Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Product addition: GitLab #85

Closed
wants to merge 1 commit into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file added icons/gitlab.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
58 changes: 58 additions & 0 deletions products/gitlab.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
name = "GitLab"
description = "A web-based DevOps tool that provides a Git-respository manager."
slug = "gitlab"
hostnames = ["gitlab.com"]
sources = ["https://about.gitlab.com/privacy/", "https://about.gitlab.com/privacy/privacy-compliance/"]
contributors = ["Deivedux"]

[rubric.behavioral-marketing]
value = "yes-opt-out"
citations = [
"We may use your personal information, with your consent, for specific purposes such as marketing, surveys, and research.",
"You may opt-out of email marketing by clicking the “unsubscribe” link located at the bottom of any email you receive or by visiting our preference center and unsubscribing.",
"If you wish to opt-out of interest-based advertising, please visit the Cookie Policy to see your options."
]

[rubric.data-breaches]
value = "no"
notes = ["The policy does not specify a data breach protocol."]
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Via GDPR page:

Individuals must be directly notified of security breaches that affect their personal data within 72 hours.

Supervisory authorities must be advised of security breaches that present a risk to the rights and freedom of individuals within 72 hours. The general public must be immediately alerted of security breaches that are sufficiently serious.

Copy link
Contributor Author

@Deivedux Deivedux Jun 17, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The GDPR is a thing that always affects all companies that operate in EU, but it doesn't say that they treat non-EU citizens the same way, no? My idea was to rate the privacy policy as it is, considering that PrivacySpy's design makes people aware of the GDPR to begin with.


[rubric.data-collection-reasoning]
value = "mostly"
notes = ["The policy lists most, but not explicitly all reasons for collecting personal data."]

[rubric.data-deletion]
value = "no"
citations = ["Please note that due to the open source nature of our Services, we may retain limited personal information indefinitely in order to provide a transactional history. For example, if you provide your information in connection with a blog post or comment, we may display that information even if you have deleted your account as we do not automatically delete community posts."]
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could arguably be yes-automated, as you can delete your personal data; although by nature of Git, as the quote regards, it's much harder to remove things like commit histories.


[rubric.history]
value = "last-modified"
citations = ["GitLab may change its Privacy Policy from time to time. When we do, we will update the date at the top of this Policy."]
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A changelog is available in the form of a Git history here


[rubric.law-enforcement]
value = "reasonable"
citations = ["GitLab may disclose personal information or other information we collect about you to law enforcement if required in response to a valid subpoena, court order, search warrant, a similar government order, or when we believe in good faith that disclosure is necessary to comply with our legal obligations, to protect our property or rights, or those of third parties or the public at large."]

[rubric.list-collected]
value = "generally"
notes = ["The policy lists the data they collect, though uses ambiguous wordings like \"such as\"."]

[rubric.noncritical-purposes]
value = "no"
notes = ["You may limit their use of your data, but not whether they are collected."]

[rubric.revision-notify]
value = "yes"
citations = ["If we decide to make a significant change to our Privacy Policy, we will post a notice of the update on the homepage of our Website. We may also provide notification via email of any material changes to our Privacy Policy."]

[rubric.security]
value = "somewhat"
citations = ["We work hard to protect your personal information. We employ administrative, technical, and physical security controls where appropriate, to protect your information."]
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Audited by Bitsight. More info here and here


[rubric.third-party-access]
value = "no"
notes = ["They're not sharing personal information with third-parties."]
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Data is shared with third parties who provide sales, consulting, support and technical services for our Services. Where permitted and with your consent (if required), we may share your data with these partners and resellers.


[rubric.third-party-collection]
value = "yes"
citations = ["We may also receive information about you from third parties such as vendors, resellers, partners, or affiliates. For example, we receive information from our resellers about you and your orders, or we may supplement the data we collect with demographic information licensed from third parties in order to personalize the Services and our offers to you."]