-
Notifications
You must be signed in to change notification settings - Fork 16
/
privacy.html
129 lines (102 loc) · 13.6 KB
/
privacy.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
---
title: Privacy Policy
layout: project
---
<article>
<div class="inner">
<div class="project-main">
<em>Last updated: January 31st, 2019</em>
<br>
<h2>Introduction</h2>
<p>We take the protection of our users (“User/you/your”) personal data very seriously and strictly comply with applicable data protection laws and regulations.
<br>In this privacy policy for our website on <a href="https://foundation.travis-ci.org">foundation.travis-ci.org</a> (“Website”) we provide you with an overview of what data we process when you visit our website and how we ensure the protection of the data.</p>
<h2>Controller and contact details</h2>
<p>The controller is <strong>Travis Foundation gUG (haftungsbeschränkt)</strong>, Rigaer Straße 8, 10247 Berlin/Germany, registered at the local court (<em>Amtsgericht</em>) of Charlottenburg under HRB 158047 B), represented by the managing director Anika Lindtner (“we/us/our”).</p>
<p>If you have any questions regarding the processing of your data you may contact us any time by email (<a href="mailto:[email protected]">[email protected]</a>) or as set forth <a href="https://foundation.travis-ci.org/imprint">here</a>.</p>
<h2>Personal Data and Data Processing</h2>
<p>Personal data are any information relating to an identified or identifiable natural person.</p>
<p>Applicable legal provisions are, in particular, those of the regulation (EU) 2016/679 of the European Parliament and Council of 27 April 2016, repealing the directive 95/46/EC, on the protection of individuals with regard to the processing of personal data, on the free movement of such data (“General Data Protection Regulation”, GDPR) as well as in the Federal Data Protection Act (<em>Bundesdatenschutzgesetz, BDSG</em>) and the German Telemedia Act (<em>Telemediengesetz, TMG</em>).</p>
<p>We, as well as our obliged external service partners, process your data for the purpose of providing our services on the Website. You provide data if this is necessary for the aforementioned purposes. In the event you refrain from providing such data you may face legal disadvantages, for example, no possibility of displaying the website in a functioning way.</p>
<a name="visiting-the-website"></a><h2>Visiting the Website</h2>
<p>If you browse our Website the provider of the website collects and stores information automatically in so-called “server log files” that your browser transfers to us. These are:</p>
<ul>
<li>name of the retrieved website/file (URL),</li>
<li>date and time of retrieval,</li>
<li>transferred data volume,</li>
<li>notification of successful retrieval (HTTP status),</li>
<li>browser type and version,</li>
<li>the User's operating system,</li>
<li>referrer URL (previously visited page),</li>
<li>the browser’s user agent, IP address and the requesting provider.</li>
</ul>
<p>We use these data only for statistical analysis for the purpose of operation, security and optimization of our Website. If such data are considered personal data such processing is based on Art. 6 (1) c. or f. GDPR or TMG and we wish to achieve the legitimate interests of stabilizing and improving our Website, quality insurance and fraud prevention.</p>
<h2>Contacting us</h2>
<p>When contacting us via email, your details are stored for the purpose of processing the enquiry and, if applicable, follow-up questions based on your consent (legal basis of Art. 6 (1) a. GDPR) or for pursuing your request (legal basis of Art. 6 (1) b. GDPR).</p>
<h2>Data processed when making donations</h2>
<p>You may make donations for financial support of our projects and initiatives via the Website. For making a donation you should provide your name, email address, the amount to be donated and applicable payment data. If you wish to receive a donation receipt you should also provide us with your postal address for invoicing. Such data are processed by us (or the external payment provider Stripe) for proceeding your donation through the Website and (as applicable) for providing you with a donation receipt.</p>
<p>We do not receive or process any payment data needed for the purpose of making such donations but such payment data are processed by the external payment provider Stripe (by Stripe, Inc., 185 Berry Street, Suite 550, San Francisco, CA 94107, USA). Stripe may process data outside the EU but guarantees the compliance with data protection standards applicable in the EU (<a href="#table-third-parties">see table below</a>).</p>
<p>When we process data for the purpose of making donations this is based on your consent (legal basis of Art. 6 (1) a. GDPR) and/or for pursuing your donation (legal basis of Art. 6 (1) b. GDPR).</p>
<h2>Analysis of Data</h2>
<p>We also process aggregated, pseudonymized or anonymous user data regarding the usage of our services. The user data we collect is used to improve our websites and program and the quality of our service. We only collect personal data that is required to provide our services, and we only store it insofar that it is necessary to deliver these services. If such data are considered personal data the legal basis for such data processing is Art. 6 (1) f. GDPR based on our legitimate interests of marketing and quality assurance or TMG.</p>
<h2>Third parties processing your data and data processing outside the EU</h2>
<p>We use third-party providers and hosting partners to provide the necessary hardware, software, networking, storage, outsourced IT services and related technology required to run our Website. We will never share your personal data with a third party without a legal basis or your prior authorization.</p>
<p>For further information you may contact us any time via email to <a href="mailto:[email protected]">[email protected]</a>q.</p>
<p>We transfer data with third-parties necessary to our ability to provide our services, all of whom are GDPR-compliant and provide the necessary safeguards required if they are outside of the European Union (EU). Such providers are:</p>
<a name="table-third-parties"></a>
<table>
<thead>
<tr>
<th>Third-party provider</th>
<th>Data processing purpose</th>
<th>Data Processing outside the EU / Compliance with EU Data Protection Standard</th>
<th>Further Information</th>
</tr>
</thead>
<tbody>
<tr>
<td>GitHub</td>
<td>We use the service by Github Inc., 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA for the purpose of hosting your data on the Website.</td>
<td>Github, Inc. is certified according to the EU-US agreement “Privacy Shield”. The “Privacy Shield” is an agreement between the European Union (EU) and the USA to ensure compliance with European data protection standards in the USA.</td>
<td>For further information please refer to <a href="https://help.github.com/articles/github-privacy-statement/">Github’s privacy statement</a> or use the contact form under <a href="https://github.com/contact/privacy">https://github.com/contact/privacy</a></td>
</tr>
<tr>
<td>Stripe</td>
<td>We use the services of Stripe, Inc., 185 Berry Street, Suite 550, San Francisco, CA 94107, USA for processing data regarding payments. Regarding any processes of payments we do not receive, collect and/or store any payment data. Stripe will use such data for the purpose of managing the payments relating to our services.</td>
<td>Stripe, Inc. is certified according to the EU-US agreement “Privacy Shield”. The “Privacy Shield” is an agreement between the European Union (EU) and the USA to ensure compliance with European data protection standards in the USA.</td>
<td>For further information please refer to <a href="https://stripe.com/de/privacy">Stripe's privacy policy</a>.</td>
</tr>
<tr>
<td>Google Cloud</td>
<td>We use the cloud service by Google LLC, Mountain View, CA, USA for the purpose of hosting, managing and storing your data.</td>
<td>Google LLC is certified according to the EU-US agreement “Privacy Shield”. The “Privacy Shield” is an agreement between the European Union (EU) and the USA to ensure compliance with European data protection standards in the USA.</td>
<td>For further information please refer to <a href="https://policies.google.com/privacy?hl=de">Google's privacy policy</a>.</td>
</tr>
</tbody>
</table>
<h2>Links to other Websites</h2>
<p>Our Website contains links to other websites. We do not exercise any controlling measures over third-party websites except as required by law. These other websites may place their own cookies or other files on your device and collect and process personal data. In general and without a respective notification, we are not responsible for the content, privacy and security practices, and policies of third-party websites or services to which links or access are provided through our Website. We encourage you to read the privacy policies or statements of the other websites you visit.</p>
<h2>Your Rights</h2>
<p>As a data subject you have the right:</p>
<ul>
<li>to withdraw your consent to us at any time. As a result, we are no longer allowed to continue the processing of data based on this consent in the future;</li>
<li>to object to the processing of your personal data, if your personal data are processed on the basis of legitimate interests pursuant to Art. 6 (1) f. GDPR insofar as there are reasons for this arising from your particular situation;</li>
<li>to obtain from us access to your personal data. In particular, you may request access to the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed; where possible, the envisaged period for which the personal data will be stored; the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; the right to lodge a complaint with a supervisory authority; where the personal data are not collected from the data subject, any available information as to their source and the existence of automated decision-making, including profiling and meaningful information about this event;</li>
<li>to obtain from us without undue delay the rectification of inaccurate personal data concerning you;</li>
<li>to obtain the erasure of your personal data stored with us, unless the processing is necessary to exercise the right to free expression of opinion and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;</li>
<li>to demand the restriction of the processing of your personal data, if the accuracy of the data is disputed by you, the processing is unlawful, but you refuse its deletion and we no longer need the data, but you need it to assert, exercise or defend legal claims or you have filed an objection against the processing; and</li>
<li>to receive your personal data, which you have provided to us, in a structured, current and machine-readable format or to request the transmission to another controller.</li>
</ul>
<p>If you wish to make use of your rights mentioned above please send an email to [email protected].
<br>You have the right to lodge a complaint vis-á-vis a supervisory authority of your choice (for example for Berlin/Germany: <a href="https://www.datenschutz-berlin.de/kontakt.html">https://www.datenschutz-berlin.de/kontakt.html</a>).
<br>An overview of the European National Data Protection Authorities may be found <a href="http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080">here</a>.</p>
<h2>Duration of the storage of personal data</h2>
<p>We only store your personal data for as long as your account is active or otherwise for a limited period of time as long as it is necessary for the execution of the respective purpose. We store the data set forth under <a href="#visiting-the-website">“Visiting the Website”</a> for 14 days.</p>
<p>Criteria for the storage period include whether the data are still up-to-date, whether a contractual relationship with us still exists, whether an inquiry has already been processed, whether a process has been completed or not, and whether legal retention periods for the personal data concerned are relevant or not. Such legal retention periods are set forth in the German Commercial Code (<em>Handelsgesetzbuch, HGB</em>) and German Fiscal Code (<em>Abgabenordnung, AO</em>) and the legal basis for storing such data is Art. 6 (1) c. GDPR.</p>
<h2>Security</h2>
<p>All data and information transmitted via our Websites is secured by SSL protocol.</p>
<p>Your data are only processed on servers in the European Union (EU), unless we provide other information in this Privacy Policy or otherwise.</p>
<h2>Changes and Contact</h2>
<p>We are allowed to amend this Privacy Policy as provided for in and according to applicable law. If you have any questions regarding the processing of your data you may contact us any time via email to <a href="mailto:[email protected]">[email protected]</a>.</p>
</div>
</div>
</article>