machinewitness

Data protection · GDPR

Privacy Policy

Last updated 23 July 2026

This policy explains how Martin Schenk S.L. ("we") handles personal data in connection with the MachineWitness archive and this website. We designed the project to touch as little personal data as possible; most of what we record is technical policy files that contain none.

Controller  Martin Schenk S.L., Calle Claudio Coello 14, 5G, 28001 Madrid, Spain
Contact  contact@machinewitness.eu

1. Visitors to this website

This is a static website. We do not use cookies, analytics, tracking pixels, or advertising, and we build no profiles of visitors. To deliver and protect the site, our hosting/CDN provider processes technical connection data (such as your IP address and browser type) for the short time needed to serve the page and defend against attacks. The legal basis is our legitimate interest in a secure, functioning site (Art. 6(1)(f) GDPR). If you email us, we process your message to reply.

If you suggest a domain

The suggestion form on the coverage page asks for a domain, your e-mail address, and your reason. We use them to decide on the suggestion and to reply to you, and for nothing else: no newsletter, no profile, no disclosure to third parties. The legal basis is our legitimate interest in taking suggestions about what to observe, and yours in receiving an answer (Art. 6(1)(f) GDPR). Suggestions are deleted once they have been decided and answered, at the latest after twelve months. The coverage check itself is different and sends no personal data at all: the domain you type is hashed in your browser, and only the hash is transmitted.

If you order an evidence extract

The order form on the evidence extract page asks for a domain, a period, the files you need, your reply address and your billing details, and lets you add a note. We use them to answer the order, to establish its scope, and to invoice it. We do not use them for anything else, and we disclose them to no one. The legal basis is Art. 6(1)(b) GDPR, because the processing is necessary for steps taken at your request before a contract, and Art. 6(1)(c) GDPR for the invoicing records Spanish commercial and tax law requires us to keep. Those records are retained for the statutory period, currently six years; everything else about an order is deleted once the matter is closed, at the latest after twelve months. You receive a written confirmation of what we recorded, so that a mistake in it costs a reply rather than an invoice.

The form is protected by Cloudflare Turnstile, which checks that a person and not a robot is submitting it. Turnstile processes technical connection data for that check; it sets no advertising cookie and builds no profile across sites. The legal basis is our legitimate interest in not having the order queue filled by machines (Art. 6(1)(f) GDPR).

2. The archive: data from third-party domains

MachineWitness visits public European domains and stores exactly the small machine-readable files they serve: robots.txt, ai.txt, text-and-data-mining reservation files, llms.txt, the homepage's response headers, and the fingerprint and five parsed fields of the TLS certificate presented at the time (not the certificate itself). These are technical and policy declarations. Most contain no personal data. Some may contain personal data incidentally, for example a contact name in a file, or a domain that is itself a person's name.

Purpose

To keep a neutral, tamper-evident record of what each domain served to machines on a given day, so that it can be independently verified years later. We do not evaluate, rank, or profile anyone. A witness, not a detective.

Legal basis

Our legitimate interest, and the public interest, in maintaining a verifiable evidentiary archive of the machine-readable web: Art. 6(1)(f) GDPR. Where archived material is later the subject of an erasure request, the retention of the cryptographic fingerprint rests on Art. 17(3)(e) GDPR, because without it the proof chain of every other observation sealed on the same day would collapse. We have documented the required balancing test and our erasure procedure, and will provide them on request.

Data minimisation and crawler conduct

We deliberately fetch only a handful of tiny, machine-readable files per domain per day. We do not crawl page content, we do not follow links into applications, we do not log in, and we apply hard size and rate limits. Our crawler identifies itself with a contact address and respects each site's robots.txt. See Crawler & contact.

Recipients and transfers

Only cryptographic fingerprints (hashes) of each sealed day leave our systems, to be time-stamped by external services (for example OpenTimestamps and an RFC 3161 time-stamp authority). These fingerprints reveal nothing about their contents. The archived files themselves are not shared or sold.

Retention

The archive is intended to be permanent: its value lies precisely in being able to show what was served in the past. This is subject to your rights below.

3. Your rights

You have the rights of access, rectification, erasure, restriction, objection, and portability under the GDPR, exercised by writing to contact@machinewitness.eu.

Erasure and the "tombstone". On a legitimate request, we erase the affected content: the stored file is deleted and replaced by a marker (a "tombstone"). The cryptographic hash and proof structure are kept, so the integrity of the surrounding record still holds: we can show that something was removed, without keeping what it was. We can also exclude your domain from all future crawling on request.

You may lodge a complaint with a supervisory authority, in Spain the Agencia Española de Protección de Datos (AEPD), or the authority in your country of residence.

This policy applies to a project that is still coming online. Where a described process is not yet active, that will be reflected here as it becomes so.