The Nile Collection · an independent record

Privacy

What this site records about you, why, for how long, and what you can demand of us. Written under Articles 13 and 14 of the GDPR.

The short version

This site sets no cookies. There is nothing to consent to and no banner to dismiss.

There is no login, no account, no comment box and no search box. The only thing you can send us is an answer to the one question in the panel that appears near the bottom of the page, and only if you choose one of its four options. Closing it sends nothing.

Three things do happen automatically. The web server writes a log line for every request, this site keeps its own record of which search engines and AI systems read which pages, and an analytics script counts the visit without identifying you. All three are described below in full.

One thing is stored on your device: a single note that you have already seen that question, so you are not asked again. It contains no identifier, it is never sent anywhere, and it is the only item this site has ever written to a browser. Its own section is below.

One thing here is not as clean as it should be, so it is said plainly rather than buried: the page fonts are still loaded from Google, which means your browser contacts Google and Google sees your IP address. We are fixing it. It has its own section below.

Who is responsible

The controller under Article 4 (7) GDPR.

Controller
Christoph Paterok
Nordstrand 500A
18609 Ostseebad Binz
Germany
Email
christoph@chptk.de
Telephone
+49 151 28872425
Data protection officer
None appointed. A one-person operation that does not process personal data as its core activity is below the threshold in § 38 BDSG. Send data protection questions to the address above and they reach the person responsible directly.

What actually happens when you open a page

Server logs

Every request to this site is written to the web server's log file, the way every web server on the internet does it. Nobody reads these lines in the normal course of things. They exist so that an attack or a fault can be traced afterwards.

What is recorded
Your IP address, the date and time, the page requested, the HTTP status returned, the number of bytes sent, the referring page if your browser sent one, and your browser's user agent string.
Why
To deliver the page you asked for, to keep the server running, and to investigate attacks and abuse.
Legal basis
Article 6 (1) (f) GDPR, legitimate interests. The interest is operating a website securely and being able to establish what happened after an incident.
How long
14 days, then the file is deleted automatically. Longer only if a specific line is needed as evidence in an ongoing investigation of an attack.
Who else sees it
Nobody. The logs stay on the server and are not exported, sold or shared.

Which machines read the site, and who arrives from an answer

This site is written to be read by search engines and AI assistants as well as by people, so it keeps its own record of which ones came and which pages they took. It is the same information as the server log above, kept in a form that can be counted, and it is used to answer one question: is this material reaching the systems that now answer people's questions for them.

The referring page, which the server log has always recorded, is also counted for a second reason: when an assistant names this site in an answer and somebody follows the link, the request usually arrives marked with the name of that assistant. Counting those tells us an answer reached a person, which is the one thing the crawler figures cannot show. It is a count of arrivals, not of visitors. Nobody is identified, and nothing about it is passed on.

Two deliberate limits, because this record lasts longer than the server log. A full IP address is kept only where the request was identified as an automated agent, where the address belongs to a company rather than to a person. Every other request, which means every request from a browser, including yours, is stored with its address replaced by an irreversible hash. The hash is salted with a value that changes every day and is never written to disk, so two visits on two different days cannot be linked to each other, and nothing in this record can be traced back to you.

What is recorded
The date and time, the page requested, the HTTP status, the bytes sent, how long the page took, the referring page, the user agent string, and which named crawler that user agent belongs to if any. Plus the IP address for an automated agent, or an irreversible daily-salted hash of it for everyone else.
Why
Measuring which search engines and AI systems read the site and which pages they read, and counting how many people arrive here from an AI assistant's answer. Also to tell a genuine crawler from something impersonating one, which happens on this site.
Legal basis
Article 6 (1) (f) GDPR, legitimate interests. The interest is knowing whether an independent editorial site is being read by the systems that increasingly answer travel questions instead of showing search results. Against that we set the fact that a person's address is never stored in a recoverable form for this purpose.
How long
400 days, then the row is deleted. Longer than the server log on purpose: a year plus a margin is the shortest window in which this year can be compared with last year.
Who else sees it
Nobody. It stays on the same server and is not exported, sold or shared. Counts drawn from it may be published on this site or written about; those are counts of crawlers, never of people.

Visitor statistics

We count visits with Plausible Analytics, run by Plausible Insights OÜ, Estonia. It was chosen because it does not use cookies and does not build a profile of you. It tells us that a page was read, not who read it.

What is recorded
The page address, the referring site, the browser and operating system in rough terms, whether you are on a phone or a desktop, and your country, region and city derived from your IP address.
What is not recorded
No cookie is set. The analytics script itself writes nothing to your browser's storage; the one item this site does store is the survey note described in the next section, which the analytics service never sees. Your IP address and the full user agent string are used to derive the figures above and are then discarded, not stored. Repeat visits are counted with a hash that is regenerated daily and cannot be traced back to you or followed across days, sites or devices.
Why
To see which pages are read and which are not. This site has no revenue, so the only way to know whether the work is worth continuing is whether anybody reads it.
Legal basis
Article 6 (1) (f) GDPR, legitimate interests. The interest is understanding whether the site is used. This counting stores nothing on your device and reads nothing from it, so § 25 TDDG does not require your consent for it. The one item this site does store is covered in the next section, and it does not require consent either, so there is no cookie banner.
Where the data is
Inside the EU, on infrastructure the provider states is European-owned. The provider is established in Estonia and acts as our processor under Article 28 GDPR.
Their own description
https://plausible.io/data-policy, checked 13 September 2026.

The one question we ask, and the note it leaves on your device

About 7 seconds after a page opens, a panel appears near the bottom asking one question: Where are you with your Nile trip?. It offers four options. We ask because a record like this can be written for somebody idly reading or for somebody choosing between two boats next spring, and those are different jobs. Knowing roughly who is here decides what gets written next.

It is built to be ignored. Nothing is greyed out behind it, the page stays readable and clickable while it is open, and it closes on one click, on the Escape key, or by the skip link inside it. If you close it, nothing about the question is sent. We would rather have fewer answers than answers given to get rid of a box.

To ask it only once we have to remember that you have seen it, and that is the one thing this site stores on your device. It is not a cookie and it is never transmitted: it is a single entry in your browser's local storage, under the name nc_survey_v1, holding a value of exactly this shape.

{"status":"answered","on":"2026-09-15"}

A status and a date. No identifier, no visitor number, nothing that could be matched to you or to any other visit. You can read it yourself in your browser's developer tools, and deleting your site data removes it, after which the question would be asked once more. If your browser refuses that storage, the panel never appears at all, because a question we cannot stop asking is not a question you are free to decline.

What is sent to us
Two counts, through the analytics service described above: that the panel was shown, and, if you chose one, which of the four options it was. Nothing else. The option is stored as one of four fixed words and is attached to the page you were reading, so we can see which pages reach which kind of reader. It is not attached to you.
What is stored on your device
The single local-storage entry quoted above, until you clear your browser's site data. Nothing else, and no cookie.
Why
To learn who this record is actually being read by, and to honour your decision not to answer by never asking again.
Legal basis
For the stored entry, § 25 (2) no. 2 TDDG: it is strictly necessary to provide a service you asked for by closing or answering the panel, which is the ability not to be asked twice. Storing nothing would mean asking you again on every page, and it exists for no other purpose. For the counts, Article 6 (1) (f) GDPR, legitimate interests, the interest being knowing which readers this is reaching. There is still no cookie banner because there is still no cookie and nothing here requires your consent.
How long
The counts are kept as aggregate statistics with no expiry, the same as the page counts above, because they are not about a person. The entry on your device stays until you delete it.
Who else sees it
Only the analytics processor named above, which receives the two counts in the same way it receives a page view. Nobody else, and the totals are never broken down to anything smaller than a page.
Checked
15 September 2026. If the question changes, or if it ever stores more than the line quoted above, this section changes on the same day.

Fonts loaded from Google

The typefaces this site is set in are currently requested from Google's font service when a page loads. That means your browser makes a connection to Google, and Google receives your IP address and can see which site you were reading at that moment. We do not receive anything from Google in return and we set no Google cookie.

This is a real transfer of personal data to a US company and it is the one thing on this site we would rather not be doing. It is being removed by serving the font files from this domain instead. Until that is done, the honest statement is the one above.

Recipient
Google Ireland Limited, with onward transfer to Google LLC in the United States.
Legal basis
Article 6 (1) (f) GDPR, legitimate interests, the interest being a legible page. We note that a German court has held this basis insufficient for embedded Google Fonts, which is why we are removing the dependency rather than defending it.
How to avoid it now
Block third-party requests in your browser or use a content blocker. The site is designed to remain fully readable in its fallback typefaces.

Hosting

The site runs on a server operated for us by Letaido on Hetzner Cloud in Helsinki, Finland, inside the EU. The platform operator processes data only on our instructions, as a processor under Article 28 GDPR. Anything your browser sends to this site passes through that server.

The connection is encrypted with TLS. You can check this in your browser's address bar.

If you write to us

If you send an email or call, we keep what you sent, your address or number, and our reply, so that we can answer you and so that a later exchange makes sense. Legal basis: Article 6 (1) (b) GDPR where you are asking about something we are doing with you, otherwise Article 6 (1) (f), the interest being answering enquiries.

Correspondence about the accuracy of something published here is kept for as long as the statement in question is published, and for three years afterwards. We record who asked, when, what they claimed, what we checked and what we did. That record is what makes the corrections log verifiable, and it is the reason we can say a correction was made rather than merely asserting it. Other correspondence is deleted when it is clearly finished with.

Email is not secure in transit unless both ends encrypt it. Do not send us anything sensitive by email.

People named on this site

This is an editorial record of boats and the companies that run them. It occasionally names a person: the owner of an operator, a captain, the author of a press article we cite. That is journalistic and editorial processing under Article 85 GDPR and § 23 MStV, and the reporting privilege applies to it.

We name a person only where it is necessary to identify who is responsible for a boat or a claim, and only from a source we can cite and have archived. We do not publish hearsay about individuals. Where a person's name appeared in a source but did not meet that test, it stays out of the record and the reason is given in the open questions.

If you are named here and believe the entry is wrong, write to us. We correct errors of fact fast and in public. We do not remove accurate, dated, sourced statements on request.

Your rights

Articles 15 to 21 GDPR. Exercise any of them at christoph@chptk.de. It costs you nothing and we answer within one month.

One honest limit on all of these. The server logs, the machine-readership record and the visitor statistics contain nothing that lets us find you. If you ask what we hold about you, we cannot search the logs by name and will not ask you for more identifying information than we already have in order to try (Article 11 GDPR). If you have written to us, we can answer fully.

Complaining about us

Article 77 GDPR. You can complain to a supervisory authority without going through us first. The authority competent for this site:

Authority
Der Landesbeauftragte für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern
Schloss Schwerin
Lennéstraße 1
19053 Schwerin
Germany

Things this site does not do

No advertising, no advertising networks, no retargeting pixels, no tracking of any kind beyond the counting described above.

No social media buttons, no embedded videos, no maps, no comment system, no chat widget, no content delivery network. The only requests your browser makes to a third party are the font request described above, which is going away, and the analytics script.

No profiling and no automated decision-making within the meaning of Article 22 GDPR.

No newsletter and no email address collected anywhere. If that changes, this page is updated before the field appears, not after, and subscribing will require a confirmed opt-in.

We do not sell data. There is no arrangement under which anyone pays us for anything, which is set out in the imprint.


Version of 15 September 2026. When what this site does changes, this page changes on the same day and the version date moves. A privacy notice with no date cannot be checked against what a site was actually doing on the day you visited it.