Last updated: 6 October 2026
This is a translation for convenience. If the two versions differ, the German Datenschutzerklärung prevails.
1. Controllers
We are joint controllers for the processing of personal data on theweeklydash.com (Art. 26 GDPR):
Kevin Kyburz, Hasen 64, 6462 Lauerz, Switzerland
Daniel Müller, Volkartstr. 24, 80634 Munich, Germany
You can reach both of us at hello@theweeklydash.com.
We run the website together and decide together which data we process, for which purposes and by which means. In an agreement under Art. 26 GDPR we have laid down that we answer requests about your rights jointly through the address above, and that Daniel Müller is the contact person for data protection supervisory authorities in the EU, and Kevin Kyburz for the Swiss Federal Data Protection and Information Commissioner. Regardless of this, you can exercise your rights against each of us.
This policy also serves as the privacy notice under the Swiss Federal Act on Data Protection (FADP).
2. In short
- We show no ads and use no tracking cookies or services that follow you across other websites.
- The whole website runs on Cloudflare. We don't embed any other providers, and we serve the fonts ourselves.
- For visitor statistics we use Cloudflare Web Analytics, which works without cookies (section 4).
- We protect the comment feature and the contact form against spam with Cloudflare Turnstile (section 6).
3. Hosting and delivery through Cloudflare
theweeklydash.com runs on the platform of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare runs the server (Cloudflare Workers), the database (D1), the image storage (R2) and the website's outgoing email (Email Sending) for us, and delivers the pages through its worldwide network of data centers.
With every request, Cloudflare processes the data your browser sends for technical reasons: your IP address, date and time, the requested address, the previously visited page (referrer), and details of your browser and operating system. Cloudflare uses this data to deliver and cache the pages and to protect the website against attacks and abuse. Where Cloudflare provides us with server logs for troubleshooting, they are deleted automatically after seven days at the latest.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to provide the website reliably, quickly and securely.
Cloudflare processes the data on our behalf; we have a data processing agreement with Cloudflare under Art. 28 GDPR. Data may be transferred to the USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR); for Switzerland, the Swiss-U.S. Data Privacy Framework applies. In addition, Cloudflare has agreed to the European Commission's standard contractual clauses. More information is in Cloudflare's privacy policy.
4. Visitor statistics with Cloudflare Web Analytics
To see which articles are read and how fast the pages load, we use Cloudflare Web Analytics. For this, Cloudflare adds a small script to our pages as it delivers them, which your browser loads from static.cloudflareinsights.com and runs.
When a page is opened, the script sends Cloudflare: the address of the page, the previously visited page (referrer), browser, operating system and device type, and measurements of load time and page rendering. The country is derived from the IP address; according to Cloudflare, the IP address itself is discarded at the nearest data center and not stored.
Web Analytics sets no cookies, stores nothing in your browser and, according to Cloudflare, builds no profiles of individual visitors. We only see aggregated figures, such as page views per article or the split by country, and cannot link them to a person. Cloudflare keeps the individual measurements for seven days and only in condensed form after that; we can access the statistics for the past six months.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to learn which content our readers are interested in and to improve the website's load times. Section 3 applies to the transfer to the USA. You can prevent the collection by blocking scripts from static.cloudflareinsights.com, for example with a content blocker in your browser.
5. Comments
You can comment below our articles. For this we process:
- the name you enter (a pseudonym is fine),
- your email address,
- the text of your comment and the time you send it,
- a check value (hash) of your IP address, from which the address cannot readily be recovered, and your browser's identifier (user agent).
We review your first comment before it appears. Once we have approved a comment under your email address, further comments under that address appear right away; we can still remove them at any time. Only the name, text and date are published. We don't publish your email address; we use it to recognize whether we have already approved a comment from you, and to reach you with questions about your comment. We use the check value of the IP address and the browser identifier to fend off spam and abuse and to limit the number of comments per sender.
When a comment is waiting for our approval, we send the two of us an email with your name, the text of the comment and the link to the article, so we can review it promptly. It does not contain your email address. We send it through Cloudflare (section 3) to our own mailboxes at Google Workspace and delete it once we have reviewed the comment. Google processes the message there on our behalf; data may be transferred to the USA in the process, for which Google is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to enable a discussion of our articles, to publish contributions you send us for that purpose, and to protect the comment feature against abuse.
Approved comments remain stored as long as the article they belong to is online, or until you ask us to delete them. Comments we don't approve are deleted after review. The data used to limit the number of comments is deleted automatically after about an hour. The comments are stored in our database at Cloudflare (section 3).
6. Spam protection with Cloudflare Turnstile
To keep automated programs (bots) from submitting comments or messages through the contact form, we use Cloudflare Turnstile. As soon as you click into the comment form or the contact form, your browser loads a script from challenges.cloudflare.com for this; Turnstile is not loaded while you only read an article or open the contact page. It runs small checks in the background, such as computational puzzles and queries of browser features; you don't see a puzzle or a checkbox. In doing so, Cloudflare processes your IP address, your browser's identifier (user agent), technical characteristics of your connection (TLS fingerprint) and our website's identifier. Your browser sends the result of the check to us together with your comment or message, and our server has Cloudflare confirm it. We don't accept comments or messages without a valid result. Turnstile does not receive what you type into the form or the text of your comment or message.
For detecting bots, Cloudflare processes the data on our behalf (section 3). According to Cloudflare, it also uses the data to improve Turnstile's bot detection; Cloudflare is itself responsible for that. Details are in the Turnstile Privacy Addendum.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to protect the comment feature and the contact form against spam and automated abuse. The legal basis for accessing your device is § 25(2) no. 2 TDDDG, because the check is strictly necessary for the comment feature or the contact form you started to use. Section 3 applies to the transfer to the USA.
7. Search
When you use the search, your search term is sent to our server to find matching articles. We don't analyze search terms and don't store them separately. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is to offer you a search.
8. Cookies
If you explicitly choose the "Light" or "Dark" color scheme in the footer, we store this choice in a cookie named theme for one year. If you choose "System", the cookie is deleted. The cookie contains only the chosen setting.
To fend off automated access, Cloudflare may set technically necessary cookies such as __cf_bm or cf_clearance. They serve only the security of the website.
The legal basis for storing these cookies on your device is section 25(2) no. 2 of the German TDDDG (Telecommunications Digital Services Data Protection Act), because they are strictly necessary for the display you asked for or for operating the website securely. We set no other cookies.
9. Contact by email and through the contact form
If you write to us at hello@theweeklydash.com, we process your email address, your name if you give it, and the content of your message in order to reply. Messages to this address are received by Cloudflare Email Routing and placed in our shared mailbox, which we run in our own Cloudflare account. Cloudflare stores the messages and their attachments on our behalf in data centers in Western Europe; our replies are sent through Cloudflare as well (section 3).
You can also write to us through the contact form at theweeklydash.com/en/contact. For this we process your name (a pseudonym is fine), your email address, the text of your message, and whether you sent the form from the German or the English page. Our server checks your details, has Cloudflare confirm the result of the spam check (section 6) and sends your message as an email through Cloudflare (section 3) to hello@theweeklydash.com, with your email address as the reply-to address. Your message thus lands in the same shared mailbox as an email to that address and is handled the same way. We don't store your details on the website itself, and we don't send you a copy by email.
To keep anyone from using the form in bulk, our server counts how many messages arrive from the same connection within one minute. For this it hands Cloudflare a check value (hash) of your IP address instead of the address itself; Cloudflare keeps the count only for that one-minute window.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is to answer your request and to protect the contact form against abuse. Where your request aims at entering into or performing a contract with us, the legal basis is Art. 6(1)(b) GDPR. We delete your message once your request has been dealt with, unless statutory retention obligations apply.
10. Links to social networks
Below our articles you'll find links to share an article on Bluesky, X or LinkedIn and links to the authors' profiles; the footer links our profile on X. These are plain links. Only when you click one is the respective service opened and receives data from you. The respective provider alone is responsible for the processing there.
11. Your rights
You have the right of access to the data we process about you (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR) and to data portability (Art. 20 GDPR). To exercise them, write to us at hello@theweeklydash.com.
Right to object: Where we process data on the basis of Art. 6(1)(f) GDPR, you can object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR).
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence. The authority responsible for Daniel Müller is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany: www.lda.bayern.de. In Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) is responsible: www.edoeb.admin.ch.
You are not obliged to provide us with any data. Without the technically necessary access data, however, the website cannot be delivered, and without a name and email address you can neither comment nor use the contact form. No automated decision-making, including profiling, takes place.
12. Changes
We update this policy when the website or the law changes. The version published here applies.