Privacy Policy

Last updated: August 8, 2026

1. Data Controller

[full_name — pending owner input] ("we" or "us") [street_address — pending owner input] [postal_code_city — pending owner input] [country — pending owner input]

Email for privacy inquiries: [email — pending owner input]

We are responsible for deciding how we hold and use personal data about you. This privacy policy explains how we collect, use, and protect your information.

2. What Personal Data We Collect

Our website processes two categories of personal data:

Admin Authentication Data

  • Email address (used for login)
  • Password hash (encrypted; we cannot see your actual password)

Portfolio Content

  • Image files you upload to the portfolio management system
  • Image metadata (alt text, title, captions, chapter assignments)

What we do NOT collect:

  • Analytics data or behavioral tracking
  • Browsing history
  • Device information
  • Location data
  • Cookies other than session authentication

3. Lawful Basis for Processing

We rely on our Legitimate Interest (GDPR Article 6(1)(f)) to process your personal data. Our legitimate interests are:

  1. Maintaining a secure authentication system to protect access to portfolio management tools
  2. Preventing unauthorized access to your private portfolio data
  3. Providing and improving website functionality

We have concluded that these interests are proportionate to your expectations as an admin user and do not override your fundamental rights and freedoms.

4. Purpose of Processing

Your personal data is processed for these specific purposes:

| Purpose | Data Used | Retention | |---------|-----------|-----------| | Admin authentication and session management | Email, password hash | Duration of active account use | | Portfolio image storage and management | Images, metadata | Duration of portfolio management | | System security and fraud prevention | Email, login records | 90 days |

5. Recipients of Your Data

Your personal data is processed by:

Supabase Inc. (Data Processor)

  • Purpose: Cloud hosting, authentication, and image storage
  • Data Location: [supabase_region — pending owner input] (e.g., us-east-1, eu-west-1)
  • Data Transfer Safeguards: Standard Contractual Clauses (SCCs)
  • Processor Agreement: In place via Supabase Terms of Service

No other third parties receive your personal data. We do not use:

  • Analytics platforms (Google Analytics, Mixpanel, etc.)
  • Marketing services
  • Email marketing tools
  • Customer support systems with external access
  • CDNs that process personal data

Important Note on Data Location

If your Supabase project is hosted outside the European Union, your data is transferred internationally. Supabase implements Standard Contractual Clauses (SCCs) to ensure your data receives adequate protection. Following the EU Court of Justice Schrems II ruling, we acknowledge that US law may permit government access to personal data, but Supabase implements technical and organizational measures to minimize these risks.

6. How Long We Keep Your Data

Admin Account Data

  • Active account: Retained for the duration of your active use
  • After account deletion: Email and password hash are permanently deleted within 30 days
  • After logout: Session cookie expires after [session_expiry_hours — pending owner input] hours

Image Data

  • Active portfolio: Retained while images remain in the portfolio
  • After deletion: Images and associated metadata are permanently deleted immediately
  • Deleted images cannot be recovered

Login Attempts Log

  • Login records: Failed login attempts retained for 90 days for security monitoring
  • Purpose: Detecting unauthorized access attempts

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

Right of Access (Article 15)

You can request a copy of all personal data we hold about you. We will provide this within 30 days of your request.

How to request: Email [email — pending owner input]

Right to Rectification (Article 16)

You can correct, update, or amend your personal data. For your email and password, you can update these directly in the admin panel.

How to request: Update directly in Settings, or email [email — pending owner input]

Right to Erasure ("Right to be Forgotten") (Article 17)

You can request deletion of your account and all associated personal data at any time.

Important: This action is permanent and includes:

  • Deletion of your admin account and login credentials
  • Deletion of all portfolio images and metadata
  • Deletion cannot be undone

How to request: Contact [email — pending owner input]

Right to Restrict Processing (Article 18)

You can request that we stop processing your personal data while you consider other rights.

How to request: Email [email — pending owner input]

Right to Data Portability (Article 20)

You can request a copy of your data in a structured, commonly used, machine-readable format (e.g., JSON, CSV).

How to request: Email [email — pending owner input]

We will provide this within 30 days of your request.

Right to Object (Article 21)

You can object to processing of your personal data. Since we rely on Legitimate Interest, you have the right to object on grounds relating to your particular situation.

How to request: Email [email — pending owner input]

Right to Lodge a Complaint

If you believe we have violated your privacy rights, you have the right to lodge a complaint with your national Data Protection Authority:

Austria: Austrian Data Protection Authority (dsb.gv.at) EU: List of Data Protection Authorities by country: https://edpb.ec.europa.eu/about-edpb/board/members_en Germany: Bundesbeauftragte für Datenschutz und Informationsfreiheit (BfDI)

8. Security Measures

We implement technical and organizational measures to protect your personal data:

Encryption in Transit

  • All connections use HTTPS with TLS 1.2 or higher
  • Content Security Policy (CSP) headers prevent injection attacks
  • CSRF tokens protect form submissions

Encryption at Rest

  • Password hashes use bcrypt (via Supabase auth)
  • Image files encrypted by Supabase at rest
  • Database encrypted by default in Supabase

Authentication & Access Control

  • Password-based authentication via Supabase Auth
  • Session cookies are HttpOnly (not accessible to JavaScript)
  • Session cookies are Secure (only transmitted over HTTPS)
  • Session cookies are SameSite=Lax (prevent CSRF)
  • Only authenticated admin users can access portfolio data
  • No public upload functionality
  • Private storage bucket (unauthenticated users cannot access images directly)

Monitoring & Logging

  • Minimal logging of authentication events and errors
  • No user activity tracking or analytics
  • Failed login attempts logged for security monitoring (90 days)

Breach Response

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay and in no case later than 72 hours after becoming aware of the breach, unless the risk is low.

How to report a breach: Email [email — pending owner input] with "DATA BREACH REPORT" in the subject line.

9. Cookies

Session Cookies (Essential)

We use session cookies to maintain your authenticated login session. These cookies are:

  • Type: First-party, HttpOnly, Secure
  • Provider: Supabase Auth
  • Purpose: Maintaining your admin session
  • Expiry: After [session_expiry_hours — pending owner input] hours of inactivity

These cookies are necessary for the website to function. They cannot be disabled without losing access to the admin panel.

No Other Cookies

We do NOT use:

  • Third-party cookies
  • Tracking cookies
  • Analytics cookies (Google Analytics, Hotjar, etc.)
  • Marketing cookies
  • Advertising cookies

You can delete session cookies at any time by:

  1. Logging out of the admin panel
  2. Clearing your browser cookies
  3. Using "Clear Site Data" in your browser settings

10. Automated Decision-Making & Profiling

Your personal data is NOT subject to:

  • Automated decision-making
  • Automated profiling or classification
  • Algorithmic analysis or scoring
  • Behavioral tracking or analytics

All decisions about your portfolio are made by you manually through the admin panel. We do not use AI/ML systems to process your data.

11. Children's Privacy

Our website is not intended for children under 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it immediately.

12. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of significant changes by:

  • Updating the "Last Updated" date at the top of this policy
  • Posting a notice on the website
  • Sending an email notification (if required by law)

Continued use of the website after changes constitutes your acceptance of the updated privacy policy.

13. Legal Basis Summary

Under GDPR, organizations must have a lawful basis to process personal data. Here is our basis for each processing activity:

| Processing Activity | Lawful Basis | Justification | |-------------------|------------|---------------| | Admin authentication | Legitimate Interest (Art. 6(1)(f)) | Necessary to secure access to admin panel and prevent unauthorized access | | Portfolio image storage | Legitimate Interest (Art. 6(1)(f)) | Necessary to provide portfolio management functionality | | Security monitoring | Legitimate Interest (Art. 6(1)(f)) | Necessary to detect and prevent unauthorized access attempts |

14. Contact & Requests

For all privacy-related requests, inquiries, or to exercise your rights:

Email: [email — pending owner input]

Postal Address: [full_name — pending owner input] [street_address — pending owner input] [postal_code_city — pending owner input] [country — pending owner input]

Response Time: We will respond to all requests within 30 days.


Compliance Notes

  • This privacy policy complies with GDPR (EU General Data Protection Regulation)
  • This policy applies to visitors from all jurisdictions
  • For additional information on GDPR, visit: https://gdpr-info.eu/
  • Austrian data protection requirements (ECG, Mediengesetz) are supplementary to GDPR