Consumer Rights Wiki:Privacy policy
Consumer Rights Wiki Privacy Policy
Last Updated: September 24, 2026
This Privacy Policy explains how the Consumer Rights Wiki ("CRW," "we," "us," or "our"), our service providers, and our partners, collect, use, share, and protect Personally Identifying Information (PII), and other data, in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
This policy covers the wiki at consumerrights.wiki, and the CRW Zulip (our self-hosted community chat server at zulip.consumerrights.wiki). The CRW Zulip runs the open-source Zulip server software on infrastructure we operate; the FULU Foundation is the data controller for it.
1. Data Controller
The data controller responsible for your personal data is:
FULU Foundation Fulu Foundation, Austin, Texas 78705 Email: [email protected]
2. Legal Basis for Processing
We process personal data based on the following legal grounds under Article 6 of the GDPR:
Contract (Article 6(1)(b)) Data used for:
- Account registration and management
- User authentication and login
- Enabling wiki contributions and editing
- Chat account registration, authentication, and delivery of messages on the CRW Zulip
Legitimate Interests (Article 6(1)(f)) Data used for:
- IP address processing for security and anti-spam protection
- Privacy-preserving analytics through Plausible Analytics
- Maintaining the integrity and security of the wiki
- Prevention of abuse and vandalism
- Moderation of the CRW Zulip and prevention of abuse, spam, and harassment
Consent (Article 6(1)(a)) Data used for:
- Optional CRW Zulip profile information you choose to provide (avatar, custom profile fields)
- Optional email notifications and digest emails, which you can disable at any time
2.1 Data Minimization
We adhere to the principle of data minimization, collecting only the personal data that is necessary for the specific purposes outlined in this policy. We do not collect excessive or irrelevant data.
2.2 Special Categories of Data
We do not intentionally collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation). If such data is inadvertently collected through user-generated content, including messages posted on the CRW Zulip, it is not processed by us for any purpose.
3. PII and other data We Collect
3.1 Account Information
When you create an account, we collect:
- Username - Stored indefinitely, or until account deletion request
- Email address - Stored indefinitely, or until account deletion request
- Hashed and salted password - Stored indefinitely, or until account deletion request
3.2 Contribution Data
- Edit history and contributions - Stored indefinitely as necessary for wiki functionality and attribution under legitimate interest
- Timestamps of edits - Stored indefinitely as part of contribution history
- Discussion posts and comments - Stored indefinitely as part of wiki content
3.3 Technical Data
- IP addresses - Stored in server logs and backups for 90 days for security purposes, and indefinitely in edit history for attribution and anti-vandalism purposes
- Browser type and version - Processed temporarily for technical compatibility and for generation of anonymized analytics
- Device information - Processed temporarily for technical compatibility and for generation of anonymized analytics
3.4 Analytics Data (via Plausible Analytics)
Our self-hosted Plausible Analytics instance collects:
- Page views and navigation patterns
- Referrer information
- Country of origin (derived from IP addresses, which are immediately discarded)
- Device type and browser information
Important: Plausible does not use cookies or persistent identifiers, or create profiles. All data is aggregated and anonymous.
3.5 Security Services
hCaptcha processes the following when you interact with protected forms:
- Technical connection data (IP address, timestamp)
- Interaction data with the captcha interface
CloudFlare processes the following when you connect to the site:
- Technical connection data (Traffic routing data, HTTP request metadata)
3.6 CRW Zulip Chat Data
The CRW Zulip is a separate service from the wiki and requires its own account. Data is stored on infrastructure we operate.
Account data:
- Email address - Stored until account deletion request
- Full name / display name - Stored until account deletion request
- Hashed password - Stored until account deletion request (where password authentication is used)
- Optional profile data (avatar, custom profile fields, time zone) - Stored until removed by you or account deletion
- Account role and status (owner, administrator, moderator, member, guest) - Stored until account deletion request
Message and interaction data:
- Message content in public channels, private channels, and direct messages, including topics, timestamps, and edit history - Retained per section 4.1
- Uploaded files and images - Retained per section 4.1
- Emoji reactions, polls, server-synced drafts, and scheduled messages
- Read state, read receipts, starred messages, and alert words
- Presence data ("last active" time) and typing indicators
- User status (status text and emoji)
Technical and log data:
- IP addresses - Stored in server logs for 30 days for security and anti-abuse purposes
- Browser type and User Agent - Processed for session security and technical compatibility
- Session data and API keys - Stored while the session or key is active
- Audit logs recording account and configuration changes - Retained per section 4.1
- Aggregate usage statistics (message and active-user counts)
Important: Chat messages you send are visible to other users according to the channel type. As with any self-hosted chat system, server and organization administrators may be able to access private channel content and direct messages through their administrative access to the server. Do not share sensitive information in chat that you would not want an administrator to be able to access.
4. Data Retention and Backup Schedule
4.1 Primary Data Retention
| Data Type | Retention Period | Justification |
|---|---|---|
| Account data (username, email, hashed and salted password) | Indefinitely until deletion request | Necessary to perform contract |
| Contribution history | Indefinitely | Legitimate interest in maintaining wiki integrity and attribution |
| IP addresses in server logs | 30 days | Security and anti-abuse purposes |
| IP addresses in edit history | Indefinitely until deletion request | Attribution and anti-vandalism |
| Analytics data (aggregated) | Indefinitely | Legitimate interest in service improvement |
| Zulip account data (email, display name, hashed password, profile) | Indefinitely until deletion request | Necessary to perform contract |
| Zulip message content and uploads | Indefinitely | Legitimate interest in maintaining community discussion history |
| Deleted Zulip messages (archived) | 30 days, then permanently deleted | Recovery from accidental or malicious deletion |
| Zulip IP addresses in server logs | 30 days | Security and anti-abuse purposes |
| Zulip audit logs (account and configuration changes) | Indefinitely | Legitimate interest in moderation and security accountability |
Note on Zulip deletion: When a message is deleted, whether by a user or by an automatic retention policy, it is moved to an archive where an administrator can restore it for 30 days, after which it is permanently deleted. Deactivating a Zulip account prevents login but does not by itself delete messages or files that account previously sent; see section 6.3.
4.2 Backup and Recovery Schedule
| Backup Type | Frequency | Retention Period | Data Included |
|---|---|---|---|
| Daily backups | Every 24 hours | 7 days | Full database, user accounts, contribution history, configuration |
| Monthly backups | 1st of each month | 6 months | Full database, user accounts, contribution history, configuration |
| Server logs | Continuous | 30 days rolling | Access logs, error logs, security logs |
Important Notes on Backups:
- All backups are fully encrypted
- Deleted data may persist in backups until the backup retention period expires
- Maximum possible retention through backups: 6 months for monthly backups
- After backup expiration, data is permanently deleted unless specifically retained under section 4.1
5. International Data Transfers
Our servers are hosted by Hetzner in the United States. This constitutes an international data transfer from the EU/EEA. We ensure appropriate safeguards through:
- EU-US Data Privacy Framework: Our hosting providers participate in the EU-US Data Privacy Framework, ensuring adequate protection for your personal data
- hCaptcha transfers: Data may be transferred to Intuition Machines, Inc. in the USA under the EU-US Data Privacy Framework (European Commission adequacy decision C(2023) 4745)
- Resend transfers: Email addresses and email content sent from the CRW Zulip are processed and stored in the United States by Resend, Inc., under the EU-US Data Privacy Framework and Standard Contractual Clauses, and are covered by a Data Processing Addendum
6. Your Rights Under GDPR
You have the following rights regarding your personal data:
6.1 Right of Access (Article 15)
You can request a copy of your personal data we hold.
6.2 Right to Rectification (Article 16)
You can request correction of inaccurate personal data.
6.3 Right to Erasure (Article 17)
You can request deletion of your personal data, subject to legal obligations and legitimate interests (e.g., contribution history may be retained for attribution). On the CRW Zulip you can delete your own messages and uploads where permitted, and you can request account deactivation or deletion by contacting us. Note that messages you sent to other users may remain visible to those recipients, and content quoted or replied to by others may persist in their messages.
6.4 Right to Restriction (Article 18)
You can request restriction of processing in certain circumstances.
6.5 Right to Object (Article 21)
You can object to processing based on legitimate interests.
6.6 Right to Data Portability (Article 20)
You can request your data in a structured, machine-readable format.
6.7 Right to Lodge a Complaint
You have the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact us at: [email protected]
7. Data Sharing and Third Parties
We do not sell or rent your personal data. We share data only with:
7.1 Service Providers (Data Processors)
| Service Provider | Data Types Processed | Location | Purpose |
|---|---|---|---|
| Hetzner | Server infrastructure, web application data, user data, backups | US/EU | Primary hosting infrastructure |
| CloudFlare | Analytics data, traffic patterns, security logs, attack mitigation data | USA | DDoS protection, CDN, security analytics |
| hCaptcha | IP addresses, interaction data | USA | Spam prevention |
| Resend | Email addresses, email subject and content of CRW Zulip notifications | USA | Transactional email delivery for the CRW Zulip |
7.1.1 Privacy statement for the service hCaptcha
When accessing some sub-services of our website, additional information is processed.
Processed data categories: technical connection data of the server access (IP address, date, time, requested page, browser information), data about the use of the website, and the logging of clicks on individual elements.
Purpose of processing: avoid non-human and automated input.
The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).
Legitimate interests: strong economic interest in safe and functioning operation of the technical systems.
Data are transmitted: to the data processor Intuition Machines, Inc., 1065 SW 8th St #704, Miami FL 33130, USA (https://www.hcaptcha.com).
This may also mean a transfer of personal data to a country outside the European Union. The data are transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).
Please read the hCaptcha's full privacy policy for more information.
7.1.2 Privacy statement for the service Hetzner
Our website infrastructure and web application are hosted on servers provided by Hetzner.
Processed data categories: Web application data, server infrastructure data, technical connection data (IP address, date, time, requested page, browser information), server configuration and usage metrics, network traffic data.
Purpose of processing: provision of hosting infrastructure for the web application, ensuring system availability and performance.
The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).
Legitimate interests: strong economic interest in reliable and functioning operation of the technical systems and infrastructure.
Data are transmitted: to the data processor Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (https://www.hetzner.com).
Hetzner operates servers in both the European Union and the United States. When US servers are used, data transfers are covered under standard contractual clauses.
Please read Hetzner's full privacy policy for more information.
7.1.3 Privacy statement for the service CloudFlare
Our website uses CloudFlare services for content delivery, security, and performance optimization. CloudFlare processes analytics and security-related data, but does not have access to user account data or personal information stored in our databases.
Processed data categories: Traffic routing data, HTTP request metadata (HTTP headers, user agent, query-string, path, host, HTTP method, HTTP version, TLS cipher version), request and error rates, DDoS attack patterns and mitigation data, aggregated analytics data about website usage, security threat intelligence data.
Purpose of processing: content delivery network (CDN) services, DDoS attack protection and mitigation, traffic routing and optimization, security monitoring and threat detection, performance analytics to improve website speed and user experience.
The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).
Legitimate interests: strong economic interest in secure, reliable, and functioning operation of the website, protection against cyber attacks, and optimization of service performance.
Data are transmitted: to the data processor Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (https://www.cloudflare.com).
This may also mean a transfer of personal data to a country outside the European Union. The data are transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).
Please read Cloudflare's full privacy policy for more information.
7.1.4 Privacy statement for the service Resend
The CRW Zulip uses Resend to deliver transactional email, such as account confirmations, password resets, invitations, missed-message notifications, and digest emails.
Processed data categories: recipient email address, email subject and body content (which may include chat message content unless you disable message content in your notification settings), sending and delivery metadata, and delivery logs.
Purpose of processing: reliable delivery of account-related and notification emails for the chat service.
The legal basis for processing: performance of a contract (Art. 6 (1) b GDPR) for account and authentication emails, and consent (Art. 6 (1) a GDPR) for optional notification and digest emails, which you may disable at any time.
Data are transmitted: to the data processor Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA (https://resend.com).
Resend is SOC 2 Type II compliant and a Data Processing Addendum under Art. 28 GDPR is in force. Resend stores customer data in the United States, including email content and delivery logs, and uses Amazon Web Services as a sub-processor. Data are encrypted in transit (TLS) and at rest (AES-256). The transfer to the USA takes place on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, as the recipient participates in the Data Privacy Framework, supplemented by Standard Contractual Clauses.
Please read Resend's full privacy policy for more information.
7.2 Legal Requirements
We may disclose data when required by law or to protect the rights and safety of users.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Hashing and salting of passwords
- Regular security updates
- Access controls and authentication
- The full encryption of all backups made
8.1 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
- Notify affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms
- Document all breaches in accordance with GDPR requirements
9. Automated Decision-Making
We do not engage in automated decision-making that produces legal or similarly significant effects. Our anti-spam tools (hCaptcha) involve automated processing but:
- Do not produce significant effects on users
- Allow for easy appeals via email or Discord
We do not engage in profiling activities as defined under GDPR.
10. Children's Privacy
The CRW and the CRW Zulip are not intended for children under 16. We do not knowingly collect personal data from children. If we become aware of such collection, we will promptly delete the data and deactivate the associated account.
11. Cookies
We do not use tracking cookies. The wiki may use strictly necessary session cookies for authentication, which are deleted when you close your browser.
The CRW Zulip at zulip.consumerrights.wiki uses its own strictly necessary cookies: a session cookie to keep you signed in, and a CSRF token to protect form submissions against cross-site request forgery. The Zulip web application also uses browser local storage to cache messages and settings for performance. None of these are used for analytics, advertising, or cross-site tracking.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last Updated" date will always reflect the most recent version.
Previous versions of the policy can be seen by viewing the Privacy Policy page history.
13. Data Protection Queries
For any questions about this Privacy Policy or our data practices, please contact:
Data Protection Contact Email: [email protected] FULU Foundation FULU Foundation, Austin, Texas 78705
14. Complaint Rights
If you are unsatisfied with our response to your data protection query, you have the right to lodge a complaint with your local data protection authority. For EU residents, you can find your local authority at: https://edpb.europa.eu/about-edpb/board/members_en
---
By using the Consumer Rights Wiki or the CRW Zulip, you acknowledge that you have read and understood this Privacy Policy.