This Privacy Policy outlines how the FixingBook Registry ("we", "us", or "our") processes personal data in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or "GDPR").
1. Data Controller & Contact Details
The Data Controller for the processing of your personal data on this platform is:
FixingBook Project Team ("FixingTeam")
Represented by the Core Operations Group
Contact Email: privacy@fixingbook.com
For inquiries regarding our data handling practices or to exercise your statutory data subject rights, please email the address listed above with the subject line "GDPR Data Subject Request".
2. Categories of Personal Data We Process
We collect and process only the minimal data necessary to deliver the technical registry service. This includes:
- Account Identifiers: Name (if provided), public profile avatar, and unique account IDs issued by federated identity providers.
- Contact Credentials: Private email address used for sign-in verification and transactional communications.
- Pseudonymous Public Identifiers: Automatically generated public Node Signatures derived via secure cryptographic hashes from your user profile. This enables contribution tracking without exposing your private email address to the public.
- Device and Setup Metadata: Information regarding target hardware models, peripheral setups, and operating system variants provided by you when writing or verifying guides.
- Access Logs & Technical Telemetry: Internet Protocol (IP) addresses, browser user agent strings, HTTP status codes, time logs, and request paths.
- Anti-Abuse Data: Network telemetry and interaction markers analyzed by security scripts (e.g. Cloudflare Turnstile) to verify human activity and prevent denial-of-service attempts.
3. Purpose and Legal Basis for Processing
Under Article 6(1) of the GDPR, we process your personal data based on the following legal foundations:
| Processing Purpose | Data Categories involved | Legal Basis (GDPR Art. 6(1)) |
|---|---|---|
| User Authentication: Providing account sign-in via magic link or social login providers, managing sessions, and verifying access rights. | Email address, social account IDs, session tokens. | Performance of a Contract (Art. 6(1)(b)): Necessary to establish and fulfill our service agreement with you. |
| Contributions Logging: Recording edits, guides, and validation flags under your public Node Signature. | Public Node Signature, user ID, contributed guide text, and target system specifications. | Performance of a Contract (Art. 6(1)(b)): Fulfilling database ledger submission guidelines. |
| Security & Anti-Abuse: Protecting login forms, blocking automated spam, and validating requests. | IP address, browser user-agent, Cloudflare Turnstile token signals. | Legitimate Interest (Art. 6(1)(f)): Maintaining the security, availability, and integrity of the database registry. |
| Transactional Email: Sending sign-in links and account status reports. | Email address, verification tokens. | Performance of a Contract (Art. 6(1)(b)): Necessary to execute user-requested magic link delivery. |
4. Third-Party Processors & Data Recipients
We do not sell, trade, or distribute your private personal data to marketing organizations. We transfer data strictly to the following subprocessors who are contractually bound to comply with standard security and privacy policies:
- Resend, Inc. (US-based transactional email carrier) – Processes email addresses and verification URLs solely to deliver magic link logs.
- Cloudflare, Inc. (Global content delivery network and security provider) – Processes network traffic, IP addresses, and Turnstile security widgets to shield our infrastructure from denial-of-service attacks.
- Identity Provider (Google LLC) – Receives validation tokens and credentials when you request sign-in using federated OAuth links.
5. International Transfer of Personal Data
The platform servers and the subprocessors listed above are situated primarily within the United States. If you access our Services from the European Economic Area ("EEA"), Switzerland, or the United Kingdom, your personal data will be transferred outside these jurisdictions.
To ensure your personal data receives an adequate level of protection, we verify that our US-based subprocessors reside under the EU-US Data Privacy Framework or utilize European Commission-approved Standard Contractual Clauses (SCCs).
6. Data Subject Rights under the GDPR
If you reside within the EEA, UK, or Switzerland, you possess the following statutory rights under Chapter III of the GDPR:
- Right of Access (Art. 15): You have the right to request confirmation as to whether we process your data and receive a copy of your personal data.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (Art. 17): You have the right to request the deletion of your personal data. Account deletions will permanently strip private email records, names, and social links. Note that technical troubleshooting guides contributed under open-source licenses will remain published on the Platform but will be associated with a generic, deactivated node signature.
- Right to Restriction of Processing (Art. 18): You have the right to request that we restrict processing under specific conditions.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): You have the right to object to processing based on our legitimate interests.
To file a request to exercise any of these rights, email us at privacy@fixingbook.com. We will respond to your request within thirty (30) days.
7. Right to Lodge a Complaint with a Supervisory Authority
In accordance with Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data infringes this Regulation.
8. Cookies & Session Storage
We use essential cookies strictly to maintain authentication sessions. We do not use advertising or profiling cookies.
| Cookie Name | Type / Provider | Purpose | Duration |
|---|---|---|---|
better-auth.session_token | First-party (Essential) | Stores your secure encrypted session token to maintain login status. | Session/Persistent |
9. Automated Decision-Making and Profiling
We do not subject you to decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.