Skip to content
RADIATEGeospatial Software Engineer | 3D GIS
HomeProjectsAboutOnline DemosDEEN

Data protection

Privacy Policy

Information about personal data processing when visiting radiate.berlin, using optional functions and accessing the protected online demos.

Last updated: 1 August 2026

Contents Controller Server logs Consent management Reach measurement Cloudflare Turnstile Login and online demos Uploads and job data External map content Contact Your rights

1. Controller

Oliver Förster
Bartningallee 29
10557 Berlin
Germany
Email: oli@radiate.berlin
Phone: +49 30 70220640

2. Hosting and provision

The website is hosted on a server provided by IONOS SE. Technically necessary connection data is processed to deliver content to the user's device and to detect attacks on the server. Where the hosting provider processes data on behalf of the controller, this is based on a data processing agreement pursuant to Article 28 GDPR.

3. Server log files

When the website is accessed, the following technical access data may in particular be logged: IP address, date and time, requested URL, HTTP method, status code, amount of data transferred, referrer and browser/user-agent information.

Purpose: technical provision, troubleshooting, prevention of abuse and protection against IT security incidents. Legal basis: Article 6(1)(f) GDPR. The legitimate interest is the secure and reliable operation of the website.

Storage period: Full IP addresses in regular server log files are generally retained for no more than seven days and are then deleted. Longer retention only takes place where a specific security incident requires evidence preservation or legal enforcement. Full IP addresses are not used for long-term statistics.

4. Consent management, cookies and local storage

A privacy settings dialog is displayed on the first visit. You can allow optional functions or use only technically necessary functions. Either decision can be made with one click. Your selection can be changed or withdrawn at any time using the permanently available “Privacy settings” button.

To remember this selection, only the entry radiate_privacy_consent_v2 is stored in the browser's local storage. It contains the selected categories, the version of the consent text, the time of selection and an expiry date. The choice is stored for no more than 180 days. This storage is necessary to respect the decision and avoid displaying the dialog on every page view.

Optional functions are not activated without consent. In the protected login area, technically necessary session cookies may additionally be used for authentication and access control.

5. Self-hosted reach measurement

After your consent, self-hosted reach measurement may run on selected public pages. Its purpose is to collect events concerning use of the home page and the “About” page for aggregated evaluation and to improve the website. No analytics or advertising data is transmitted to an external analytics provider.

The measurement creates a random identifier for the current browser session in sessionStorage under the name radiate_analytics_session_v2. The data processed includes the internal page visited, selected link or button targets, a referrer reduced to a host name or internal page reference, and technical indicators showing whether JavaScript and browser automation were detected. URL query parameters and form contents are not included in the analytics event. The IP address is necessarily transmitted to the website's own server with the HTTP request; the information on server log files applies.

Legal basis: your consent under Article 6(1)(a) GDPR and, where information is accessed on or stored in the terminal equipment, section 25(1) TDDDG. The session identifier ends with the browser session. If consent is withdrawn, the identifier is removed from sessionStorage and no further analytics events are sent.

6. Cloudflare Turnstile for demo access

Cloudflare Turnstile is used at https://radiate.berlin/wps-demo/access/ to limit automated access requests and abuse of the public WPS demo service. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.

The Turnstile script and verification widget are not loaded merely by opening the access page. Separate information is shown first. Only after you select “Load Cloudflare Turnstile” does your browser establish a connection to challenges.cloudflare.com. If you decline, Turnstile is not loaded and you are redirected to the project page. For technical and security reasons, temporary public WPS credentials cannot be issued without the security check.

When Turnstile runs, Cloudflare may in particular process the IP address, time and destination of the request, browser and device information, user agent, operating system, language settings, technical browser and environment signals, interaction and verification signals, cookies or local storage where applicable, and a short-lived verification token. Cloudflare also provides the operator with verification and statistics information that may relate to dimensions including hostname, country, browser and IP address. The generated token is checked server-side via Cloudflare's “Siteverify” interface. According to Cloudflare, Turnstile verification tokens are valid for no more than five minutes and can be used only once; Cloudflare's contractual and privacy retention rules apply to further verification and statistics data. Within the RADIATE system, the IP address is processed as an HMAC pseudonym for its own quotas and security events; independently of this, Cloudflare receives the connection data technically required for Turnstile.

Purpose: bot detection, prevention of abuse and protection of limited demo resources. Legal basis: your separate consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Consent is voluntary; however, the requested access credentials cannot be issued without the security check. You can leave the page before loading the widget or end the consent by reloading the page. Transfers already made remain lawful.

Processing may also take place in the United States or other countries outside the European Economic Area. Cloudflare states that it relies on its certification under the EU-U.S. Data Privacy Framework for transfers to the United States and additionally provides European Commission Standard Contractual Clauses in its Data Processing Addendum.

Further information: Cloudflare Privacy Policy, Cloudflare Turnstile documentation and the Cloudflare Data Processing Addendum.

7. Login and protected portfolio area

For protected online demos, account, login and session data may be processed. This may include a user name or email address, a secure password hash, session identifier, timestamps, login events and security-related technical information. A technically necessary session cookie is used only for login and access control and is not used for analytics or advertising. The legal basis is Article 6(1)(b) GDPR where processing is required to provide the requested function, and Article 6(1)(f) GDPR for abuse prevention and IT security.

8. Uploads, processing jobs and job data

When online demos are used, uploaded files, file names, job parameters, generated results, status information and technical logs may be processed. This data is required to perform the processing operation initiated by the user. The legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR for test and demonstration use.

Job and upload data remains stored until it is deleted using the provided cleanup function or is no longer required for operation, troubleshooting and security. Sensitive or personal source data should only be uploaded where an adequate legal basis exists. The online demos are not intended for particularly sensitive data.

9. External map and 3D content

Depending on the selected base map, individual protected map or 3D applications may retrieve map data from external providers, particularly OpenStreetMap or CARTO. The IP address is necessarily transmitted to the relevant provider. Such content is not loaded on the purely public information pages, but only when the respective protected application is deliberately opened.

10. Contact

If you contact the controller by email or telephone, the information you provide is processed to handle the request. The legal basis is Article 6(1)(b) GDPR for contract-related enquiries and otherwise Article 6(1)(f) GDPR. The data is deleted once the request has been conclusively handled and no statutory retention obligations or legitimate documentation interests prevent deletion.

11. Rights of data subjects

Subject to the statutory requirements, you have rights including access, rectification, erasure, restriction of processing, data portability and objection. Consent may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

You also have the right to lodge a complaint with a data protection supervisory authority. In particular, the following authority is competent:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany
Email: mailbox@datenschutz-berlin.de
www.datenschutz-berlin.de

12. Updates to this policy

This privacy policy will be updated if functions, services used or legal requirements change.

RADIATE

CityGML, Blender and automated geospatial workflows.

AboutImprintPrivacy