1. Who is responsible?
Reiko Ince, operating under The Mapping Dwarf, is the controller within the meaning of Article 4(7) GDPR. The postal and email contact details are shown above. This notice applies to this portfolio and its interactive account, messaging and favourites functions.
2. What this website does
Personal data is processed only to deliver and secure the website, provide functions you request, communicate with you and meet legal obligations. The current website does not process payments or run a newsletter.
The current application code contains no marketing analytics, advertising pixels, externally hosted fonts, third-party trackers or embedded third-party media. If that changes, this notice and, where required, the consent choices will be updated before those tools are used.
- displaying the public portfolio and protected media previews;
- providing registered accounts and random guest sessions;
- saving messages, favourites and short-lived presence information;
- preventing abuse, diagnosing faults and keeping the service secure.
3. Hosting, delivery and technical access data
The website is delivered through Cloudflare Workers and Cloudflare's content delivery and security network. Application records are stored in Cloudflare D1 and portfolio files in Cloudflare R2. The R2 bucket is configured with EU jurisdiction; this does not mean that Workers, D1, network processing or technical logs are restricted to the EU only.
When a page or file is requested, technical data can be processed: IP address, date and time, requested URL, request method, response status, transferred volume, referrer, user-agent and browser/device information, together with security and diagnostic events. This is necessary to send the requested content, defend the service and investigate errors.
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, acts as a processor under its Data Processing Addendum. Depending on network routing and the Cloudflare product involved, data may also be processed outside the EEA. Cloudflare's DPA provides for the EU-US Data Privacy Framework where applicable and the EU Standard Contractual Clauses for restricted transfers where required.
The legal basis is Article 6(1)(f) GDPR. The legitimate interests are reliable delivery, IT security, abuse prevention and fault analysis. Cloudflare Workers Logs is currently enabled on the Workers Free plan, but automatic invocation logs are disabled; the application records only targeted error logs. Cloudflare currently documents a retention period of up to three days for that plan. Retention is plan-dependent and will be checked against the active plan and dashboard settings when the configuration changes. The logs are not used here for advertising or visitor profiling.
Cloudflare Privacy Policy · Cloudflare Data Processing Addendum · Cloudflare Workers Logs documentation
4. Registered accounts
Registration requires a nickname and password; an email address is voluntary. The account record also contains an internal ID, role and status, and creation/update timestamps. Passwords are not stored in plain text. A salted PBKDF2-SHA-256 derived verifier is stored instead.
For login, a random session token is placed in the HTTP-only tmd_user_session cookie, while only its hash, the account association and session timestamps are stored in D1. The login session is valid for 30 days. An optional email address is used as an alternative login identifier and for account-related contact where needed; the site does not currently send marketing email.
The legal basis is Article 6(1)(b) GDPR for providing the account functions you request and Article 6(1)(f) GDPR for access control and account security. Account data is kept until the account is deleted or the purpose ends, unless data must temporarily be restricted and retained to establish or defend legal claims or because a specific statutory duty applies. Account management and deletion are available through the profile area.
5. Guest identity and presence
Interactive use without an account is associated with a random technical guest identity and a random Traveler number. They are linked to the guest session cookie, not derived from the visitor's IP address, and are not intended to identify the visitor directly. D1 stores the random identity, a hash of the session token, creation and last-seen timestamps and the session expiry.
The tmd_session cookie can remain valid for up to 180 days of inactivity and is renewed when the guest session is used. It lets a returning guest reach the same conversation and favourites. Presence timestamps also support a short online/offline indicator in chat; they are not used to build a behavioural profile.
The legal basis is Article 6(1)(b) GDPR when the session is needed for a function requested by you, and otherwise Article 6(1)(f) GDPR. The legitimate interests are reliable conversation assignment, continuity of requested features and protection against misuse. Once a guest identity has been inactive for at least 180 days, it and its server-side conversation, messages and favourites are deleted by a daily scheduled cleanup or its rate-limited request fallback.
6. Messages, favourites and portfolio interactions
If you use chat, the website stores the conversation subject, message text, sender type, optional reference to a portfolio item, read/visibility state and timestamps. The conversation is associated with your account or random guest identity. The controller can read and answer these messages in the administration area.
If you mark a portfolio item as a favourite, its item ID is stored for the account or guest identity. A local browser copy is created only after the favourites function is used. The administrator can also see the server-side favourite item IDs together with the associated conversation so that referenced portfolio work can be understood. The chosen language is stored locally after a language choice so the interface can remember it.
Minimising or removing a conversation from the customer view does not delete the server-side conversation. Complete deletion takes place through deletion of the account or Traveler data, or through final deletion by the administrator. Please do not send health data, other special categories of personal data or similarly sensitive information through chat unless this has been expressly requested and is necessary.
Processing requested interactions is based on Article 6(1)(b) GDPR. Article 6(1)(f) GDPR also applies to orderly customer communication, synchronisation, message status, basic presence and protection of the service. The legitimate interests are answering enquiries and operating these functions reliably.
7. Communication by email
If you contact The Mapping Dwarf by email, the sender address, any name or nickname you provide, the subject, message content, attachments, date and time and technical email header data are processed to answer your enquiry and manage the correspondence. Please do not send health data, other special categories of personal data or similarly sensitive information unless this has been expressly requested and is necessary.
Selecting a mailto link on this website only asks the browser to open the email program configured on your device. The website does not submit a contact form or transmit the message at that point. Your message and its data are sent only when you actively send the email.
The mailbox is provided through WEB.DE, a service of 1&1 Mail & Media GmbH, Zweigniederlassung Karlsruhe, Brauerstr. 48, 76135 Karlsruhe, Germany. The provider is involved in transmitting and storing email and processes relevant data under its own privacy information.
The legal basis is Article 6(1)(b) GDPR where the message concerns a contract or steps requested by you before entering into a contract. General enquiries and the orderly, secure management and documentation of correspondence are processed under Article 6(1)(f) GDPR; the legitimate interests are responding to enquiries and maintaining reliable business communication. Correspondence is deleted when the matter has been conclusively resolved and no follow-up or legal claim is reasonably expected, unless statutory retention obligations or the establishment, exercise or defence of legal claims require longer storage. Provider-side copies and technical data are also subject to the WEB.DE account settings and provider retention rules.
8. Registration abuse limit
To limit automated or excessive registrations, the source IP address is transformed into a secret-keyed, pseudonymous hash. The raw IP address is not written to the registration-limit table. The hash and timestamp are used only to count registrations within a rolling 24-hour window. Entries older than 24 hours are no longer considered and are removed by a daily scheduled cleanup or its rate-limited request fallback, rather than by an exact deletion timer.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is preventing automated account creation and keeping the service available. This registration control is separate from any technical access data processed by Cloudflare when a request reaches its network.
9. Cookies and local storage
The application uses only storage needed for a service explicitly requested by the visitor or to secure its delivery: authentication, a stable guest conversation, favourites, the selected language and, where the relevant Cloudflare protection is active, bot or challenge protection. The application's session cookies are HTTP-only, SameSite=Lax and sent over secure connections in production.
Cloudflare may additionally set __cf_bm only when Bot Management or Bot Fight Mode is active, and cf_clearance when an active Challenge is passed or JavaScript Detections is used. These conditional security cookies support bot detection or preserve proof of a successful security check. They are not application analytics or advertising trackers.
For these operations, consent is not required under section 25(2)(2) TDDDG because the storage or access is strictly necessary to provide the expressly requested digital service. No marketing or analytics cookies are set by the application. If optional technology is introduced later, it will not be activated before any legally required consent is obtained.
| Name | Purpose | Duration |
|---|---|---|
tmd_session | HTTP-only guest session token for a stable random Traveler identity, chat, favourites and presence. Only a hash of the token is stored server-side. | Up to 180 days of inactivity; the period is renewed when the guest session is used. |
tmd_user_session | HTTP-only login session token. It keeps a registered user signed in; only a hash of the token is stored server-side. | 30 days. |
tmd-language (localStorage) | Remembers the language selected by the visitor. | Until it is removed in the privacy controls or browser settings. |
tmd-favourites (localStorage) | Keeps a local copy of portfolio favourites after the visitor uses the favourites feature. | Until it is removed in the privacy controls or browser settings. |
__cf_bm (Cloudflare, conditional) | Set by Cloudflare only if Bot Management or Bot Fight Mode is active. It supports bot detection and protects the website from automated misuse; it is not an application analytics or advertising cookie. | 30 minutes after the visitor becomes inactive. |
cf_clearance (Cloudflare, conditional) | Set only when an active Cloudflare Challenge is passed or JavaScript Detections is used. It stores proof of the security check so the visitor does not have to repeat it immediately; it is not an application analytics or advertising cookie. | For the challenge-passage period configured in Cloudflare; the default for a challenge is 30 minutes. Active JavaScript Detections can update the cookie. |
Official text of section 25 TDDDG · Cloudflare cookie documentation · Cloudflare Challenge Passage settings
10. How long data is kept
Data is kept only while it is needed for the purposes described above, to establish or defend legal claims, or to meet a statutory retention duty. There is deliberately no invented fixed deletion period for a live chat: account details, conversations, messages and server-side favourites remain until the user deletes them, the conversation or account is deleted, the purpose has ended, or a legal obligation requires retention.
A daily scheduled cleanup, backed by a rate-limited cleanup during application requests, removes expired guest and account session records. It does not delete an account merely because its login session expired. Once a guest identity has been inactive for at least 180 days, its identity, server-side conversation, messages and favourites are deleted. Registration-limit hashes are no longer considered after 24 hours and are removed by the same cleanup mechanism.
Automatic Cloudflare invocation logs are disabled. The targeted error logs recorded by the application are currently retained for up to three days on the active Workers Free plan; the period is plan-dependent and is checked against the current plan and configuration. Data may remain for a limited additional period in technically necessary provider backups until it is overwritten in the ordinary cycle. Email retention is described separately in the email section.
11. Who receives data
Within The Mapping Dwarf, data is available only where needed to operate the service; in particular, the controller can access account administration, conversations and associated server-side favourite item IDs. Cloudflare processes hosting, delivery, database, object-storage and diagnostic data as the technical service provider. 1&1 Mail & Media GmbH is involved as the WEB.DE mail service provider when communication takes place by email.
Personal data is not sold. It is disclosed to public bodies, courts or advisers only where a legal obligation applies, this is necessary to establish or defend legal claims, or another lawful basis exists.
12. External links
Links on this website, including portfolio buttons and legal or provider references, may lead to services such as Discord, Patreon or other third-party websites. No connection to those destinations is made merely because this page is displayed. Their operators receive data, including the destination request and IP address, only after you activate the link; their own privacy information then applies.
13. Your data protection rights
Subject to the legal requirements, you may request access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18) and data portability (Article 20). Your separate right to object under Article 21 GDPR is highlighted below. Where processing is required by contract, not providing the necessary data means the requested account, chat or favourites function cannot be provided.
Send a request to the email address shown above. You also have the right under Article 77 GDPR to lodge a complaint with a supervisory authority. For the controller's location, the competent authority is the State Commissioner for Data Protection of Lower Saxony (LfD Niedersachsen).
The website does not make decisions producing legal or similarly significant effects solely by automated means and does not carry out profiling.
Official GDPR text on EUR-Lex · LfD Niedersachsen complaint form
14. Your right to object under Article 21 GDPR
You have the right, on grounds relating to your particular situation, to object at any time to processing of your personal data based on Article 6(1)(f) GDPR. After an objection, the data will no longer be processed for that purpose unless compelling legitimate grounds for the processing override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
This website currently does not use personal data for direct marketing. If personal data were ever processed for direct marketing, you could object to that processing at any time without stating reasons; the data would then no longer be processed for that purpose. Send an objection to the email address shown above. No special wording is required.
15. Changes to this notice
This notice is reviewed when the website, providers or legal requirements change. The current version and its date are always published on this page. Material changes affecting an account or active service will also be communicated in an appropriate way where required.