Effective Date: June 2026
Administrative Authority: The Commission of Civil Registry / The Executive Council
Document Classification: Public Statutory Compliance
Who we are
We are the Executive Council of the State of Danubia. Your data is collected, secured, and managed under the collective authority of the Commission of Civil Registry (the primary data controller for identity infrastructure) and the Commission of Treasury & Audit (the processor for payment-related logs).
All operations are executed under the strict administrative oversight of the appointed Commissioners and the supreme executive command of the High Commissioner.
Information We Collect & Cookies
Identifiable Information: This includes your full legal name, verified email address, official national identity card/passport scans, and photographic verification matches (selfies), depending on your active status (Tier 1, Tier 2, or Tier 3).
Physical Sizing Data: For volunteers applying to the Danubian Honour Guard (DHG), we collect height (cm), shoe size, and standard apparel metrics to ensure precise uniform tailoring.
Cookies & Local Tracking: Our digital interface utilises minimal, clinical, and privacy-first technical cookies. We do not deploy third-party advertising trackers or behavioural profiling scripts. Our cookies exist solely to maintain encrypted portal session data, verify secure logins, and prevent cross-site scripting (XSS) attacks on the centralised cryptographic ledger.
Data Sharing (Strict Internal-Only Mandate)
We do not share, sell, lease, or externally distribute your personal data to any foreign corporate entity, commercial advertiser, or external government.
Your data is processed strictly within our internal network and is shared exclusively between authorised domestic sectors to maintain systemic continuity:
The Danubian Honour Guard Desk: Strictly for background security vetting and operational logistics of active enlistees.
The Commission of Civil Registry: For background auditing, identity verification updates, and passport issuance routing.
The Commission of Treasury & Audit: To match fixed administrative card transaction confirmations without exposing raw card digits.
Data Routing & Where It Is Sent
Because the administration operates under an active territorial blockade phase, our critical infrastructure is globally decentralised.
Commercial Interface Processing: When executing card transactions for physical credentials (PVC permits or passport books), data fragments are securely routed through a wholly-owned international corporate intermediary functioning as our compliant merchant of record to bypass arbitrary regional gateway blocks.
Encryption and Redundancy: Your data is encrypted using high-grade multi-factor encryption layers and mapped across redundant geographic server clusters secured by the Commission of Infrastructure & Land Mapping.
Data Retention: How Long We Keep It
Your civil identity file, unique Civil Registry Number (CRN), and associated historical data are kept conditionally based on active, good-faith civil standing.
Cryptographic Erasure: If an investigative audit confirms actions of structural malice, identity fraud, parallel micro-state alignments, or bad-faith digital agitation, the Commissioner will issue a Decree of Disenfranchisement. This triggers immediate, permanent cryptographic erasure—wiping your entire identity file, portal access, and civil history from the database, rendering any physical documents legally dead.
Continuous Term: Data is retained indefinitely to support your progression through the 12-month citizenship fast-track incentive program and ensure your place on the permanent population roll.
Sovereign Rights of the Individual
In alignment with global data privacy frameworks and the Public Treasury & Financial Compliance Act (TAD-PTFCA-2026-003), you possess clear sovereign rights regarding your data:
The Right to Voluntary Forfeiture: You may voluntarily request the closure of your civil registry file, which will result in the safe decommissioning and deactivation of your CRN.
The Right to Inspect (The 30-Day SLA): Verified Tier 2 and Tier 3 individuals hold the legal right to request a full validation summary of their data and entries in the internal financial ledger. Once a formal request and a civic security affirmation are submitted, the Treasury guarantees data fulfilment within 14 to 30 days, subject to mandatory security redactions (masking other individuals’ personal banking fragments or sensitive hosting infrastructure details).
The Right to Rectification: You may request updates to your background file or core registration packet if documents are outdated. The Commission evaluates and executes valid corrections within fourteen (14) business days.
How long do we retain your data
Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users who register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Additional Structural Protections (Anti-Distortion & Security)
To ensure the absolute integrity of our ecosystem, the following digital guardrails are strictly maintained:
Secure Infrastructure Mapping: All main domain registries and cloud backup nodes are officially classified as state infrastructure, monitored continuously to safeguard citizen information from bad-faith external cyber-attacks or unauthorised technical entry.
Cartographic & Ledger Protections: Any intentional attempt to corrupt, alter, or falsify coordinate sets, spatial data, or financial logs will be treated as an act of structural malice, triggering immediate cryptographic deactivation.
