Privacy policy
How we process personal data in accordance with the GDPR and German data protection law.
Version: 16 August 2026
1. Controller
Maximilian Braun, Burgstallgasse 10, 93309 Kelheim, Germany. Email: info@dvlotteryalert.com.
2. Data we process
We process the minimum data needed to run the service: email address, DV year, public X post URL and status ID, verification and activation timestamps, notification delivery status, support messages, technical security logs, and monitoring evidence. We do not request passport, date of birth, visa, government login, or DV confirmation data.
3. Purposes and legal bases
- Email alerts, the X-post activation process, support, and withdrawals: performance of a contract or steps requested before a contract, Article 6(1)(b) GDPR.
- Security, abuse prevention, validation of free-alert claims, reliable monitoring, and limited operational logs: legitimate interests, Article 6(1)(f) GDPR.
4. Hosting and database
The application is intended to be hosted by Vercel Inc. and stores operational data in Supabase. The production Supabase project must be created in an EU region. Data processing agreements must be accepted with both providers. Technical requests may still involve providers or subprocessors outside the EEA under an adequacy decision or standard contractual clauses.
5. Payments
The alert is currently free. We do not request or process payment-card data.
6. Email and X
Hostinger Email processes email addresses and message delivery metadata to send transactional messages through the mailbox operated for this website. The applicable data processing terms and subprocessor information must be reviewed before launch. You publish the post yourself under X's terms. We do not post to your account or receive account access. We store the public post URL and numeric status ID you submit.
7. Free-alert records
We store a hashed email-verification token, verification state, DV year, activation record and delivery status. We may open the public URL to confirm that the site link and required statement are present. Unverified requests expire after 24 hours. Activated alert records are retained through the relevant DV cycle plus one year to prevent duplicate claims and handle support.
8. Cookies and local storage
We use only storage strictly necessary for security and administration. No advertising or analytics cookies are set. Therefore, no consent banner is used. If optional analytics or advertising is added, consent handling and this policy must be updated first.
For abuse prevention, a one-way hash derived from the request network address and endpoint is kept in short-lived rate-limit records. The raw address is not stored in that table. The legal basis is our legitimate interest in service security, Article 6(1)(f) GDPR.
9. Retention
Unverified requests expire after 24 hours and are deleted by the retention job. Activated alerts and their delivery status are kept through the relevant DV cycle plus one year for duplicate prevention, proof and support. Rate-limit records are deleted after 24 hours. Monitoring evidence, support messages and withdrawal emails are kept only as long as needed for operation, dispute handling and legal obligations.
10. Recipients
Recipients are limited to Supabase, Vercel, Hostinger Email, and advisers or authorities where legally required. X processes the post you choose to publish under its own privacy terms. We do not sell personal data.
11. Your rights
You may request access, correction, deletion, restriction, portability, and object to processing based on legitimate interests. You may withdraw consent prospectively. You also have the right to complain to a supervisory authority. In Bavaria, the competent authority is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany, lda.bayern.de (external).
12. Required data and automated decisions
An email address and public X post URL are required to provide the free alert. We do not make decisions producing legal or similarly significant effects solely by automated means.
13. Security and changes
We use access controls, encrypted transport, secret separation, database policies, expiring tokens, and data minimisation. No system is entirely risk-free. We update this notice when processing changes materially.
Legal review
This source is a tailored privacy template and must receive legal review. Provider DPAs, subprocessor lists, actual hosting regions, and retention jobs must be verified before production.