1. Who we are
The websites and services of Christian Albert Mueller β lps.world (including all subdirectories under /k/, /claw/, /christianalbertmueller/) and aros.ai with its subdomains β are operated by Christian Albert Mueller, an individual based in Munich, Germany. We are the "data controller" under the EU General Data Protection Regulation (GDPR) and equivalent laws.
Schwanseestr. 47
81549 MΓΌnchen, Germany
USt-IdNr.: DE298983586
Email: hello@christianalbertmueller.com
Full contact details are in our Imprint.
Data Protection Officer
We have appointed an external Data Protection Officer (Datenschutzbeauftragter) you can contact directly with any privacy questions:
DG Datenschutz
Franz-Joseph-Str. 11
80801 MΓΌnchen, Germany
Tel: +49 (0)800 β 6264376
Email: info@dg-datenschutz.de
Web: dg-datenschutz.de
2. What personal data we collect
Data you give us directly
- Email address β when you subscribe to our newsletters (MyDaysX Mag, Claw's Mag, Munich Talk, CTRL & CLAW Capital).
- Optional name β when you provide it in subscribe forms or contact us.
- Message content β anything you type into a contact form or send by email.
Data collected automatically
- IP address β temporarily, in standard server access logs.
- Browser type, OS, referring page, page visited, timestamp β standard server logs.
- Cookies set by our hosting/CDN for technical operation (see Cookies section).
- Newsletter open events β when your email client loads the embedded 1Γ1 pixel, we record a SHA-256 hash (truncated to 16 chars) of your email + the campaign ID. Apple Mail and most enterprise gateways pre-fetch the pixel before you ever see the message, so opens are a rough engagement signal not a true read count.
- Newsletter click events β when you click a link in one of our emails, the link first hits our redirect endpoint
aros.ai/newsletter/studio/click.phpwhich logs the click (hashed email + campaign ID + the URL clicked) and immediately forwards you to the destination. The redirect adds a few milliseconds; we never modify or inspect the destination URL. - Page interaction events β anonymous "likes" and play counts on videos.
Data we do NOT collect
- We do not use Google Analytics, Facebook Pixel, or any third-party advertising tracker.
- We do not sell your data, ever.
- We do not profile you for advertising.
3. Why we collect it (legal bases)
Under GDPR, we rely on these legal bases:
- Consent (Art. 6(1)(a) GDPR) β for newsletter subscriptions. You can withdraw consent any time.
- Contract (Art. 6(1)(b)) β to deliver content you've signed up for.
- Legitimate interests (Art. 6(1)(f)) β for security logs, anti-spam, basic engagement metrics. We balance this against your privacy and you can object (see Your Rights).
- Legal obligation (Art. 6(1)(c)) β to retain certain logs where required by law.
4. How we collect it
- Subscribe forms on lps.world and its subdomains.
- Email tracking β a 1Γ1 transparent pixel + click-through redirect URLs in our newsletters (see Β§ 2 above).
- Server logs: standard access logs at our web hosts (Namecheap shared hosting + AWS EC2 for some services).
5. Who we share data with
We use third-party processors β they only get the minimum needed to deliver their service:
- AWS (Amazon Web Services) β email sending (SES), bounce handling (SNS), some hosting (EC2 in eu-central-1). Servers in EU. AWS Privacy
- Namecheap shared hosting β primary hosting for lps.world. Namecheap Privacy
- MongoDB Atlas / self-hosted MongoDB β subscriber database. EU region.
- YouTube (Google) β when you watch our embedded videos. Google Privacy
- SoundCloud β when you listen to embedded audio. SoundCloud Privacy
We never share data with advertisers or data brokers.
5b. Where our emails come from
We send via Amazon SES from these verified domains:
aros.aiβ newsletters, support replies, automated mailslps.worldβ personal mails and magazine blastsmydaysx.clubβ MyDaysX product newsletters
The From address per send is chosen by us when composing (e.g. support@aros.ai, chris@lps.world). The Reply-To header matches the From. Mails sent to any @aros.ai address are forwarded by Namecheap to a single human inbox.
5c. Bounce & complaint handling
Amazon SES notifies us automatically when an address bounces (hard or soft) or someone clicks "spam". Both events:
- Are recorded in our send-log (SQLite, encrypted at rest)
- Cause AWS to add the address to its account-wide suppression list β we will never try again
- Cause the address to be removed entirely from our active subscriber list within 24 hours via a daily cron sync β deleted, not merely flagged
- Leave behind only an irreversible one-way fingerprint (a hash of the address) on a small suppression list, so we can be certain never to email or re-import it β we keep no readable copy of a removed address
6. Cookies & tracking
We use the absolute minimum cookies needed for the site to work:
- Strictly necessary cookies β set by the web server for session handling. Lifespan: session.
- YouTube/SoundCloud embeds β when you click play, those services may set their own cookies. We use privacy-enhanced YouTube embeds (
youtube-nocookie.comwhen possible).
You can disable cookies in your browser settings. Most of the site works fine without them.
How we count visits (cookieless analytics)
We measure page views and unique visitors on our own server β no Google Analytics, no Facebook Pixel, no third-party analytics service. For this we store nothing on your device: no cookie, no local-storage identifier.
To count a unique visitor without identifying you, our server derives a short, one-way hash from your IP address combined with a secret salt that rotates every month. Your raw IP address is never stored in our analytics, the hash cannot be reversed back to your IP, and it changes each month so you cannot be tracked over time. We also use Cloudflare's own country signal for rough, country-level geography β so your IP is not sent to any separate location-lookup service. None of this analytics data is shared with third parties.
We do not use a cookie consent banner because we don't set non-essential cookies and we don't store any tracking identifier on your device. If that ever changes, we'll add one.
Affiliate links
Some links on our site and in our newsletters are affiliate links β for example via Digistore24, ClickBank, Impact.com, or directly with a brand. If you click one and make a purchase, we may earn a commission at no extra cost to you.
When you click an affiliate link, the partner network may set its own cookie in your browser to attribute a possible sale to us. We do not receive your payment details or your individual purchase data β only aggregate, anonymised commission reports (e.g. "3 sales this month"). The partner network is the data controller for whatever happens after you leave our site; please see their own privacy policy. We only feature products we'd genuinely recommend, and a recommendation is our opinion, not professional advice.
7. How long we keep your data
- Newsletter subscriptions: until you unsubscribe + 30 days (audit window).
- Bounced or undeliverable addresses: removed from our active list promptly (within 24 hours of the bounce, or once verified undeliverable). We keep only an irreversible one-way hash on a suppression list β never a readable address β solely to guarantee we never contact or re-import it.
- Contact form messages: 24 months, then deleted.
- Server logs β kept for 14 days via standard nginx logrotate, then auto-deleted.
- Email engagement events (opens + clicks) β kept for 12 months on our server in a SQLite database (encrypted at rest), then automatically purged via a daily cron at 04:00 UTC. We don't aggregate; we delete the row entirely after 12 months.
8. Your rights
Under GDPR, CCPA, and similar laws, you have the right to:
- Access β request a copy of all data we hold on you.
- Rectify β correct inaccurate data.
- Erase ("right to be forgotten") β have your data deleted.
- Restrict processing β pause how we use it.
- Object β to processing based on legitimate interests.
- Portability β receive your data in a machine-readable format.
- Withdraw consent at any time (e.g. unsubscribe from emails).
- Lodge a complaint with your local data protection authority. In Germany: Bayerisches Landesamt fΓΌr Datenschutzaufsicht (BayLDA).
To exercise any right, email us at the address below. We respond within 30 days.
9. International data transfers
Most of our infrastructure is in the EU (eu-central-1). Where data is processed outside the EU/EEA (e.g. by AWS US-based parent, or Google for YouTube embeds), the transfer relies on Standard Contractual Clauses (SCCs) and adequacy decisions where available.
10. Children's privacy
Our content is intended for adults. We do not knowingly collect data from children under 16. If you believe a child has subscribed, contact us and we'll delete their data immediately.
11. Security
We use TLS (HTTPS) for all traffic. Subscriber email addresses in our primary database (MongoDB) and in our send-logs (SQLite) are encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA256), with the encryption key wrapped by AWS KMS so a leaked database snapshot alone does not expose any addresses. Admin access is via SSH key authentication only (no password login). We rotate API credentials when we suspect exposure, when team members change, or at minimum annually. No system is 100% secure β we'll notify affected users if a breach occurs that is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR).
12. Changes to this policy
We may update this page when our practices or the law changes. Material changes will be announced in our newsletter. The "Last updated" date at the top always reflects the current version.
13. Contact us
Email: hello@christianalbertmueller.com
Privacy questions: privacy@christianalbertmueller.com
Franz-Joseph-Str. 11, 80801 MΓΌnchen Β· +49 (0)800 β 6264376
info@dg-datenschutz.de
We are a small independent operation. If you write us about your data, you'll get a personal reply β usually within 48 hours.