Privacy policy
Draft version
Controller
The controller within the meaning of article 4 number 7 GDPR is:
- Kolja Sagorski, Einzelunternehmen (sagorski.it)
- Address: Meisterweg 16, 45896 Gelsenkirchen, Deutschland
- Email for data protection requests: datenschutz@vpn-matrix.com
Data protection officer
On current assessment no data protection officer has to be appointed, because the thresholds of section 38 of the German Federal Data Protection Act are not reached and no processing takes place that would trigger an appointment on other grounds. This assessment will be reviewed before the public launch. Data protection requests go to the address named above.
Principles
These points apply to the whole service. They are not a statement of intent, they are fixed in the technical setup:
- Application, database, file storage and mail sending run entirely on Cloudflare, Inc., based in San Francisco, California, in the United States.
- No resources are loaded from external servers. No fonts, no scripts, no images, no map services, no video embeds.
- There is no advertising, no profiling and no cross device recognition.
- Cloudflare, Inc. is a processor based in the United States. The full IP address and the connection data of every request are processed there. This is a transfer to a third country and is described in detail under Recipients.
- Anyone who only reads needs no account and leaves none behind.
Processing activities in detail
Server logs
Every request creates a technical log entry. The IP address is truncated before the entry is written, so it is never stored in full in our log.
- Data: Truncated IP address, timestamp, requested address, status code, amount of data transferred, browser identification, referring page.
- Purpose: Operation and troubleshooting, defence against attacks and automated abuse.
- Legal basis: Article 6 paragraph 1 point f GDPR, legitimate interest in secure and reliable operation.
- Retention: 7 days, then deleted automatically.
The truncation only affects our own log. Cloudflare, as the operator of the infrastructure, receives the request before we do and processes the full IP address in doing so. That applies to every request and cannot be switched off in this mode of operation.
Accounts for editors and contributors
Anyone who wants to suggest changes or work editorially creates an account. Registration is completed through a confirmation link sent by email (double opt in), so that nobody can enter someone else's address.
- Data: Email address, display name, role, time of confirmation, password stored as a non reversible hash, time of the most recent sign in.
- Purpose: Sign in, attribution of suggestions and editorial changes, notifications about your own account.
- Legal basis: Article 6 paragraph 1 point a GDPR, consent. It can be withdrawn at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.
- Retention: Until withdrawal or until the account is deleted.
Editorial changes appear in the public changelog. What is visible there is the display name, not the email address. If an account is deleted, the changes remain for the sake of accountability, from then on without a name.
Business customer data from the Verified programme
Providers taking part in the paid Verified programme enter into a contract. That requires details about the company and about a contact person.
- Data: Company name, address, name and business contact details of the contact person, invoicing and payment data, documented permissions such as a logo release.
- Purpose: Conclusion and performance of the contract, invoicing, evidence of the permissions granted.
- Legal basis: Article 6 paragraph 1 point b GDPR, performance of a contract. For the retention of accounting records additionally article 6 paragraph 1 point c GDPR in conjunction with section 147 of the German Fiscal Code and section 257 of the German Commercial Code.
- Retention: For the duration of the business relationship. Accounting records for up to ten years, counted from the end of the respective calendar year.
Messages you send us
Writing to us means sending us data. We answer the message and keep it no longer than the matter requires.
- Data: Sender address, subject, content of the message and anything you choose to include.
- Purpose: Handling the enquiry. For reports about a data point additionally the record of what a change was based on.
- Legal basis: Article 6 paragraph 1 point f GDPR, legitimate interest in answering. For contractual matters article 6 paragraph 1 point b GDPR.
- Retention: Until the matter is settled. Reports that led to a change in the matrix are kept longer as evidence of where that change came from.
Request statistics of the infrastructure
We ship no counting script and set no identifier in the browser. Cloudflare keeps statistics on incoming requests for the domain by itself. They arise at the server, we see them only as aggregate figures, and they cannot be switched off in this mode of operation.
- Data: Page requested, timestamp, status code, approximate country, coarse device class. In the report shown to us, no full IP address and no identifier that would allow a device or a person to be recognised again.
- Purpose: Seeing which content is read, noticing load peaks and errors.
- Legal basis: Article 6 paragraph 1 point f GDPR, legitimate interest in a frugal evaluation of operations.
- Retention: Only aggregated counts are stored, no individual events with a personal reference.
No consent under section 25 paragraph 1 TDDDG is needed for this, because no information is stored on your device and none is read from it. We evaluate only what your browser sends to the server anyway in order to receive the page. That does not answer what Cloudflare as the operator processes beyond this, which is set out under Recipients.
Cookies and storage on your device
There is no consent banner, because there is nothing that would require consent. A banner collecting consent that nobody needs would be a nuisance without a purpose.
- After signing in, a session cookie is set. It keeps the signed in session and is strictly necessary for that, so it falls under the exemption in section 25 paragraph 2 number 2 TDDDG. Without a sign in, no cookie is set.
- Your chosen appearance, light or dark, is kept in the browser localStorage. That too is strictly necessary in order to deliver exactly the appearance you explicitly asked for. The value is never sent to the server and never used to recognise you.
- Selection, filters and sorting of the matrix live in the address bar, not in storage on your device. That is why any view can be shared without us storing anything about you.
- There are no cookies for audience measurement, advertising, recognition or personalisation.
Recipients
Processor for the entire infrastructure
Cloudflare, Inc., based in San Francisco, California, United States of America.
Cloudflare runs the delivery of the pages, the execution of the application (Workers), the database (D1), the file storage (R2), the cache (KV), the sending of transactional mail (Email Sending), the scheduled maintenance runs (Cron Triggers) and the name resolution of the domain (DNS). There is no further operator.
- Data: What is processed there: the full IP address and the connection data of every request, the requested address, timestamp and browser identification, as well as all content held in the database, the file storage and the mail sending.
- Purpose: The purpose is the operation of this service: delivery, execution of the application, storage of the data, sending of confirmation and notification mail, and defence against overload and automated abuse.
- Legal basis: Article 6 paragraph 1 point f GDPR, legitimate interest in secure and available operation, and for content from accounts and contracts additionally article 6 paragraph 1 point a or point b GDPR. Processing takes place on our instructions, on the basis of a data processing agreement under article 28 GDPR.
Because Cloudflare is based in the United States, this involves a transfer of personal data to a third country under chapter V GDPR. The transfer is intended to rest on the standard contractual clauses of the European Commission under article 46 paragraph 2 point c GDPR, together with an assessment of the legal situation in the receiving country.
As a company based in the United States, Cloudflare is subject to the law there. Whether and to what extent this creates disclosure obligations towards US authorities, and which additional measures follow from that, is among the points still to be reviewed legally.
PlaceholderThe data processing agreement with Cloudflare, Inc. has not been concluded yet, the standard contractual clauses have not been signed, and the assessment of the legal situation in the receiving country is outstanding. Both are recorded as open points in docs/legal.md and must be in place before the public launch.
PlaceholderThere are no further service providers at present. Should one be added, it will be named here with its place of business before it is used.
Data is passed to authorities only where we are legally obliged to do so.
Transport security
These pages are served exclusively over encrypted HTTPS. Passwords are never stored in clear text.
Your rights
As a data subject you have the following rights against the controller:
- Access to the data processed about you (article 15 GDPR).
- Rectification of inaccurate data (article 16 GDPR).
- Erasure (article 17 GDPR).
- Restriction of processing (article 18 GDPR).
- Data portability in a common format (article 20 GDPR).
- Objection to processing based on a legitimate interest (article 21 GDPR).
- Withdrawal of a consent you have given, with effect for the future (article 7 paragraph 3 GDPR).
An objection under article 21 GDPR can be raised on grounds relating to your particular situation. After that we stop processing the data concerned, unless there are compelling legitimate grounds that override your interests.
For all of these, an email to the data protection address is enough. Where there is reasonable doubt about your identity we may ask for further details, purely to prevent someone else from obtaining information about you.
There is no charge. We answer within one month.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, article 77 GDPR gives you the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement.
Supervisory authority responsible for the operator: The competent authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Postfach 20 04 44, 40102 Düsseldorf, Germany.
No automated decision making
There is no automated decision making in individual cases and no profiling within the meaning of article 22 GDPR. No profiles are built about visitors.
Obligation to provide data
You do not have to provide any data in order to read this service. An account requires an email address, a contract in the Verified programme requires the usual company and invoicing details. Without them, the account or the contract cannot come about.
Changes to this policy
This policy is updated whenever the processing changes. Every change is traceable through the public history of the source code.
Status: Draft ahead of legal review, not yet in force.