1. Controller
The controller is USDB community service, physical service address not yet configured, admin@usdb.at. See the operator page for further details.
2. Data, purposes, and legal bases
- Account and profile data for registration, authentication, and account functions: GDPR Article 6(1)(b).
- Contributions and communications to provide the community service: Article 6(1)(b); public catalog attribution also relies on the legitimate interest in an auditable collaborative catalog, Article 6(1)(f).
- Security and technical data, including timestamps, sessions, IP-derived abuse identifiers, request/device information, and authentication/moderation logs, for security, diagnostics, and abuse prevention: Article 6(1)(f).
- Legal notices and moderation records to comply with law and handle legal claims: Article 6(1)(c) and (f).
- Transactional email for verification, security, and necessary account notices: Article 6(1)(b) and (f).
The legitimate interests are a secure, functional, auditable community service, protection of users, and handling legal claims.
3. Visibility and recipients
Usernames, shared profile fields, and attributed contributions may be shown to members or publicly and distributed through the API, downloads, or Git mirrors. Private messages are visible to participants; notices and internal moderation data only to authorized reviewers. Hosting, email, and operations providers receive only data needed for their contracted work. Authorities or rights holders receive data only with a legal obligation or valid legal basis.
4. International transfers
The operator does not intend transfers outside the EEA. Transactional email is delivered to the provider selected by the user, which may process outside the EEA. If a contracted processor handles data in a third country, this occurs only under an adequacy decision or safeguards such as EU Standard Contractual Clauses. Contact the controller for current recipient details.
5. Retention
Account data is generally held until account deletion. Sessions end on expiry or logout; security and server logs remain only as long as needed for diagnostics and abuse prevention. Aggregated daily traffic counters contain no visitor identifiers. For transactional email, subject, sender, recipients, time, and success or error are retained for up to 180 days for delivery troubleshooting; message bodies are not copied into this delivery log. Private messages are stored as conversation history; erasure or restriction requests are assessed with the rights of both participants and necessary abuse or legal evidence in mind. Contributions and revision/moderation history may remain with reduced personal linkage after closure where catalog integrity, licence evidence, or claims require it. Legal notices remain through resolution and applicable limitation/evidence periods. Backups expire through the scheduled overwrite cycle. Retention is reviewed regularly and statutory duties prevail.
6. Cookies and devices
USDB2 uses only technically necessary session, language/preference, and CSRF-protection cookies. They are necessary to provide the expressly requested service under section 25(2)(2) TDDDG, so consent is not required. No advertising or analytics cookies are currently used. Consent will be obtained before any future non-essential cookies are stored.
7. Required data and automated decisions
A username, email, and credentials are required for an account; optional profile fields are voluntary. There is no solely automated decision producing legal or similarly significant effects and no profiling under GDPR Article 22. Automated security checks may trigger human review.
8. Your rights
Subject to statutory conditions, you have rights of access, rectification, erasure, restriction, portability, and objection. Consent may be withdrawn prospectively at any time. You may object to Article 6(1)(f) processing for reasons arising from your situation; no direct marketing takes place. Contact admin@usdb.at. Identity verification may be required.
9. Complaint
You may complain to a supervisory authority, particularly where you live, work, or the alleged infringement occurred. The German Data Protection Conference list identifies the competent state authority.
10. Legacy data
If an old USDB account is claimed, username, contact details, and contribution attribution originate from the former USDB dataset. They are processed for account recovery, attribution, and catalog continuity under Article 6(1)(b) and (f). Unclaimed legacy data remains only while attribution, integrity, and legitimate recovery require it.