-
-
Notifications
You must be signed in to change notification settings - Fork 30
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Product addition: GitLab #85
Conversation
Thanks for submitting this pull request. @ibarakaiev has been assigned to review these changes, provide feedback, and determine next steps. If you haven't already, please ensure your changes pass all the automated tests. Look in the "Checks" box below and "Files changed" tab to see test results. To learn about the PrivacySpy contribution process, check out the contribution guide.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry for the hot while for a review. Here's my thoughts!
|
||
[rubric.data-breaches] | ||
value = "no" | ||
notes = ["The policy does not specify a data breach protocol."] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Via GDPR page:
Individuals must be directly notified of security breaches that affect their personal data within 72 hours.
Supervisory authorities must be advised of security breaches that present a risk to the rights and freedom of individuals within 72 hours. The general public must be immediately alerted of security breaches that are sufficiently serious.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The GDPR is a thing that always affects all companies that operate in EU, but it doesn't say that they treat non-EU citizens the same way, no? My idea was to rate the privacy policy as it is, considering that PrivacySpy's design makes people aware of the GDPR to begin with.
|
||
[rubric.data-deletion] | ||
value = "no" | ||
citations = ["Please note that due to the open source nature of our Services, we may retain limited personal information indefinitely in order to provide a transactional history. For example, if you provide your information in connection with a blog post or comment, we may display that information even if you have deleted your account as we do not automatically delete community posts."] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This could arguably be yes-automated
, as you can delete your personal data; although by nature of Git, as the quote regards, it's much harder to remove things like commit histories.
|
||
[rubric.history] | ||
value = "last-modified" | ||
citations = ["GitLab may change its Privacy Policy from time to time. When we do, we will update the date at the top of this Policy."] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
A changelog is available in the form of a Git history here
|
||
[rubric.security] | ||
value = "somewhat" | ||
citations = ["We work hard to protect your personal information. We employ administrative, technical, and physical security controls where appropriate, to protect your information."] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
|
||
[rubric.third-party-access] | ||
value = "no" | ||
notes = ["They're not sharing personal information with third-parties."] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Data is shared with third parties who provide sales, consulting, support and technical services for our Services. Where permitted and with your consent (if required), we may share your data with these partners and resellers.
Type of pull request: product addition
Related issues: #73