Privacy Policy
Draft
The operator's details are not filled in yet (OPERATOR_NAME, OPERATOR_ADDRESS, OPERATOR_EMAIL). Set them in the server settings. The site must not go live like this.
Version 1. Last updated .
DRAFT: This text was written as a starting point. A lawyer must review it before the site goes live. Remove this line when it has been reviewed.
Who we are
Open Talk is a small social network where people write short public posts. The service is run by:
- [OPERATOR_NAME not set]
- [OPERATOR_ADDRESS not set]
- Email: [OPERATOR_EMAIL not set]
In this policy "we" means this operator. We are the controller of your personal data in the sense of the General Data Protection Regulation (GDPR).
What this policy covers
This policy explains which personal data we collect when you visit or use https://open-talk.cz, why we collect it, how long we keep it, and which rights you have. You can read the site without an account. Most of what follows applies when you create an account.
What we collect, and why
Data you give us
- Handle (your user name). It is public. You cannot change it later.
- Email address. It is private. We use it as a login name and, if we switch on email features, to verify your address and to reset your password.
- Password. We never store it. We store only a one-way hash (argon2id).
- Profile: your bio, a link to your website, and a profile picture. All of it is public. We remove hidden metadata (such as location data) from pictures.
- Posts and replies. They are public. Anyone on the internet, including search engines, can read them.
- Reports you send about other people's content. Only our admins can see who sent a report.
- Your confirmation that you are at least 16 years old, and the version of the terms and privacy policy you accepted.
Data we create
- The date you registered. It is public.
- Sessions: a random code in a cookie that keeps you logged in, and its time of last use.
- If an admin suspends or removes content or your account, a record of what was done and the reason. You are shown the reason.
- An audit log of admin actions.
Data from your browser
- Server logs: when you visit, our server (and the web server or hosting platform in front of it) writes a log line with your IP address, the time, the page you asked for, and the answer that was given. We use this to keep the service secure and working. We keep these logs for at most 30 days. We do not store IP addresses in our database.
We do not use advertising, analytics, tracking pixels or third-party scripts. We do not sell your data. We do not make decisions about you by automated means that have legal effects.
Why we may use your data (legal basis)
- To provide the service you asked for, which is your account and the posts you publish (GDPR Article 6(1)(b), contract).
- To keep the site secure, stop abuse and spam, and handle reports (Article 6(1)(f), our legitimate interest in running a safe service).
- To follow the law, including rules for hosting services about illegal content and about explaining moderation decisions (Article 6(1)(c), legal obligation).
We do not rely on your consent for anything, so there is nothing to withdraw.
Who receives your data
- Everyone, for public data: your handle, bio, website, picture, registration date, posts and replies.
- Our hosting provider, who runs the servers for us and may see the data stored there. They act on our instructions (processor).
- An email service provider, only if we switch on email features. They deliver messages for us (processor).
- Authorities, if the law requires us to share data.
Where the hosting provider or email provider is outside the European Economic Area, we make sure the transfer is covered by a legal mechanism such as an adequacy decision or standard contractual clauses.
Cookies
We use only two cookies, and both are strictly necessary. For this reason the law does not require a consent banner.
- A session cookie, which keeps you logged in.
- A security cookie, which protects the forms on this site against attacks from other websites.
We set no other cookies.
How long we keep data
- Account data: until you delete your account.
- When you delete your account (Settings, Delete account) or an admin deletes it: we erase your email, password hash, bio, website and picture, we end all sessions, and we remove your replies. Your posts are emptied: the text and your name are removed, but the empty post stays so that replies by other people keep their place. Your handle stays reserved, so nobody can pretend to be you later.
- Server logs: at most 30 days.
- Audit log of admin actions and reports: as long as needed to show that moderation was fair. They do not contain the text of removed content.
- Backups: the operator may keep database backups. Deleted data can remain in an old backup until that backup is deleted or replaced. If a backup is restored, deletion requests made after it was created are carried out again.
Your rights
Under the GDPR you have the right to:
- Access your data. Settings has a button to download your data.
- Correct your data. You can edit your profile, password and email in Settings.
- Erase your data. You can delete your account in Settings.
- Receive your data in a common format (the same download, as JSON).
- Object to or ask us to restrict some processing. Write to us.
- Complain to a data protection authority, for example in the EU country where you live or work.
To use a right that Settings does not cover, write to [OPERATOR_EMAIL not set]. We answer within one month.
Children
You must be at least 16 years old to use Open Talk. If we learn that someone younger has an account, we delete it.
Security
We protect your data with measures such as hashed passwords, encrypted connections, restricted admin access and limited log retention. No service is perfectly secure. If a breach puts your rights at risk, we will tell you and the authorities as the law requires.
Changes to this policy
We keep every version of this policy. When we make a big change, we ask you to accept the new version the next time you log in. The date at the top of the page shows when the current version took effect.
Contact
[OPERATOR_NAME not set], [OPERATOR_ADDRESS not set], [OPERATOR_EMAIL not set]. You can also use the Contact page.