Muellners Foundation data protection policy for all subscribed membership activity.
UPDATED 27th Nov 2022
We are an open engineering based global community. Transparency to the processing and control of our member space data is paramount to us.
Beyond the following actions of voluntary members of the subscribed membership activity of the Foundation, this policy lays down the fundamental principles of safe processing and control of member's data:
a. Moderation of member messages on Foundation's public forums
b. Privacy Controls and triggers on Member's space such as 2 Factor login authentications, Invite only subscription, Actions on Inactive Member Profiles etc.
Website(s) and services, including connected third party services;
- https://finscale.biz, and any subdomains thereofhttps://open-bank.org, and any subdomains thereofhttps://fineract.net and any subdomains thereofserenity.vote, serenity.vin, serenity.wiki, serenity.pg, subnet.live and any subdomains thereofhttps://muellnersfoundation.net and any subdomains thereofhttps://muellnersfoundation.org and any subdomains thereofhttps://muellnersfoundation.info and any subdomains thereofhttps://opensource.exchange and any subdomains thereofhttps://openconstitution.ai and any subdomains thereof
- Third Party/Other uniform resource locators(URLs) where Forms or (both web browser and mobile) applications are hosted to collect confidential information and are generated through third party services(Slack, Discord, Facebook, Twitter, Linkedin, Discourse, Gitbook, Atlassian, Github, Google Calendar, Telegram Broadcast channels, Stripe), either directly shared to you by the Muellners on its own or public platforms of communication
- List of Third Party Legal Bodies, and 'Your' usage of the connected services is covered by this Data Protection framework.
Atlassian Inc. Google Inc. Slack Inc. Microsoft Inc. Github Inc. Gitbook Inc. Salesforce Inc. Civilised Discourse Construction Kit Inc. Canva Pty Ltd. Amazon Web Services Inc. Docusign Inc, Stripe Inc
These organisations support Open Constitution digital public goods and services, with their generous grants and Non for Profit programs.
Subscribed Membership is an 'invite only'
Following data is received by the Foundation to create a guest account:
- 1.Email account
- 2.Name, Phone no.
- 3.Social media accounts of members
Verified citizens of Open Constitution gain access to the "citizen", generally full rights to different communication channels of the Foundation.
Once, an account is created, subscribed member posts on both private and public forums of the Foundation's community.
Following types of data are classified for all membership activity:
- 1.Data attributable to Foundation's Public facing records on its public forums.
- 2.Data attributable to Foundation's ongoing project discussion and thus attributable to Foundation's public facing records in a documentation release.
- 3.Private and non public personal information(NPPI).
- 4.Explicit Personal Expression of a Member of the Foundation's community.
- 5.Third party data.
For all subscribed membership activity on the above communications system of Muellners Foundation:
a. The subscribed membership activity on any of the above communication platforms & member's privacy is protected and governed foremost by privacy laws of EU's GDPR & subsequently Internet privacy laws of Denmark.
b. The Internet based communication platforms, forums, that the Foundation uses, maintains and are licensed to Muellners Foundation, Denmark, either through a grant, strategic partnership or a purchase agreement, ratified by the Independent Boards.
Foundation also complies with relevant third party vendor license terms, as accorded by the service provider of the specific communications platform.
In accordance with Article 5 of GDPR,
a. Foundation is responsible for processing personal data in a lawful, fair and transparent way.
b. Foundation shall only process personal data for a limited and specific purpose.
c. Foundation shall only process the personal data that is necessary for its purposes.
d. Foundation shall ensure that personal data it is processing is accurate and up-to-date.
e. Foundation shall store personal data only for as long as is necessary.
f. Foundation shall keep personal data safe and confidential.
g. Foundation shall be accountable for how it processes personal data.
For the purposes of this policy; What does “processing” mean?
“collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction”
Foundation uses following criteria(s) as the lawful bases for processing its member’s data:
a. Consent - the member has freely permitted Foundation to process their data. The consents are digitally recorded e.g when a member joins Foundation slack or discord server, or signs up on a web url which takes the member to Foundation’s communication systems.
b. Contract - member has voluntarily signed up and joined the membership space, and Foundation needs to process their data to carry out and maintain subscribed membership activities, within the Foundation’s guidelines.
c. Legal obligation - the law requires the Foundation to process the member's data in a particular way: i.e for records, audit, moderation of hatred, free speech on its public forums and community space.
d. Legitimate interest - Foundation is processing a member's data to protect Foundation's statutory compliance with the laws governing the Foundation’s statutory existence in accordance with the business laws of Denmark.
Data Protection Officer(s): Voluntarily organised Foundation members appoint moderators from the community who uphold the community’s Code of Conduct.
List of Other Third Party Data Processors and link to their data processing agreements, whose compliance is binding on the Foundation, when the Foundation accesses the license to use these third party services:
- 4.IBM, Inc.
- 5.Atlassian, Inc.
- 6.Zoho Corporation Pvt Ltd, India
- 7.Cloudflare, Inc.
- 8.Microsoft Inc.
- 9.Github Inc.
- 10.AWS Inc.
- 11.Civilized Discourse Construction Kit, Inc.
- 12.Docusign Inc.
- 13.Salesforce Inc.
- 14.Stripe Inc.
Foundation may at times act as a data processor to another Data Controller such as an Open Constitution Partner organisation. If your organisation is the partner in the Open Constitution Program, please read the Data Protection clauses in the partner agreement that covers the rights of your organisation.
It is important to note that when members from your organisation sign up independently on the Foundation’s member space, their data protection is governed exclusively by this data protection policy.