Paul Tillich

Legal

Privacy policy

This site is deliberately frugal. There are no accounts, no sign-in, no comments, no tracking cookies and no external font services. Audience measurement runs cookie-free on our own server. Whatever is nevertheless processed is set out in full below.

1. Controller

The controller for data processing on this website is:

Julius Maximilian University of Würzburg
Institute for Protestant Theology and Religious Education
Chair of Protestant Theology II
Wittelsbacherplatz 1, 97074 Würzburg, Germany
Phone: +49 931 31-80369
Email: i.nord@uni-wuerzburg.de

The controller is the natural person or legal entity that, alone or jointly with others, decides on the purposes and means of processing personal data.

2. Hosting and server logs

The website is delivered statically and hosted externally. When a page is requested, your browser transmits technically necessary data which the host records in log files: browser type and version, operating system, referrer URL, hostname of the accessing computer, time of the request and IP address. This data is required for error-free delivery and to fend off attacks; the legal basis is Art. 6(1)(f) GDPR. It is not merged with other data sources, and user behaviour is not analysed.

3. Progress and saving code

This platform has no accounts and no sign-in. Anyone who wants to keep their progress beyond the current browser creates a code in the format TIL-XXXX. The code is assigned at random and is not linked to any person.

Stored under this code are: tick marks against module and task IDs, passage marks (the position in the text or the second in a recording, together with the marked wording) and, if you write one, your own note on a mark. No name, no email address, no IP address and no history over time are stored.

The note is the only free text. It is limited to 280 characters and is shown to you alone — it is visible to no one else and is not evaluated. Please do not write anything there that you would not carry on a slip of paper in your pocket: no names of other people, no health data, nothing that would allow conclusions about you or others. The legal basis is your consent, given when you create a code (Art. 6(1)(a) GDPR).

You can delete at any time: each mark individually where it stands, or all of them together on the page “What I have kept”. Deletion takes effect immediately, including on the server.

As long as no code has been created, nothing leaves the browser. Saving is an offer, not a requirement; the platform is fully usable without a code.

The code itself is kept locally in the browser (localStorage) so that the same session continues on your next visit. This storage is technically necessary for the function you requested and does not serve tracking purposes; it is based on Art. 6(1)(a) GDPR in conjunction with § 25(2) TDDDG. You can delete the entry at any time through your browser settings.

Progress stored under a code is deleted after 12 months without access. If you lose the code you lose access to that progress — it cannot be recovered, and by design it must not be, since recovery would require personal data.

There is no scoring, no assessment and no transfer of progress to third parties. Progress is a memory aid, not a record of achievement.

4. Cookies, fonts, audience measurement

This site sets no tracking cookies and embeds no external font services; all typefaces come from your own device. There is no advertising and no profiling.

For audience measurement we use Umami, software running on our own server in Germany (t.godsapp.de). It sets no cookies, assigns no cross-device identifier and stores no IP addresses. What is recorded: the page visited, the referring source, approximate location at country level, screen size, browser and operating system — each in broad categories and without reference to a person. No data is passed to third parties.

We also count which functions are used: that a module was opened, a box ticked, a recording played, a video loaded or a PDF opened. What is counted is the kind of action and the module identifier — never your progress code, no input, no search terms and no linking of individual actions into a history. The legal basis is our legitimate interest in shaping the service to actual needs (Art. 6(1)(f) GDPR). As no information is stored on or read from your device, no consent under § 25 TDDDG is required.

If your browser sends the “Do Not Track” signal, nothing is measured.

5. External videos

Individual modules refer to videos hosted by a third party. These videos are loaded only after you explicitly click. Before that click no request goes to the third party — no preview images, no scripts, no DNS prefetching. By clicking you consent to the connection (Art. 6(1)(a) GDPR); from that moment the provider can collect data, including your IP address. Where an alternative exists, a transcript is offered alongside the video.

6. Contact by email

This site contains no contact form. If you write to us by email, your details are stored and processed in order to deal with your request (Art. 6(1)(f) or Art. 6(1)(b) GDPR). We do not pass this data on without your consent. It remains with us until you ask for deletion or the purpose no longer applies; statutory retention periods are unaffected.

7. Your rights

You have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients and the purpose of processing, as well as a right to rectification, erasure, restriction of processing and data portability. You may revoke any consent given at any time with effect for the future. You also have the right to lodge a complaint with the competent supervisory authority.

The competent authority is the Bavarian Data Protection Commissioner, Wagmüllerstraße 18, 80538 Munich, Germany.

8. SSL / TLS encryption

Transmission is encrypted. You can recognise an encrypted connection by the address line of your browser beginning with “https://”.

9. Version

This statement is dated 2026. It will be updated whenever the platform changes.