Who is responsible for the site
The website is published under the Cronaca Faro project name. In this build the operator is identified as Stephan Everding, with the public contact region Dublin, Ireland. Privacy questions and data requests can be sent to [email protected].
The project does not publish a street address because the build should not imply a physical public office that has not been documented. If the legal status or contact details of the operator change, this notice should be updated before the new details are relied upon.
Information you choose to send
The free consultation form asks for four items: name, email address, telephone number and the subject, company, platform or domain you want to research. A consent checkbox confirms that you have read the privacy information and are asking the project to use those details to respond to the request.
The form is not intended for passwords, one-time codes, seed phrases, private keys, full bank-card numbers, copies of identity documents or other information that is not needed to understand the research question.
- Name — used to address and organise the request
- Email — used to reply
- Telephone — supplied as an alternative contact route
- Research subject — used to understand the public-source question
Advertising context and the “o” parameter
The site can receive a URL parameter named “o”. Its purpose is to carry the keyword or research context into the landing page and prefill the research interface. If a consultation is submitted while that context is present, the term may be stored with the form record so the request is not separated from the subject the reader was looking at.
The parameter is not a hidden verdict and it does not cause different content to be served to a crawler and a person. Links to the Central Bank, CRO, CCPC, Garda and other official sources are deliberately kept clean and do not receive the “o” parameter.
Technical information and security logs
A normal web server or hosting provider may process IP address, request time, requested URL, browser/user-agent information and error information in server logs. Those records are used for security, availability, abuse prevention and troubleshooting.
The PHP application itself does not create an advertising profile from those logs. The exact server-log retention period is a hosting configuration, not a value hard-coded in this website, so the operator should verify the hosting provider’s current settings after deployment and update this notice if necessary.
How the consultation record is stored and retained
Submissions are written server-side to a CSV file in the protected storage directory. The application stores the submission time, language, name, email, phone, research subject, optional “o” context and a one-way hash derived from the IP address for basic abuse/security handling.
The application includes a 90-day cleanup routine for consultation records. Older rows are removed when the consultation area is used. Backups created by the hosting provider can have a separate lifecycle; if backups are enabled, their retention and deletion process should be checked in the hosting account.
Cookies and local browser storage
The consultation page uses a short-lived technical PHP session called “osint_session” to support the anti-CSRF token. The cookie banner stores “osint_cookie_choice=accepted” for up to 180 days and mirrors that acknowledgement in localStorage as a fallback. Neither is used for behavioural advertising.
The delivered code contains no Google Analytics, Google Ads remarketing tag, Meta Pixel, TikTok Pixel, fingerprinting script or affiliate cookie. If the operator adds a non-essential tracker later, the cookie mechanism and this notice must be reviewed before the tracker is enabled.
Purpose and legal basis
Contact details are used because the reader has asked the project to review and respond to a specific research question. Security measures and limited technical records are used to operate the site, protect the form and investigate failures or abuse. The operator should keep processing limited to those stated purposes unless a new purpose is properly disclosed and supported by an appropriate legal basis.
This notice is a description of the delivered site, not a substitute for legal advice about a particular hosting, employment or business arrangement.
Who receives the data
Consultation information is intended for the site operator and any service provider genuinely required to host, secure or maintain the website. The build does not sell the form data, rent it to advertisers or automatically send leads to brokers or trading platforms.
When you choose an external official-source link, you leave Cronaca Faro and the destination organisation processes your visit under its own privacy and cookie rules.
Your data-protection rights
Under the GDPR, rights can include access, rectification, erasure, restriction, objection and, in relevant circumstances, data portability. The exact right depends on the processing and the legal basis. To make a request, email [email protected] and identify enough information for the project to locate the relevant submission without sending unnecessary sensitive data.
You can also consult or complain to the Irish Data Protection Commission. The DPC publishes plain-language explanations of individual rights, including the right of access.
Changes to this notice
This notice should be reviewed whenever the form changes, a new analytics or advertising tool is added, data is sent to a new service provider, the hosting arrangement changes materially or the operator’s identity/contact details change.
The update date at the top of the page is intended to make those changes visible rather than leaving a generic policy in place after the technical behaviour has changed.