BesluitBron 1.4.4-23 Status Sign in

Privacy and cookies

What this website records, why, who it is shared with and how long it is kept. This text describes what the site actually does, established by measuring the running site rather than by writing down the intention.

Who runs this site

BesluitBron is an initiative of the Stichting Common Sense in Actie foundation. Questions about this statement, about your own data, or a request for access or deletion go to info@besluitbron.nl.

What this site does not do

There are no advertisements on this site and no advertising profile is built. There are no social media buttons and nothing is shared with social media platforms. No data is sold or passed to third parties for their own purposes. This is stated because the standard text of a consent vendor often mentions exactly those things: if the consent dialogue on this site says so, the dialogue is wrong and that is worth reporting.

Without consent

The following happens on every visit, including when the consent dialogue is refused. It is needed to make the site work, or to be able to see that it is broken.

An IP address is shortened before it is recorded: on IPv4 the last 16 bits are dropped, on IPv6 only the leading 32 bits are kept. What remains points at a network and not at a visitor. An e-mail address that ends up in a record is replaced by an irreversible value out of a range of 65,536 possibilities, which so many addresses share that the value points at nobody.

WhatWhat forHow long
Cookie .AspNetCore.CultureRemembering the chosen language.One year.
bbn.pages in the browser's local storageCounting how many pages have been viewed in this browser, so the invitation to keep informed appears at most once.Stays in the browser and is never sent to the server.
bbn.analytics.sessionStart in session storage, and bbn.analytics.visitDates with its "reached" flags in the browser's local storageEstablishing whether a visit lasts thirty minutes or is spread over at least ten days, for the event below. These records never leave the browser themselves; only the outcome, and only with consent, goes to Matomo.The session value until the tab closes; the stored dates up to thirty at most, and until the threshold is reached.
The answer to the consent dialogueRemembering what was chosen, so the question does not return on every visit.As configured in the consent dialogue.
Sign-in cookie, only after signing inAn administrator's signed-in session.Twenty-four hours.
Error records: the address requested, the method, the shortened IP address, the browser identification and, when signed in, the user nameBeing able to see that and why a page failed.90 days. An administrator can clear them earlier with a button on the administration screen.
The server's technical traceDiagnosing failures.30 days.
Log of calls on the MCP endpoint, with the client's browser identification and, when the client sends it, the organisation the client states for itselfSeeing how the endpoint is used and where it fails.90 days.
Search log of the search screen: the search term typed, the number of results per source and in totalSeeing which search terms are used and which sources answer them.90 days.

The service clears up after itself every 24 hours. A record older than its window is therefore gone within a day of becoming so, including on a server that runs for months on end with nobody touching anything.

Only with consent: visitor statistics

When the consent dialogue is accepted, which pages are viewed is measured. That exists to see which pages are read and which are not, and nothing beyond that. When consent is refused, or while nothing has been chosen yet, no measurement request leaves the browser at all. Which parties are involved is listed below and on the Processors page.

The consent dialogue itself comes from another party and is loaded by the tag container. That means opening a page contacts those suppliers before anything has been chosen, in order to be able to show the dialogue. Their servers see the visitor's IP address in doing so, as any server does for any request. Nothing is measured and nothing is stored at that moment beyond the record of the consent itself.

The same consent also measures three kinds of events. Executing a query, typed by hand or started through the explorer, with only the connector involved (for example "ori") and never the content of the query. An error: an unexpected error in the page's own JavaScript, with the file, the line, the error type and the error message itself, or an error page the server shows for an HTTP error such as 500 or 404, with the status code, the requested URL and the error message. Either can, in rare cases, carry back what a visitor typed or requested; that risk is deliberately accepted so a fault can be investigated. And whether a visit lasts thirty minutes or is spread over at least ten days, without recording anything that points at a visitor while doing so. None of the three leaves the browser without the consent this section opened with. The error page itself used to show no consent dialogue and measure nothing; since this extension it does, the same way every other page does.

The choice can be revised at any time through the consent dialogue, which can be reopened from the browser's settings for this site or by clearing this site's cookies.

What is recorded when you leave something behind

Keeping informed

Leaving an e-mail address to be kept informed records: the e-mail address, the page the form was opened from, the number of pages viewed in this browser, the browser identification, the shortened IP address and the language. The address is used only to report that something about BesluitBron has changed, and is kept until deletion is requested.

Thumbs up or down

The question whether a page was helpful records only the address of the page, the verdict and the language. No name, no e-mail address. Somebody who adds a message has that message recorded and delivered to the administrator by e-mail. An e-mail address with it is optional and serves only to be able to reply.

Who anything is passed to

The complete list of parties that can receive anything is on Processors, stating per party what for, where, in what capacity, and whether that party is actually reached on this installation. The list lives in one place in the software and is rendered on that page, so it does not have to be maintained in four places separately. The same list is machine readable at /processors.json.

  • DeepL Machine translation of the documentation vault and of the titles a federated search finds at a source, from Dutch into the reader's language. European Economic Area

Nothing else leaves the site. The source platforms BesluitBron reads receive no data about the visitor: it is the server that asks them, not the browser.

Rights

There is a right of access to your own data, to correction and to deletion, and to object to processing. Such a request goes to info@besluitbron.nl and is answered within one month. Anyone who considers a request badly handled can complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.

A request may also concern records held against an IP address. Such a request is handled, with one limit that follows from the technique: the address recorded is shortened to a network, and that network is shared by many people. Records selected that way cannot be attributed to one person. What is given is therefore a count and a description of what is held, and not the contents of those lines, since that would hand over other people's traffic.

Reporting a security issue

Anyone finding a vulnerability in this site will find the reporting address in security.txt.