This policy explains what personal data AltNet’s account service collects, why, and your rights under the EU General Data Protection Regulation (GDPR). It covers the panmox.org account / registration service (the “Service”). The AltNet peer-to-peer network itself is account-less — see “The peer-to-peer network” below for how data behaves there.
The data controller for the Service is:
Gabriel Wenzel (operating as PANMOX)
Prague, Czech Republic
Full postal address available on request via the contact email.
Contact: abuse.report@panmox.org (also for privacy questions)
We are a small operator. We have not appointed a Data Protection Officer because our processing does not require one under GDPR Art. 37; you can reach a human at the address above.
We only collect what the Service needs to work and to keep it safe from abuse.
| Data | Why we hold it | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Email address | Account identity, login, verification, password reset, abuse correspondence | Contract (Art. 6(1)(b)) |
| Password (stored only as a bcrypt hash, never in plaintext) | Authentication | Contract |
| Email verification / password-reset codes (short-lived) | Confirm you control the email; anti-abuse | Legitimate interest (Art. 6(1)(f)) |
| Login sessions (random token + timestamps) | Keep you signed in | Contract |
Domain requests (the .alt name, your description, status, timestamps) | Review and approve .alt registrations | Contract; legal obligation (Art. 6(1)(c)) |
Abuse reports (the reported .alt name, the reason text, and the reporter’s email) | Handle illegal-content notices; keep an audit trail | Legal obligation (EU DSA); legitimate interest |
| Account flags (verified, admin, suspended) | Operate and moderate the Service | Contract; legitimate interest |
We do not collect: real names, addresses, phone numbers, payment data (the Service is free), advertising or tracking identifiers, or any special-category data. We do not profile users or sell data. There are no third-party analytics or advertising cookies — the only cookie / token is the strictly-necessary login session.
Running an AltNet node, and browsing .alt sites, happens on a decentralised peer-to-peer network — not on our servers and without an account:
If this matters to you, use a VPN and be mindful that publishing to a public P2P network is, by design, public.
We use a small number of service providers to run the Service. Each acts as a data processor under a data-processing agreement:
Some of these providers are global and may process data outside the European Economic Area. Where that happens, transfers rely on an adequacy decision or the European Commission’s Standard Contractual Clauses. We do not otherwise disclose your data, except where legally required (e.g. a valid court order) or to act on an illegal-content notice.
Backend account data is processed on EU-based infrastructure (Oracle Cloud, Frankfurt). Email and DNS providers are listed in §4.
Under the GDPR you have the right to: access your data, rectify it, erase it (“right to be forgotten”), restrict or object to processing, and data portability.
You also have the right to lodge a complaint with your supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ) — www.uoou.gov.cz.
Passwords are stored only as bcrypt hashes. The account API is served over HTTPS. We apply reasonable technical measures, but no system is perfectly secure; please use a strong, unique password.
The Service is not directed at children. You must be at least 18 to create an account. We do not knowingly collect data from children below this age.
We may update this policy. Material changes will be announced on panmox.org. The “Last updated” date above reflects the current version.
Questions or requests: abuse.report@panmox.org, or by post at the address in §1 (available on request).