Privacy handoff, 4 October 2026
The user approved implementing independent, optional saved search history and returning-browser analytics in the two metadata finders, voluntary result feedback without visitor identity, accurate disclosures, bounded retention and reduced security-log content. No accounts, consent wall or removal of the university’s copied privacy statement was introduced. This privacy deployment leaves production ranking unchanged; later document experiments are offline only.
privacy.qmd contains a current GeoLAB addendum above the copied university accordion. Preserve the entire raw HTML accordion, including YouTube, Matomo and its historical finder description. The new text explicitly identifies that older finder description as historical. During this change, the raw accordion was compared byte-for-byte with the pre-change Git revision and matched. The original file’s missing trailing newline was normalised; the legal HTML itself was not edited.
Implementation and the detailed operations record are published in both repositories:
Production is the university VM with Caddy and native systemd services, not old Cloudflare demo tunnels. The website is rendered by Quarto and deployed with publish_live.sh; source is this university GitLab repository, not the personal GitHub Pages website. The finders share backend code but independently scope their consent choices and random browser IDs.
Engineering checks passed: backend/API tests, default-off/expiry/blocked-storage tests, both frontend builds, desktop/mobile Playwright checks of both finders (including one-row CSV export, feedback, reload and withdrawal), Quarto render, and production before/after ranking comparisons. All three consent choices start off and have equally styled allow/decline buttons. New security log entries omit query strings and all request headers; security IP retention stays approximately six days. Private query/feedback/browser records have a daily 90-day purge and are excluded from general backups, including cleanup of pre-existing telemetry backup copies.
Review items, not completed legal approvals
- Raw-query retention now requires its own optional consent under Article 6(1)(a), rather than invoking an unconfirmed university public-task basis. Legacy clients cannot save raw questions. On explicit user instruction, old raw logs were replaced with daily counts, not retroactively consented. Check controller, authorised operators, necessity and Article 13 wording with the DPO; this engineering change is not institutional approval of all processing.
- The Why Geodata? interactive map is entirely local: CARTO tile calls removed, existing grid/district polygon calls preserved, local Natural Earth lakes/place labels added. Natural Earth is public domain; pinned inputs/checksums are in
assets/html/local_basemap_provenance.json, with rebuild scriptscripts/localize_demo_map.py(existinggeoconda environment/Shapely). No CARTO tiles were downloaded, cached or proxied and no contract was accepted. The widget’s CSP blocks all external subresources. Test pan/zoom and network capture after any future rebuild. The predecessor’s linked GitHub Pages Data Explorer remains external and unchanged; inspect its licensing and SOEP aggregate release permissions before rehosting (seeDATAEXPLORER_HANDOFF.md). - Existing Quarto theme/tab local-storage writes remain to be reviewed for the essential-storage exception. Absence of cookies is not an exemption from §25 TDDDG.
The full copied university text was intentionally retained. This is an implementation record, not a guarantee of GDPR compliance, and opt-in analytics does not authorise unrelated processing.