machinewitness ← back

Data protection · GDPR

Privacy Policy

Last updated 23 July 2026

This policy explains how Martin Schenk S.L. ("we") handles personal data in connection with the MachineWitness archive and this website. We designed the project to touch as little personal data as possible; most of what we record is technical policy files that contain none.

Controller  Martin Schenk S.L., Calle Claudio Coello 14, 5G, 28001 Madrid, Spain
Contact  [email protected]

1. Visitors to this website

This is a static website. We do not use cookies, analytics, tracking pixels, or advertising, and we build no profiles of visitors. To deliver and protect the site, our hosting/CDN provider processes technical connection data (such as your IP address and browser type) for the short time needed to serve the page and defend against attacks. The legal basis is our legitimate interest in a secure, functioning site (Art. 6(1)(f) GDPR). If you email us, we process your message to reply.

2. The archive: data from third-party domains

MachineWitness visits public European domains and stores exactly the small machine-readable files they serve — robots.txt, ai.txt, text-and-data-mining reservation files, llms.txt, the homepage's response headers, the TLS certificate chain, and crawler-identity records. These are technical and policy declarations. Most contain no personal data. Some may contain personal data incidentally — for example a contact name in a file, or a domain that is itself a person's name.

Purpose

To keep a neutral, tamper-evident record of what each domain served to machines on a given day, so that it can be independently verified years later. We do not evaluate, rank, or profile anyone. A witness, not a detective.

Legal basis

Our legitimate interest, and the public interest, in maintaining a verifiable evidentiary archive of the machine-readable web (Art. 6(1)(f) GDPR), together with the safeguards for archiving in the public interest (Art. 89 GDPR in conjunction with Art. 85, and the corresponding provisions of Spanish law, LOPDGDD 3/2018).

Data minimisation and crawler conduct

We deliberately fetch only a handful of tiny, machine-readable files per domain per day. We do not crawl page content, we do not follow links into applications, we do not log in, and we apply hard size and rate limits. Our crawler identifies itself with a contact address and respects each site's robots.txt. See Crawler & contact.

Recipients and transfers

Only cryptographic fingerprints (hashes) of each sealed day leave our systems, to be time-stamped by external services (for example OpenTimestamps and an RFC 3161 time-stamp authority). These fingerprints reveal nothing about their contents. The archived files themselves are not shared or sold.

Retention

The archive is intended to be permanent: its value lies precisely in being able to show what was served in the past. This is subject to your rights below.

3. Your rights

You have the rights of access, rectification, erasure, restriction, objection, and portability under the GDPR, exercised by writing to [email protected].

Erasure and the "tombstone". On a legitimate request, we erase the affected content: the stored file is deleted and replaced by a marker (a "tombstone"). The cryptographic hash and proof structure are kept, so the integrity of the surrounding record still holds — we can show that something was removed, without keeping what it was. We can also exclude your domain from all future crawling on request.

You may lodge a complaint with a supervisory authority, in Spain the Agencia Española de Protección de Datos (AEPD), or the authority in your country of residence.

This policy applies to a project that is still coming online. Where a described process is not yet active, that will be reflected here as it becomes so.