Version: 18 August 2026
1. Controller
The controller responsible for processing personal data through Deskbrew is:
Elias AnderlohrHeidestraße 23
60316 Frankfurt am Main
Germany
- [email protected]
- Telephone
- +49 156 79713762
2. Data we process
You can browse Deskbrew without an account. Depending on how you use the service, we process the following categories:
- Connection and request data, including the IP address while the connection is made, request time, route, response status, user agent and technical error data.
- A random guest token in a signed, HTTP-only cookie and its one-way hash in the database. The token is not a name and is not publicly displayed.
- Contribution data such as office details, a taste score, optional short reaction, factual confirmations, source information, timestamps and moderation state.
- Map position and, only after browser permission, device coordinates used to centre the map or suggest a city and country.
- Anonymous product events — an interaction name, the server time and bounded product fields — only while you have allowed optional measurement.
- Name, email address and notice details when you contact us or report allegedly illegal content.
3. Access, security and abuse prevention
We process request metadata to deliver the site, diagnose failures and protect the service from misuse. Application logs contain the route without its query string, method, response status, duration, a request ID, deployment version and shortened pseudonymous security hashes. Request bodies, cookies, authorisation headers, email addresses and raw search terms are not written to the application log.
A client IP address is necessarily processed while a network connection is made. For rate limiting, the API immediately converts it with a secret-keyed, non-reversible HMAC; it does not retain the raw address as an identity. IPv6 addresses are first reduced to a /56 network. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in a secure, reliable and manipulation-resistant service.
4. Guest sessions and contributions
When you open a contribution flow, we issue a guest cookie and store only a hash of its random token. This lets the service recognise the same browser, enforce one active rating per office, show and update that browser’s own rating, and connect factual confirmations to one pseudonymous contributor. We process submissions to provide the requested contribution service (Art. 6(1)(b) GDPR) and to moderate, secure and credibly rank contributions (Art. 6(1)(f) GDPR). You are not required by law to provide this data; without it, you cannot submit a contribution.
Office facts, aggregated scores and approved short reactions may be public. Guest tokens, internal IDs, security hashes, individual workplace membership and moderation records are not public. Comments start in a moderation queue. Automated integrity signals can temporarily hold a rating out of scoring; a moderator decides lasting restrictions.
5. Location, map and address search
Deskbrew asks for device location only through the browser permission prompt. If you agree, coordinates centre the map and can be sent through our own server to Geoapify to resolve a city or country. Our application does not store those device coordinates on the server or attach them to a contribution. The current map camera may be kept in your browser and written, rounded, into a shareable URL. You can deny or revoke browser permission at any time. The legal basis for the one-time device-location use is your consent (Art. 6(1)(a) GDPR); withdrawing it does not affect earlier lawful processing.
The interactive base map loads vector tiles and fonts from OpenFreeMap. OpenFreeMap therefore receives ordinary connection data such as your IP address, user agent and the requested map resources. Loading the map is based on Art. 6(1)(f) GDPR and our legitimate interest in providing geographic discovery. If the provider fails, Deskbrew falls back to a local schematic map.
6. Cloudflare Turnstile
Before a public write, Cloudflare Turnstile checks whether the request comes from a person rather than an automated bot. Cloudflare processes signals including IP address, TLS fingerprint, user-agent header, site key and origin. Deskbrew sends the returned verification token to Cloudflare’s verification endpoint but deliberately does not add the client IP to that server-side request.
This processing and any strictly necessary Turnstile storage are based on Art. 6(1)(f) GDPR and § 25(2)(2) TDDDG. Our legitimate interest is protecting an account-free contribution service from spam and manipulation. Cloudflare acts as our processor for site protection and also describes limited processing as its own controller for improving bot detection.
7. Product measurement
Deskbrew can record limited first-party product events to understand whether public office pages lead to ratings and referrals. This measurement is optional and off until you allow it: with no answer, or after you decline, no event is sent or stored, and the site is fully usable either way. When it is on, events contain only a fixed interaction name, server time, and the allowlisted product fields needed for that measure, such as public office or company IDs, referral source, rating-count bucket, or ranking state. They do not contain IP addresses, user agents, referrers, account identifiers, rating comments, search text, advertising or cross-site cookies, or fingerprinting data.
The legal basis is your consent (Art. 6(1)(a) GDPR), and § 25(1) TDDDG for reading the answer stored on your device. We ask once, in a single banner that covers every optional purpose and offers refusal in one step of equal weight, and we treat no answer as refusal. You can withdraw your consent at any time under Privacy settings or using the contact details above, with effect for the future; withdrawal does not affect the lawfulness of processing carried out beforehand and does not restrict any feature. We do not use this measurement for advertising, profiles, or decisions about people.
8. Cookies and storage on your device
No advertising cookies are used. Storage that is strictly necessary for a feature you request or for service security is used under § 25(2)(2) TDDDG and needs no consent. Optional product measurement, remembering the map camera and creating an offline cache are three separate purposes: all three are off by default and activate only after your consent under § 25(1) TDDDG, which is asked for in one banner and recorded together. You can change any of these choices below at any time.
- Guest cookie
- Signed, HTTP-only, SameSite=Lax and Secure in production; valid for one year. It keeps your contributions associated with your browser and is created only when a contribution feature needs it.
- Language cookie
- Stores the language you explicitly select for one year; SameSite=Lax.
- Consent record
- Your answers to the consent banner, the version of the question you answered and the date you answered it, kept in local browser storage so we ask once and can show what you chose. It holds no identifier, is written whether you agree or refuse, and remains until you change it or clear your browser storage. When we change what the question covers, the stored version stops matching, every optional purpose returns to off, and the banner asks again.
- Local browser storage
- An explicit colour-theme choice and whether you answered the initial location prompt stay on the device so Deskbrew can honour those requests. The last map camera is stored only after you enable ‘Remember map position’. Disabling it deletes any saved map camera.
- Offline cache
- A service worker is registered and public pages and static assets are cached only after you enable ‘Offline access’. Disabling it stops caching, unregisters the Deskbrew service worker and deletes Deskbrew’s offline caches. API responses, authorised requests and responses marked no-store are always excluded.
9. Legal bases
- Art. 6(1)(b) GDPR for requested contribution, update and support functions.
- Art. 6(1)(f) GDPR for secure operation, fraud prevention, moderation, public factual listings, aggregated rankings and defence of legal claims. Our interests are balanced against the limited and pseudonymous nature of the data and your reasonable expectations.
- Art. 6(1)(a) GDPR and § 25(1) TDDDG for optional device-location processing, optional product measurement, map-position memory and offline storage where requested.
- Art. 6(1)(c) GDPR where processing is necessary to comply with a legal order, statutory retention duty or Digital Services Act notice obligation.
10. Recipients and international transfers
Access is limited to authorised operators and processors who need it to run or protect Deskbrew. We do not sell personal data. Depending on the feature, recipients are:
- EU-based hosting, database, storage and network infrastructure operated for Deskbrew; production uses self-hosted application and Supabase services.
- OpenFreeMap for directly requested vector tiles and fonts.
- Geoapify for address autocomplete and reverse geocoding through our server. Geoapify states that API services are hosted in EU data centres and successful API request data is generally retained for no more than 24 hours.
- Cloudflare, Inc. for Turnstile human verification and any related security processing.
Cloudflare operates globally and processing can involve countries outside the EEA. Where no adequacy decision applies, transfers must rely on appropriate safeguards such as the EU Standard Contractual Clauses. Provider details and safeguards are available in the linked notices.
11. Retention
- Application access and security logs are normally deleted after 14 days; rate-limit counters expire with their relevant window, no later than 24 hours. Data needed to investigate a concrete incident may be kept until the incident and related claims are resolved.
- First-party product events are automatically deleted after 30 days. They contain no visitor identifier and cannot be used to reconstruct an individual visitor’s history, so a withdrawal stops further collection rather than picking events out of the aggregate.
- The guest cookie and active session expire after one year. An expired pseudonymous session record remains while a contribution or mandatory audit record still references it, but can no longer recognise the browser.
- Published contributions are kept while they serve the public directory. After deletion or withdrawal, the public content is removed; restricted version and moderation history may be kept for up to three years after the end of the calendar year to document score integrity, handle disputes and defend legal claims, unless law requires longer storage.
- Legal notices and related correspondence are kept for three years after the matter is closed, or longer while a proceeding or legal duty requires it.
- Browser storage and offline caches remain until replaced or cleared through your browser; cookie expiry periods are stated above.
12. Your rights
Subject to the statutory conditions, you have the following rights under the GDPR:
- Access to your personal data (Art. 15 GDPR).
- Rectification of inaccurate data (Art. 16 GDPR).
- Erasure (Art. 17 GDPR).
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR).
- Objection to processing based on legitimate interests (Art. 21 GDPR).
- Withdrawal of consent at any time with future effect (Art. 7(3) GDPR).
Contact the controller at the address above. Because Deskbrew has no accounts and holds pseudonymous data, we may need the guest cookie or contribution details to identify your record and must not disclose another person’s data. Clearing the cookie prevents future recognition but does not itself delete server records.
Right to object: You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
13. Complaint to a supervisory authority
You may complain to a data-protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the alleged infringement. The authority responsible for the controller in Hesse is:
The Hessian Commissioner for Data Protection and Freedom of InformationWilhelmstraße 7
65185 Wiesbaden
Germany
14. Security
We use transport encryption, signed and HTTP-only cookies, one-way and secret-keyed hashes, access controls, input validation, rate limits, human verification, redacted logs and moderated publication. No internet service can guarantee absolute security.
15. Changes to this notice
We update this notice when the service, providers or law changes. The version date above identifies the current text. Material changes are announced prominently before they take effect where reasonably possible. If a change affects what we ask your consent for, your earlier answer stops applying and the consent banner asks again before anything optional runs.
Privacy requests and questions: [email protected]