Version: 2026-06-11
1. Controller
Controller within the meaning of the GDPR:
Alexey Sokolovskiy Business designation: Alex Sokolov · Data Protection & IT Security Baumstr. 15 47445 Moers Germany Phone: +49 2841 9496-220 Email: alex@alex-sokolov.de
→ Full mandatory disclosures: Imprint.
2. General notes
The following notes provide a simple overview of what happens to your personal data when you visit my website, view my social media profiles, or contact me by email. Personal data is any data that can identify you personally.
This policy covers:
- the website
alex-sokolov.de(DE/EN/RU) - email communication to
*@alex-sokolov.de - my professional Instagram profile @alex.sokolov.itsec
- my associated Facebook page (Meta platform; serves solely the technical administration of the Instagram profile; Messenger is deactivated)
3. Web hosting and server logs
This website runs on a virtual server managed by me at STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. The server is located in Germany; hosting involves no third-country transfer.
When you visit this website, the web server transiently processes your IP address and connection data as technically required to deliver the requested pages.
No access logs: The web server is deliberately configured without access logging. No visitor logs are stored — no IP addresses, no requested pages, no browser identifiers. Only technical system and error messages without systematic personal reference are kept briefly in the system journal and rotated automatically.
Legal basis of the transient processing: Art. 6 (1) (f) GDPR (legitimate interest — delivery and secure operation of the website).
Processing agreement: A data processing agreement per Art. 28 GDPR is in place with STRATO GmbH (server infrastructure).
4. Contact by email
If you contact me by email, your details (email address, name if provided, message content) are processed to handle the enquiry.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual steps) or Art. 6 (1) (f) GDPR (legitimate interest in efficient communication).
Retention: Emails remain in the mail file for as long as required for the engagement, and at minimum according to statutory retention obligations (German HGB / AO, up to 10 years).
Mail hosting: mailbox.org (Heinlein Hosting GmbH, Berlin, Germany). A processing agreement is in place.
5. Instagram profile and Facebook page (Meta)
I operate a professional profile on Instagram (@alex.sokolov.itsec) and an associated Facebook page (Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland — “Meta”). The Facebook page serves solely the technical administration of the Instagram profile; Facebook Messenger is deactivated. When you visit my profile or page, comment on a post, react to a story, or send me a direct message, Meta processes your data on its own responsibility; for certain processing operations I act as a second joint controller.
5.1. Joint controllership for Insights
For the statistical evaluations Meta provides me about visitors of my profile or page (“Instagram Insights” / “Page Insights”), Meta and I are joint controllers under Art. 26 GDPR. Basis:
- CJEU judgment C-210/16 (“Wirtschaftsakademie Schleswig-Holstein”, 5 June 2018) — profile/page operators are jointly responsible for Insights processing
- Meta’s “Page Insights Controller Addendum” — as operator I am bound by this addendum; available at https://www.facebook.com/legal/terms/page_controller_addendum
This joint controllership is limited exclusively to Insights. For all other processing (account data, advertising, tracking outside my profile, cookies, device identifiers) Meta is solely responsible.
5.2. Data categories processed (Insights)
Meta provides me with aggregated statistics only:
- number of profile/page visitors per day/week
- demographic breakdown (age, gender, region) exclusively at aggregate level
- reach and interactions of my posts and stories
- time and frequency of visits
I receive no personal data about individual visitors from Meta — only aggregated statistics. What data Meta collects beyond that on its own responsibility (e.g. cookies, device IDs, movement profiles within Meta platforms) is outside my knowledge and control.
5.3. Direct messages and comments
My Meta presences serve reach only; no substantive consulting takes place there. If you nevertheless send me a direct message (DM) or comment on a post, I process this content solely to redirect you to a secure channel (email, phone). No substantive handling takes place via Instagram/Facebook. Meta additionally stores the content on its own servers.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest — redirection to an appropriate communication channel).
Retention: I delete incoming DMs/comments after redirection, at the latest after 30 days.
Switch to a secure channel: For any matter, in particular confidential ones and from engagement initiation onward, please use email (mailbox.org, see §4) or phone. Instagram DMs are technically unsuitable for confidentiality (readable by Meta, no E2E on my account).
5.4. Third-country transfer (USA)
Meta transfers data to the USA. The transfer is based on the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023, Decision C(2023) 4745) and, additionally, on EU Standard Contractual Clauses.
5.5. Your rights vis-à-vis Meta
For data access, deletion requests and objections towards Meta, contact Meta directly:
- Meta privacy policy: https://privacycenter.instagram.com/policy/
- Privacy enquiries to Meta: https://www.facebook.com/help/instagram/contact/505535973176353
For the joint Insights processing (§5.1), both controllers are points of contact — you may also contact me directly (alex@alex-sokolov.de).
5.6. Voluntariness / alternatives
Using my Meta presences is voluntary. If you prefer not to transfer data to Meta:
- my profile can be viewed without an Instagram account — avoid logging in
- contact is alternatively possible by email (§4) or phone
- all essential content also appears on this website
6. Cookies
This website sets no cookies other than technically necessary ones (e.g. language preference). There is no web analytics, no conversion tracking, and no advertising pixels.
If extended features are activated in the future (e.g. appointment booking, newsletter signup), this policy will be extended and — where required — consent obtained per § 25 of the German TDDDG. As long as this note is here, that is not the case.
7. Your rights
You have the following rights at any time:
- Access (Art. 15 GDPR) — what data I process about you
- Rectification (Art. 16 GDPR) — correction of inaccurate data
- Erasure (Art. 17 GDPR) — deletion, unless retention obligations apply
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR) — competent: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Postfach 200444, 40102 Düsseldorf, Germany
Requests to alex@alex-sokolov.de. Reply within one week on working days; statutory deadline 30 days.
8. TLS encryption
This site uses continuous TLS/SSL encryption with automatic certificate renewal for security and confidentiality.
9. Changes to this privacy policy
This policy is updated upon material changes. Current version: see date above.
Change history: 2026-05-17 full review (MVP start) · 2026-05-25 Instagram section adapted to reach-only · 2026-06-11 hosting section switched to STRATO (Germany) — formerly Hostiman, the third-country transfer (Russian Federation) no longer applies; appointment-booking section removed (service not in operation); Facebook page added to the Meta section; sections renumbered; no-access-log configuration documented.
Note on translations: The German version is legally binding. The EN and RU translations are for information.