Privacy Policy
Privacy policy for US Gov Navigator (usgovnavigator.com). Last updated: August 2026. German version: /datenschutz.
1. Controller
Controller within the meaning of the GDPR:
Markus Bertan
An der Alster 6, 20099 Hamburg, Germany
Email: [email protected]
Phone: 040 46898063
Further details: Imprint. No data protection officer is legally required; for privacy questions use the contact details above.
2. Scope and legal bases
We process personal data only as needed to operate a functional website and provide our directory, or where you have consented. Legal bases include Art. 6 (1)(a) GDPR (consent), Art. 6 (1)(b) GDPR (pre-/contractual steps), and Art. 6 (1)(f) GDPR (legitimate interests, e.g. security and reliable search).
3. Hosting and server logs
The website is hosted with a professional hosting provider (typically Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, or an equivalent provider under a data-processing agreement). Server logs may include browser type/version, operating system, referrer URL, hostname, time of request, and IP address (possibly truncated). Logs are used for security and technical operation (Art. 6 (1)(f) GDPR) and are deleted or anonymized after a short period (usually within 7 days) unless a longer retention is required for security investigations.
4. Cookies and similar technologies
We use technically necessary cookies or local storage only where needed for security or basic functionality (§ 25 (2) TDDDG / Art. 6 (1)(f) GDPR). We do not load Google Analytics or Google AdSense on this site.
For internal operations we record first-party page-view signals (path, truncated hashed visitor id derived from IP + user agent, referrer / UTM source classification, and timestamp). This is stored on our own servers as an anonymized hit log, used only to understand traffic sources and improve the directory (Art. 6 (1)(f) GDPR). Bots and our own admin browsing are excluded. We do not use this data for advertising profiles or sell it to third parties. Retention is limited (typically under ~13 months of hit history, with automatic trimming).
5. Search (Meilisearch)
Search queries are processed by Meilisearch running as part of our application stack to return office and service results. Purpose: provide fast, relevant search (Art. 6 (1)(f) GDPR). Queries are not permanently linked to contact data for profiling.
6. Contact by email
If you email us at [email protected], we process the data you send to handle your request (Art. 6 (1)(b) or (f) GDPR). We keep the correspondence only as long as needed and delete it when the purpose ends, subject to statutory retention duties.
7. Links to third parties
Pages link to official .gov and other third-party sites. When you follow those links, their privacy policies apply. We do not control their processing.
8. Recipients
Processors may include hosting and infrastructure providers under Art. 28 GDPR agreements. We do not sell personal data.
9. Retention
Personal data is stored only as long as necessary for the stated purposes or as required by law.
10. Your rights
You have the rights of access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent where processing is based on consent (Arts. 15–21, 7 (3) GDPR). You may lodge a complaint with a supervisory authority (Art. 77 GDPR), typically where you live or where the controller is established (Hamburg, Germany).
11. Security
We use TLS/SSL and appropriate technical and organizational measures to protect data against unauthorized access, loss, or manipulation.
12. Changes
We may update this policy when the service or the law changes. The current version is always available on this page.