The server records limited request information so it can deliver and protect the site. Optional Google Analytics starts only after you chooseAllow analytics. Search words stay in your browser and are not sent to Google Analytics.
The controller and contact details
Mihaly Kertesz, a private individual in Hungary operates The Dreaming Cafe and is the controller of the personal data described in this notice. The Dreaming Cafe is the publication name. Privacy questions and data-protection requests can be sent to km@kerteszmihaly.com.
This notice covers the public website
This notice covers the pages and browser features provided onhttps://thedreamingcafe.com. It does not govern independent websites linked from articles. Those sites decide how they handle information when you visit them.
The site has no user accounts, purchases, comments, newsletter signup, advertising, contact form, or facility for submitting dreams. It does not build personal dream profiles or make automated decisions that produce legal or similarly significant effects.
Server logs help deliver and protect the site
The site's Nginx access log records the requested host, IP address, request date and time, request method, path and protocol, response status and size, referring page when supplied by the browser, and browser or device user-agent string. It does not record a request body, account details, submitted dream text, or an analytics cookie identifier.
The logs are used to deliver files, diagnose technical failures, prevent abuse, investigate security incidents, and establish or defend legal claims. The legal basis is the controller's legitimate interests under Article 6(1)(f) GDPR in operating and securing a public website. Logs are not used for advertising, personal dream interpretation, or routine visitor profiling.
The site-specific log is rotated daily. The current log and up to 14 rotations are retained, with older rotations compressed. A relevant record may be preserved longer only when reasonably necessary for a documented security incident, legal obligation, or legal claim.
The site runs on a self-managed virtual server supplied byContabo GmbH. Contabo receives the technical request information needed to provide its infrastructure and may use approved subprocessors under its published service and data-processing terms.
Search words remain in the browser
Search uses a Pagefind index delivered with the website. The words you enter are processed in your browser to identify matching pages. They are kept in the URL fragment after the # character, which is not included in an ordinary request to this server.
Search words are not sent to Google Analytics. If analytics is allowed, the site may report that a search happened, its character count, whether results were found, how many appeared, and whether Pagefind or the local fallback supplied them.
Theme and consent choices stay on your device
The browser stores tdc-theme to remember your light or dark theme and tdc-analytics-consent-v1 to remember your analytics choice and its time. The consent choice expires after 180 days. The theme remains until you change it or clear site data. Neither value is sent to this server or to Google.
These settings provide the preference you requested and remember whether the optional tag may load. They are not used to identify or profile you. If browser storage is blocked, a preference may need to be selected again.
Google Analytics is optional
Google Analytics 4, measurement ID G-XBR11WJ649, loads only on the production Dreaming Cafe domain and only after you chooseAllow analytics. Choosing Decline orDecide later does not load the Google tag. Declining does not reduce access to the site.
When allowed, Google Analytics may process:
- a sanitized page URL, page title, content group, and page type;
- a referring site with external query strings removed;
- browser, device, operating-system, language, approximate screen, session, and engagement information;
- approximate location derived during collection;
- approved campaign fields such as
utm_source; - navigation, content-selection, related-guide, source-link, and outbound-link events;
- article reading milestones at 25, 50, 75, and 90 percent; and
- the privacy-safe search measurements described above.
The implementation does not intentionally send:
- the words entered into search, dream text, or another free-text message;
- names, email addresses, telephone numbers, or postal addresses;
- a site-assigned user ID or fine-grained GPS location;
- account or purchase information, because those features do not exist; or
- arbitrary URL parameters that are not approved campaign fields.
Google Signals, user-provided-data collection, advertising personalization, advertising storage, advertising user data, and advertising product links are disabled. The site does not sell Analytics data or use it for targeted advertising.
Google Ireland Limited processes Analytics data under Google's applicable service and data-processing terms. For visitors in the EEA, Google explains that IP addresses are used to derive approximate location and are discarded before Analytics data is logged. ReadGoogle's EU-focused Analytics information andhow Google uses information from sites that use its services.
The legal basis is your consent under Article 6(1)(a) GDPR and the applicable browser-storage consent rule. Google may set first-party cookies including_ga and _ga_*. This site limits them to 180 days. The GA4 property retains event-level and user-level data for 14 months without resetting that period on new activity. Aggregate reports can remain available for longer until they or the property are deleted.
Analytics consent can be withdrawn
Use Analytics choices in the footer to allow, decline, or withdraw Analytics at any time. Withdrawal stops future collection, updates the consent signal, removes GA cookies the site can access, and reloads an active page when needed to stop the session cleanly.
Withdrawal does not make earlier lawful processing unlawful and cannot automatically remove data already aggregated by Google. You may contact the controller to exercise a data-protection right concerning previously collected information.
Email creates a correspondence record
If you email the contact address, the controller receives the address you use, your name if provided, message content and metadata, attachments you choose to send, information reasonably needed to verify or answer the request, and the reply and case history.
This information is used to handle the message, comply with legal duties, prevent abuse, and establish, exercise, or defend legal claims. The legal bases are Article 6(1)(c) GDPR where processing is needed for a legal obligation and Article 6(1)(f) for correspondence administration, accountability, security, and legal claims.
Email is supplied by Hostinger International Limited. Active correspondence is kept while the matter is handled and may then be retained for up to five years when necessary for legal obligations, GDPR accountability, or legal claims. It is deleted earlier when no longer needed. A documented dispute, authority request, or legal hold may require longer retention.
Do not send dream narratives, medical records, identity documents, or other sensitive information unless a proportionate item is specifically requested to verify a rights request. The contact address does not provide personal dream interpretations.
Recipients are limited to necessary providers
Personal data may be disclosed only as necessary to:
- Contabo GmbH, which supplies the VPS infrastructure;
- Google Ireland Limited and approved subprocessors when you allow Analytics;
- Hostinger International Limited, when you send an email;
- authorized technical, security, privacy, or legal advisers bound by appropriate duties; and
- courts, regulators, law-enforcement bodies, or other authorities when disclosure is legally required or necessary to protect legal rights.
The site does not sell personal data or disclose visitor information for targeted advertising.
Some providers process data internationally
Contabo is established in Germany and Hostinger International Limited is established in Cyprus. Google and provider subprocessors may process data in other countries. Where GDPR applies to a transfer outside the EEA, the applicable provider terms use a recognized safeguard such as an adequacy decision or approved standard contractual clauses. You may request information about the safeguard relevant to your data from the controller.
Your data-protection rights
Depending on the processing and applicable law, you may have the right to:
- receive information about how your data is used;
- obtain access to personal data about you;
- correct inaccurate or incomplete data;
- have data erased when there is no lawful reason to retain it;
- restrict processing in the circumstances set by law;
- receive data you supplied in a structured, commonly used, machine-readable format when portability applies;
- object to processing based on legitimate interests; and
- withdraw consent whenever consent is the legal basis.
Email km@kerteszmihaly.com to exercise a right. Describe the request and provide only what is reasonably needed to identify the relevant record. Proportionate identity verification may be requested to avoid giving information to the wrong person.
A complete request is normally answered within one month. The period may be extended by up to two further months when the request is complex or numerous. If that happens, you will be told within the first month and given the reason. Requests are normally free. A reasonable fee or refusal applies only where the law permits it, such as for a manifestly unfounded or excessive request.
Complaints can be made to a supervisory authority
You may ask the controller to investigate a concern by emailing km@kerteszmihaly.com. You may also complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
- 1055 Budapest, Falk Miksa utca 9-11, Hungary
- Postal address: 1363 Budapest, Pf. 9, Hungary
- Email: ugyfelszolgalat@naih.hu
- Telephone: +36 1 391 1400
- NAIH contact information
You may instead contact another competent supervisory authority, particularly where you live, work, or believe an infringement occurred. A complaint does not remove another judicial remedy available to you.
The site is not directed to children under 16
The Dreaming Cafe is a general educational publication and is not directed to children under 16. It does not knowingly ask children for names, contact details, dream narratives, or other submissions. A visitor under 16 should not allow optional Analytics without the authorization required from a parent or guardian under applicable law. If the controller learns that a child's data was collected contrary to this notice, reasonable deletion steps will be taken.
Security controls reduce risk
The site uses HTTPS, restrictive security headers, isolated site configuration, limited administrative access, consent-gated third-party scripts, data minimisation, site-specific logs, log rotation, and atomic deployment. Access to service and correspondence records is limited according to operational need. No internet service can promise absolute security.
This notice changes when processing changes
The notice is reviewed when the site adds a feature, changes a provider or retention period, expands Analytics, or otherwise changes how personal data is handled. The last-updated date identifies the current version. Where required, a new consent choice will be requested before new optional processing starts. Continued browsing does not substitute for consent where the law requires it.
Privacy questions can be sent by email
Contact km@kerteszmihaly.com about this notice or the handling of personal data.