Who is responsible

Stefan Grunert operates the Warré Archive and is responsible for the processing described here. Questions and privacy requests can be sent to [email protected].

Archive material

The archive preserves correspondence, participant names or profiles, dates, photographs and attachments from the warrebeekeeping Yahoo Group and its continuation on Google Groups. The full source archive is available only to approved group members. Public digests are edited to remove participant names, source links and identifying detail.

This material is kept as the long-term historical record of the community. Processing is based on the legitimate interests in preserving the group’s knowledge and making it available within the same community, while limiting public exposure.

Membership and account data

A daily read-only synchronization imports the email addresses of Google Group members. It does not change the Google Group. The archive stores the approved email address and role. If an account is created, it also stores account creation, verification and last-login times and a salted password hash. The password itself is never stored.

Membership data is used to restrict the archive to the group, send a requested access link and protect accounts. Access is removed when the daily synchronization confirms that an address is no longer a group member. The account record may remain until it is no longer needed or deletion is requested.

Security and technical data

The service processes IP addresses and timestamps for access-link requests, failed logins, rate limiting and security logs. Standard web-server logs may also contain the requested URL and browser information. Access links are valid for one hour and only a cryptographic digest of each link token is stored in the database.

Security and operational records are kept only while needed to operate and protect the service, investigate faults or abuse and maintain backups. The precise retention periods are under review; older records are removed during maintenance when they are no longer needed.

Search and AI-assisted material

The meaning-based part of archive search sends the words entered in the search box to the OpenAI API to create a numerical search representation. Search text, limited to 500 characters in the cache, may be retained locally so repeated searches do not require another API call. Do not enter sensitive personal information in the search box.

Archive text and images have also been processed with AI tools to prepare search embeddings, translations, summaries, captions and draft digests. These outputs support discovery and editorial work; they do not make decisions about members and public digests are manually reviewable, anonymised publications.

Legal basis

The processing is based primarily on legitimate interests under Article 6(1)(f) GDPR: preserving and providing the community archive, verifying member access, delivering requested functions and protecting the service. Where processing is required by law, Article 6(1)(c) GDPR applies. No personal data is sold or used for advertising.

Cookies

Public pages do not create a cookie for anonymous visitors. A first-party session cookie is used only when a visitor requests session-backed functionality such as signing in, setting up access or opening protected material, or when an existing session is resumed.

Cookie Purpose Maximum lifetime
warre_session Random session identifier used for login state, form security and the one-time password-link flow. 48 h

There are no analytics, advertising, social-media or third-party cookies. The interface language is carried in the URL and is not stored in a cookie. Because no optional cookies are used, there is no consent banner.

Service providers and recipients

Only the data needed for the stated purpose is shared with these providers:

  • Hetzner — hosting and database infrastructure in Finland
  • Cloudflare — TLS proxying, network delivery and protection against abuse
  • Resend — delivery of requested transactional access emails
  • OpenAI — semantic search embeddings and offline AI-assisted processing
  • Google — Google Group membership source and the read-only Apps Script synchronization

Some providers may process data outside the European Economic Area. Where this occurs, the provider’s applicable transfer safeguards and contractual terms are used. Follow the provider links for current details.

Your rights

Subject to the conditions in the GDPR, you can ask for:

  • access to and a copy of your personal data
  • correction of inaccurate data
  • deletion or restriction of processing
  • an export of data you provided where data portability applies
  • an objection to processing based on legitimate interests

You may also lodge a complaint with the data protection authority in your country. The Norwegian authority is Datatilsynet. Datatilsynet

Contact

For a privacy request, identify the email address or archive identity concerned and write to [email protected]. Identity may need to be verified before account or archive data is disclosed or changed.

[email protected]