Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GDPR compliance ticket #416

Closed
2 tasks done
Terkwood opened this issue Oct 23, 2020 · 0 comments · Fixed by #453
Closed
2 tasks done

GDPR compliance ticket #416

Terkwood opened this issue Oct 23, 2020 · 0 comments · Fixed by #453
Labels
enhancement New feature or request

Comments

@Terkwood
Copy link
Owner

Terkwood commented Oct 23, 2020

Goals

  • Link to our privacy policy on the front page.
  • Document our policy in a github-hosted markdown file.

Resource: GDPR compliance for US companies

Read more here.

Detail: Client ID

We store a Client ID (large, random number) in the user's browser, which the user can delete by clearing all their browser data (local storage). The ID contains no personally identifiable information. We should make sure the user understands this.

Detail: IP logging by Caddy

We have a very minimal caddy configuration which acts as a reverse proxy for gateway & botlink. It sometimes logs IP addresses. This data is ephemeral.

According to the following article, we don't explicitly need to ask for consent for this. Let's just point out that we log and eventually destroy IP addresses as a standard security practice.

@Terkwood Terkwood added the enhancement New feature or request label Oct 23, 2020
This was referenced Nov 9, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant