last updated: 26 August 2026. This notice is updated when functions, recipients or legal bases change. The German privacy notice remains authoritative if this translation differs.