Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GRPD & privacy policy compliant to CA #45

Open
benoitc opened this issue Feb 9, 2021 · 5 comments
Open

GRPD & privacy policy compliant to CA #45

benoitc opened this issue Feb 9, 2021 · 5 comments

Comments

@benoitc
Copy link
Collaborator

benoitc commented Feb 9, 2021

we need to clarify for our members what is processed/keept from our members. This is a legal requirements.

@benoitc
Copy link
Collaborator Author

benoitc commented Mar 7, 2021

this a must have actually. maybe we should hire a professional for it ? cc @ahw59

@benoitc
Copy link
Collaborator Author

benoitc commented Mar 7, 2021

we need to clarify for our members what is processed/keept from our members. This is a legal requirements.

I am starting here a list of items we should have to build a policy compliant with the GRPD or CA law.

  • what third-party services are we using
  • what data do we have
  • what personal data do we keep. How long?
  • what data do we share with third party services
  • who have access to the data provided by our members, sponsors and others. in which way
  • how do we ensure the right to be forgotten

Anything else?

@starbelly
Copy link
Member

If we want some kind of certification of compliance, then yes we need to hire a professional.

@benoitc
Copy link
Collaborator Author

benoitc commented Mar 15, 2021

@starbelly what third party tools/services are used for the website? What data are shared with them?

So far I see:

  • wildapricot
  • vultr
  • dns ?
  • fastmail

what is missing?

Also what data do we collect from members? Do we have a way to easily remove or extract all the data for a member if requested?

@starbelly
Copy link
Member

There is also plausible for analytics and honeybadger for error reporting. I believe that covers it.

Also what data do we collect from members? Do we have a way to easily remove or extract all the data for a member if requested?

Data to plausible is completely anonymized, anything that might end up in honeybadger is retained for 15 days.

In the website itself we do not store anything more than an email address and name, the rest are system settings if you will.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants