Privacy Policy
Version 1.1 · Effective Date: August 29, 20261. Controller & Contact
This website (djruben.eu) is operated by DJ Ruben. For privacy inquiries or to exercise your statutory data rights, contact: tdai89qmj@mozmail.com.
2. Data Processing, Legal Basis & Retention
We process pseudonymous technical data strictly necessary to deliver website content and manage access passes:
- Backstage Access Tokens: When generating or redeeming a pass, a pseudonymous unique identifier (UID) and access token are processed in Google Cloud / Firebase Firestore and stored in your browser’s
localStorage.
Legal Basis: Performance of a contract / service request (Art. 6(1)(b) GDPR) & Legitimate interest (Art. 6(1)(f) GDPR).
Retention: Pass records are retained for the duration of access (up to 90 days) and purged thereafter. - Server & Network Logs: Hosting infrastructure automatically processes visitor IP addresses and user agents for routing, load management, and anti-abuse defense.
Legal Basis: Legitimate interest in securing web infrastructure (Art. 6(1)(f) GDPR).
Retention: Temporary security logs are retained for standard operational periods (up to 30 days) and overwritten. -
Bot & Abuse Prevention (Google reCAPTCHA Enterprise / Firebase App Check):
To protect our database from automated spam, brute-force requests, and abuse, we use Google reCAPTCHA Enterprise and Firebase App Check. This service evaluates technical and interaction telemetry (such as device characteristics, IP address, and interaction patterns) to verify human visitors and issue temporary security tokens.
Legal Basis: Legitimate interest in securing web assets and preventing infrastructure abuse (Art. 6(1)(f) GDPR).
Retention: Telemetry is processed dynamically in real time by Google's security infrastructure; access tokens expire automatically within 1 hour. -
Anti-Fraud & Pass Abuse Prevention (Device Verification):
When generating or claiming Backstage Passes, we process a non-reversible cryptographic hash of your device's technical hardware characteristics (including screen dimensions, color depth, CPU concurrency, and graphics rendering identifiers). We do not collect, read, or store raw hardware profiles.
Purpose: To prevent self-referrals, duplicate pass redemptions, and automated abuse of access passes.
Legal Basis: Legitimate interest in securing the platform and preventing pass abuse (Art. 6(1)(f) GDPR).
Retention: The cryptographic hash is retained alongside the pass redemption record for as long as the pass remains active or until access expiration.
3. Third-Party Processors & Transfers
We rely on the following third-party infrastructure providers who act as data processors:
- Google Firebase (Google Ireland Ltd. / Google LLC): Database and hosting services. International data transfers to the US, where applicable, are governed by the EU-U.S. Data Privacy Framework and standard contractual clauses (SCCs).
- Google LLC / Google Ireland Ltd. (Firebase & reCAPTCHA Enterprise): Provides cloud hosting, database management, and automated anti-abuse security services. Processed under Google's Cloud Data Processing Addendum and standard contractual clauses (SCCs).
4. Local Storage & Cookies
We do not use advertising, marketing, or third-party behavioral tracking cookies. We utilize browser localStorage solely for strictly necessary functional purposes (maintaining your backstage pass validation across sessions) in compliance with ePrivacy regulations.
5. Your Rights Under GDPR (Articles 15–22)
Under the General Data Protection Regulation, you have the right to request access to, rectification of, or erasure of your personal data, as well as the right to restrict or object to processing and the right to data portability. You also have the right to lodge a complaint with a supervisory authority (such as the Dutch Autoriteit Persoonsgegevens).
Automated decision-making and profiling (Art. 22 GDPR) are not used on this website.
© 2026 DJ Ruben · djruben.eu
Protected by reCAPTCHA Enterprise. Google Privacy Policy and Terms of Service apply.