Privacy Policy

1. Data controller

The processing described in this notice is carried out by Pálfi József, a private individual, as the operator of the Delta Sentinel platform (the "Controller"). The Controller is not a company — Delta Sentinel is a community-funded project run by a natural person.

Contact: hello@deltasentinel.online

2. Scope and applicable law

This notice covers the deltasentinel.online public reporting site (and all of its subdomains), the related portal.deltasentinel.online reporter sign-in, and the corresponding server-side processing. Processing is carried out in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Hungarian data protection law.

3. What data we process, and why

3.1 Public incident reports (deltasentinel.online)

A report submitted through the guided chat may include:

  • a category (water, gas, electricity, fire, graffiti, road damage, vandalism, other) and a text description;
  • the GPS coordinates of the location (latitude, longitude) — required, since without it the report cannot be placed on the map;
  • optionally, up to 5 photos or videos, taken directly with the camera or chosen from your gallery;
  • an optionally provided email address, used solely so you can track the status of your report.

For every attached image, the server reads and stores the available EXIF metadata — typically the time the photo was taken, the camera/phone model, and, if present in the file, the GPS coordinates of the shot. This is supplemented by client-side metadata sent by your browser: the exact GPS latitude and longitude from your browser's own location lookup, together with its accuracy and timestamp (if you allowed location access for that submission), your device's platform (e.g. its operating-system/manufacturer identifier), your screen's pixel ratio (devicePixelRatio) and browser window size (viewport), the image file's own last-modified timestamp, and whether the photo came from the camera or the gallery. We process this data to more precisely identify the reported location and to help detect duplicate reports.

We keep the photo/video's original, full EXIF data (including any GPS coordinates) because the competent authority or utility company actually handling your report may need it to pinpoint the location precisely. What appears on the public nearby reports map/list, however, is a different copy of the photo: stripped of EXIF metadata and downscaled — always paired with the report's rounded location, never the exact coordinates (see section 4).

If you attach a photo, an on-device AI model (TensorFlow.js) running in your browser attempts to pre-label its content locally, to speed up triage. This pre-analysis runs only on your own device; its result is informational and is submitted together with the report. The server independently re-processes every submission — the on-device label is never the sole basis for how a report is handled.

Legal basis: your consent (GDPR Art. 6(1)(a)), given by voluntarily submitting the report.

3.2 Extensions and "still present" flags

Anyone (even without signing in) can add a comment to an approved, non-private report, flag that the issue also exists at their location, and attach an additional photo. Your email address is stored and linked to such a comment only if you submitted it while signed in; for anonymous submissions, only a technical identifier for abuse prevention (a cryptographic hash of your IP address) is recorded, which on its own cannot identify you.

Legal basis: your consent (GDPR Art. 6(1)(a)); recording the technical identifier rests on the Controller's legitimate interest (abuse prevention, GDPR Art. 6(1)(f)).

3.3 Ratings (stars + review)

Signed-in reporters can rate other approved, publicly visible reports with a star rating and a written review. The rating is linked to the report and, for point-calculation purposes, to the rating reporter's email address relative to the report's owner; the rater's identity is never shown in the public view.

Legal basis: your consent (GDPR Art. 6(1)(a)).

3.4 Gamification points (Sentinel programme)

If you submit a report or an extension while signed in, or if others rate your report, we credit points to your account and compute a level from them (e.g. "New Sentinel", "Bronze Sentinel", etc). The exact point and level rules are described on the Sentinel programme page. Point events (when, on what basis, how many points) are recorded in an internal event ledger, which supports transparency and lets abuse be audited.

Legal basis: your consent (GDPR Art. 6(1)(a)), given by signing in and voluntarily using the service.

3.5 Reporter sign-in (magic link) — portal.deltasentinel.online

If you provided an email address with your report, you can request sign-in (on the portal, or directly on deltasentinel.online) using that email address. We then send a single-use, 15-minute sign-in link (a "magic link") to the address you provided. After a successful sign-in, your browser receives a ds_reporter session cookie, valid for 7 days. This cookie is scoped to all deltasentinel.online subdomains (so your sign-in stays valid on both portal.deltasentinel.online and deltasentinel.online), is HttpOnly, and — as above — is used solely to maintain your sign-in state, never for advertising or tracking.

Legal basis: taking steps at your request prior to / for performance of a service (GDPR Art. 6(1)(b)) and your consent.

3.6 Bug reports, contact and support messages

The bug-report form on the site lets you submit a subject, a message body, and an optional email address for system errors, contact requests, or other feedback. These messages are kept separate from public incident reports and are used only to operate the site and fix issues.

Legal basis: your consent (GDPR Art. 6(1)(a)).

3.7 Server logs

Every request generates a technical log entry containing the IP address, the browser identifier (user agent), a timestamp, and the type of submission. We use this data to operate the service securely, to protect against abuse (e.g. excessive automated submissions), and to enforce rate limiting.

Legal basis: the Controller's legitimate interest in operating the service securely (GDPR Art. 6(1)(f)).

3.8 Processing based on a legal obligation

Exceptionally, where a law or a competent authority lawfully requires it (e.g. an official request in proceedings connected to a report), we disclose data we hold to the extent necessary to comply with that obligation. The legal basis for this is compliance with a legal obligation (GDPR Art. 6(1)(c)).

4. What we publish — and what we never publish

Approved, non-private reports may appear in the public nearby reports view. There, only the following is shown: the report's code, category, a shortened text description, its cover photo/gallery, how long ago it was submitted, its rounded location (roughly 10-metre precision), the average rating, the number of extensions and "still present" flags, and the text of any publicly published extension under a masked author name (e.g. "p***" or a voluntarily chosen display name).

The cover photo and gallery images shown in the public view are always a stripped (no EXIF metadata) and downscaled copy of the photo/video you uploaded — only the parties actually handling your report (the competent authority, utility company, or operator) have access to the file with its original, full EXIF data (including any GPS coordinates).

The public view never shows: the email address or any other direct identifier of the reporter or of anyone who commented, the exact (non-rounded) GPS coordinates of the report or an uploaded photo, or any data from which the exact location of your home or another private property could be clearly identified.

5. Processors and recipients

  • Mailgun (EU region) — the email delivery provider used to send magic-link emails and bug-report / contact replies. Mailgun processes this data on EU-based infrastructure (eu.mailgun.net).
  • Hosting — the system's servers are located within the European Union.
  • Competent authorities and utility companies — only to the extent necessary to handle a report, or where required by law.

We do not share data with any other third party, except where required by law.

6. Data retention

  • Magic-link tokens become invalid once used, or at the latest 15 minutes after being sent.
  • The ds_reporter sign-in session is valid for at most 7 days, after which it expires automatically.
  • Reports, their photos/videos and EXIF metadata, extensions, ratings, and point events are kept for as long as necessary to handle them and to keep the service transparent and auditable; after that they are deleted or, if retained for statistical purposes, anonymized.
  • Server logs are kept for a limited period (typically a few weeks) for security purposes, then deleted.

7. Cookies and local storage

The system uses only the following strictly necessary (essential) cookies. No prior consent is required for these, since the related service (sign-in) could not function without them — nevertheless, in the interest of transparency we also notify visitors via a banner.

We do not use marketing, analytics, or tracking cookies. Your choice made in the cookie banner (ds-cookie-consent) is stored in your browser's local storage, not in a cookie, and is never sent to the server.

Your browser's local storage may also hold the following entries, which stay on your own device only:

  • ds-online-report-queue — a temporary, local save of a report you tried to submit while offline, kept until it can be sent once you are back online;
  • ds-basemap — remembers which map layer (streets/satellite) you last selected.

8. Your rights

Under the GDPR, you have the following rights regarding data relating to you:

  • Right of access — you can ask whether we process data about you, and if so, what data.
  • Right to rectification — you can ask us to correct inaccurate data.
  • Right to erasure ("right to be forgotten") — you can ask us to delete your data once there is no longer a legal basis for processing it.
  • Right to restriction of processing.
  • Right to object to processing based on legitimate interest.
  • Right to data portability — you can ask for the data we hold about you in a machine-readable format.

You can submit a request at hello@deltasentinel.online. We respond within a reasonable time, and no later than 30 days.

If you believe our processing of your data violates the law, you can lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

  • Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
  • Postal address: 1363 Budapest, Pf. 9., Hungary
  • Phone: +36 1 391 1400
  • Email: ugyfelszolgalat@naih.hu
  • Website: www.naih.hu

You may also seek judicial remedy to enforce your rights.

9. Data security

The Controller applies appropriate technical and organizational measures (access control, encrypted transport, logging, rate limiting) to keep data secure and to prevent unauthorized access, alteration, or loss.

10. Contact

For any questions about this processing, contact us at hello@deltasentinel.online

Privacy Policy — Delta Sentinel