Privacy Policy
Last updated: July 8, 2026
1. Data Controller
Case Law Hub is a content aggregator for EU court decisions and regulatory acts. The Website is operated as a non-commercial research and information service.
Contact email: [email protected]
We are a data controller as defined under Article 4(7) of the GDPR. If you have any questions about this Privacy Policy or your data rights, please contact us at the email above.
2. What Data We Collect
2.1 Personal Data You Provide
We do not collect any personal data from visitors to the Website. Specifically:
- No registration: The Website does not offer visitor registration, sign-up forms, or user accounts for the general public.
- No comments or submissions: The Website does not have comment sections, contact forms, forums, or any user-generated content features.
- No payment processing: The Website does not process payments and does not collect financial information.
The only personal data we process relates to admin panel users (site administrators), who are created internally by a super administrator. This data includes:
| Data Field | Purpose |
|---|---|
| Email address | Account identification and login |
| Password (bcrypt-hashed) | Authentication |
| Name (optional) | User display name |
| Role (admin / super_admin / viewer) | Access control |
| Last login timestamp | Security audit |
2.2 Data Collected Automatically
When you visit the Website, certain information is automatically collected through third-party services:
- Google Analytics 4 (GA4): Page views, referrer URL, browser type and version, operating system, screen resolution, approximate geographic location (country/city level, not precise), and interactions with the Website. We use Measurement ID G-P07EZL4EQ2. This data is anonymized and aggregated; we do not use it to identify individual visitors.
- Google AdSense: Information about your browsing habits and interests to serve contextual advertisements. This may include the pages you visit, your IP address (truncated for EEA users), browser and device information, and the ads you interact with.
2.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies. For full details, please see the Cookie Consent section below.
3. Legal Basis for Processing (GDPR)
| Processing Activity | Legal Basis (GDPR Article) |
|---|---|
| Serving the Website and its content | Legitimate interest (Art. 6(1)(f)) — providing access to public court records |
| Strictly necessary cookies | Legitimate interest (Art. 6(1)(f)) — enabling core Website functionality |
| Analytics cookies | Consent (Art. 6(1)(a)) — obtained via the cookie consent banner |
| Marketing/advertising cookies | Consent (Art. 6(1)(a)) — obtained via the cookie consent banner |
| Admin user account management | Contractual necessity (Art. 6(1)(b)) — necessary for admin panel access |
For processing based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
4. How We Use Your Data
We use the collected information for the following purposes:
- To operate and maintain the Website — providing access to court decisions and legal content
- To analyze and improve the Website — understanding how visitors use the service, which content is most popular, and how to improve the user experience
- To serve advertisements — displaying contextual ads through Google AdSense to support the Website's operation
- To ensure security — monitoring for abuse, unauthorized access, and technical issues
- To comply with legal obligations — responding to lawful requests from authorities
5. Cookie Consent and GCM v2
We comply with the ePrivacy Directive and GDPR requirements for cookie consent. Our consent management system is integrated with Google Consent Mode v2 (GCM v2).
5.1 Cookie Categories
| Category | Purpose | Examples | Consent Required | Can Be Withdrawn |
|---|---|---|---|---|
| Strictly Necessary | Essential for Website operation. Enables navigation, remembers your consent preferences, and maintains session security. | cookie-consent | No (legitimate interest) | No |
| Analytics | Helps us understand how visitors interact with the Website by collecting anonymous usage data. | _ga, _ga_* (Google Analytics) | Yes | Yes |
| Marketing | Used by Google AdSense to deliver relevant advertisements, measure ad performance, and prevent showing the same ad repeatedly. | DoubleClick/AdSense cookies | Yes | Yes |
5.2 GCM v2 Implementation
We use Google Consent Mode v2 to communicate your consent choices to Google services (Google Analytics and Google AdSense). The consent parameters are:
| Parameter | Controls | Default State |
|---|---|---|
analytics_storage | Google Analytics cookies | denied (until consent) |
ad_storage | AdSense/advertising cookies | denied (until consent) |
ad_user_data | Use of user data for ads | denied (until consent) |
ad_personalization | Ad personalization | denied (until consent) |
When you grant consent via the cookie banner, the relevant parameters are updated to granted. Google's tags respect these signals and behave accordingly — no cookies are set for a category until you consent.
5.3 The cookie-consent Cookie
We store your consent preferences in a first-party cookie named cookie-consent with the following attributes:
- Storage: useCookie (Nuxt, auto-serialized JSON)
- Max age: 365 days
- SameSite: Lax
- Data stored: Version, choice type (all, none, custom), analytics consent boolean, marketing consent boolean, timestamp
5.4 Managing Your Consent
- Accept All: Grants consent for analytics and marketing cookies
- Reject All: Denies analytics and marketing cookies (only strictly necessary cookies are set)
- Customize: Choose preferences per category
- Withdraw consent: Click 'Manage Cookies' in the footer at any time to change your preferences
6. Third-Party Services
| Service | Purpose | Data Processed | Privacy Policy | Jurisdiction |
|---|---|---|---|---|
| Google Analytics 4 | Website analytics | Page views, device info, anonymized IP | Google Privacy Policy | USA (EU-US Data Privacy Framework) |
| Google AdSense | Contextual advertising | Browsing behavior, anonymized IP, ad interactions | Google Privacy Policy | USA (EU-US Data Privacy Framework) |
| Self-hosted Fonts (@fontsource) | Typography rendering | No data sent to third parties — fonts served from our own server | N/A — no third-party processor | N/A |
| Hetzner Online GmbH | Server hosting | IP address, server logs | Hetzner Privacy Policy | Germany (EU) |
6.1 International Data Transfers
Google services (Analytics, AdSense, Fonts) are based in the United States. We rely on the EU-US Data Privacy Framework (adequacy decision under Article 45 of the GDPR) and Standard Contractual Clauses (SCCs) as appropriate transfer safeguards for data transferred to Google LLC.
6.2 Google Analytics 4 (GA4)
We use GA4 with the following privacy safeguards:
- IP anonymization: IP addresses are truncated (anonymized) before processing
- Data retention: User-level and event-level data is retained for 14 months
- No data sharing: We do not share Google Analytics data with other Google services for advertising purposes
- Consent gating: GA4 only loads if you have granted analytics consent via our cookie banner
6.3 Google AdSense
AdSense serves contextual advertisements. We have configured AdSense to:
- Respect GCM v2 consent signals (ad storage, ad user data, ad personalization are all denied by default)
- Show non-personalized ads to EEA users who have not granted marketing consent
- Serve contextually relevant ads based on page content, not user behavior, when consent is not given
7. Data Retention
| Data Type | Retention Period | Rationale |
|---|---|---|
| Cookie consent preferences | 365 days (cookie lifetime) | User preference persistence |
| GA4 analytics data | 14 months (event-level) | Trend analysis and improvement |
| AdSense data | Per Google's retention policy | Ad serving and reporting |
| Admin user account data | Until account deletion | Administrative access |
| Server logs | 7 days (rotating) | Security and troubleshooting |
Court decision data (the content of the Website) is retained indefinitely as it represents public legal records. No personal data is contained in these records.
8. Your Rights Under GDPR
As a data subject in the European Economic Area (EEA), you have the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Right of Access (Art. 15) | Request a copy of your personal data we process | Contact us via email |
| Right to Rectification (Art. 16) | Correct inaccurate personal data | Contact us via email |
| Right to Erasure (Art. 17) | Request deletion of your personal data ("right to be forgotten") | Contact us via email |
| Right to Restriction (Art. 18) | Restrict processing of your personal data | Contact us via email |
| Right to Data Portability (Art. 20) | Receive your data in a machine-readable format | Contact us via email |
| Right to Object (Art. 21) | Object to processing based on legitimate interest | Contact us via email |
| Right to Withdraw Consent (Art. 7(3)) | Withdraw consent for analytics/marketing cookies | Use "Manage Cookies" in the footer |
| Right to Lodge a Complaint (Art. 77) | File a complaint with your local data protection authority | Contact your national DPA |
Note: Since we collect no personal data from visitors, the majority of these rights pertain to the management of cookies and third-party data processing. We will respond to any request within one month as required by law.
8.1 How to Exercise Your Rights
To exercise any of your rights, please contact us at:
We will respond within 30 days. We may need to verify your identity before processing your request.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit: All connections use TLS 1.3 (HTTPS)
- Encryption at rest: Database is encrypted at the storage level
- Password hashing: Admin passwords are hashed with bcrypt (cost 12)
- Token security: Access tokens are stored in memory only (not localStorage); refresh tokens use httpOnly Secure cookies with SHA-256 hashing
- Access control: Role-based access control (RBAC) for the admin panel with three tiers: viewer, admin, super_admin
- Regular updates: All dependencies are kept current
- Docker isolation: Each service runs in its own container with minimal privileges
10. Children's Privacy
The Website is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated 'Last updated' date. Material changes will be notified via a notice on the Website.
We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
Data Protection Officer: Not appointed (exempt under Article 37 of the GDPR as we are not a public authority, do not engage in large-scale systematic monitoring, and do not process special categories of data on a large scale).
This Privacy Policy was last updated on July 8, 2026. It replaces all previous versions.