Jump to content

Consumer Rights Wiki:Privacy policy

Consumer Rights Wiki Privacy Policy

Last Updated: September 24, 2026

This Privacy Policy explains how the Consumer Rights Wiki ("CRW," "we," "us," or "our"), our service providers, and our partners, collect, use, share, and protect Personally Identifying Information (PII), and other data, in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

This policy covers the wiki at consumerrights.wiki, and the CRW Zulip (our self-hosted community chat server at zulip.consumerrights.wiki). The CRW Zulip runs the open-source Zulip server software on infrastructure we operate; the FULU Foundation is the data controller for it.

1. Data Controller

The data controller responsible for your personal data is:

FULU Foundation Fulu Foundation, Austin, Texas 78705 Email: [email protected]

We process personal data based on the following legal grounds under Article 6 of the GDPR:

Contract (Article 6(1)(b)) Data used for:

  • Account registration and management
  • User authentication and login
  • Enabling wiki contributions and editing
  • Chat account registration, authentication, and delivery of messages on the CRW Zulip

Legitimate Interests (Article 6(1)(f)) Data used for:

  • IP address processing for security and anti-spam protection
  • Privacy-preserving analytics through Plausible Analytics
  • Maintaining the integrity and security of the wiki
  • Prevention of abuse and vandalism
  • Moderation of the CRW Zulip and prevention of abuse, spam, and harassment

Consent (Article 6(1)(a)) Data used for:

  • Optional CRW Zulip profile information you choose to provide (avatar, custom profile fields)
  • Optional email notifications and digest emails, which you can disable at any time


2.1 Data Minimization

We adhere to the principle of data minimization, collecting only the personal data that is necessary for the specific purposes outlined in this policy. We do not collect excessive or irrelevant data.

2.2 Special Categories of Data

We do not intentionally collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation). If such data is inadvertently collected through user-generated content, including messages posted on the CRW Zulip, it is not processed by us for any purpose.


3. PII and other data We Collect

3.1 Account Information

When you create an account, we collect:

  • Username - Stored indefinitely, or until account deletion request
  • Email address - Stored indefinitely, or until account deletion request
  • Hashed and salted password - Stored indefinitely, or until account deletion request

3.2 Contribution Data

  • Edit history and contributions - Stored indefinitely as necessary for wiki functionality and attribution under legitimate interest
  • Timestamps of edits - Stored indefinitely as part of contribution history
  • Discussion posts and comments - Stored indefinitely as part of wiki content

3.3 Technical Data

  • IP addresses - Stored in server logs and backups for 90 days for security purposes, and indefinitely in edit history for attribution and anti-vandalism purposes
  • Browser type and version - Processed temporarily for technical compatibility and for generation of anonymized analytics
  • Device information - Processed temporarily for technical compatibility and for generation of anonymized analytics

3.4 Analytics Data (via Plausible Analytics)

Our self-hosted Plausible Analytics instance collects:

  • Page views and navigation patterns
  • Referrer information
  • Country of origin (derived from IP addresses, which are immediately discarded)
  • Device type and browser information

Important: Plausible does not use cookies or persistent identifiers, or create profiles. All data is aggregated and anonymous.

3.5 Security Services

hCaptcha processes the following when you interact with protected forms:

  • Technical connection data (IP address, timestamp)
  • Interaction data with the captcha interface

CloudFlare processes the following when you connect to the site:

  • Technical connection data (Traffic routing data, HTTP request metadata)

3.6 CRW Zulip Chat Data

The CRW Zulip is a separate service from the wiki and requires its own account. Data is stored on infrastructure we operate.

Account data:

  • Email address - Stored until account deletion request
  • Full name / display name - Stored until account deletion request
  • Hashed password - Stored until account deletion request (where password authentication is used)
  • Optional profile data (avatar, custom profile fields, time zone) - Stored until removed by you or account deletion
  • Account role and status (owner, administrator, moderator, member, guest) - Stored until account deletion request

Message and interaction data:

  • Message content in public channels, private channels, and direct messages, including topics, timestamps, and edit history - Retained per section 4.1
  • Uploaded files and images - Retained per section 4.1
  • Emoji reactions, polls, server-synced drafts, and scheduled messages
  • Read state, read receipts, starred messages, and alert words
  • Presence data ("last active" time) and typing indicators
  • User status (status text and emoji)

Technical and log data:

  • IP addresses - Stored in server logs for 30 days for security and anti-abuse purposes
  • Browser type and User Agent - Processed for session security and technical compatibility
  • Session data and API keys - Stored while the session or key is active
  • Audit logs recording account and configuration changes - Retained per section 4.1
  • Aggregate usage statistics (message and active-user counts)

Important: Chat messages you send are visible to other users according to the channel type. As with any self-hosted chat system, server and organization administrators may be able to access private channel content and direct messages through their administrative access to the server. Do not share sensitive information in chat that you would not want an administrator to be able to access.

4. Data Retention and Backup Schedule

4.1 Primary Data Retention

Data Type Retention Period Justification
Account data (username, email, hashed and salted password) Indefinitely until deletion request Necessary to perform contract
Contribution history Indefinitely Legitimate interest in maintaining wiki integrity and attribution
IP addresses in server logs 30 days Security and anti-abuse purposes
IP addresses in edit history Indefinitely until deletion request Attribution and anti-vandalism
Analytics data (aggregated) Indefinitely Legitimate interest in service improvement
Zulip account data (email, display name, hashed password, profile) Indefinitely until deletion request Necessary to perform contract
Zulip message content and uploads Indefinitely Legitimate interest in maintaining community discussion history
Deleted Zulip messages (archived) 30 days, then permanently deleted Recovery from accidental or malicious deletion
Zulip IP addresses in server logs 30 days Security and anti-abuse purposes
Zulip audit logs (account and configuration changes) Indefinitely Legitimate interest in moderation and security accountability

Note on Zulip deletion: When a message is deleted, whether by a user or by an automatic retention policy, it is moved to an archive where an administrator can restore it for 30 days, after which it is permanently deleted. Deactivating a Zulip account prevents login but does not by itself delete messages or files that account previously sent; see section 6.3.

4.2 Backup and Recovery Schedule

Backup Type Frequency Retention Period Data Included
Daily backups Every 24 hours 7 days Full database, user accounts, contribution history, configuration
Monthly backups 1st of each month 6 months Full database, user accounts, contribution history, configuration
Server logs Continuous 30 days rolling Access logs, error logs, security logs

Important Notes on Backups:

  • All backups are fully encrypted
  • Deleted data may persist in backups until the backup retention period expires
  • Maximum possible retention through backups: 6 months for monthly backups
  • After backup expiration, data is permanently deleted unless specifically retained under section 4.1

5. International Data Transfers

Our servers are hosted by Hetzner in the United States. This constitutes an international data transfer from the EU/EEA. We ensure appropriate safeguards through:

  • EU-US Data Privacy Framework: Our hosting providers participate in the EU-US Data Privacy Framework, ensuring adequate protection for your personal data
  • hCaptcha transfers: Data may be transferred to Intuition Machines, Inc. in the USA under the EU-US Data Privacy Framework (European Commission adequacy decision C(2023) 4745)
  • Resend transfers: Email addresses and email content sent from the CRW Zulip are processed and stored in the United States by Resend, Inc., under the EU-US Data Privacy Framework and Standard Contractual Clauses, and are covered by a Data Processing Addendum

6. Your Rights Under GDPR

You have the following rights regarding your personal data:

6.1 Right of Access (Article 15)

You can request a copy of your personal data we hold.

6.2 Right to Rectification (Article 16)

You can request correction of inaccurate personal data.

6.3 Right to Erasure (Article 17)

You can request deletion of your personal data, subject to legal obligations and legitimate interests (e.g., contribution history may be retained for attribution). On the CRW Zulip you can delete your own messages and uploads where permitted, and you can request account deactivation or deletion by contacting us. Note that messages you sent to other users may remain visible to those recipients, and content quoted or replied to by others may persist in their messages.

6.4 Right to Restriction (Article 18)

You can request restriction of processing in certain circumstances.

6.5 Right to Object (Article 21)

You can object to processing based on legitimate interests.

6.6 Right to Data Portability (Article 20)

You can request your data in a structured, machine-readable format.

6.7 Right to Lodge a Complaint

You have the right to lodge a complaint with your local supervisory authority.

To exercise any of these rights, contact us at: [email protected]

7. Data Sharing and Third Parties

We do not sell or rent your personal data. We share data only with:

7.1 Service Providers (Data Processors)

Service Provider Data Types Processed Location Purpose
Hetzner Server infrastructure, web application data, user data, backups US/EU Primary hosting infrastructure
CloudFlare Analytics data, traffic patterns, security logs, attack mitigation data USA DDoS protection, CDN, security analytics
hCaptcha IP addresses, interaction data USA Spam prevention
Resend Email addresses, email subject and content of CRW Zulip notifications USA Transactional email delivery for the CRW Zulip

7.1.1 Privacy statement for the service hCaptcha

When accessing some sub-services of our website, additional information is processed.

Processed data categories: technical connection data of the server access (IP address, date, time, requested page, browser information), data about the use of the website, and the logging of clicks on individual elements.

Purpose of processing: avoid non-human and automated input.

The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).

Legitimate interests: strong economic interest in safe and functioning operation of the technical systems.

Data are transmitted: to the data processor Intuition Machines, Inc., 1065 SW 8th St #704, Miami FL 33130, USA (https://www.hcaptcha.com).

This may also mean a transfer of personal data to a country outside the European Union. The data are transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).

Please read the hCaptcha's full privacy policy for more information.

7.1.2 Privacy statement for the service Hetzner

Our website infrastructure and web application are hosted on servers provided by Hetzner.

Processed data categories: Web application data, server infrastructure data, technical connection data (IP address, date, time, requested page, browser information), server configuration and usage metrics, network traffic data.

Purpose of processing: provision of hosting infrastructure for the web application, ensuring system availability and performance.

The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).

Legitimate interests: strong economic interest in reliable and functioning operation of the technical systems and infrastructure.

Data are transmitted: to the data processor Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (https://www.hetzner.com).

Hetzner operates servers in both the European Union and the United States. When US servers are used, data transfers are covered under standard contractual clauses.

Please read Hetzner's full privacy policy for more information.

7.1.3 Privacy statement for the service CloudFlare

Our website uses CloudFlare services for content delivery, security, and performance optimization. CloudFlare processes analytics and security-related data, but does not have access to user account data or personal information stored in our databases.

Processed data categories: Traffic routing data, HTTP request metadata (HTTP headers, user agent, query-string, path, host, HTTP method, HTTP version, TLS cipher version), request and error rates, DDoS attack patterns and mitigation data, aggregated analytics data about website usage, security threat intelligence data.

Purpose of processing: content delivery network (CDN) services, DDoS attack protection and mitigation, traffic routing and optimization, security monitoring and threat detection, performance analytics to improve website speed and user experience.

The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).

Legitimate interests: strong economic interest in secure, reliable, and functioning operation of the website, protection against cyber attacks, and optimization of service performance.

Data are transmitted: to the data processor Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (https://www.cloudflare.com).

This may also mean a transfer of personal data to a country outside the European Union. The data are transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).

Please read Cloudflare's full privacy policy for more information.

7.1.4 Privacy statement for the service Resend

The CRW Zulip uses Resend to deliver transactional email, such as account confirmations, password resets, invitations, missed-message notifications, and digest emails.

Processed data categories: recipient email address, email subject and body content (which may include chat message content unless you disable message content in your notification settings), sending and delivery metadata, and delivery logs.

Purpose of processing: reliable delivery of account-related and notification emails for the chat service.

The legal basis for processing: performance of a contract (Art. 6 (1) b GDPR) for account and authentication emails, and consent (Art. 6 (1) a GDPR) for optional notification and digest emails, which you may disable at any time.

Data are transmitted: to the data processor Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA (https://resend.com).

Resend is SOC 2 Type II compliant and a Data Processing Addendum under Art. 28 GDPR is in force. Resend stores customer data in the United States, including email content and delivery logs, and uses Amazon Web Services as a sub-processor. Data are encrypted in transit (TLS) and at rest (AES-256). The transfer to the USA takes place on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, as the recipient participates in the Data Privacy Framework, supplemented by Standard Contractual Clauses.

Please read Resend's full privacy policy for more information.

We may disclose data when required by law or to protect the rights and safety of users.

8. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Hashing and salting of passwords
  • Regular security updates
  • Access controls and authentication
  • The full encryption of all backups made

8.1 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
  • Notify affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms
  • Document all breaches in accordance with GDPR requirements

9. Automated Decision-Making

We do not engage in automated decision-making that produces legal or similarly significant effects. Our anti-spam tools (hCaptcha) involve automated processing but:

  • Do not produce significant effects on users
  • Allow for easy appeals via email or Discord

We do not engage in profiling activities as defined under GDPR.

10. Children's Privacy

The CRW and the CRW Zulip are not intended for children under 16. We do not knowingly collect personal data from children. If we become aware of such collection, we will promptly delete the data and deactivate the associated account.


11. Cookies

We do not use tracking cookies. The wiki may use strictly necessary session cookies for authentication, which are deleted when you close your browser.

The CRW Zulip at zulip.consumerrights.wiki uses its own strictly necessary cookies: a session cookie to keep you signed in, and a CSRF token to protect form submissions against cross-site request forgery. The Zulip web application also uses browser local storage to cache messages and settings for performance. None of these are used for analytics, advertising, or cross-site tracking.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last Updated" date will always reflect the most recent version.

Previous versions of the policy can be seen by viewing the Privacy Policy page history.

13. Data Protection Queries

For any questions about this Privacy Policy or our data practices, please contact:

Data Protection Contact Email: [email protected] FULU Foundation FULU Foundation, Austin, Texas 78705


14. Complaint Rights

If you are unsatisfied with our response to your data protection query, you have the right to lodge a complaint with your local data protection authority. For EU residents, you can find your local authority at: https://edpb.europa.eu/about-edpb/board/members_en

---

By using the Consumer Rights Wiki or the CRW Zulip, you acknowledge that you have read and understood this Privacy Policy.