Privacy Policy
Version: 1.1 — P
Last updated: 2 October 2026
This Privacy Policy explains how personal data is processed when you visit or use PMF ResearchLab at https://pmfresearchlab.com.
PMF ResearchLab provides a private workspace for managing sports memorabilia collections, documenting provenance, comparing photographs and preserving research findings.
1. Controller and Contact
The controller responsible for the processing described in this Privacy Policy is:
Christian Hintermeier
PhotoMatchForensics / PMF ResearchLab
Bottenäcker Str. 36
71711 Murr
Germany
Email: ch@photomatchforensics.com
Telephone: +1 475-276-5505
No data protection officer has been appointed. Please direct privacy enquiries and requests to exercise your rights to the controller using the contact details above.
2. Website Access and Hosting
When you access the website, technical information is processed to deliver the requested pages and maintain the security and availability of the service.
This may include:
• your IP address;
• the date and time of access;
• requested pages and files;
• response codes and transferred data volumes;
• browser and operating system information;
• referring pages, where transmitted by your browser.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are operating a secure and reliable website, identifying technical problems and preventing misuse.
Our hosting provider is:
ALL-INKL.COM – Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68
02742 Friedersdorf
Germany
Our retention policy provides for the deletion of server access logs after seven days and application error logs after 14 days. Relevant records may be retained longer where necessary to investigate a specific incident or establish, exercise or defend legal claims.
3. Registration and Account Management
When you register and use an account, we process information including:
• your first and last name;
• your email address and country;
• a password hash;
• registration and email verification details;
• account status and selected package;
• package permissions and expiry information;
• records of the versions of the terms and privacy information acknowledged by you.
Passwords are stored as password hashes rather than in plain text. Time-limited verification and password reset links support account security.
Account information is processed under Article 6(1)(b) GDPR to establish and perform the agreement for your use of PMF ResearchLab. Necessary security and accountability records may also be processed under Article 6(1)(f) GDPR.
Information identified as mandatory during registration is necessary to create and operate your account. Without it, we cannot provide the registered service.
Acknowledging this Privacy Policy does not constitute blanket consent to unrelated processing or marketing.
Registrations that have not been verified within 30 days are deleted.
4. Collection Information and Research Content
We process the information and files you choose to store in your workspace. These may include:
• collection item descriptions;
• player, team, season and event information;
• item photographs and reference images;
• documents, acquisition records and provenance information;
• research notes and source references;
• purchase prices and estimated values;
• photomatches, comparison sets and evidence points;
• generated PDF reports and export files.
We process these contents to provide the storage, editing, comparison, analysis and export functions you request.
Where this involves your personal data, the legal basis is Article 6(1)(b) GDPR.
Uploaded material may also contain personal data about other people, such as individuals pictured in photographs or identified in provenance documents. To the extent we process such data as controller, processing requires an applicable legal basis. Article 6(1)(f) GDPR may apply where processing is necessary for legitimate interests in private collection documentation and research, provided those interests are not overridden by the rights and interests of the individuals concerned.
Your workspace contents are not automatically published or made available to other users. Access to private files is subject to authentication and authorisation checks.
Authorised administrators and service providers may access information where necessary for support, maintenance, security, handling misuse or complying with legal obligations. Private storage does not mean end-to-end encryption or that access by the operator is technically impossible.
Please upload personal information about other people only where you are entitled to do so. Remove or redact unnecessary information, such as private addresses, signatures or bank details in supporting documents.
If you download or share a report outside PMF ResearchLab, that copy is no longer protected by the platform’s access controls.
5. Essential Cookies and Login Sessions
PMF ResearchLab uses essential session cookies to maintain login sessions, associate requests with the correct account and protect forms against unauthorised requests.
The application uses:
• PMF_USER for the user area;
• PMF_ADMIN for the separate administration area.
These are session cookies without a persistent expiry date. Their treatment also depends on your browser’s settings, including session restoration.
Server-side login sessions expire after [insert the confirmed inactivity period; the application’s default is 120 minutes].
We also process session information, including browser or device descriptions, expiry times and the time of the most recent activity. Expired session records are removed during routine maintenance. Verification and password reset tokens have limited validity and are removed after use or during expiry cleanup.
Storage of or access to information on your device that is strictly necessary to provide a service you explicitly request is based on Section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act, or TDDDG.
The associated processing of personal data is based on Article 6(1)(b) GDPR for providing account functionality and Article 6(1)(f) GDPR for maintaining security.
Blocking essential cookies may prevent account and security functions from working correctly.
6. IP Addresses and Pseudonymous Identifiers
IP addresses are processed as part of establishing connections to the website and protecting the service.
For specific application functions, the application derives pseudonymous identifiers from IP addresses using HMAC-SHA-256 with a secret key.
For visitor statistics, the identifier incorporates the IP address, browser information and the current day. This produces a different identifier on different days. The statistics table stores the resulting identifier rather than a separate plain-text IP address.
For abuse prevention, separate keyed identifiers are used to limit excessive requests, such as repeated registration or login attempts. These records have limited validity and are removed through expiry cleanup.
Hashing is itself a form of data processing. These identifiers are treated as pseudonymous data, not as a guarantee of complete anonymity.
Hosting logs are separate from these application-level mechanisms and may contain full IP addresses.
7. Collection Analytics and Website Statistics
Personal collection analytics
We analyse the collection information you store to provide features such as breakdowns by player, team, season, research status or estimated value.
This processing is based on Article 6(1)(b) GDPR and supports the collection management functions you request.
Operational statistics
We may evaluate account numbers, package allocations, storage use, uploads and feature usage to manage the service.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are capacity planning, troubleshooting and maintaining the availability of the platform.
Public website visitor statistics
Our self-hosted visitor statistics record public page visits, timestamps, entry pages, device categories, browser and operating system categories, referring domains and the daily pseudonymous identifier described above.
The purpose is to understand website usage and improve the service’s usability and technical operation. This statistics feature does not set additional analytics cookies.
The intended legal basis is Article 6(1)(f) GDPR, subject to an assessment of necessity, proportionality and the rights and interests of visitors.
Pseudonymous visitor statistics are retained for 30 days. Longer-term statistical summaries may be retained only where they are genuinely anonymised and no longer permit individuals to be identified.
8. Service Emails and Enquiries
We process your email address and the necessary message contents to send communications such as:
• email verification messages;
• password reset links;
• necessary account and security notices;
• information about package status or expiry;
• responses to your enquiries.
When you contact us, we process the information you provide to handle your request.
The legal basis is Article 6(1)(b) GDPR where communication concerns your use of the service or steps before entering into an agreement. Other enquiries may be processed under Article 6(1)(f) GDPR, based on our legitimate interest in responding to communications.
We use ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, as our SMTP email delivery provider.
The provider processes recipient addresses, message contents and technical information necessary for email delivery.
Application records of automated email delivery, including retained message copies, recipient addresses, subjects, delivery status and timestamps, are deleted 30 days after the delivery process has been completed or finally abandoned.
Ordinary support correspondence is deleted six months after the enquiry has been resolved, unless continued retention is necessary for a legal obligation, an ongoing dispute or another documented lawful purpose.
These periods concern records under our control. Any separate retention by the email provider must be assessed under the applicable service arrangements.
Creating a ResearchLab account does not automatically subscribe you to promotional emails. Where consent is required for marketing, it will be requested separately.
9. Security and Activity Records
We record selected account, administrative and security-related events to protect the platform and investigate problems.
Depending on the event, these records may include:
• the relevant account identifier;
• the date and time;
• the type of action;
• necessary details about changes to records or permissions;
• technical information required to investigate misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are protecting private content, preventing unauthorised access and investigating errors or misuse.
Routine security and activity records are retained for 30 days.
Records needed to investigate a specific incident or establish, exercise or defend legal claims may be retained for longer. Such retention is limited to the relevant records and reviewed when the incident or proceedings have concluded.
10. Retention, Archiving and Deletion
Account and collection contents
PMF ResearchLab is designed for the long-term documentation and preservation of private collections and research.
We retain account information and stored collection contents for the duration of the account relationship, insofar as this remains necessary to provide the service. You may delete individual contents earlier using the available functions.
Long-term storage is part of the service. However, personal data is not retained indefinitely merely because no deletion request has been received. Continued retention must remain necessary and lawful.
Inactive accounts
An extended period without signing in does not automatically result in the deletion of your collection.
After 24 months without a recorded account login, our retention procedure provides for a review of the account and, where appropriate, a reminder to the registered email address. This is a review threshold, not an automatic deletion deadline.
Archived items and package changes
Archiving an item does not delete it. Archived items and their associated files and research remain stored and can be restored.
Package expiry or a downgrade does not automatically delete existing content.
Individual records and account deletion
You may use the available functions to permanently delete individual records. If a file remains linked to other research, those links may need to be removed before deletion can proceed.
To request deletion of your account, contact ch@photomatchforensics.com.
We will assess your request and erase personal data where the legal conditions are met. Where information must be retained to comply with a legal obligation or establish, exercise or defend legal claims, its processing will be restricted to those purposes.
Copies that you or other recipients have downloaded outside the platform are not removed by deleting the corresponding platform record.
Backups
Our own backups, where created, are retained on a rolling basis for a maximum of 30 days.
Deleted information may remain in protected backups until those backups are overwritten or expire. Backup copies are used for recovery rather than ordinary access to deleted content. If a backup is restored, applicable deletion actions must be reapplied before the restored data returns to normal use.
[Before publication: confirm the separate maximum retention periods for ALL-INKL’s website, database and email backups and insert them here. The 30-day period above must not be presented as ALL-INKL’s confirmed policy.]
Retention overview
Data category Retention period or criterion
Account and collection contents For the duration of the account relationship, insofar as necessary to provide the service
Archived collection items As for other collection contents; archiving does not trigger deletion
Unverified registrations 30 days
Pseudonymous visitor statistics 30 days
Server access logs under our control Seven days
Application error logs 14 days
Routine security and activity records 30 days
Automated email delivery records and retained message copies 30 days after completion or final abandonment of delivery
Ordinary support correspondence Six months after resolution
Our own backups Maximum rolling retention of 30 days
Hosting-provider backups and separate provider logs The verified periods specified in the relevant sections above
Documented legal obligations, specific security incidents and legal claims may require limited exceptions to these periods.
11. Recipients and International Transfers
Personal data is disclosed only where necessary for the purposes described in this policy and where a legal basis exists.
Recipients may include:
• hosting and email providers;
• technical maintenance or support providers;
• authorities or courts where disclosure is legally required;
• professional advisers where necessary to protect or exercise legal rights.
Where a provider processes personal data on our behalf, an appropriate data processing agreement is required.
External source links lead to websites operated by other providers. Their privacy policies apply when you visit those websites.
12. Your Rights
Subject to the applicable legal conditions, you have the right to:
• obtain access to your personal data;
• have inaccurate data corrected and incomplete data completed;
• request erasure;
• request restriction of processing;
• receive qualifying data in a structured, commonly used and machine-readable format and, where applicable, have it transferred to another controller;
• withdraw consent at any time where processing is based on consent.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to object: Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will stop that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or processing is necessary for establishing, exercising or defending legal claims.
You may object to processing for direct marketing at any time, without giving reasons.
Please send requests to ch@photomatchforensics.com. We may request reasonable additional information where necessary to verify your identity.
We respond to requests without undue delay and normally within one month. Where an extension is permitted because of the complexity or number of requests, we will notify you within that initial month and explain the reasons.
You also have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State of your habitual residence, place of work or the alleged infringement.
The supervisory authority for Baden-Württemberg can be contacted at:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany
Email: poststelle@lfdi.bwl.de
Website: www.baden-wuerttemberg.datenschutz.de
13. Automated Decision-Making
PMF ResearchLab does not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
Automatic application of package durations and feature limits implements the service permissions associated with your selected package.
14. Updates to This Policy
We may update this Privacy Policy when our processing activities, service functions or applicable requirements change.
The current version is available on this website. Where required, we will provide additional notice of material changes.
