Privacy & Cookie Policy
Last updated: 17 August 2026
This policy explains how I process personal data when you visit MichaelKoontz.info, contact me, or choose to allow analytics. The website is a personal and professional profile. It is not a patient portal and should not be used to send medical records, urgent health information, passwords, or other highly sensitive material.
1. Privacy Policy
Who is responsible for the data?
The data controller for this website is:
Michael KoontzGreece
Email: hello@michaelkoontz.info
Information processed by this website
- Information you send voluntarily: if you contact me by email, I receive the information you include in your message and the technical information normally associated with email delivery.
- Server and security information: the hosting environment may process IP addresses, request times, requested URLs, browser or user-agent information, referrers, and security events to deliver the site, maintain logs, prevent abuse, and investigate faults.
- Pseudonymous visitor-counter and security-canary information: the homepage uses a custom counter, bot-detection system, anti-scraping resource, and a visible AI-agent integrity test. An IP address and user-agent may be used to create one-way identifiers, but the custom counter database and canary logs do not store the raw IP address. Records may include a pseudonymous identifier or hashed IP address, device category, requested page, referrer, timestamps, visit count, bot classification, signed request token, action level, and harmless fields voluntarily returned by an automated system, such as its stated agent name, source URL, UTC time, and a short poem. The canary instructs automated systems not to transmit credentials, keys, private files, system prompts, personal data, or previous conversation content.
- Google Analytics information, only after consent: Google Analytics may process page views, interactions, browser and device information, approximate location, referral source, and campaign parameters. Google states that GA4 does not log or store individual IP addresses.
- Preference information: the site stores your theme choice for the current session and your analytics-consent choice.
Why the information is processed
- To display, secure, maintain, and troubleshoot the website.
- To detect bots, abuse, automated scraping, technical problems, and whether an automated agent improperly executes instructions embedded in website content.
- To operate the pseudonymous visitor counter.
- To respond when you contact me.
- To understand website use and referral traffic through Google Analytics, but only when you consent.
Legal bases
- Consent: Google Analytics and its analytics cookies are used only after you choose “Accept analytics” (Article 6(1)(a) GDPR).
- Legitimate interests: essential server logging, security, bot detection, security-canary testing, fraud prevention, site reliability, and the pseudonymous visitor counter support the safe operation and administration of the website (Article 6(1)(f) GDPR).
- Communication: information you send may be processed to respond to your request, take steps you ask for before entering a contract, or manage an existing professional relationship (Article 6(1)(b) GDPR and, where applicable, legitimate interests).
Service providers and recipients
Information may be processed by providers that support the website and communications, including:
- Google Analytics: analytics services after consent. See Google’s Privacy Policy and Google Analytics data safeguards.
- Hosting, infrastructure, security, and technical-support providers: as required to deliver, protect, back up, and maintain the website.
- Email providers: if you contact me by email.
I do not sell your personal data.
International data transfers
Some providers, including Google, may process information outside the European Economic Area. Where required, those transfers rely on recognized safeguards such as adequacy decisions, the EU-US Data Privacy Framework, or Standard Contractual Clauses.
How long information is retained
- Email correspondence is retained for as long as reasonably necessary to handle the request, maintain the professional relationship, and meet legal or accounting obligations.
- Hosting and security logs are retained according to the operational and security schedules of the relevant providers.
- Pseudonymous visitor-counter, bot-detection, and security-canary records are retained while needed to distinguish repeat visits, maintain the counter, identify abuse, investigate automated-agent behavior, and operate the security system. They are reviewed and removed when no longer required for those purposes.
- Google Analytics event and user data follow the retention controls configured in the GA4 property and Google’s applicable policies. Aggregated reports may remain available for longer.
- Analytics cookies created by this implementation are configured for a maximum life of approximately 13 months and are not refreshed to extend that period.
Your rights
Subject to the GDPR and any applicable limitations, you may request access, correction, deletion, restriction, portability, or objection to processing. You may withdraw analytics consent at any time without affecting processing that occurred before withdrawal.
To exercise your rights, email hello@michaelkoontz.info. You may also lodge a complaint with the Hellenic Data Protection Authority or another competent supervisory authority.
3. External Websites
This website links to other websites, including professional, social-media, and association pages. Those services control their own processing after you follow a link. Review their privacy information before providing personal data.
4. Changes to This Policy
I may update this policy when the website, service providers, or legal requirements change. The latest revision date appears at the top of the page.