Bỏ qua, tới nội dung chính

Privacy Policy

Last updated: 27 August 2026

This policy explains what personal data costdown.org collects, why, how long it is kept, who else sees it, and what you can do about it. It is the information notice required by Article 13 and Article 14 of the EU General Data Protection Regulation (GDPR).

It describes what the service actually does today. Where a statement could not be verified against the running system, it is not in this document.

1. Who is responsible (data controller)

costdown.org is operated by an individual, not a registered company. That individual is the data controller within the meaning of Article 4(7) GDPR and is based in Vietnam.

No public email address is published for the controller. All contact — including every request described in section 8 — goes through the contact form. Messages sent there are stored, and you receive a reference number immediately, so a request cannot quietly disappear.

2. Data Protection Officer

No Data Protection Officer has been appointed. Article 37(1) GDPR requires one only where the core activity involves large-scale regular monitoring of individuals, or large-scale processing of special categories of data. costdown.org does neither: it processes business cost-reduction data, and the personal data it holds is limited to what is listed in section 3.

3. What data is collected

DataWhere it comes fromWhy
Email address, password (stored only as a hash), full nameYou, when registeringTo create and secure your account
Account role, account code, language preference, verification and suspension statusGenerated by the serviceTo run the account
Phone number, short bio, country, time zoneYou, optionally, in your profileShown on your public profile if you fill them in
Company name, industry, country, company sizeYou, optionallyTo place your case studies in the right benchmark group
Case studies, cost figures, engagements, verifications and comments you writeYouThis is the content of the service; published items are visible to everyone
IP address recorded with case-study viewsYour browserTo count views and detect abuse
IP address held temporarily while rate-limiting requestsYour browserTo stop automated abuse of registration, password reset and the contact form
A change log of edits to savings, investment, verification, status and role — old value, new value, who, whenGenerated by the serviceAuditability: a benchmark platform is only worth anything if figures cannot be changed silently
Name, email, message, IP address from the contact formYouTo answer you and to stop abuse of the form

There is no tracking of you across other websites, no advertising profiling, and no automated decision-making or profiling that produces legal effects within the meaning of Article 22 GDPR.

4. Cookies and browser storage

While you are logged out, costdown.org sets no cookies at all, and stores nothing in your browser’s local or session storage. This was verified against the live site.

After you log in, one cookie is set — user_id — which holds a signed session token. It is strictly necessary to keep you logged in, so no consent banner is required for it under the ePrivacy Directive. Logging out deletes it.

Traffic measurement uses Cloudflare Web Analytics, which is cookieless: it does not set an identifier in your browser and does not follow you to other sites.

5. Legal basis for processing

ProcessingLegal basis
Creating and running your account; publishing the content you submitArticle 6(1)(b) — performance of a contract with you
Session cookie, password hashing, login-attempt limits, IP rate limitingArticle 6(1)(f) — legitimate interest in keeping the service and its users secure
View counts and aggregate traffic measurementArticle 6(1)(f) — legitimate interest in knowing whether the service is used
The immutable change log of financial and verification figuresArticle 6(1)(f) — legitimate interest in data that can be trusted, which is the entire purpose of the platform
Handling messages you send through the contact formArticle 6(1)(b) where it concerns the service; Article 6(1)(c) — legal obligation — where it is a request under Articles 15–22
Transactional email (verification, password reset, account notices)Article 6(1)(b) — necessary to provide the account

You are not obliged to provide any of this. But an account cannot exist without an email address, a name and a password, so declining those means the service cannot be provided. Everything marked optional in section 3 can be left empty with no loss of function.

6. Who else receives the data

RecipientWhat they seeRole
Hetzner Online GmbH (Nuremberg, Germany)Everything stored by the service — they host the server and databaseProcessor
Cloudflare, Inc.Your IP address, user agent and requested URLs, as the network in front of the site; plus cookieless traffic measurementProcessor
Google (Gmail SMTP)The recipient address and content of transactional email sent to youProcessor
Other users of costdown.orgAnything you publish: case studies, cost figures, comments, and the profile fields you fill inNot a processor — publication is the purpose

Personal data is not sold, and is not shared with advertisers or data brokers. It is disclosed to public authorities only where the law requires it.

7. International transfers

The server and the database are located in Germany, inside the EU. Day-to-day operation of the service therefore involves no transfer of your data out of the EEA.

Three exceptions, stated plainly:

  • Cloudflare, Inc. is a US company operating a global network. Traffic to costdown.org may be handled at an edge location outside the EEA. Cloudflare relies on the European Commission's Standard Contractual Clauses and the EU–US Data Privacy Framework.
  • Email is sent through Google's SMTP service, which may process message content outside the EEA under the same frameworks.
  • Encrypted database backups are copied from the German server to the operator's own machine in Vietnam, so that a failure of the hosting provider cannot destroy every copy at once. Vietnam has no European Commission adequacy decision. The backups are encrypted with AES-256 before they leave the server and are held only by the controller.

8. How long data is kept

DataRetention
Account and profile dataUntil you ask for deletion. Ask through the contact form and it is removed.
Case studies and other content you publishedUntil you delete it, or ask us to. Note that figures already used in a published benchmark comparison may remain in aggregate form, where no individual can be identified.
Change log of financial and verification figuresKept for the life of the record and deliberately cannot be edited or deleted early — this is enforced by the database itself, not by application code. Without that, no figure on this platform could be trusted. It records what changed and by which account, not personal details.
IP addresses recorded with case-study viewsKept with the view record; removed when the case study is deleted.
IP addresses used for rate limitingHeld in memory only, and expire automatically within the rate-limit window (at most one hour).
Contact-form messagesKept while the matter is open and afterwards as evidence that a legal request was answered in time; deleted on request once it is closed.
Encrypted backupsHourly backups on the server are kept for 72 hours. Daily copies held off-site by the controller are kept for 30 days. Data you asked to delete can survive in backups until those windows pass.

9. Your rights as a data subject

Under the GDPR you may exercise the following rights at any time and free of charge. Each is named below by its legal term as well as in plain words, because the legal term is what binds:

  • Right of access (Article 15) — ask what data is held about you and receive a copy of it.
  • Right to rectification (Article 16) — have inaccurate data corrected, or incomplete data completed.
  • Right to erasure, also called the right to be forgotten (Article 17) — have your data deleted.
  • Right to restriction of processing (Article 18) — have processing frozen while a dispute is resolved.
  • Right to data portability (Article 20) — receive your data in a structured, commonly used, machine-readable form, and have it sent to another controller where technically feasible.
  • Right to object (Article 21) — object to processing based on legitimate interests, including the view counting described above.
  • Right to withdraw consent (Article 7(3)) — where processing rests on consent, withdraw it at any time, without affecting what was lawful beforehand.
  • Right not to be subject to automated decision-making (Article 22) — costdown.org makes no automated decisions producing legal or similarly significant effects, so this right is not engaged.

Use the contact form and choose Personal data request. You will get a reference number at once, and an answer within one month, as Article 12(3) requires. If the request is complex, we may extend that by up to two further months and will tell you why before the first month is out.

10. Right to complain to a supervisory authority

If you think your data has been handled unlawfully, you may lodge a complaint with a data protection supervisory authority — you can go to the one in your country of residence, your place of work, or where the alleged infringement happened (Article 77 GDPR). You do not need to contact us first, though it is usually faster if you do.

A list of the EU and EEA authorities is published by the European Data Protection Board at edpb.europa.eu. Because the server is in Germany, the German federal and Bavarian state authorities are also competent.

11. Security

  • Passwords are stored only as hashes; they are never stored or logged in readable form.
  • The whole site is served over HTTPS with HSTS.
  • Repeated failed logins lock the account temporarily, and requests to registration, password reset and the contact form are rate-limited by IP.
  • Every read and write of your data is checked against your permissions on the server, not only in the browser.
  • Backups are encrypted with AES-256, and restoring from them is tested rather than assumed.

No system is perfectly secure. If you find a vulnerability, please report it through the contact form before disclosing it publicly.

12. Children

costdown.org is a tool for people working in manufacturing and is not directed at children. Accounts are not knowingly created for anyone under 16. If you believe a child has registered, tell us through the contact form and the account will be removed.

13. Changes to this policy

The date at the top changes whenever this document does. If a change materially affects your rights, registered users are notified by email rather than left to notice it.

Privacy Policy | costdown.org