pp.rst (11003B)
1 Privacy Policy 2 ============== 3 4 Last Updated: 12.07.2022 5 6 This Privacy Policy describes the policies and procedures of GNUnet e.V. 7 (“we,” “our,” or “us”) pertaining to the collection, use, and 8 disclosure of your information on our sites and related mobile 9 applications and products we offer (the “Services”). This Privacy 10 Statement applies to your personal data when you use our Services, and 11 does not apply to online websites or services that we do not own or 12 control. 13 14 15 Overview 16 -------- 17 18 Your privacy is important to us. We follow a few fundamental 19 principles: We don’t ask you for personally identifiable information 20 (defined below). That being said, your contact information, such as 21 your phone number, social media handle, or email address (depending on 22 how you contact us), may be collected when you communicate with us, 23 for example to report a bug or other error related to TalDir. We 24 don’t share your information with third parties except when strictly 25 required to deliver you our Services and products, or to comply with 26 the law. If you have any questions or concerns about this policy, 27 please reach out to us at taldir@gnunet.org. 28 29 30 How you accept this policy 31 -------------------------- 32 33 By using our Services or visiting our sites, you agree to the use, disclosure, 34 and procedures outlined in this Privacy Policy. 35 36 37 What personal information do we collect from our users? 38 ------------------------------------------------------- 39 40 The information we collect from you falls into two categories: (i) personally 41 identifiable information (i.e., data that could potentially identify you as an 42 individual) (“Personal Information”), and (ii) non-personally identifiable 43 information (i.e., information that cannot be used to identify who you are) 44 (“Non-Personal Information”). This Privacy Policy covers both categories and 45 will tell you how we might collect and use each type. 46 47 We do our best to not collect any Personal Information from TalDir 48 users. The detailed Personal Information TalDir asks from you 49 during the regular registration process at the beginning is 50 processed to verify that your are actually the holder of a certain account. 51 The information is never stored in plain text and only used to create a 52 cryptographic account identifier which does not allow us to recover any of your 53 details. 54 55 That being said, when using our Services to register a mapping from your 56 identity to a wallet, we may inherently receive the following information 57 (depending on your choice of authentication method): 58 59 * Your phone number when using SMS authentication. We rely on third party providers (such as your mobile network operator) to deliver the SMS to you. These third parties will see the SMS message sent to you and could thus learn that you are using TalDir. SMS is inherently insecure, and you should expect many governments and private parties to be able to observe these messages. However, we do not store your phone number for SMS communication on our systems, except maybe in short-term logs to diagnose errors. 60 61 * Your e-mail address when using E-mail authentication. We rely on the Internet and your E-mail provider to deliver the E-mail to you. Internet service providers will see the E-mail message sent to you and could thus learn that you are using TalDir. E-mail is inherently insecure, and you should expect many governments and private parties to be able to observe these messages. However, we do not store your E-mail address on our systems, except maybe in short-term logs to diagnose errors. 62 63 * Your twitter handle when using Twitter authentication. We rely on Twitter to deliver a message to you. Twitter will see the message sent to you and could thus learn that you are using TalDir. Twitter is inherently insecure, and you should expect many governments and private parties to be able to observe these messages. However, we do not store your twitter handle on our systems, except maybe in short-term logs to diagnose errors. 64 65 * When you contact us. We may collect certain information if you choose to contact us, for example to report a bug or other error with the Taler Wallet. This may include contact information such as your name, email address or phone number depending on the method you choose to contact us. We strictly only use the information provided by you in these instances to answer your request or to deliver the services requested by you. 66 67 68 How we collect and process personal data 69 ---------------------------------------- 70 71 We may process your personal data for the following reasons: 72 73 * to authenticate you during registration 74 * to support you using Taldirs when you contact us 75 76 77 How we share and use the information we gather 78 ---------------------------------------------- 79 80 We may share your authentication data with other providers that assist 81 us in performing the authentication. We will try to use providers that 82 to the best of our knowledge respect your privacy and have good 83 privacy practices. We reserve the right to change authentication 84 providers at any time to ensure availability of our services. 85 86 We primarily use the limited information we receive directly from you to 87 enhance TalDir. Some ways we may use your Personal Information are 88 to: Contact you when necessary to respond to your comments, answer your 89 questions, or obtain additional information on issues related to bugs or 90 errors with the TalDir application that you reported. 91 92 93 Agents or third party partners 94 ------------------------------ 95 96 We may provide your Personal Information to our employees, contractors, 97 agents, service providers, and designees (“Agents”) to enable them to perform 98 certain services for us exclusively, including: improvement and maintenance of 99 our software and Services. 100 101 102 Protection of us and others 103 --------------------------- 104 105 We reserve the right to access, read, preserve, and disclose any information 106 that we reasonably believe is necessary to comply with the law or a court 107 order. 108 109 110 What personal information can I access or change? 111 ------------------------------------------------- 112 113 You can request access to the information we have collected from 114 you. You can do this by contacting us at taldir@gnunet.org. We will 115 make sure to provide you with a copy of the data we process about 116 you. To comply with your request, we may ask you to verify your 117 identity. We will fulfill your request by sending your copy 118 electronically. For any subsequent access request, we may charge you 119 with an administrative fee. If you believe that the information we 120 have collected is incorrect, you are welcome to contact us so we can 121 update it and keep your data accurate. Any data that is no longer 122 needed for purposes specified in the “How We Use the Information We 123 Gather” section will be deleted after ninety (90) days. 124 125 126 What are your data protection rights? 127 ------------------------------------- 128 129 GNUnet e.V. would like to make sure you are fully aware of all of your 130 data protection rights. Every user is entitled to the following: 131 132 **The right to access**: You have the right to request GNUnet e.V. for 133 copies of your personal data. We may charge you a small fee for this 134 service. 135 136 **The right to rectification**: You have the right to request that 137 GNUnet e.V. correct any information you believe is inaccurate. You also 138 have the right to request GNUnet e.V. to complete information you 139 believe is incomplete. The right to erasure - You have the right to 140 request that GNUnet e.V. erase your personal data, under certain 141 conditions. 142 143 **The right to restrict processing**: You have the right to request 144 that GNUnet e.V. restrict the processing of your personal data, under 145 certain conditions. 146 147 **The right to object to processing**: You have the right to object to 148 GNUnet e.V.'s processing of your personal data, under certain 149 conditions. 150 151 **The right to data portability**: You have the right to request that 152 GNUnet e.V. transfer the data that we have collected to another 153 organization, or directly to you, under certain conditions. 154 155 If you make a request, we have one month to respond to you. If you 156 would like to exercise any of these rights, please contact us at our 157 email: taldir@gnunet.org 158 159 You can always contact your local data protection authority to enforce 160 your rights. 161 162 163 Data retention 164 -------------- 165 166 Information entered into our bug tracker will be retained indefinitely 167 and is typically made public. We will only use it to triage the 168 problem. Beyond that, we do not retain personally identifiable 169 information about our users for longer than one week. 170 171 172 Data security 173 ------------- 174 175 We are committed to making sure your information is protected. We employ 176 several physical and electronic safeguards to keep your information safe, 177 including encrypted user passwords, two factor verification and authentication 178 on passwords where possible, and securing connections with industry standard 179 transport layer security. You are also welcome to contact us using GnuPG 180 encrypted e-mail. Even with all these precautions, we cannot fully guarantee 181 against the access, disclosure, alteration, or deletion of data through 182 events, including but not limited to hardware or software failure or 183 unauthorized use. Any information that you provide to us is done so entirely 184 at your own risk. 185 186 187 Changes and updates to privacy policy 188 ------------------------------------- 189 190 We reserve the right to update and revise this privacy policy at any time. We 191 occasionally review this Privacy Policy to make sure it complies with 192 applicable laws and conforms to changes in our business. We may need to update 193 this Privacy Policy, and we reserve the right to do so at any time. If we do 194 revise this Privacy Policy, we will update the “Effective Date” at the top 195 of this page so that you can tell if it has changed since your last visit. As 196 we generally do not collect contact information and also do not track your 197 visits, we will not be able to notify you directly. However, TalDir clients 198 may inform you about a change in the privacy policy once they detect that the 199 policy has changed. Please review this Privacy Policy regularly to ensure that 200 you are aware of its terms. Any use of our Services after an amendment to our 201 Privacy Policy constitutes your acceptance to the revised or amended 202 agreement. 203 204 205 International users and visitors 206 -------------------------------- 207 208 Our Services are (currently) hosted in Germany. If you are a user 209 accessing the Services from Switzerland, Asia, US, or any other 210 region with laws or regulations governing personal data collection, 211 use, and disclosure that differ from the laws of Germany, please be 212 advised that through your continued use of the Services, which is 213 governed by the law of the country hosting the service, you are 214 transferring your Personal Information to Germany and you consent to 215 that transfer. 216 217 218 Questions 219 --------- 220 221 Please contact us at taldir@gnunet.org if you have questions about our 222 privacy practices that are not addressed in this Privacy Statement.