Gitea Privacy Statement gitea.sensin.eu


Last updated: 2020-08-13

Who is running this site?

This site is run by STZ SensIn‘ for internal usage. Please do not use if you are not part of SensIn‘. This is no public service. See impressum

What Personal Data Do We Collect?

We collect following personal data (collectively called User Personal Information):

  1. Registration information (username, email, password, etc.)
  2. Profile information for your Account (such as your full name, biography, website, gpg key, and location.)
  3. Usage information (pages you view, your IP address, referring site, session information, and request date and time.)
  4. Device information (its IP address, client application information, language preference, operating system and application version, device type, ID, model and manufacturer.)
  5. Git data that you upload to a repository
  6. Cookies and Similar Technologies

How We Share Information We Collect?

We may share your User Personal Information with third-parties under following circumstances:

With your Consent

We share your User Personal Information, if you consent, after letting you know what information will be shared, with whom, and why. For example, if you allow third party applications to access your Account using OAuth2 providers, we share all information associated with your Account, including private repos and organizations. You may also direct us through your action on SensIn‘ Gitea Instance to share your User Personal Information, such as when joining an Organization.

With Service Providers

We share User Personal Information with a limited number of service providers. Currently this is our hosting provider. Our service providers have agreed to privacy restrictions similar to the ones in our Privacy Statement by signing data protection agreements. All processing happens in Germany / EU.

How We Use Your Information?

We may use your information for following purposes:

  1. We use your Registration Information to create your account, and to provide you the Service.
  2. We use your User Personal Information, specifically your username, to identify you on SensIn‘ Gitea Instance.
  3. We use your Profile Information to fill out your Account profile and to share that profile with other users if you ask us to.
  4. We use your email address to communicate with you, if you’ve said that’s okay, and only for the reasons you’ve said that’s okay.
  5. We use User Personal Information and other data to make recommendations for you, such as to suggest projects you may want to follow or contribute to. We learn from your public behavior on SensIn‘ Gitea Instance—such as the projects you star—to determine your coding interests, and we recommend similar projects. These recommendations are automated decisions, but they have no legal impact on your rights.
  6. We use Usage Information and Device Information to better understand how our Users use SensIn‘ Gitea Instance and to improve our Website and Service.
  7. We may use your User Personal Information if it is necessary for security purposes or to investigate possible fraud or attempts to harm SensIn‘ Gitea Instance or our Users.
  8. We may use your User Personal Information to comply with our legal obligations, protect our intellectual property, and enforce our Terms of Service.
  9. We limit our use of your User Personal Information to the purposes listed in this Privacy Statement. If we need to use your User Personal Information for other purposes, we will ask your permission first. You can always see what information we have, how we’re using it, and what permissions you have given us in your user profile.

How SensIn‘ Gitea Instance Secures Your Information?

SensIn‘ Gitea Instance takes all measures reasonably necessary to protect User Personal Information from unauthorized access, alteration, or destruction; maintain data accuracy; and help ensure the appropriate use of User Personal Information.

To the extent above, we enforce a written security information program, which:

  • aligns with industry recognized frameworks;
  • includes security safeguards reasonably designed to protect the confidentiality, integrity, availability, and resilience of our Users‘ data;
  • is appropriate to the nature, size, and complexity of SensIn‘ Gitea Instance’s business operations;
  • includes incident response and data breach notification processes; and
  • complies with applicable information security-related laws and regulations in the geographic regions where SensIn‘ Gitea Instance does business.

In the event of a data breach that affects your User Personal Information, we will act promptly to mitigate the impact of a breach and notify any affected Users without undue delay.

Transmission of data on SensIn‘ Gitea Instance is encrypted using SSH, HTTPS (TLS), and git repository content is encrypted at rest. We host SensIn‘ Gitea Instance at our hosting partner, which they provide data centers with high level of physical and network security.

Disclaimer: No method of transmission, or method of electronic storage, is 100% secure, therefore, we cannot guarantee absolute security.

Cookies and Tracking Usage

Cookies

We uses cookies to make interactions with our service easy and meaningful. Cookies are small text files that websites often store on computer hard drives or mobile devices of visitors. We use cookies (and similar technologies, like HTML5 localStorage) to keep you logged in, remember your preferences, and provide information for future development of SensIn‘ Gitea Instance. For security purposes, we use cookies to identify a device. By using our Website, you agree that we can place these types of cookies on your computer or device. If you disable your browser or device’s ability to accept these cookies, you will not be able to log in or use our services.

Tracking and Analytics

This site does not use third-party analytics.

Repository Contents

Our employees do not access private repositories unless required to for security purposes, for support, to maintain integrity of the Service, or to comply with our legal obligations. While we don’t generally search for content in your repositories, we may scan our servers and your content to detect tokens or security signatures, known malwares, or child exploitation imagery.

If your repository is public, anyone may view its contents. If you include private, confidential or Sensitive Personal Information, such as email addresses or passwords, in your public repository, that information may be indexed by search engines or used by third parties.

Public Information

Many of our services and feature are public-facing. If your content is public-facing, third parties may access and use it in compliance with our Terms of Service, such as by viewing your profile or repositories or pulling data via our API. We do not sell that content; it is yours. However, we do allow third parties, such as research organizations or archives, to compile public-facing SensIn‘ Gitea Instance information. Other third parties, such as data brokers, have been known to scrape SensIn‘ Gitea Instance and compile data as well.

Your User Personal Information associated with your content could be gathered by third parties in these compilations of SensIn‘ Gitea Instance data. If you do not want your User Personal Information to appear in third parties’ compilations of SensIn‘ Gitea Instance data, please do not make your User Personal Information publicly available and be sure to configure your email address to be private in your user profile and in your git commit settings.

If you would like to compile SensIn‘ Gitea Instance data, you must comply with our Terms of Service regarding scraping and privacy, and you may only use any public-facing User Personal Information you gather for the purpose for which our user authorized it. For example, where a SensIn‘ Gitea Instance user has made an email address public-facing for the purpose of identification and attribution, do not use that email address for commercial advertising. We expect you to reasonably secure any User Personal Information you have gathered from SensIn‘ Gitea Instance, and to respond promptly to complaints, removal requests, and „do not contact“ requests from SensIn‘ Gitea Instance or SensIn‘ Gitea Instance users.

In similar fashion, projects on SensIn‘ Gitea Instance may include publicly available User Personal Information collected as part of the collaborative events.

Organizations

If you collaborate on or become a member of an Organization, then its Account owners may receive your User Personal Information. When you accept an invitation to an Organization, you will be notified of the types of information owners may be able to see. If you accept an invitation to an Organization with a verified domain, then the owners of that Organization will be able to see your full email address(es) within that Organization’s verified domain(s).

Please note, SensIn‘ Gitea Instance may share your username, Usage Information, and Device Information with the owner of the Organization you are a member of, to the extent that your User Personal Information is provided only to investigate or respond to a security incident that affects or compromises the security of that particular Organization.

If you collaborate with or become a member of an Account that has agreed to a Data Protection Addendum (DPA) to this Privacy Policy, then that DPA governs in the event of conflicts between this Privacy Policy and DPA with respect to your activity in the Account.

Please contact the Account owners for more information about how they might process your User Personal Information in their Organization and the ways for you to access, update, alter, or delete the User Personal Information stored in the Account.

How You Can Access and Control the Information We Collect?

If you’re already a SensIn‘ Gitea Instance user, you may access, update, alter, or delete your basic user information by editing your user profile. You can control the information we collect about you by limiting what information is in your profile, or by keeping your information current.

If SensIn‘ Gitea Instance processes information about you, such as information receives from third parties, and you do not have an account, then you may, subject to applicable law, access, update, alter, delete, or object to the processing of your personal information by contacting our support.

Data Portability

As a SensIn‘ Gitea Instance User, you can always take your data with you. You can clone your repositories to your computer, or you can perform migrations using the provided interfaces, for example.

Data Retention and Deletion of Data

In general, SensIn‘ Gitea Instance retains User Personal Information for as long as your account is active, or as needed to provide you service.

If you would like to cancel your account or delete your User Personal Information, you may do so in your user profile. We retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements, but barring legal requirements, we will delete your full profile (within reason) within 90 days of your request. Feel free to contact our support to request erasure of the data we process on the bassis of consent within 30 days.

After an account has been deleted, certain data, such as contributions to other Users‘ repositories and comments in others‘ issues, will remain. However, we will delete or de-identify your User Personal Information, including your username and email address, from the author field of issues, pull requests, and comments by associating them with a ghost user.

That said, the email address you have supplied via your Git commit settings will always be associated with your commits in the Git system. If you choose to make your email address private, you should also update your Git commit settings. We are unable to change or delete data in the Git commit history — the Git software is designed to maintain a record — but we do enable you to control what information you put in that record.

Our Global Privacy Practices

We store and process the information that we collect in Germany in accordance with this Privacy Statement.

How We Communicate with You?

We use your email address to communicate with you, if you’ve said that’s okay, and only for the reasons you’ve said that’s okay. For example, if you contact our support with a request, we respond to you via email. You have a lot of control over how your email address is used and shared on and through SensIn‘ Gitea instance. You may manage your communication preferences in your user profile.

By design, the Git version control system associates many actions with a User’s email address, such as commit messages. We are not able to change many aspects of the Git system. If you would like your email address to remain private, even when you’re commenting on public repositories, you can create a private email address in your user profile. You should also update your local Git configuration to use your private email address. This will not change how we contact you, but it will affect how others see you.

Depending on your email settings, SensIn‘ Gitea instance may occasionally send notification emails about changes in a repository you’re watching, new features, requests for feedback, important policy changes, or to offer customer support. We also send marketing emails, based on your choices and in accordance with applicable laws and regulations. There’s an “unsubscribe” link located at the bottom of each of the marketing emails we send you. Note that you can opt out of any communications with us, except the important ones (like from our support and system emails).

Our emails may contain a pixel tag, which is a small, clear image that can tell us whether or not you have opened an email and what your IP address is. We use this pixel tag to make our email more effective for you and to make sure we’re not sending you unwanted email.

Changes to this Privacy Policy

Although most changes are likely to be minor, SinsIn‘ Gitea Instance may change our Privacy Statement from time to time. We will provide notification to Users of material changes to this Privacy Statement through our Website at least 30 days prior to the change taking effect by posting a notice on our home page or sending email to the primary email address specified in your account.

Contact

If you have any concerns about privacy, please contact us at privacy@your-gitea-instance. We will respond promptly, within 45 days.

COPYING

This document is licensed under CC0 Public Domain License. See full legal code here.