Privacy Policy
General Information
The following information provides an overview of what happens to your personal data when you visit this website. The term “personal data” covers all data that can be used to identify you personally.
Quick Summary
28mm is an editorial photography magazine. This website is something you read: there is no shop, no user account, no newsletter, no comment function and no contact form.
When you visit, we process the technical data needed to deliver the pages to you, and nothing beyond that.
No cookies are set, and nothing is written to your browser’s web or session storage.
There is no advertising, no profiling, no sale of your data, and no automated decision-making.
No analytics or tracking is currently in use. Should that change, it will require your prior consent, which you may give or withdraw at any time.
You may contact us at any time to access, correct or delete your data, using the address below.
Data Recording on This Website
The data processing controller for this website is (pursuant to Article 4(7) of the EU General Data Protection Regulation):
Schweikert Consulting
Simon Phumin Schweikert
c/o Christian Jahnke
Gulisastraße 93
56072 Koblenz
Email: privacy@28mmagazine.com
The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data.
Data Protection Officer
According to Article 37 GDPR in conjunction with § 38 BDSG, we are not required to appoint a data protection officer. If you have any concerns regarding privacy or wish to exercise your rights, please contact us directly at the address above.
Data Subject Rights
Your Rights
Under the General Data Protection Regulation, you have the following rights:
The right of access to information about the categories of personal data processed, the purposes of processing, the retention periods, and any recipients of the data (Article 15 GDPR and § 34 BDSG).
The right to rectification or erasure of inaccurate or incomplete personal data (Articles 16 and 17 GDPR and § 35 BDSG).
The right to restriction of processing, subject to the conditions of Article 18 GDPR or § 35(1) sentence 2 BDSG.
The right to object to the processing of your personal data on grounds relating to your particular situation, where the processing is based on legitimate interests (Article 21(1) GDPR).
The right to withdraw your consent at any time, with effect for the future (Article 7(3) GDPR).
The right to data portability, i.e., to receive the personal data you have provided to us in a commonly used and machine-readable format (Article 20 GDPR).
The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR, including the definition in Article 4(4) GDPR).
The right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement.
Procedure
If you exercise your rights under the GDPR and the BDSG, we process the data you provide in order to fulfil your request. We subsequently store your request and our corresponding response for documentation purposes until the expiry of the statutory limitation period for administrative offences, which is three years.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest arises from our obligation to respond to your request and our need to demonstrate, in any administrative proceedings, that we complied properly. You may object to this processing under the conditions set out in Article 21 GDPR, though such documentation is regarded as mandatory within the meaning of Article 21(1) GDPR, as no equally suitable means of verification is available.
Data Security Measures
This site uses SSL or TLS encryption for the protection of content transmitted between your browser and our servers. You can recognise an encrypted connection when your browser’s address line changes from “http://” to “https://” and the lock icon is displayed.
Data Processing
Sources and Categories of Personal Data
Data you provide directly: none. The website contains no forms, no sign-up and no checkout, so there is nothing for you to submit to us through it.
Data generated by your use of the website: your IP address, the time of your visit, and the pages or files requested.
We do not purchase personal data, and we do not collect it from registers, press, social media or other publicly accessible sources.
Data Transfers to Third Countries Outside the EU
The two providers we rely on are established in the United States and Norway respectively, or operate global networks, so your data may be processed outside the European Union. Where this occurs, it is covered by an adequacy decision of the European Commission (the EU-U.S. Data Privacy Framework) or by the EU Standard Contractual Clauses.
Each provider is named below together with its role, its location, and a reference to its own privacy information, so that it is clear who receives which data.
Disclosure of Data and Data Processing by Third Parties
We never disclose your personal data to unauthorised third parties. Data is passed on only with your explicit consent, to comply with a legal obligation, or where required by law, a regulatory authority or a court order.
The service providers listed below process data on our behalf and according to our instructions. Each is contractually obligated pursuant to Article 28 GDPR, including sufficient guarantees that appropriate technical and organisational measures are in place. Despite involving processors, we remain the controller responsible for the processing of your personal data.
Purpose of Processing
We use your data only for the purpose for which it was collected. Further processing for a different purpose may occur only if the new purpose is compatible with the original one (Article 5(1)(b) GDPR).
Specific Data Processing Activities
The sections below set out which data is processed, at what point, on what legal basis, and for what purpose.
Server Log Files
Every time you access this website or retrieve data from a server, general information is automatically transmitted to the server providing the content. This is an essential part of communication between devices on the internet.
This data includes your IP address, browser and operating system information (user agent), the website from which you accessed our site (referrer), the date and time of the request, the HTTP status, and the volume of data transmitted. We use it to identify and resolve errors, to analyse load peaks, and to detect unauthorised access attempts.
These data are stored temporarily in server log files for a short period, currently up to seven days, and are then deleted automatically. They are not combined with other data and are not used to identify you.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of the website. You may object under Article 21 GDPR, though the website cannot be delivered at all without this processing.
Cookies and Web/Session Storage
This website sets no cookies at all. Nothing is written to your browser’s web storage or session storage either, and no tracking, marketing, advertising or profiling technology of any kind is used.
Because nothing is stored on or read from your device, § 25 TDDDG does not apply and there is no cookie banner and nothing for you to accept or refuse.
Anything that is not strictly necessary, such as analytics, would require your prior consent under § 25(1) TDDDG. No such technology is currently in use. If it is ever introduced, you will be asked beforehand, it will remain switched off until you agree, and refusing will be exactly as easy as accepting.
Fonts and Other Assets
All fonts and scripts used on this website are hosted by us and delivered from the same infrastructure as the site itself. Nothing is loaded from a third-party network such as Google Fonts, so no request is made to any such provider when you visit, and no data is transmitted to one.
Hosting and Infrastructure
Cloudflare, Inc. (Front End and Delivery)
The front end of this website is delivered in its entirety by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. The application code runs on Cloudflare Workers, and Cloudflare additionally acts as a content delivery network and security layer in front of every request.
As a result, your IP address and connection metadata are routed through Cloudflare’s network on every visit. Requests are served from the location closest to you, which may be inside or outside the European Union. We operate no database of personal data on this infrastructure.
A Data Processing Agreement in accordance with Article 28 GDPR has been concluded with Cloudflare, and Cloudflare is certified under the EU-U.S. Data Privacy Framework. Privacy policy: https://www.cloudflare.com/privacypolicy/
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable delivery of the website.
Sanity (Editorial Back End)
The editorial content of this website, including the magazine pages, the catalogue, the imprint and this privacy policy, is stored and managed in Sanity, a content platform operated by Sanity AS, Oslo, Norway, together with its affiliate Sanity, Inc. in the United States. Depending on the hosting region of the content dataset, content may be processed within the European Union or in the United States.
Sanity serves as the editorial back end and holds published editorial content, not personal data about visitors. When your browser loads an image, that image is requested from Sanity’s image delivery network, which means your IP address and user agent are transmitted to Sanity for that request.
A Data Processing Agreement in accordance with Article 28 GDPR has been concluded. Privacy policy: https://www.sanity.io/legal/privacy
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in operating an editable website and delivering images efficiently.
Data Retention
Server log files are deleted automatically after a short period, currently within seven days. Correspondence in which you exercise your data protection rights is kept for three years, that being the statutory limitation period for the administrative offences concerned.
No order, payment, account or contact data is collected through this website, so none is retained and no statutory commercial or tax retention period applies to it.
Unless otherwise specified in this privacy policy, personal data is retained only as long as necessary for the purpose for which it was collected.
Consent Management
Nothing is currently stored on or read from your device, so there is nothing you are required to agree to in order to use this website. If optional storage is ever introduced, you will be asked before anything is set, it will remain switched off until you agree, and refusing will be exactly as easy as accepting. Withdrawing consent would be as easy as giving it and would take effect immediately for the future.
Updates to This Policy
This privacy policy may be amended in line with legal or technical developments. The version available at the time of your visit applies.
Last updated: August 2026