{"id":774,"date":"2026-09-25T12:11:59","date_gmt":"2026-09-25T10:11:59","guid":{"rendered":"https:\/\/www.ea1fsc.es\/?page_id=774"},"modified":"2026-09-25T12:11:59","modified_gmt":"2026-09-25T10:11:59","slug":"politica-de-privacidad-y-tratamiento-de-datos-infraestructura-homelab-y-nube-hibrida","status":"publish","type":"page","link":"https:\/\/www.ea1fsc.es\/en\/politica-de-privacidad-y-tratamiento-de-datos-infraestructura-homelab-y-nube-hibrida\/","title":{"rendered":"Privacy Policy and Data Processing (Homelab and Hybrid Cloud Infrastructure)"},"content":{"rendered":"<h1><strong>Last updated:<\/strong> September 25, 2026<\/h1>\n<p>This document establishes the privacy policies and strict data processing terms applicable to the IT infrastructure services independently operated and managed by <strong>Juan G\u00f3mez L\u00f3pez<\/strong> (technical alias <strong>\u00abea1fsc\u00bb<\/strong>), hereinafter referred to as \"the Data Controller\".<\/p>\n<p>The design, deployment, and maintenance of this infrastructure are based on the principles of maximum privacy, decentralization, and data sovereignty. Consequently, this policy has been drafted in strict compliance with current European legislation, in particular the <strong>Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR).<\/strong>.<\/p>\n<hr \/>\n<h3>1. Infrastructure Topology and Data Sovereignty<\/h3>\n<p>The provided services operate under a hybrid architecture model, divided into two isolated environments but under the exclusive and non-delegable control of the Data Controller:<\/p>\n<ol>\n<li><strong>Self-Hosted Environment (Homelab On-Premise):<\/strong> Physical server operated locally by the Data Controller. All processing and storage of sensitive data occurs within this physical perimeter, without delegation to public clouds.<\/li>\n<li><strong>Cloud Environment (IaaS - Oracle Cloud):<\/strong> Two Virtual Machines (VMs) hosted on Oracle Cloud infrastructure. In this environment, the provider (Oracle) acts solely and exclusively as an Infrastructure as a Service (IaaS) provider at the hardware and hypervisor level, lacking logical access to the encrypted file systems or the software containers running on them.<\/li>\n<\/ol>\n<h3>2. Data Minimization Principle and Categories of Data Collected<\/h3>\n<p>In compliance with Article 5.1(c) of the GDPR (Data Minimization Principle), the Data Controller explicitly declares that <strong>no personal data that could compromise the privacy, identity, or integrity of the users is collected, stored, or processed.<\/strong><\/p>\n<p>The deployed services are private in nature and oriented toward strictly functional use. The only data processed is intrinsically linked to the active use by the user of the following hosted services:<\/p>\n<ul>\n<li><strong>Identity and Access Management (Authentik):<\/strong> Authentication credentials are processed. Passwords are never stored in plain text; they are subjected to one-way cryptographic key derivation algorithms.<\/li>\n<li><strong>Credential Management (Vaultwarden):<\/strong> Governed under a <strong>cifrado de conocimiento cero (Zero-Knowledge Encryption)<\/strong>Governed under a Zero-Knowledge Encryption model. The server only stores the vaults in the form of end-to-end encrypted blobs. The Data Controller has neither the technical nor the cryptographic capability to access the passwords or data stored by the users.<\/li>\n<li><strong>Document, Financial, and Media Management (Paperless-ngx, Firefly III, Immich, Joplin, ConvertX):<\/strong> Input data (documents, photographs, notes, financial data) remains on private storage volumes within the Homelab, dedicated exclusively for the personal consultation of the user who owns them.<\/li>\n<li><strong>Location Telemetry (Find My Device - FOSS):<\/strong> Geographical coordinates are recorded ephemerally or persistently solely and exclusively at the user's request for personal tracking purposes, without being shared, profiled, or transferred to third parties for spatial or advertising analysis.<\/li>\n<li><strong>Network Infrastructure and Deployment (NetBird and Fluxer - Oracle VMs):<\/strong> The SD-WAN routing and administration services limit their collection to network health metrics, public IP addresses of the peers, and WireGuard cryptographic routing keys, which is data strictly necessary for establishing secure tunnels.<\/li>\n<\/ul>\n<h3>3. Absence of Tracking and Third-Party Analytics<\/h3>\n<p>This infrastructure is free of tracking scripts (trackers), tracking pixels, and commercial telemetry tools. No third-party cookies are used, nor are profiles generated for advertising, monetization, or behavioral analysis purposes.<\/p>\n<h3>4. Security Architecture, Network, and Cryptography<\/h3>\n<p>The Data Controller has designed the network infrastructure applying the \"Defense in Depth\" principle and implementing the following rigorous technical and organizational measures:<\/p>\n<ul>\n<li><strong>Isolated Containerization:<\/strong> 100% of the services are encapsulated and isolated using <strong>Docker technology<\/strong>, utilizing independent bridge networks to minimize the attack surface and cross-service access.<\/li>\n<li><strong>Cryptographic Tunnels and Internet Access:<\/strong> Internet exposure of the Homelab environment is obfuscated through a reverse tunnel. A Full (Strict) cryptographic policy is applied <strong>Full (Strict)<\/strong>, ensuring that the connection between the origin network and the security perimeter is continuously encrypted and validated using Cloudflare Origin Certificates.<\/li>\n<li><strong>Reverse Proxy and TLS Termination:<\/strong> Incoming traffic is managed and routed by <strong>Nginx Proxy Manager (NPM)<\/strong>, enforcing connections through TLS 1.2 \/ 1.3 protocols with robust cipher suites.<\/li>\n<li><strong>Cloud Traffic Management:<\/strong> For services hosted in Oracle Cloud (NetBird and Fluxer), Cloudflare operates exclusively under a network-level IP forwarding model, with no perimeter TLS termination that intercepts or decrypts packet payloads.<\/li>\n<\/ul>\n<h3>5. Data Disclosure and Transfer<\/h3>\n<p>All managed information remains within the network perimeter designed by the Data Controller. <strong>No data is disclosed, sold, or transferred to third parties.<\/strong>External network providers (such as Cloudflare) act solely as an encrypted transit conduit (Data in Transit) for DDoS mitigation or DNS resolution, with no capacity for payload inspection in Full Strict and Zero-Knowledge connections.<\/p>\n<h3>6. Exercise of Data Subject Rights (GDPR Rights)<\/h3>\n<p>Despite the privacy-oriented architecture, users fully retain their rights protected under the GDPR. Any user with access to the services of this infrastructure has the inalienable right to request:<\/p>\n<ul>\n<li><strong>Access<\/strong> to the account data or technical infrastructure linked to their user.<\/li>\n<li><strong>Rectification<\/strong> of inaccurate data.<\/li>\n<li><strong>Erasure (Right to be Forgotten)<\/strong> permanently and cryptographically secure of all their data in databases and storage volumes.<\/li>\n<li><strong>Restriction or Objection<\/strong> to the processing of their technical data.<\/li>\n<\/ul>\n<p>To exercise any of these rights or for technical inquiries regarding this policy, the data subject must send their request to the System Administrator through the following contact address:<\/p>\n<p><strong>Data Controller:<\/strong> Juan G\u00f3mez L\u00f3pez (ea1fsc)<br \/>\n<strong>Technical and Privacy Contact:<\/strong> <a href=\"mailto:contact@ea1fsc.es\">contact@ea1fsc.es<\/a><\/p>\n<p>Requests will be handled diligently and resolved within a maximum period of 30 business days, ensuring the complete deletion of records when requested.<\/p>","protected":false},"excerpt":{"rendered":"<p>\u00daltima actualizaci\u00f3n: 25 de septiembre de 2026 El presente documento establece las pol\u00edticas de privacidad y los estrictos t\u00e9rminos de tratamiento de datos aplicables a los servicios de infraestructura inform\u00e1tica operados y administrados de forma independiente por Juan G\u00f3mez L\u00f3pez (alias t\u00e9cnico \u00abea1fsc\u00bb), en adelante, \u00abel Responsable\u00bb. El dise\u00f1o, despliegue y mantenimiento de esta infraestructura [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-774","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.ea1fsc.es\/en\/wp-json\/wp\/v2\/pages\/774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ea1fsc.es\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.ea1fsc.es\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.ea1fsc.es\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ea1fsc.es\/en\/wp-json\/wp\/v2\/comments?post=774"}],"version-history":[{"count":1,"href":"https:\/\/www.ea1fsc.es\/en\/wp-json\/wp\/v2\/pages\/774\/revisions"}],"predecessor-version":[{"id":775,"href":"https:\/\/www.ea1fsc.es\/en\/wp-json\/wp\/v2\/pages\/774\/revisions\/775"}],"wp:attachment":[{"href":"https:\/\/www.ea1fsc.es\/en\/wp-json\/wp\/v2\/media?parent=774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}