This Privacy Policy outlines how the FixingBook Registry ("we", "us", or "our") processes personal data in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or "GDPR").

1. Data Controller & Contact Details

The Data Controller for the processing of your personal data on this platform is:

FixingBook Project Team ("FixingTeam")
Represented by the Core Operations Group
Contact Email: privacy@fixingbook.com

For inquiries regarding our data handling practices or to exercise your statutory data subject rights, please email the address listed above with the subject line "GDPR Data Subject Request".

2. Categories of Personal Data We Process

We collect and process only the minimal data necessary to deliver the technical registry service. This includes:

3. Purpose and Legal Basis for Processing

Under Article 6(1) of the GDPR, we process your personal data based on the following legal foundations:

Processing PurposeData Categories involvedLegal Basis (GDPR Art. 6(1))
User Authentication: Providing account sign-in via magic link or social login providers, managing sessions, and verifying access rights.Email address, social account IDs, session tokens.Performance of a Contract (Art. 6(1)(b)): Necessary to establish and fulfill our service agreement with you.
Contributions Logging: Recording edits, guides, and validation flags under your public Node Signature.Public Node Signature, user ID, contributed guide text, and target system specifications.Performance of a Contract (Art. 6(1)(b)): Fulfilling database ledger submission guidelines.
Security & Anti-Abuse: Protecting login forms, blocking automated spam, and validating requests.IP address, browser user-agent, Cloudflare Turnstile token signals.Legitimate Interest (Art. 6(1)(f)): Maintaining the security, availability, and integrity of the database registry.
Transactional Email: Sending sign-in links and account status reports.Email address, verification tokens.Performance of a Contract (Art. 6(1)(b)): Necessary to execute user-requested magic link delivery.

4. Third-Party Processors & Data Recipients

We do not sell, trade, or distribute your private personal data to marketing organizations. We transfer data strictly to the following subprocessors who are contractually bound to comply with standard security and privacy policies:

  1. Resend, Inc. (US-based transactional email carrier) – Processes email addresses and verification URLs solely to deliver magic link logs.
  2. Cloudflare, Inc. (Global content delivery network and security provider) – Processes network traffic, IP addresses, and Turnstile security widgets to shield our infrastructure from denial-of-service attacks.
  3. Identity Provider (Google LLC) – Receives validation tokens and credentials when you request sign-in using federated OAuth links.

5. International Transfer of Personal Data

The platform servers and the subprocessors listed above are situated primarily within the United States. If you access our Services from the European Economic Area ("EEA"), Switzerland, or the United Kingdom, your personal data will be transferred outside these jurisdictions.

To ensure your personal data receives an adequate level of protection, we verify that our US-based subprocessors reside under the EU-US Data Privacy Framework or utilize European Commission-approved Standard Contractual Clauses (SCCs).

6. Data Subject Rights under the GDPR

If you reside within the EEA, UK, or Switzerland, you possess the following statutory rights under Chapter III of the GDPR:

To file a request to exercise any of these rights, email us at privacy@fixingbook.com. We will respond to your request within thirty (30) days.

7. Right to Lodge a Complaint with a Supervisory Authority

In accordance with Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data infringes this Regulation.

8. Cookies & Session Storage

We use essential cookies strictly to maintain authentication sessions. We do not use advertising or profiling cookies.

Cookie NameType / ProviderPurposeDuration
better-auth.session_tokenFirst-party (Essential)Stores your secure encrypted session token to maintain login status.Session/Persistent

9. Automated Decision-Making and Profiling

We do not subject you to decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.