Website operator and data controller
Dário PascoalUpdated: 2026-09-28
Accounts and service email
We store your email address, display name, password hash, verification status, role, account status and relevant dates. You can add a biography, location, website and avatar; those details can appear with approved photographs. If an administrator invites you, they provide your name and email, and you receive a link to choose a password. Account messages cover verification, invitations and password recovery, not a newsletter. Your email and password hash are not included in public contributor profiles.
Two-factor authentication
If you enable two-factor authentication, we store an encrypted authenticator secret, hashed single-use recovery codes, enrollment dates and the last accepted code counter to prevent replay. Short-lived sign-in challenges and session verification records protect access. Security changes and recovery-code use are recorded in the administrative audit. Administrators can inspect notification email delivery status, recipient addresses and retry counts, but cannot view your authenticator secret or recovery codes.
Operational records and administrator notes
Administrators can add private notes relevant to account support. They are available only in site administration and are removed with the account; the audit records note additions and deletions without the note text. Contact the operator to request access to information that is not included in the automatic account export. The account timeline combines existing account, contribution, review and security records; it is not a full browsing history. Application failures are recorded as fixed categories, hourly counts and timestamps for 30 days, without request contents, URLs, email addresses, passwords or tokens. Backup restore reports contain operational counts and verification results.
Photographs and other contributions
Photographs, videos and PDF documents are uploaded through this website. We store the file, original filename, checksum, title, description, year, credit, source URL, permission details, status and review notes. Pending or rejected files are private to the contributor and authorised administrators. Approved files can be viewed and downloaded with the contributor’s public profile. Original files retain embedded metadata; remove private information before uploading. Incomplete uploads expire after 24 hours and are removed by the hourly cleanup. Submission and review take place in your account; files are not submitted by email.
Review notifications
Review decisions create private account notifications containing the submission title or text excerpt, decision, reviewer feedback and date. We keep read/unread state and your optional email preference and language. Review emails are off by default and link to your signed-in notification inbox without including private review notes. When enabled, delivery is queued and retried after temporary failures; disabling it cancels waiting alerts, although an email already being sent may arrive. Notifications and detailed review records are removed with account deletion; existing backups and the separate administrative audit can retain records.
Guestbook and contact messages
Guestbook names, optional cities and messages are public when submitted. Avoid private contact details in a public message. Emails sent to the operator include the address, content and attachments you choose to send, together with delivery metadata. They are used to handle your enquiry or request.
Why we use this information
Account information supports the service you request (GDPR Article 6(1)(b)). Permission to publish optional contributions supports their publication (Article 6(1)(a)); you can withdraw that permission by contacting the operator. Security records and abuse prevention support the legitimate interest in keeping the guide available and safe (Article 6(1)(f)). Moderation is performed by people; there is no automated decision-making with legal or similarly significant effects.
Cookies and browser storage
Signing in sets an essential session cookie, valid for up to seven days. Signing out ends that session; a password reset invalidates existing sessions. The light/dark preference is stored in your browser until you change or clear it. The guide's own code does not add advertising or analytics trackers. External services described below have their own practices.
Connection and security records
Server logs can contain IP addresses, request paths, browser details and errors. The application also keeps hashed identifiers and counters to limit abusive requests, and records moderation actions. These records are not public. Hashing an identifier does not necessarily make it anonymous.
Visitor reports and session details
The server keeps aggregate page-request counts by hour, page, referring domain, broad browser/device/system category and page language. These reports exclude administrative browsing and do not store IP addresses, visitor identifiers, full referring URLs, query strings or tracking cookies. They count requests, not unique people; bot classification is approximate. Aggregate rows older than 90 days are removed during ongoing traffic. Separately, your account’s session list stores sign-in/last-active times and a browser description so you can manage signed-in devices. Reports also group requests by approximate country. The client IP is used transiently with an offline DB-IP country database and is not saved in visitor reports or sent to a geolocation service. VPNs and network routing can affect accuracy. Earlier visits and addresses that cannot be located appear as unknown; countries are not reconstructed for past visits.
Who can access information
The operator and authorised administrators can access information needed to run accounts, review contributions and handle requests. The website and mail service run on operator-managed infrastructure hosted with Hetzner. Hosting and email-delivery providers process technical information needed to supply their services. Approved contributions and guestbook messages are accessible to website visitors.
Maps, videos and other websites
Opening the map requests tiles from OpenStreetMap. Embedded YouTube videos use the youtube-nocookie.com domain, but loading a player can still send your IP address and browser information to Google. External links open services governed by their own policies; their processing may occur outside the EEA. Review the provider's privacy information before using those services.
How long information remains
Accounts and contributions remain until removed; unverified accounts and rejected submissions are not automatically purged. Verification links expire after 24 hours and reset links after 30 minutes, which does not itself delete the account or every stored token record. Security logs rotate according to service settings. Moderation history, correspondence and backups currently have no single fixed automatic deletion schedule. Contact the operator about retained information.
Deletion and backup copies
You can delete your own photographs, remove your avatar, export your account data and revoke sessions from your account. Members and administrators can delete their own account after entering their password and confirming their email; the site owner account is protected. Account deletion removes live profile, photo and written-contribution records and queues uploaded files for background removal. Guestbook and other requests can be sent to the operator. Older backups and moderation records may remain, and copies made by other people or search engines are outside the site’s direct control.
Your choices and rights
Contact the operator to request access, correction, deletion, restriction or portability where applicable, to object to processing based on legitimate interests, or to withdraw publication consent. Include the relevant account address or page link. We may ask for enough information to verify the request; never send a password or a verification/reset link. You may also complain to your competent data protection authority.
Sign-in security metadata
For account security, new sign-ins record the IP address and browser user-agent alongside the session creation, last activity and expiry times. Authorized administrators can see active-session IP addresses and approximate browser, operating system and device labels. These records are session-scoped and are deleted with the session, including sign-out, revocation or expiry cleanup; existing backups can retain them. They are separate from anonymous aggregate visitor reports, which do not retain IP addresses.
Community mailboxes
Creating a mailbox stores your chosen address and its link to your website account. The mail service stores messages, attachments, folders, contacts, preferences and delivery records. Each account has a 1 GB limit across all folders. The integrated inbox uses an essential cookie on mail.entroncamento.org; access depends on your active website session. Site administrators can see addresses, mailbox status and storage usage, and suspend access. Mail is not public, but server operators have technical access to stored data. Deleting a website account suspends its mailbox; messages remain until the operator removes the mailbox. Contact the operator for mailbox deletion or a complete mail export. The website account export includes mailbox details, not message contents.