Consumer Rights Wiki:Privacy policy: Difference between revisions
upd |
No edit summary |
||
| (2 intermediate revisions by the same user not shown) | |||
| Line 40: | Line 40: | ||
* '''Username''' - Stored indefinitely, or until account deletion request | * '''Username''' - Stored indefinitely, or until account deletion request | ||
* '''Email address''' - Stored indefinitely, or until account deletion request | * '''Email address''' - Stored indefinitely, or until account deletion request | ||
* '''Hashed password''' - Stored indefinitely, or until account deletion request | * '''Hashed and salted password''' - Stored indefinitely, or until account deletion request | ||
===3.2 Contribution Data=== | ===3.2 Contribution Data=== | ||
| Line 78: | Line 78: | ||
! Justification | ! Justification | ||
|- | |- | ||
| Account data (username, email, password) | | Account data (username, email, hashed and salted password) | ||
| Indefinitely until deletion request | | Indefinitely until deletion request | ||
| Necessary to perform contract | | Necessary to perform contract | ||
| Line 132: | Line 132: | ||
==5. International Data Transfers== | ==5. International Data Transfers== | ||
Our servers are hosted by Hetzner | Our servers are hosted by Hetzner in the United States. This constitutes an international data transfer from the EU/EEA. We ensure appropriate safeguards through: | ||
* '''EU-US Data Privacy Framework''': Our hosting providers participate in the EU-US Data Privacy Framework, ensuring adequate protection for your personal data | * '''EU-US Data Privacy Framework''': Our hosting providers participate in the EU-US Data Privacy Framework, ensuring adequate protection for your personal data | ||
| Line 178: | Line 178: | ||
|- | |- | ||
| '''Hetzner''' | | '''Hetzner''' | ||
| Server infrastructure, web application data | | Server infrastructure, web application data, user data, backups | ||
| US/EU | | US/EU | ||
| Primary hosting infrastructure | | Primary hosting infrastructure | ||
|- | |- | ||
| '''CloudFlare''' | | '''CloudFlare''' | ||
| Line 220: | Line 215: | ||
Our website infrastructure and web application are hosted on servers provided by Hetzner. | Our website infrastructure and web application are hosted on servers provided by Hetzner. | ||
Processed data categories: Web application data, server infrastructure data, technical connection data (IP address, date, time, requested page, browser information), server configuration and usage metrics, network traffic data | Processed data categories: Web application data, server infrastructure data, technical connection data (IP address, date, time, requested page, browser information), server configuration and usage metrics, network traffic data. | ||
Purpose of processing: provision of hosting infrastructure for the web application, ensuring system availability and performance. | Purpose of processing: provision of hosting infrastructure for the web application, ensuring system availability and performance. | ||
| Line 234: | Line 229: | ||
Please read Hetzner's [https://www.hetzner.com/legal/privacy-policy full privacy policy] for more information. | Please read Hetzner's [https://www.hetzner.com/legal/privacy-policy full privacy policy] for more information. | ||
====7.1.3 | ====7.1.3 Privacy statement for the service CloudFlare==== | ||
Our website uses CloudFlare services for content delivery, security, and performance optimization. CloudFlare processes analytics and security-related data, but does not have access to user account data or personal information stored in our databases. | Our website uses CloudFlare services for content delivery, security, and performance optimization. CloudFlare processes analytics and security-related data, but does not have access to user account data or personal information stored in our databases. | ||
| Line 276: | Line 253: | ||
We implement appropriate technical and organizational measures to protect personal data, including: | We implement appropriate technical and organizational measures to protect personal data, including: | ||
* | * Hashing and salting of passwords | ||
* Regular security updates | * Regular security updates | ||
* Access controls and authentication | * Access controls and authentication | ||