Skip to content
watchDB
Overview
DE EN
Sign in

Privacy policy

This notice informs you pursuant to Art. 13 and 14 GDPR which personal data is processed when you visit this website.

Note for the operator: the legal notice is incomplete. Please fill in the IMPRINT_* environment variables in your .env file before making this site publicly reachable.

1. Controller

The controller responsible for data processing on this website is:

—
Deutschland

2. Data protection officer

No data protection officer has been appointed, as the statutory conditions for doing so are not met.

3. Server log files

When you access this website, technically necessary access data is processed: the requested address, the time, the HTTP status code and the amount of data transferred. The IP address is truncated before storage and thereby anonymised; it cannot be traced back to an individual. The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in secure and stable operation. The retention period is 7 days.

4. Cookies

This website uses strictly necessary cookies only. Under § 25 (2) no. 2 TDDDG these do not require consent, so no cookie banner is needed.

  • Session cookie (watchdb.sid) — keeps you signed in. It is only set after you sign in and expires after 14 days.
  • Language cookie (watchdb.locale) — remembers the display language you chose. It expires after one year.
  • The session cookie also carries a token protecting against cross-site request forgery.

5. User accounts

For a user account we process the email address, display name, a password (stored only as an Argon2id hash), the assigned role, the preferred language and the times of creation and last sign-in. The legal basis is Art. 6 (1) (b) GDPR. The data is erased as soon as the account is deleted.

6. Submitted content

Watches, images and descriptions are stored together with the account that created them and an audit log. The log exists so that editorial changes remain traceable; the legal basis is Art. 6 (1) (f) GDPR.

7. Email

We send email to operate user accounts: password resets, invitations for new accounts and confirmation of a password change. This processes the email address, the display name and the time. The legal basis is Art. 6 (1) (b) GDPR (performance of the user relationship) and Art. 6 (1) (f) GDPR for the security notification about a password change. No advertising or newsletters are sent.

Reset links and invitations contain a one-time token. Only a hash of it is stored in the database; the token itself exists solely in the email. It expires after the configured period, can be used only once, and is deleted after seven days at the latest.

Sending through a service provider

Delivery runs through our own mail server; no data is passed to third parties.

8. No third-party services

This website embeds no external content. Fonts, images, stylesheets and scripts are served exclusively from our own server. There is no usage analysis, no audience measurement and no disclosure to third parties.

9. Hosting

The operator has not yet provided hosting details.

10. Your rights

You have the following rights vis-à-vis the controller:

  • Access to the data stored about you (Art. 15 GDPR). Signed-in users can download their data at any time under “My account”.
  • Rectification of inaccurate data (Art. 16 GDPR).
  • Erasure (Art. 17 GDPR). You can delete your account yourself at any time.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR).
  • Objection to processing based on legitimate interests (Art. 21 GDPR).

11. Right to lodge a complaint

The competent authority is the data protection supervisory authority of the federal state in which the controller is established.

12. Changes to this policy

We update this privacy policy whenever changes to the website make it necessary. The version available here always applies.

Legal notice Privacy policy