Commit 1d29537e authored by jaywink's avatar jaywink

Various updates to Privacy Policy

* Add mention of DPO
* Change email to privacy@feneas.org (not yet functional)
* Add some text about Federation, Federated and Federated Data.
* Add some text about Content

Set to come effective 15th October to give time to send update warning.
parent d73bf33e
Pipeline #2356 passed with stage
in 57 seconds
# Privacy Policy
Effective date: July 07, 2018
Effective date: October 15, 2019
Federated Networks Association ("us", "we", or "our") operates the feneas.org
website including all services associated with the Domain name (the "Service").
We also have a membership program (the "Membership" or "Member"). Our policies
towards your data and your rights are also covered by this privacy policy. When we talk
about "Service" or "Membership" in this page, those terms should be thought as the same.
This page informs you of our policies regarding the collection, use,
and disclosure of personal data when you use our Service and
the choices you have associated with that data.
and disclosure of personal data when you use our Service or join us as
a Member, and the choices you have associated with that data.
We use your data to provide and improve the Service. By using the Service,
you agree to the collection and use of information in accordance with this policy.
Unless otherwise defined in this Privacy Policy, terms used in this
Privacy Policy have the same meanings as in our Terms and Conditions, accessible from https://www.feneas.org
We use your data to provide and improve the Service or your Membership experience.
By using the Service or being a Member, you agree to the collection and use of
information in accordance with this policy. Unless otherwise defined in this
Privacy Policy, terms used in this Privacy Policy have the same meanings as in
our Terms and Conditions, accessible from https://www.feneas.org
## GDPR (General Data Protection Regulation)
### Legal Basis for Processing
We process your data under [Legitimate Interest](https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/legitimate-interests/when-can-we-rely-on-legitimate-interests/).
This means that we process your data only as necessary to deliver the Service,
and in a manner that you understand and expect.
This means that we process your data only as necessary to deliver the Service
or Membership, and in a manner that you understand and expect.
In situations where the interests of the individual appear to be in conflict
with the broader societal interests, we will seek to reconcile
......@@ -29,12 +33,14 @@ those differences guided by our policy.
### Right to Erasure
You can request that we delete your copy of message and files by instructing us
to deactivate your account. You can do this by contacting us via email to [hq@feneas.org](mailto:hq@feneas.org).
to deactivate your accounts on our Service or Membership. You can do this by
contacting us via email to [privacy@feneas.org](mailto:privacy@feneas.org).
### Data Portability
Under GDPR you have a right to request a copy of your data in a commonly-accepted format.
If you would like a copy of your data, please send a request via email to [hq@feneas.org](mailto:hq@feneas.org).
If you would like a copy of your data, please send a request via email to
[privacy@feneas.org](mailto:privacy@feneas.org).
### Your Rights as Data Subject
......@@ -52,27 +58,43 @@ your rights under GDPR are:
The right to object
Rights in relation to automated decision making and profiling.
For more details about these rights, please see [the guidance provided by the ICO](https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/).
For more details about these rights, please see
[Wikipedia](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#III_Rights_of_the_data_subject).
If you have any questions or are unsure how to exercise your rights,
please contact us via email ([hq@feneas.org](mailto:hq@feneas.org)).
please contact us via email ([privacy@feneas.org](mailto:privacy@feneas.org)).
## Information Collection And Use
We collect several different types of information for various purposes to provide and improve our Service to you.
We collect several different types of information for various purposes to provide and improve
our Service or Membership to you.
### Types of Data Collected
#### Personal Data
While using our Service, we may ask you to provide us with certain personally
While using our Service or being a Member, we may ask you to provide us with certain personally
identifiable information that can be used to contact or identify you ("Personal Data").
Personally identifiable information may include, but is not limited to:
* Username
* Email address
* First name and last name
* Phone number
* Address, State, Province, ZIP/Postal code, City
* Full name
* City and Country
* Cookies and Usage Data
* Profile picture
#### Created Content
Any content you create ("Content") while using our Service or being a Member will be stored
within our Service and made available to other users, services and third-parties, depending
on the visibility of the Content you have set. This may include, but is not limited to:
* Social media posts
* Blog entries
* Binary files
* Photos and drawings
* Audio
* Code files
#### Usage Data
......@@ -104,6 +126,9 @@ Examples of Cookies we use:
Federated Networks Association uses the collected data for various purposes:
* To maintain a list of Members (as per requirement by law)
* To notify you of important details related to your Membership
* To invite you to Annual General Meetings of the association
* To provide and maintain the Service
* To notify you about changes to our Service
* To allow you to participate in interactive features of our Service when you choose to do so
......@@ -114,13 +139,17 @@ Federated Networks Association uses the collected data for various purposes:
#### Transfer Of Data
Your information, including Personal Data, may be transferred to - and maintained on - computers located outside of your state,
province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
Your information, including Personal Data, may be transferred to - and maintained on -
computers located outside of your state,
province, country or other governmental jurisdiction where the data protection laws may
differ than those from your jurisdiction.
If you are located outside Finland and choose to provide information to us,
please note that we transfer the data, including Personal Data, to Finland and process it there.
If you choose to provide information to us, please note that we transfer the data to
any location that we need to process it in. We also transfer your data on a need be basis
as "Federated Data".
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
Your consent to this Privacy Policy followed by your submission of such information
represents your agreement to that transfer.
Federated Networks Association will take all steps reasonably necessary to ensure
that your data is treated securely and in accordance with this Privacy Policy
......@@ -128,11 +157,40 @@ and no transfer of your Personal Data will take place to an organization or
a country unless there are adequate controls in place including the security
of your data and other personal information.
#### Federated data
Our Service is a part of the larger federated web ("Federation" or "Federated").
As such, we will constantly transfer your Content to other services
outside our control. This happens automatically and transparently.
By using our Service, you accept that we do not control the data
we have transferred to services outside our control after it has been transferred.
You agree that your Content stored on the third-party services, even if created on
our Service, is covered by the privacy policy of the third-party site.
We may also transfer specific Personal Data to third-party services automatically,
if it is required to implement the Service. This may include, but is not limited to:
* Username
* Email address
* Full name
* Profile picture
##### Removal of Federated Data
When you request the deletion of your Personal Data or Content that has been transferred
to a third-party service, we will make automatic Federation requests for that data to be deleted
from the third-party service.
The third-party site is responsible for processing and respecting these requests. By giving
us your Personal Data or Content, you agree that we do not control the third-party sites
and cannot force them to remove any Federated Data that we have transferred to them.
### Disclosure Of Data
#### Legal Requirements
Federated Networks Association may disclose your Personal Data in the good faith belief that such action is necessary to:
Federated Networks Association may disclose your Personal Data in the good faith
belief that such action is necessary to:
* To comply with a legal obligation
* To protect and defend the rights or property of Federated Networks Association
......@@ -188,6 +246,7 @@ Changes to this Privacy Policy are effective when they are posted on this page.
#### Contact Us
If you have any questions about this Privacy Policy, please contact us:
If you have any questions about this Privacy Policy, please contact us via email.
The named Data Protection Officer is Jason Robinson, email: privacy@feneas.org
By email: hq@feneas.org
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment