-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Privicy Policy #69
Comments
https://app.privacypolicies.com/wizard/privacy-policy helps build from standard templates. |
I can look deeper into this. Do we plan on collecting any PII from users for a KYC or are we just sticking with email address? |
@sudoebm I believe just email address for now. I don't see a need for further information. |
Possibly IP address &| locale for security and user experience |
Would locale need to be logged though and tied to their account, or simply a token from the browser to set timestamps correctly? |
Honestly not sure what info I can pull through the browser yet, the little reading I have done locale != Timezone |
1 similar comment
Honestly not sure what info I can pull through the browser yet, the little reading I have done locale != Timezone |
Sorry, vocab mix-up. Yes, locale and IP would be useful. We should only log the most recent instance so the user can compare it to their current info, no need to keep a detailed log. "Your last login was from [IP] located in [locale], if this appears incorrect please contact support immediately." |
As an email or notification on webpage? |
My research so far is telling me that it is lawful under GDPR Article 6 to log IP address information for the purpose of security.
This can also be solved with an over all consent agreement.
The other points don't apply to us as a whole. We also only need to satisfy one of these points. There is a lot more to unpack from this monster of a law, but I'll be working on it and likely draw up a more detailed Privacy Policy and terms of server for @BKdilse 's review. |
I wrote up the last set of changes to the ToS, I'll turn it into a google doc and shoot you a link. There are some edits I want to make to the wording. |
Do we use flash cookies? |
@sudoebm the only cookie i am using for for the sessionid |
The Dark/Light mode also uses a cookie, to store what mode has been selected. |
We are supposed to have 2 ways for a user to make data inquiries or data deletion requests. Do we want to make a form fillable webpage? The other options would be PO box or phone number. The Support email fulfills the 2nd requirement. |
I think a fillable form, least that could be automated in the future |
Draft policy added: https://exchange.gntl.co.uk/pages/privacy.html |
Privacy Policy.docx |
@sudoebm policy looks good. |
should include all data we collect and what we will do with it, and how to request that we delete it in accordance with GDPR
The text was updated successfully, but these errors were encountered: