Privacy Policy (please read)

Privacy Policy

  1. An overview of data protection

General

The following gives a simple overview of what happens to your personal information when you visit our website. Personal information is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy found below.

Data collection on our website

Who is responsible for the data collection on this website?

The data collected on this website are processed by the website operator. The operator’s contact details can be found in the website’s required legal notice.

How do we collect your data?

Some data are collected when you provide it to us. This could, for example, be data you enter on a contact form.

Other data are collected automatically by our IT systems when you visit the website. These data are primarily technical data such as the browser and operating system you are using or when you accessed the page. These data are collected automatically as soon as you enter our website.

What do we use your data for?

Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze how visitors use the site.

What rights do you have regarding your data?

You always have the right to request information about your stored data, its origin, its recipients, and the purpose of its collection at no charge. You also have the right to request that it be corrected, blocked, or deleted. You can contact us at any time using the address given in the legal notice if you have further questions about the issue of privacy and data protection. You may also, of course, file a complaint with the competent regulatory authorities.

Analytics and third-party tools

When visiting our website, statistical analyses may be made of your surfing behavior. This happens primarily using cookies and analytics. The analysis of your surfing behavior is usually anonymous, i.e. we will not be able to identify you from this data. You can object to this analysis or prevent it by not using certain tools. Detailed information can be found in the following privacy policy.

You can object to this analysis. We will inform you below about how to exercise your options in this regard.

  1. General information and mandatory information

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data as confidential and in accordance with the statutory data protection regulations and this privacy policy.

If you use this website, various pieces of personal data will be collected. Personal information is any data with which you could be personally identified. This privacy policy explains what information we collect and what we use it for. It also explains how and for what purpose this happens.

Please note that data transmitted via the internet (e.g. via email communication) may be subject to security breaches. Complete protection of your data from third-party access is not possible.

Notice concerning the party responsible for this website

The party responsible for processing data on this website is:

Andreas Lakeberg
E-Surfer
Vicki-Baum-Strasse 80
10317 Berlin

Website: https://e-surfer.com/en/

Telephone: +49 30 20609981
Email: info@e-surfer.com

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (names, email addresses, etc.).

Revocation of your consent to the processing of your data

Many data processing operations are only possible with your express consent. You may revoke your consent at any time with future effect. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

Right to file complaints with regulatory authorities

If there has been a breach of data protection legislation, the person affected may file a complaint with the competent regulatory authorities. The competent regulatory authority for matters related to data protection legislation is the data protection officer of the German state in which our company is headquartered. A list of data protection officers and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Right to data portability

You have the right to have data which we process based on your consent or in fulfillment of a contract automatically delivered to yourself or to a third party in a standard, machine-readable format. If you require the direct transfer of data to another responsible party, this will only be done to the extent technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and for the protection of the transmission of confidential content, such as the inquiries you send to us as the site operator. You can recognize an encrypted connection in your browser’s address line when it changes from “http://” to “https://” and the lock icon is displayed in your browser’s address bar.

If SSL or TLS encryption is activated, the data you transfer to us cannot be read by third parties.

Encrypted payments on this website

If you enter into a contract which requires you to send us your payment information (e.g. account number for direct debits), we will require this data to process your payment.

Payment transactions using common means of payment (Visa/MasterCard, direct debit) are only made via encrypted SSL or TLS connections. You can recognize an encrypted connection in your browser’s address line when it changes from “http://” to “https://” and the lock icon in your browser line is visible.

In the case of encrypted communication, any payment details you submit to us cannot be read by third parties.

Information, blocking, deletion

As permitted by law, you have the right to be provided at any time with information free of charge about any of your personal data that is stored as well as its origin, the recipient and the purpose for which it has been processed. You also have the right to have this data corrected, blocked or deleted. You can contact us at any time using the address given in our legal notice if you have further questions on the topic of personal data.

Opposition to promotional emails

We hereby expressly prohibit the use of contact data published in the context of website legal notice requirements with regard to sending promotional and informational materials not expressly requested. The website operator reserves the right to take specific legal action if unsolicited advertising material, such as email spam, is received.

  1. Data protection officer

Statutory data protection officer

We have appointed a data protection officer for our company.

Andreas Lakeberg
E-Surfer
Vicki-Baum-Strasse 80
10317 Berlin

Website: https://e-surfer.com/en/

Telephone: +49 30 20609981
Email: info@e-surfer.com

  1. Data collection on our website

Cookies

Some of our web pages use cookies. Cookies do not harm your computer and do not contain any viruses. Cookies help make our website more user-friendly, efficient, and secure. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called “session cookies.” They are automatically deleted after your visit. Other cookies remain in your device’s memory until you delete them. These cookies make it possible to recognize your browser when you next visit the site.

You can configure your browser to inform you about the use of cookies so that you can decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions or to always reject them, or to automatically delete cookies when closing your browser. Disabling cookies may limit the functionality of this website.

Cookies which are necessary to allow electronic communications or to provide certain functions you wish to use (such as the shopping cart) are stored pursuant to Art. 6 paragraph 1, letter f of DSGVO. The website operator has a legitimate interest in the storage of cookies to ensure an optimized service provided free of technical errors. If other cookies (such as those used to analyze your surfing behavior) are also stored, they will be treated separately in this privacy policy.

Server log files

The website provider automatically collects and stores information that your browser automatically transmits to us in “server log files”. These are:

Browser type and browser version
Operating system used
Referrer URL
Host name of the accessing computer
Time of the server request
IP address
These data will not be combined with data from other sources.

The basis for data processing is Art. 6 (1) (f) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.

Registration on this website

You can register on our website in order to access additional functions offered here. The input data will only be used for the purpose of using the respective site or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject your registration.

To inform you about important changes such as those within the scope of our site or technical changes, we will use the email address specified during registration.

We will process the data provided during registration only based on your consent per Art. 6 (1)(a) DSGVO. You may revoke your consent at any time with future effect. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

We will continue to store the data collected during registration for as long as you remain registered on our website. Statutory retention periods remain unaffected.

Processing of data (customer and contract data)

We collect, process, and use personal data only insofar as it is necessary to establish, or modify legal relationships with us (master data). This is done based on Art. 6 (1) (b) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract. We collect, process and use your personal data when accessing our website (usage data) only to the extent required to enable you to access our service or to bill you for the same.

Collected customer data shall be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.

Data transmitted when entering into a contract with online shops, retailers, and mail order

We transmit personally identifiable data to third parties only to the extent required to fulfill the terms of your contract, for example, to companies entrusted to deliver goods to your location or banks entrusted to process your payments. Your data will not be transmitted for any other purpose unless you have given your express permission to do so. Your data will not be disclosed to third parties for advertising purposes without your express consent.

The basis for data processing is Art. 6 (1) (b) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.

  1. Social media

Facebook plugins (Like & Share buttons)

Our website includes plugins for the social network Facebook, Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA. The Facebook plugins can be recognized by the Facebook logo or the Like button on our site. For an overview of Facebook plugins, see https://developers.facebook.com/docs/plugins/.

When you visit our site, a direct connection between your browser and the Facebook server is established via the plugin. This enables Facebook to receive information that you have visited our site from your IP address. If you click on the Facebook “Like button” while you are logged into your Facebook account, you can link the content of our site to your Facebook profile. This allows Facebook to associate visits to our site with your user account. Please note that, as the operator of this site, we have no knowledge of the content of the data transmitted to Facebook or of how Facebook uses these data. For more information, please see Facebook’s privacy policy at https://de-de.facebook.com/policy.php.

If you do not want Facebook to associate your visit to our site with your Facebook account, please log out of your Facebook account.

Twitter plugin

Functions of the Twitter service have been integrated into our website and app. These features are offered by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. When you use Twitter and the “Retweet” function, the websites you visit are connected to your Twitter account and made known to other users. In doing so, data will also be transferred to Twitter. We would like to point out that, as the provider of these pages, we have no knowledge of the content of the data transmitted or how it will be used by Twitter. For more information on Twitter’s privacy policy, please go to https://twitter.com/privacy.

Your privacy preferences with Twitter can be modified in your account settings at https://twitter.com/account/settings.

Google+ plugin

Our pages use Google+ functions. It is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Collection and disclosure of information: Using the Google +1 button allows you to publish information worldwide. By means of the Google+ button, you and other users can receive custom content from Google and our partners. Google stores both the fact that you have +1’d a piece of content and information about the page you were viewing when you clicked +1. Your +1 can be displayed together with your profile name and photo in Google services, for example in search results or in your Google profile, or in other places on websites and advertisements on the Internet.

Google records information about your +1 activities to improve Google services for you and others. To use the Google + button, you need a globally visible, public Google profile that must contain at least the name chosen for the profile. This name is used by all Google services. In some cases, this name may also replace a different name that you have used to share content via your Google account. The identity of your Google profile can be shown to users who know your email address or other information that can identify you.

Use of collected data: In addition to the uses mentioned above, the information you provide is used in accordance with the applicable Google data protection policies. Google may publish summary statistics about users’ +1 activity or share it with users and partners, such as publishers, advertisers, or affiliate websites.

Instagram plugin

Our website contains functions of the Instagram service. These functions are offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.

If you are logged into your Instagram account, you can click the Instagram button to link the content of our pages with your Instagram profile. This means that Instagram can associate visits to our pages with your user account. As the provider of this website, we expressly point out that we receive no information on the content of the transmitted data or its use by Instagram.

For more information, see the Instagram Privacy Policy: https://instagram.com/about/legal/privacy/.

Tumblr plugin

Our pages use the buttons of the Tumblr service. It is operated by Tumblr, Inc., 35 East 21st St., 10th Floor, New York, NY 10010, USA.

These functions allow you to share a post or a page on Tumblr or to follow the provider on Tumblr. When you visit one of our websites using the Tumblr button, the browser establishes a direct connection to the Tumblr servers. We have no influence on the amount of data that Tumblr gathers and transmits with the plugin. Based on our current knowledge, we believe that the user’s IP address and the URL of the respective website are transmitted.

Further information can be found in Tumblr’s privacy policy at https://www.tumblr.com/policy/de/privacy.

LinkedIn plugin

Our site uses functions from the LinkedIn network. The service is provided by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.

Each time one of our pages containing LinkedIn features is accessed, your browser establishes a direct connection to the LinkedIn servers. LinkedIn is informed that you have visited our web pages from your IP address. If you use the LinkedIn “Recommend” button and are logged into your LinkedIn account, it is possible for LinkedIn to associate your visit to our website to your user account. We would like to point out that, as the provider of these pages, we have no knowledge of the content of the data transmitted or how it will be used by LinkedIn.

More information can be found in the LinkedIn privacy policy at https://www.linkedin.com/legal/privacy-policy.

XING Plugin

Our website uses features provided by the XING network. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany.

Each time one of our pages containing XING features is accessed, your browser establishes a direct connection to the XING servers. To the best of our knowledge, no personal data is stored in the process. In particular, no IP addresses are stored nor is usage behavior evaluated.

For more information about data protection and the XING Share button, please see the XING privacy policy at https://www.xing.com/app/share?op=data_protection.

Pinterest plugin

Our website contains functions of the Pinterest social network, operated by Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA.

When you visit a page containing the Pinterest social plugin, your browser establishes a direct connection to the Pinterest servers. The plugin transmits this log data to Pinterest servers in the United States. This log data may include your IP address, the address of the websites visited, which also includes Pinterest features, browser type and settings, the date and time of the request, how you use Pinterest, and cookies.

More information about the purpose, scope and further processing and use of data by Pinterest, as well as your rights and options to protect your privacy, can be found in the privacy notices of Pinterest: https://about.pinterest.com/de/privacy-policy.

  1. Analytics and advertising

Google Analytics

This website uses Google Analytics, a web analytics service. It is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Google Analytics uses so-called “cookies”. These are text files that are stored on your computer and that allow an analysis of the use of the website by you. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.

Google Analytics cookies are stored based on Art. 6 (1) (f) DSGVO. The website operator has a legitimate interest in analyzing user behavior to optimize both its website and its advertising.

IP anonymization

We have activated the IP anonymization feature on this website. Your IP address will be shortened by Google within the European Union or other parties to the Agreement on the European Economic Area prior to transmission to the United States. Only in exceptional cases is the full IP address sent to a Google server in the US and shortened there. Google will use this information on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity, and to provide other services regarding website activity and Internet usage for the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with any other data held by Google.

Browser plugin

You can prevent these cookies being stored by selecting the appropriate settings in your browser. However, we wish to point out that doing so may mean you will not be able to enjoy the full functionality of this website. You can also prevent the data generated by cookies about your use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

Objecting to the collection of data

You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this site: Disable Google Analytics.

For more information about how Google Analytics handles user data, see Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=en.

Outsourced data processing

We have entered into an agreement with Google for the outsourcing of our data processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

Demographic data collection by Google Analytics

This website uses Google Analytics’ demographic features. This allows reports to be generated containing statements about the age, gender, and interests of site visitors. This data comes from interest-based advertising from Google and third-party visitor data. This collected data cannot be attributed to any specific individual person. You can disable this feature at any time by adjusting the ads settings in your Google account or you can forbid the collection of your data by Google Analytics as described in the section “Refusal of data collection”.

WordPress Stats

This website uses the WordPress Stats tool to perform statistical analyses of visitor traffic. This service is provided by Automattic Inc., 60 29th Street # 343, San Francisco, CA 94110-4929, USA.

WordPress Stats uses cookies that are stored on your computer and allow an analysis of the use of the website. The information generated by the cookies about the use of our website is stored on servers in the USA. Your IP address will be anonymized after processing and before storage.

WordPress Stats cookies remain on your device until you delete them.

The storage of “WordPress Stats” cookies is based on Art. 6 (1) (f) DSGVO. The website operator has a legitimate interest in analyzing user behavior to optimize both its website and its advertising.

You can configure your browser to inform you about the use of cookies so that you can decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions or to always reject them, or to automatically delete cookies when closing your browser. The functionality of our services may be limited when cookies are disabled.

You can object to the collection and use of your data at any time with future effect by clicking on this link and setting an opt-out cookie in your browser: https://www.quantcast.com/opt-out/.

If you delete the cookies on your computer, you will have to set the opt-out cookie again.

Google AdSense

This website uses Google AdSense, a service for including advertisements from Google Inc. (“Google”). It is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Google AdSense uses so-called “cookies”, which are text files stored in your computer that enable an analysis of the way you use the website. Google AdSense also uses so-called web beacons (invisible graphics). Through these web beacons, information such as the visitor traffic on these pages can be evaluated.

The information generated by cookies and web beacons relating to your use of this website (including your IP address), and delivery of advertising formats, is transmitted to a Google server in the US and stored there. This information can be passed on from Google to contracting parties of Google. However, Google will not merge your IP address with other data you have stored.

AdSense cookies are stored based on Art. 6 (1) (f) DSGVO. The website operator has a legitimate interest in analyzing user behavior to optimize both its website and its advertising.

You can prevent the installation of cookies by setting your browser software accordingly. Please be aware that in this case, you may not be able to make full use of all the features of this website. By using this website, you agree to the processing of data relating to you and collected by Google as described and for the purposes set out above.

Google Analytics Remarketing

Our websites use the features of Google Analytics Remarketing combined with the cross-device capabilities of Google AdWords and DoubleClick. This service is provided by Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.

This feature makes it possible to link target audiences for promotional marketing created with Google Analytics Remarketing to the cross-device capabilities of Google AdWords and Google DoubleClick. This allows advertising to be displayed based on your personal interests, identified based on your previous usage and surfing behavior on one device (e.g. your mobile phone), on other devices (such as a tablet or computer).

Once you have given your consent, Google will associate your web and app browsing history with your Google Account for this purpose. That way, any device that signs in to your Google Account can use the same personalized promotional messaging.

To support this feature, Google Analytics collects Google-authenticated IDs of users that are temporarily linked to our Google Analytics data to define and create audiences for cross-device ad promotion.

You can permanently opt out of cross-device remarketing/targeting by turning off personalized advertising in your Google Account; follow this link: https://www.google.com/settings/ads/onweb/.

The aggregation of the data collected in your Google Account data is based solely on your consent, which you may give or withdraw from Google per Art. 6 (1) (a) DSGVO. For data collection operations not merged into your Google Account (for example, because you do not have a Google Account or have objected to the merge), the collection of data is based on Art. 6 (1) (f) DSGVO. The website operator has a legitimate interest in analyzing anonymous user behavior for promotional purposes.

For more information and the Google Privacy Policy, go to: https://www.google.com/policies/technologies/ads/.

Google AdWords and Google Conversion Tracking

This website uses Google AdWords. AdWords is an online advertising program from Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, United States (“Google”).

As part of Google AdWords, we use so-called conversion tracking. When you click on an ad served by Google, a conversion tracking cookie is set. Cookies are small text files that your internet browser stores on your computer. These cookies expire after 30 days and are not used for personal identification of the user. Should the user visit certain pages of the website and the cookie has not yet expired, Google and the website can tell that the user clicked on the ad and proceeded to that page.

Each Google AdWords advertiser has a different cookie. Thus, cookies cannot be tracked using the website of an AdWords advertiser. The information obtained using the conversion cookie is used to create conversion statistics for the AdWords advertisers who have opted for conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a conversion tracking tag page. However, advertisers do not obtain any information that can be used to personally identify users. If you do not want to participate in tracking, you can opt-out of this by easily disabling the Google Conversion Tracking cookie by changing your browser settings. In doing so, you will not be included in the conversion tracking statistics.

Conversion cookies are stored based on Art. 6 (1) (f) DSGVO. The website operator has a legitimate interest in analyzing user behavior to optimize both its website and its advertising.

For more information about Google AdWords and Google Conversion Tracking, see the Google Privacy Policy: https://www.google.de/policies/privacy/.

You can configure your browser to inform you about the use of cookies so that you can decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions or to always reject them, or to automatically delete cookies when closing your browser. Disabling cookies may limit the functionality of this website.

  1. Newsletter

Newsletter data

If you would like to receive our newsletter, we require a valid email address as well as information that allows us to verify that you are the owner of the specified email address and that you agree to receive this newsletter. No additional data is collected or is only collected on a voluntary basis. We only use this data to send the requested information and do not pass it on to third parties.

We will, therefore, process any data you enter onto the contact form only with your consent per Art. 6 (1) (a) DSGVO. You can revoke consent to the storage of your data and email address as well as their use for sending the newsletter at any time, e.g. through the “unsubscribe” link in the newsletter. The data processed before we receive your request may still be legally processed.

The data provided when registering for the newsletter will be used to distribute the newsletter until you cancel your subscription when said data will be deleted. Data we have stored for other purposes (e.g. email addresses for the members area) remain unaffected.

  1. Plugins and tools

YouTube

Our website uses plugins from YouTube, which is operated by Google. The operator of the pages is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.

If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited.

If you’re logged in to your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.

YouTube is used to help make our website appealing. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

Further information about handling user data, can be found in the data protection declaration of YouTube under https://www.google.de/intl/de/policies/privacy.

Vimeo

Our website uses features provided by the Vimeo video portal. This service is provided by Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.

If you visit one of our pages featuring a Vimeo plugin, a connection to the Vimeo servers is established. Here the Vimeo server is informed about which of our pages you have visited. In addition, Vimeo will receive your IP address. This also applies if you are not logged in to Vimeo when you visit our website or do not have a Vimeo account. The information is transmitted to a Vimeo server in the US, where it is stored.

If you are logged in to your Vimeo account, Vimeo allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your Vimeo account.

For more information on how to handle user data, please refer to the Vimeo Privacy Policy at https://vimeo.com/privacy.

Google Web Fonts

For uniform representation of fonts, this page uses web fonts provided by Google. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.

For this purpose your browser has to establish a direct connection to Google servers. Google thus becomes aware that our web page was accessed via your IP address. The use of Google Web fonts is done in the interest of a uniform and attractive presentation of our website. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

If your browser does not support web fonts, a standard font is used by your computer.

Further information about handling user data, can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy at https://www.google.com/policies/privacy/.

Google Maps

This site uses the Google Maps map service via an API. It is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

To use Google Maps, it is necessary to save your IP address. This information is generally transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer.

The use of Google Maps is in the interest of making our website appealing and to facilitate the location of places specified by us on the website. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

Further information about handling user data, can be found in the data protection declaration of Google at https://www.google.de/intl/de/policies/privacy/.

  1. Payment service providers

PayPal

Our website accepts payments via PayPal. The provider of this service is PayPal (Europe) S.à.r.l & Cie, S.C.A. (22-24 Boulevard Royal, L-2449 Luxembourg.

If you select payment via PayPal, the payment data you provide will be supplied to PayPal based on Art. 6 (1) (a) (Consent) and Art. 6 (1) (b) DSGVO (Processing for contract purposes). You have the option to revoke your consent at any time with future effect. It does not affect the processing of data previously collected.

  1. Discourse Forum

Our forum runs on software from Civilized Discourse Construction Kit, Inc., or CDCK for short.

This notice describes how Civilized Discourse Construction Kit, Inc., or CDCK for short, collects and uses data about you.

CDCK is the company home and primary developer of Discourse, open source software for hosting Internet discussion forums. As a company, CDCK hosts forums using Discourse for customers, as well as meta.discourse.org, a discussion forum about Discourse itself, and rubytalk.org, a mirror of the Ruby-Talk mailing list for the Ruby programming language.

CDCK sets only its own privacy practices, not the privacy practices of CDCK customers or others who host Discourse forums for themselves or others. You should ask all of those involved in administering and hosting Discourse forums that you use for information about their privacy practices.

How does CDCK collect data about me?
CDCK collects data about you:

when you browse a forum that CDCK hosts

when you create and use an account on a forum that CDCK hosts

when you post, send private messages, and otherwise participate in a forum that CDCK hosts

CDCK collects data when you use forums that Discourse hosts, whether you use the forums using a web browser on your own computer, or use CDCK’s Discourse apps for mobile devices.

CDCK does not buy or otherwise receive data about you from data brokers.

What data does CDCK collect about me, and why?
CDCK collects data about visits to forums.
When you visit a forum that CDCK hosts, whether you have an account or not, the forum uses cookies, server logs, and other methods to collect data about what pages you visit and when.

CDCK uses data about how you use the website to:

optimize the forum, so that it’s quick and easy to use

diagnose and debug technical errors

defend the forum from abuse and technical attacks

compile statistics on forum and topic popularity

compile statistics on the kinds of software and computers visitors use

CDCK usually stores data about how you use the forum in identifiable form for just a few weeks. In special circumstances, like extended investigations about technical attacks, CDCK may preserve log data longer, for analysis. CDCK stores aggregate statistics about use of the forum for as long as CDCK hosts the forum, but those statistics don’t include data identifiable to you personally.

CDCK collects account data.
Many features of forums that CDCK hosts require a forum account. For example, most forums that CDCK hosts require an account to post and reply to topics.

To sign up for a forum account, Discourse requires your name, a user name, and an e-mail address.

CDCK uses your account data to identify you on the forum, and to create pages specific to you, like your profile page. If the forum is public, CDCK publishes your account data. If the forum is access-restricted, CDCK makes your account data available to everyone who can access the forum, according to the forum administrator’s configuration.

CDCK uses your e-mail address to:

notify you about posts and other activity on the forum

reset your password and help keep your account secure

contact you in special circumstances related to your account

contact you about legal requests, like DMCA takedown requests

You may provide additional data for your account, like a short biography, your location, or your birthday, on the profile settings page for your account. CDCK makes that data available to others who can access the forum. You don’t have to provide this additional information, and you can erase it at any time.

CDCK stores your account data as long as your account remains open.

CDCK collects data about posts and other activity on the forum.
CDCK collects the content of your posts, plus data about bookmarks, likes, and links you follow in order to share that data with others, through the forum. If the forum is public, CDCK publishes your activity. If the forum is access-restricted, or access restrictions apply to the specific post, CDCK makes your activity available only to users permitted to see it.

CDCK also collects data about private messages that you send through the forum. CDCK makes private messages available to senders and their recipients, and also to forum administrators.

CDCK stores your posts and other activity as long as your account remains open.

How can I make choices about data collection?
You can make choices about how data about you is used on the settings page for your account. When a forum uses access restrictions that vary by category, you can choose who will see your post by choosing the appropriate category.

CDCK does not respond to the Do Not Track HTTP header.

Where does CDCK store data about me?
Most forums that CDCK hosts store all data in CDCK’s data center in San Jose, California, USA. Some forums that CDCK hosts store data in data centers in multiple jurisdictions, such as the United States and the European Union.

CDCK participates in the Privacy Shields.
CDCK participates in the EU-US Privacy Shield and the Swiss-US Privacy Shield. Under the Privacy Shields:

CDCK must respond to questions and complaints within 45 days.

CDCK is subject to the investigatory and enforcement powers of the Federal Trade Commission.

CDCK is liable in cases of onward transfers to third parties.

CDCK commits to subject all personal data received from the EU in reliance on the Privacy Shield to the Privacy Shield Principles.

CDCK is required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

You can find the Privacy Shield list online at https://www.privacyshield.gov/list.

Does CDCK comply with the EU General Data Protection Regulation?
CDCK respects privacy rights under Regulation (EU) 2016/679, the European Union’s General Data Protection Regulation (GDPR). Information that GDPR requires CDCK to give can be found throughout this privacy notice. So can information about specific rights, like access, rectification, erasure, data portability, and objection to automated decision-making.

Where can I access data about me?
You can see your account data at any time by visiting your account page on the forum. Your account page also lists your posts and other activity on the forum.

Your account activity page also includes a link to download all of your activity in standard comma-separated values format.

How can I change or erase data about me?
You can change your account data at any time by visiting the profile settings page for your account. The settings for a particular forum may also allow you to close your account, on the settings page for your account. Closing your account starts a process of erasing or anonymizing CDCK’s records of data you provided for your account. Forum administrators can also erase and anonymize accounts.

Depending on the settings for your particular forum, you may also be able to edit, anonymize, or erase your posts. When you edit posts, CDCK will keep all versions of your posts. Forum administrators can view old versions of posts, and optionally make them visible to other forum visitors.

Does CDCK make automated decisions based on data about me?
CDCK classifies posts as spam automatically.
CDCK uses data about your posts and other activity on many forums to make automated decisions about whether your posts to meta.discourse.org and most forums that CDCK hosts are spam. When Akismet decides that a post is likely spam, the forum refuses to accept the post.

If you think a post has been wrongly blocked or removed, contact an administrator of your forum. They can override the decision that a post was spam.

CDCK uses data about posts and activity to set trust levels automatically.
Depending on how administrators of your forum configure the forum, the forum may use data about your posts and activity to award you badges and calculate a trust level for your account. Your trust level may affect how you can participate in the forum, such as whether you can upload images, as well as give you access to moderation and management powers in the forum. Your trust level therefore reflects forum administrators’ confidence in you, and their willingness to delegate community management functions, like moderation.

If you think your trust level has been set incorrectly, contact an administrator of your forum. They can manually adjust the trust level of your account.

Does CDCK share data about me with others?
CDCK shares account data with others as mentioned in the section about account data.

CDCK shares data about your posts and other forum activity with others as mentioned in the section about account data.

Apart from making data available to the customer that pays CDCK to host a forum, CDCK does not sell or give information about you to other companies or services. However, CDCK does use services from other companies on some forums that it hosts. The companies behind those services may collect data about you on their own, for their own purposes. Some of these services may be used to collect information about your online activities across different websites. All of these services are based in the United States.

Service Privacy Notice Description
Akismet https://automattic.com/privacy/ reduces spam posts on some forums
Google Analytics https://www.google.com/analytics/terms/ Compiles visitor statistics on some forums, including meta.discourse.org. You can opt out of Google Analytics using a browser extension.
Amazon Web Services https://aws.amazon.com/privacy/ Provides cloud servers and services, in service regions across the world, to host and back up some forums.
Digital Ocean https://www.digitalocean.com/legal/privacy/ Stores backups for many forums.
Fastly https://www.fastly.com/privacy Provides a content delivery network of servers that host copies of content like images and website files, so that users around the world can download them quickly, from servers close to where they are.
KeyCDN https://www.keycdn.com/privacy Provides a content delivery network.
MaxCDN https://www.maxcdn.com/legal/#pp Provides a content delivery network.
Apple Push Notification Service https://www.apple.com/legal/privacy/ Sends push notifications to users of the Discourse iOS app.
Google Cloud Messaging https://policies.google.com/privacy Sends push notifications to users of the Discourse Android app.
Other individuals and companies may also reuse data about you that CDCK publishes, such as your posts to public forums.

How can I contact CDCK about privacy?
You can send questions and complaints to:

Civilized Discourse Construction Kit, Inc
team+privacy@discourse.org

European Users with questions or complaints about GDPR compliance should also address CDCK’s representative in the Union:

Mr Hanol Régis
Civilized Discourse Construction Kit, Inc.
regis.hanol@discourse.org
105 Route des Pommiers
Centre UBIDOCA, 15232
St Martin Bellevue
74370 FILLIERE
FRANCE

For complaints under the Privacy Shields, CDCK has a contract with JAMS, an independent alternative resolution provider based in the United States. If we can’t resolve a complaint about Privacy Shield between us, you can submit a Privacy Shield claim through JAMS. Arbitrating through JAMS is free of charge to you. Under some circumstances, European Union users may invoke binding Privacy Shield arbitration, as a last resort.

For complaints under GDPR more generally, European Union users may lodge complaints with their local data protection supervisory authorities.

How can I find out about changes?
This version of CDCK’s privacy questions and answers took effect May 1, 2018.

CDCK will post the next version at https://meta.discourse.org/privacy. CDCK may change how it announces changes in future versions.

In the meantime, CDCK may update its contact information without announcing a change. Please refer to https://meta.discourse.org/privacy for the latest contact information at any time.