Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

added data policy #76

Merged
merged 11 commits into from
Jun 6, 2020
1 change: 1 addition & 0 deletions SUMMARY.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,5 +15,6 @@
- [Finance](finance.md)
- [Novel Coronavirus (2019) 🦠](coronavirus.md)
* [Guides](guides.md)
* [How We Use Data](data.md)
* [Reading Pool](reading-pool.md)
* [Glossary](glossary.md)
110 changes: 110 additions & 0 deletions data.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,110 @@
# How We Use Data

Hypha is [a worker co-operative incorporated in Ontario, Canada](https://handbook.hypha.coop/co-operative.html).
We run our public website, this member handbook, and a variety of services at the domain [hypha.coop](https://hypha.coop) and its subdomains.
This page identifes what data we collect and why, as well as where and how long we store collected data for.

This page was last updated on June 6, 2020. You can see previous versions on [GitHub](https://github.com/hyphacoop/handbook/). The outline and format is inspired by [Projects by IF: How IF uses data](https://www.projectsbyif.com/how-if-uses-data/).

### Contents

ASoTNetworks marked this conversation as resolved.
Show resolved Hide resolved
- [Our Websites and Hosted Services](#our-websites-and-hosted-services)
- [What data we collect](#what-data-we-collect)
- [Why we collect data](#why-we-collect-data)
- [Where we keep data](#where-we-keep-data)
- [How long we keep data](#how-long-we-keep-data)
- [Our Social Media Accounts and Third-party Services](#our-social-media-accounts-and-third-party-services)

## Our Websites and Hosted Services

The collowing sites and services are at the domain [hypha.coop](https://hypha.coop) and its subdomains:

- Website: [hypha.coop](https://hypha.coop)
- Handbook: [handbook.hypha.coop](https://handbook.hypha.coop)
- Meetings: [meetings.hypha.coop](https://meetings.hypha.coop)
- Shortlinks: [link.hypha.coop](https://link.hypha.coop)
- Loomio: [loomio.hypha.coop](https://loomio.hypha.coop)
- Nextcloud: [cloud.hypha.coop](https://cloud.hypha.coop)
- BigBlueButton: [bbb.hypha.coop](https://bbb.hypha.coop)
- Jitsi: [jitsi.hypha.coop](https://jitsi.hypha.coop)
- COVID-19 Solidarity: [covid19.hypha.coop](https://covid19.hypha.coop)


### What data we collect

**System logs** may contain:

- Timestamp of visit
- IP address
- Operating system
- Browser type
- User-specified URL to access the service

**User accounts** may contain:

- First and last name
- Email address

**Videoconferencing data** may contain:

- Network usage information and aggregated statistics, such as number of users, number of meetings, number of video and audio streams, session lengths, etc.
- Chat logs, notes, and uploaded content during meetings, such as presentations and images
- Phone numbers that connect to meetings (if audio connection is made via a telephone call)

We do not knowingly collect any information from children under the age of 13 without appropriate consent and authorization.
If you believe we have inadvertently collected personal information from a child under 13 without proper consents please contact <a href="mailto:%64%61%74%61%40%68%79%70%68%61%2E%63%6F%6F%70">data@hypha.coop</a> so that we may delete such information as soon as possible.

### Why we collect data

We keep standard system logs for **monitoring of system performance and debugging purposes**.

Some of our hosted services automatically log the time you access your account on our systems, and may store "cookies" on your computer.
"Cookies" are small pieces of information that a website sends to your computer's hard drive while you are viewing a website, which may stay on your computer until you delete them.
These are used by some of our hosted services to **deliver a more personal and interactive experience**.

In general, personal information you submit to us is used either to **respond to requests that you make, or to aid us in serving you better**.
We do our best to protect the personal information you share with us, and do not share them with third parties.
We may however, **display and share anonymized feedback or personal testimonials on our website and social media, or in other publicly viewable places**.

### Where we keep data

Our services are hosted on servers managed by third-party service providers, physically located in Canada.
These servers are accessible to members of Hypha, and specific collaborators as deemed necessary to deliver the services and content.
Where necessary, servers may also be accessed by other parties to comply with laws or to respond to lawful requests and legal process and in an emergency to protect the personal safety of any person.

### How long we keep data

System logs are generally retained for a duration that is appropriate for the particular system.

User accounts necessary to deliver services and content are generally kept indefinitely, and periodically backed up, until the account holders have requested to delete them.
Deleting your account on a particular service generally does not mean all your information is deleted from our periodic backups.
If you have a concern, please email <a href="mailto:%64%61%74%61%40%68%79%70%68%61%2E%63%6F%6F%70">data@hypha.coop</a>.

Videoconferencing audio and video are only kept briefly in the buffer throughout the call and not recorded.

Our [BigBlueButton server](https://bbb.hypha.coop) keeps a database for registered users and room information.
Uploaded presentations are kept for 5 days after you have ended your meeting and log history is kept for 28 days.
These are BigBlueButton's default configurations and automated purging is performed by the software.
Response to polls, raise hand events, and chat messages are cleared after the call has ended.

Our [Jitsi server](https://jitsi.hypha.coop) clears all meeting data in the room after the call has ended.

The [Matrix chat](https://chat.tomesh.net/#/group/+hyphacoop:tomesh.net) in Hypha rooms are periodically wiped to keep only the most recent 3 months of history.
However, as Matrix is a federated chat protocol, chat history older than 3 months may be retained by other homeservers, and in particular, public rooms with users from other homeservers.

## Our Social Media Accounts and Third-party Services

We use several social media accounts to share our work. We occasionally use the analytics tools provided by these platforms.
Our social media accounts include:

<ul>
<li><a href="https://link.hypha.coop/twitter" target="_blank">@hyphacoop on Twitter</a> (<a href="https://twitter.com/en/privacy" target="_blank">privacy policy</a>)</li>
<li><a href="https://link.hypha.coop/linkedin" data-proofer-ignore="true" target="_blank">Hypha Worker Co-operative on LinkedIn</a> (<a href="https://www.linkedin.com/legal/privacy-policy" target="_blank">privacy policy</a>)</li>
</ul>

We also use third-party services to host and deliver services and content, almost exclusively to our members, however in some cases we may use them with our collaborators:

- [Email services](https://mailninja.aseriesoftubez.com) by [A Series of Tubez Networks](https://www.aseriesoftubez.com)
- [Matrix chat services](https://chat.tomesh.net) by [Toronto Mesh](https://tomesh.net)

For a full list of services we use, please refer to our [Services Inventory](https://link.hypha.coop/inventory).