We process your personal data only for the following specific purposes, each with a corresponding legal basis under the GDPR:
3.1 Account creation and management Art. 6(1)(b) GDPR
Processing your email and username is necessary to create and manage your user account and to deliver the Favourites service you have requested. Without this data, we cannot provide the service.
3.2 Authentication and account security Art. 6(1)(b) + 6(1)(f) GDPR
Your email is used to verify your identity, send password reset links, and notify you of security events (e.g. suspicious login attempts). This is both a contractual necessity and a legitimate interest of Duecode in keeping the Platform secure.
3.3 Platform security and fraud prevention Art. 6(1)(f) GDPR
Technical logs (IP address, access timestamps) are processed to detect and prevent unauthorised access, abuse, and misuse of the Platform. This is a legitimate interest of Duecode and does not override your rights given the non-sensitive nature of the data and the strict retention limits applied.
3.4 Legal compliance Art. 6(1)(c) GDPR
We may retain or disclose data where required by applicable law, regulation, or a binding order from a competent authority.
We do not use your data for automated decision-making, profiling, or any purpose other than those listed above.