Privacy notice
Information pursuant to Art. 13 GDPR — version 1.0, as of 31/07/2026
This is a courtesy translation. The legally binding version of this privacy notice is the German version. In the event of any discrepancy, the German text prevails.
This privacy notice applies to the web application KERN Katalog(hereinafter “the application”) published at https://katalog.kern-ux.de. It explains which personal data are processed when you visit and use the application, for what purpose and on what legal basis, and what rights you have.
A separate privacy notice applies to https://www.kern-ux.de (the KERN project website). This notice covers the KERN Katalog only.
The public part of the catalogue — browsing and reading published entries — can be used without registering and without signing in. An account is only required to create entries yourself, to take part in the editorial process, or to comment on entries.
Controllers
The processing is subject to joint controllership pursuant to Art. 26 GDPR.
The controllers are:
Freie und Hansestadt Hamburg
Senatskanzlei / Amt für IT und Digitalisierung
Rathausmarkt 1
20095 Hamburg
E-mail: itd-dsb@sk.hamburg.de
and
Land Schleswig-Holstein
Staatskanzlei — Digitalisierung und Zentrales IT-Management (ZIT-SH)
Düsternbrooker Weg 104
24105 Kiel
E-mail: digitalisierung@stk.landsh.de
For general questions about the KERN Katalog please write to hallo@kern-ux.de. Requests concerning your data subject rights should be addressed to the data protection officer.
Data protection officer
Senatskanzlei / Amt für IT und Digitalisierung
Rathausmarkt 1
20095 Hamburg
E-mail: itd-dsb@sk.hamburg.de
Accessing the application (server logs)
When you access the application, your device transmits technically necessary data to the web server. These are recorded in operational logs:
- the IP address of your device
- date and time of access
- the address requested (URL) and the HTTP method
- HTTP status code and volume of data transferred
- the browser identification (user agent), referrer and preferred language transmitted
Purpose: technical delivery, operational security and fault analysis. Legal basis: Art. 6 (1) (e) GDPR in conjunction with § 3 BDSG (performance of a public task); the legitimate interest in secure operation follows from Art. 32 GDPR.
The logs are rotated continuously and overwritten automatically in the process. They are not merged with other data and are not evaluated to build usage profiles.
User account and profile
The following are processed in order to register and maintain a user account:
- e-mail address (also the sign-in name)
- display name
- organisation (optional)
- password — stored exclusively as an Argon2id hash; the plain-text password is never stored
- assigned roles and the approval status of the account
- time of creation and of the most recent sign-in
- if two-factor authentication is enabled: the corresponding secret, in encrypted form
Profile picture (optional). You may upload a profile picture. It is re-encoded on the server: scaled to a square of at most 256 × 256 pixels, converted to WebP and stripped of all metadata (EXIF) — in particular the location and time of capture are no longer present in the stored image. The profile picture is publicly visible once it appears next to a comment. You can replace or remove it at any time in your account.
Purpose: providing the account, attributing entries and comments, communication about the editorial process. Legal basis: Art. 6 (1) (b) GDPR (the usage agreement under the terms of use) and Art. 6 (1) (e) GDPR in conjunction with § 3 BDSG. The profile picture and the organisation are optional; they rest on your consent under Art. 6 (1) (a) GDPR, which you may withdraw at any time by removing the information.
Sign-in, sessions and cookies
The application sets no cookies for analytics or advertising. There is therefore no consent banner. Only strictly necessary cookies are used, and only after you sign in:
kern_refresh— session renewal. Set withHttpOnly,SecureandSameSite=Strict; not readable by JavaScript.- a CSRF cookie — protection against cross-site request forgery.
On the server, each session stores a hash of the session token, a hash of the browser identification, the time of issue and expiry, and any revocation. Access tokens are valid for 15 minutes, session tokens for 30 days. A reused session token immediately invalidates the entire session chain (detection of stolen tokens).
The application additionally stores small, non-personal settings in your browser’s local storage, such as the selected colour scheme (light/dark) and confirmation that you have read the terms of use. These values never leave your browser and can be deleted through your browser settings.
To protect against abuse (for example automated password guessing), request counts are held briefly in memory only. IP addresses are not stored persistently in the database.
Legal basis: Art. 6 (1) (b) GDPR and § 25 (2) no. 2 TDDDG (strictly necessary storage).
E-mails
Event-driven messages are sent to the e-mail address you provide, in particular: a welcome message after registration, password reset, account approval, and messages about the editorial process (entry submitted, published, changes requested, rejected or deleted).
Messages are sent via a mail server operated by the controllers. A log entry is created as proof of dispatch, recording the template, the recipient address, the language and the reference (for example the entry concerned). The content of the message is not logged.
Legal basis: Art. 6 (1) (b) GDPR (performance of the usage relationship). E-mail digests are sent only if you have enabled them in your notification settings — for those, Art. 6 (1) (a) GDPR applies; you may withdraw consent at any time in the settings.
Notifications
You can be notified about events in the catalog. The channels can be configured individually: in the application’s inbox, by e-mail (immediately, daily or weekly) and as a push notification on your device. Independently of these you select the notification sources: newly published entries, new comments on your own entries, new comments on any entry, and updates to published entries. Stored are your settings, your preferred language, the time each channel and each source was enabled and, per notification, the title, text, link target and the times of creation, dispatch and reading.
Data minimisation. Notifications about comments and updates contain neither the name of the acting person nor the comment text — only the title of the affected entry and a link to it. If a comment is moderated or an entry is taken out of public view before delivery, no notification is sent.
Push notifications (optional). When you register a device, the application stores the delivery address generated by your browser (endpoint URL), the associated encryption keys, a device label and the times of registration and most recent use. Delivery itself necessarily takes place through the push service of your browser vendor (for example Google, Mozilla, Microsoft or Apple). The delivery address and the encrypted message content are transmitted to that service; depending on the provider this may constitute a transfer to a third country (see “Transfers to third countries”).
Legal basis: Art. 6 (1) (a) GDPR (consent). You can deregister a device at any time in the settings; the stored delivery data are then deleted. If delivery fails repeatedly, the registration is removed automatically.
Creating and publishing entries
When you create an entry, its content and your identifier as the authoring, editing or publishing person are stored. The editorial process (draft, review, changes requested, approval, publication, archiving) is recorded with the time and the acting person; earlier versions are retained as revisions.
Once published, the content of the entry, its attachments and the attribution of authorship become publicly visible. Instead of your display name you may set a different designation (for example your team or your organisation) as the public attribution. An optional editorial contact address is published as well.
Uploaded files. Attachments are checked for their actual file type, limited in size and initially placed in a separate area. SVG files are sanitised and images are stripped of EXIF metadata. Please do not upload files containing personal data of third parties.
Legal basis: Art. 6 (1) (e) GDPR in conjunction with § 3 BDSG (performance of a task carried out in the public interest: building a reusable body of UX knowledge for public administration).
Comments
Signed-in users can comment on published entries. Stored are the text of the comment, its rendered form, your identifier as the authoring person and the times of creation and of any edit.
Comments are public and readable without signing in. Your display name and — if you have one — your profile picture are shown alongside the comment. Please bear this in mind when choosing your display name and when writing comments; do not publish personal data of third parties there.
You can edit or delete your own comments at any time. Edited comments are marked as such. People with editorial or administrative rights may also edit or delete comments for moderation purposes; the time and the deleting person are recorded so that moderation decisions remain traceable.
Legal basis: Art. 6 (1) (e) GDPR in conjunction with § 3 BDSG (professional exchange about the body of knowledge).
Logging of security-relevant events (audit log)
Administrative and security-relevant events are logged in a tamper-evident manner, for example sign-ins and failed sign-in attempts, role changes, status changes of entries and moderation decisions. An entry contains the type of event, the identifier of the acting person, the object concerned, the time and event-specific additional details. IP addresses are not stored here.
Entries are chained together by hashes so that subsequent modifications become detectable. Only people holding the system administration role can view them.
Retention: 12 months, after which entries are deleted automatically. Legal basis: Art. 6 (1) (c) and (e) GDPR, § 64 BDSG and Art. 32 GDPR.
Third-party services embedded
Depending on how the installation is configured, two additional services operated by the KERN project may be embedded. Both are loaded directly by your browser, which transmits your IP address and technical details of your browser to them.
- Feedback function (
feedback.kern-ux.de) — lets you report feedback. Only the details you enter and technical context about the report are transmitted. - Chat assistant (
chatbot.kern-ux.de) — answers questions about the KERN offering. Your input is transmitted to that service in order to answer it. Please do not enter personal or confidential data there.
Beyond that the application embeds no external content: fonts, images and program code are served exclusively from its own server. There is no web analytics and no tracking; no profiles are created.
The spelling and grammar check in the entry editor runs on our own infrastructure. The texts checked do not leave the application.
Recipients
Within the responsible bodies, access is granted only to those people who need it to perform their tasks (role and permission model). Technical operation is carried out by the Staatskanzlei Schleswig-Holstein (ZIT-SH) and the service providers it commissions, under processing agreements pursuant to Art. 28 GDPR.
Publicly accessible — and therefore visible to anyone on the internet — are: published entries including their attribution and attachments, and comments including the display name and profile picture.
Published entries can additionally be retrieved in machine-readable form through the open data interface. That interface also returns the display name and the internal identifier of the authoring people so that entries can be attributed. The editorial contact e-mail address is not returned through this interface by default.
Transfers to third countries
A transfer to a third country outside the European Economic Area is not envisaged. The application is operated in Germany.
Exception: if you have enabled push notifications, delivery necessarily takes place through the push service of your browser vendor. Depending on the vendor, that service may be operated in a third country. This transfer is based on your explicit consent pursuant to Art. 49 (1) (a) GDPR; you can end it at any time by deregistering the device. Without push notifications enabled, no such transfer takes place.
Retention periods
- User account: for the duration of the usage relationship. On request the account is deactivated and deleted.
- Session data: access tokens 15 minutes, session tokens at most 30 days; invalidated immediately on sign-out.
- Audit log: 12 months, then deleted automatically.
- Published entries: indefinitely, for as long as the public interest in their reusability persists. Earlier versions are retained as revisions.
- Comments: until deleted by you or by moderation.
- Unused file uploads: 24 hours.
- Server logs: until automatic rotation.
Deletion of an account is carried out by the administration; to request it, contact the data protection officer or write to hallo@kern-ux.de. Entries already published are generally unaffected, in so far as the public interest in their availability persists (Art. 17 (3) (d) GDPR); the public attribution can be changed on request.
Your rights
Please address any such request to the data protection officer named above.
- Right of access (Art. 15 GDPR) — you can request information about the data we process.
- Right to rectification (Art. 16 GDPR) — you can have your data corrected or completed.
- Right to erasure (Art. 17 GDPR) — you can request the deletion of your data.
- Right to restriction of processing (Art. 18 GDPR) — you can request that processing be restricted.
- Right to data portability (Art. 20 GDPR) — you can receive the data you provided in a commonly used format.
- Right to object (Art. 21 GDPR) — on grounds relating to your particular situation you may object to the processing at any time.
- Right to withdraw consent (Art. 7 (3) GDPR) — where you have given consent, you may withdraw it at any time with effect for the future.
Competent supervisory authority
Under Art. 77 GDPR you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data is unlawful. Because of the joint controllership you may contact either of the following authorities:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
Postfach 7116, 24171 Kiel
Telephone: 0431 988-1200
Fax: 0431 988-1223
E-mail: mail@datenschutzzentrum.de
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22, 20459 Hamburg
Telephone: 040 428 54-4040
E-mail: mailbox@datenschutz.hamburg.de
Changes to this notice
This privacy notice will be updated whenever the processing changes — for example because the application gains new features. The version published on this page applies; see the date at the top of the document.

