Privacy policy

Last updated: 2026-06-11

This notice describes how Open-The-File.com processes personal data when you use the website and tools. It is designed for visitors in the EU and Italy (where Italian national privacy rules may also apply alongside the GDPR), including where Google AdSense is used after consent.

1. Data controller

Julian Stricker

Postal address: Romstraße 16/b, 39014 Burgstall, Italy

Email: info@open-the-file.com

2. Server log data

When you access pages or APIs, our hosting environment typically creates server logs. These may include your IP address, date and time of the request, HTTP method and path, response status, referrer URL, user agent string, and similar technical metadata. We use this information to operate the service, detect abuse, troubleshoot errors, and protect IT security. The website runs on servers operated by Hetzner Online GmbH in their Nuremberg (Nürnberg) data centre location, Germany (European Union).

We keep server logs only as long as necessary for these purposes and delete or anonymise them on a rolling basis, usually within 30 days unless a longer period is strictly required to follow up on a security incident or legal obligation.

3. Header analyzer tool

If you use the header analyzer, only the first 64 KB of the file you select is sent to our server for analysis. We do not store the uploaded file content as a permanent archive; processing is limited to producing the analysis you requested. The analysed chunk is processed in server memory for the duration of the request to generate the result and is not written to persistent application storage.

Depending on the data contained in the analysed chunk, the tool may process personal data you voluntarily submit (for example metadata or text inside a document). Do not upload files you are not allowed to share.

4. Consent management (cookie banner)

Non-essential cookies and marketing scripts (including Google AdSense) are blocked until you make a choice. Consent preferences are managed through the cookie banner provided by the Nuxt module @dargmuesli/nuxt-cookie-control. You can reopen the banner at any time (cookie icon) to change or withdraw consent for optional categories.

5. Plausible Analytics (audience measurement)

We use self-hosted Plausible Analytics (the open-source Plausible software) to understand aggregate traffic (for example page views and referrers) in a privacy-oriented configuration. Pageview and event requests from this website are sent to our own Plausible server, not to Plausible’s commercial cloud at plausible.io. The self-hosted Plausible instance runs on the same Hetzner infrastructure in Nuremberg, Germany, as this website. Plausible Insights OÜ therefore does not receive your analytics traffic from this site as part of that processing. In our setup, Plausible’s first-party analytics cookie is not used. For technical details about categories of data the self-hosted software can process, see Plausible’s documentation for self-hosted installations.

6. Google AdSense (advertising after consent)

If you enable marketing consent, Google may load AdSense and related technologies. In that scenario, Google acts as an independent controller for many advertising and measurement activities (including selection and delivery of ads, fraud prevention, and reporting), while we decide whether to embed AdSense on our pages and which ad slots to show. This can involve processing of identifiers, device data, and interaction data. Google publishes its own privacy and advertising documentation; for categories of data and purposes, see for example https://policies.google.com/privacy and https://policies.google.com/technologies/ads . AdSense is not loaded for visitors who do not give marketing consent.

7. Legal bases (by processing activity)

We process personal data only where a GDPR legal basis applies. The main activities on this site map as follows:

  • Server logs: Art. 6(1)(f) GDPR (overriding legitimate interests in security, abuse prevention, and stable operation of our IT systems), and where applicable Art. 6(1)(c) GDPR for compliance with legal obligations.
  • Header analyzer: Art. 6(1)(b) GDPR (processing necessary to perform the analysis you request) and/or Art. 6(1)(f) GDPR (legitimate interests in providing the tool and preventing misuse), depending on the concrete operation.
  • Plausible Analytics: Art. 6(1)(f) GDPR (legitimate interests in measuring aggregated website usage and improving the service). In the current setup, Plausible is used without analytics cookies and without sending analytics traffic to Plausible’s commercial cloud. For visitors in Italy, national rules (including Legislative Decree 196/2003 as amended and cookie / ePrivacy rules) may apply in addition to the GDPR. If we change the measurement setup in a way that requires consent under applicable law, we will obtain consent before activating the changed measurement.
  • Google AdSense: Art. 6(1)(a) GDPR (consent) for loading and operation of marketing technologies after you opt in via the cookie banner.

8. Recipients, processors, and international transfers

We do not sell your personal data. Depending on how you use the site and your consent choices, data may be received by the following categories of recipients:

  • Hetzner Online GmbH (Germany), which operates the servers for this website in the Nuremberg data centre (Germany / EU), typically as a processor on our instructions.
  • Our self-hosted Plausible Analytics installation (open-source software on the same Hetzner server environment in Nuremberg, Germany, as this website) for aggregated analytics; analytics requests are not sent to Plausible’s commercial SaaS at plausible.io.
  • Google (for example Google Ireland Limited / Google LLC and affiliates) for AdSense and related advertising technologies, after marketing consent.

Because Plausible is self-hosted for this site, analytics data from this measurement is not transferred to Plausible’s commercial cloud for that purpose. Core website and log processing for this project takes place in Germany (EU) on Hetzner infrastructure in Nuremberg. Some other recipients may be located outside the European Economic Area (notably Google in the United States when you enable marketing consent). Where such transfers occur, they are carried out using appropriate safeguards recognised under the GDPR (for example the EU Commission Standard Contractual Clauses) and/or other mechanisms described in the recipient’s documentation. You can read more in Google’s privacy and advertising documentation linked from Google’s policies.

9. Your rights, withdrawal of consent, and complaints

Under the GDPR, you have rights including access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21), in each case subject to legal conditions. To exercise these rights in connection with data we control, contact us at info@open-the-file.com. We will respond within the statutory time limits.

You may withdraw consent for optional cookies and marketing at any time with future effect by adjusting your choices in the cookie banner. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. Strictly necessary operations may continue where they do not rely on consent.

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. For Italy, the supervisory authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it).

This notice summarises our practices in plain language. It is not legal advice and does not replace an individual review of your obligations (for example with qualified counsel familiar with EU and Italian privacy law).