Privacy
The data the platform processes for accounts and shared content.
Current operation
The university directory is freely accessible. Sign-in, registration and new contributions are paused. OWWZ currently creates no new sign-in sessions and sends no verification or recovery messages. The account information below describes the capabilities for future operation with accounts enabled.
Controller and contact
The legal notice identifies the operator and contact. Use that contact to request access, correction or deletion of your data.
Open the legal noticeHosting and technical requests
OWWZ runs on an OVHcloud server. Cloudflare proxies and protects the connection. Page requests involve technical information such as IP address, time, requested address and browser information so these services can deliver content and detect attacks and errors. Technical logs are used for troubleshooting and security and deleted when no longer needed for those purposes.
The legal basis is the legitimate interest in operating a secure and available directory (GDPR Article 6(1)(f)). Cloudflare infrastructure can process data outside the EU; Cloudflare describes its transfer mechanisms in its privacy policy.
Account and sign-in
Registration stores a name, email address and password hash. The password is not stored as plain text. Sign-in, verification and password reset use session or verification tokens. Profile information and university associations are stored when you add them.
Shared content
The platform stores submitted materials, descriptions, links, files, questions and replies, together with author associations and timestamps. Publicly shared content and the displayed author name are visible to others. Private materials are accessible through the permissions provided. Do not publish sensitive personal information.
Purposes and service providers
Data is used to manage accounts, provide content, enforce access permissions and protect the platform. Hosting processes technical requests and log data. The configured email service processes the recipient address and the contents of verification and recovery messages. Uploaded files are held in the configured file storage.
Cookies and device storage
Sign-in uses a session cookie. Your language choice is stored in a cookie and local device storage. Display theme preferences can also be held locally. The cookies page describes these entries.
Read about cookiesRetention and rights
Account data and contributions remain stored until removed through the available controls or a processed request. Sessions expire after one day, or 30 days with Remember me. You can request access, correction and, where applicable, erasure, restriction, portability or objection, and lodge a complaint with a data protection authority.
Data protection rights · European Commission