lukevella / rallly

Rallly is an open-source scheduling and collaboration tool designed to make organizing events and meetings easier.
https://rallly.co
GNU Affero General Public License v3.0
3.55k stars 338 forks source link

rally.co site needs a privacy statement #62

Closed mc0e closed 2 years ago

mc0e commented 6 years ago

A privacy statement is needed.

You're asking people to submit email addresses, for themselves and other people, and holding info about meetings that may potentially have privacy issues.

lukevella commented 2 years ago

Added: https://rallly.co/privacy-policy

mc0e commented 2 years ago

It's a very long time since I created this ticket, and also a long time since you first added a privacy policy (I looked at archived versions of your site). Still, I looked over your privacy policy statement.

  1. I suggest you look at adding something about requests for deletion of data, especially since people will be submitting personal details about other event participants who have likely not provided consent for you storing that data.
  2. An expiry period is probably appropriate, after which all personal data is deleted for old events and inactive participants.
lukevella commented 2 years ago

It's a very long time since I created this ticket, and also a long time since you first added a privacy policy (I looked at archived versions of your site). Still, I looked over your privacy policy statement.

Well done…

you got me

I suggest you look at adding something about requests for deletion of data, especially since people will be submitting personal details about other event participants who have likely not provided consent for you storing that data.

It's not really the case in the new version. There's no option to put in participants' email addresses. At least for now, but I thought the policy covered this by offering a contact email address. If you're aware of a template that would be a better fit I'd be open to changing it.

An expiry period is probably appropriate, after which all personal data is deleted for old events and inactive participants.

Do you know of any specific time frames that should be adhered to from a legal perspective? There's nothing set up at the moment that would do this but happy to add it in.