Home Wiki

Consumer Rights Wiki:Privacy policy

View on consumerrights.wiki ↗

Contents34
  1. Consumer Rights Wiki Privacy Policy
  2. 1. Data Controller
  3. 2. Legal Basis for Processing
  4. 2.1 Data Minimization
  5. 2.2 Special Categories of Data
  6. 3. PII and other data We Collect
  7. 3.1 Account Information
  8. 3.2 Contribution Data
  9. 3.3 Technical Data
  10. 3.4 Analytics Data (via Plausible Analytics)
  11. 3.5 Security Services
  12. 4. Data Retention and Backup Schedule
  13. 4.1 Primary Data Retention
  14. 4.2 Backup and Recovery Schedule
  15. 5. International Data Transfers
  16. 6. Your Rights Under GDPR
  17. 6.1 Right of Access (Article 15)
  18. 6.2 Right to Rectification (Article 16)
  19. 6.3 Right to Erasure (Article 17)
  20. 6.4 Right to Restriction (Article 18)
  21. 6.5 Right to Object (Article 21)
  22. 6.6 Right to Data Portability (Article 20)
  23. 6.7 Right to Lodge a Complaint
  24. 7. Data Sharing and Third Parties
  25. 7.1 Service Providers (Data Processors)
  26. 7.2 Legal Requirements
  27. 8. Data Security
  28. 8.1 Data Breach Notification
  29. 9. Automated Decision-Making
  30. 10. Children's Privacy
  31. 11. Cookies
  32. 12. Changes to This Policy
  33. 13. Data Protection Queries
  34. 14. Complaint Rights

Consumer Rights Wiki Privacy Policy

Last Updated: January 20, 2026

This Privacy Policy explains how the Consumer Rights Wiki ("CRW," "we," "us," or "our"), our service providers, and our partners, collect, use, share, and protect Personally Identifying Information (PII), and other data, in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Data Controller

The data controller responsible for your personal data is:

FULU Foundation Fulu Foundation, Austin, Texas 78705 Email: data@consumerrights.wiki

We process personal data based on the following legal grounds under Article 6 of the GDPR:

Contract (Article 6(1)(b)) Data used for:

  • Account registration and management
  • User authentication and login
  • Enabling wiki contributions and editing

Legitimate Interests (Article 6(1)(f)) Data used for:

  • IP address processing for security and anti-spam protection
  • Privacy-preserving analytics through Plausible Analytics
  • Maintaining the integrity and security of the wiki
  • Prevention of abuse and vandalism

2.1 Data Minimization

We adhere to the principle of data minimization, collecting only the personal data that is necessary for the specific purposes outlined in this policy. We do not collect excessive or irrelevant data.

2.2 Special Categories of Data

We do not intentionally collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation). If such data is inadvertently collected through user-generated content, it is not processed by us for any purpose.

3. PII and other data We Collect

3.1 Account Information

When you create an account, we collect:

  • Username - Stored indefinitely, or until account deletion request
  • Email address - Stored indefinitely, or until account deletion request
  • Hashed and salted password - Stored indefinitely, or until account deletion request

3.2 Contribution Data

  • Edit history and contributions - Stored indefinitely as necessary for wiki functionality and attribution under legitimate interest
  • Timestamps of edits - Stored indefinitely as part of contribution history
  • Discussion posts and comments - Stored indefinitely as part of wiki content

3.3 Technical Data

  • IP addresses - Stored in server logs and backups for 90 days for security purposes, and indefinitely in edit history for attribution and anti-vandalism purposes
  • Browser type and version - Processed temporarily for technical compatibility and for generation of anonymized analytics
  • Device information - Processed temporarily for technical compatibility and for generation of anonymized analytics

3.4 Analytics Data (via Plausible Analytics)

Our self-hosted Plausible Analytics instance collects:

  • Page views and navigation patterns
  • Referrer information
  • Country of origin (derived from IP addresses, which are immediately discarded)
  • Device type and browser information

Important: Plausible does not use cookies or persistent identifiers, or create profiles. All data is aggregated and anonymous.

3.5 Security Services

hCaptcha processes the following when you interact with protected forms:

  • Technical connection data (IP address, timestamp)
  • Interaction data with the captcha interface

CloudFlare processes the following when you connect to the site:

  • Technical connection data (Traffic routing data, HTTP request metadata)

4. Data Retention and Backup Schedule

4.1 Primary Data Retention

Data Type Retention Period Justification
Account data (username, email, hashed and salted password) Indefinitely until deletion request Necessary to perform contract
Contribution history Indefinitely Legitimate interest in maintaining wiki integrity and attribution
IP addresses in server logs 30 days Security and anti-abuse purposes
IP addresses in edit history Indefinitely until deletion request Attribution and anti-vandalism
Analytics data (aggregated) Indefinitely Legitimate interest in service improvement

4.2 Backup and Recovery Schedule

Backup Type Frequency Retention Period Data Included
Daily backups Every 24 hours 7 days Full database, user accounts, contribution history, configuration
Monthly backups 1st of each month 6 months Full database, user accounts, contribution history, configuration
Server logs Continuous 30 days rolling Access logs, error logs, security logs

Important Notes on Backups:

  • All backups are fully encrypted
  • Deleted data may persist in backups until the backup retention period expires
  • Maximum possible retention through backups: 6 months for monthly backups
  • After backup expiration, data is permanently deleted unless specifically retained under section 4.1

5. International Data Transfers

Our servers are hosted by Hetzner in the United States. This constitutes an international data transfer from the EU/EEA. We ensure appropriate safeguards through:

  • EU-US Data Privacy Framework: Our hosting providers participate in the EU-US Data Privacy Framework, ensuring adequate protection for your personal data
  • hCaptcha transfers: Data may be transferred to Intuition Machines, Inc. in the USA under the EU-US Data Privacy Framework (European Commission adequacy decision C(2023) 4745)

6. Your Rights Under GDPR

You have the following rights regarding your personal data:

6.1 Right of Access (Article 15)

You can request a copy of your personal data we hold.

6.2 Right to Rectification (Article 16)

You can request correction of inaccurate personal data.

6.3 Right to Erasure (Article 17)

You can request deletion of your personal data, subject to legal obligations and legitimate interests (e.g., contribution history may be retained for attribution).

6.4 Right to Restriction (Article 18)

You can request restriction of processing in certain circumstances.

6.5 Right to Object (Article 21)

You can object to processing based on legitimate interests.

6.6 Right to Data Portability (Article 20)

You can request your data in a structured, machine-readable format.

6.7 Right to Lodge a Complaint

You have the right to lodge a complaint with your local supervisory authority.

To exercise any of these rights, contact us at: data@consumerrights.wiki

7. Data Sharing and Third Parties

We do not sell or rent your personal data. We share data only with:

7.1 Service Providers (Data Processors)

Service Provider Data Types Processed Location Purpose
Hetzner Server infrastructure, web application data, user data, backups US/EU Primary hosting infrastructure
CloudFlare Analytics data, traffic patterns, security logs, attack mitigation data USA DDoS protection, CDN, security analytics
hCaptcha IP addresses, interaction data USA Spam prevention

7.1.1 Privacy statement for the service hCaptcha

When accessing some sub-services of our website, additional information is processed.

Processed data categories: technical connection data of the server access (IP address, date, time, requested page, browser information), data about the use of the website, and the logging of clicks on individual elements.

Purpose of processing: avoid non-human and automated input.

The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).

Legitimate interests: strong economic interest in safe and functioning operation of the technical systems.

Data are transmitted: to the data processor Intuition Machines, Inc., 1065 SW 8th St #704, Miami FL 33130, USA (https://www.hcaptcha.com).

This may also mean a transfer of personal data to a country outside the European Union. The data are transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).

Please read the hCaptcha's full privacy policy for more information.

7.1.2 Privacy statement for the service Hetzner

Our website infrastructure and web application are hosted on servers provided by Hetzner.

Processed data categories: Web application data, server infrastructure data, technical connection data (IP address, date, time, requested page, browser information), server configuration and usage metrics, network traffic data.

Purpose of processing: provision of hosting infrastructure for the web application, ensuring system availability and performance.

The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).

Legitimate interests: strong economic interest in reliable and functioning operation of the technical systems and infrastructure.

Data are transmitted: to the data processor Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (https://www.hetzner.com).

Hetzner operates servers in both the European Union and the United States. When US servers are used, data transfers are covered under standard contractual clauses.

Please read Hetzner's full privacy policy for more information.

7.1.3 Privacy statement for the service CloudFlare

Our website uses CloudFlare services for content delivery, security, and performance optimization. CloudFlare processes analytics and security-related data, but does not have access to user account data or personal information stored in our databases.

Processed data categories: Traffic routing data, HTTP request metadata (HTTP headers, user agent, query-string, path, host, HTTP method, HTTP version, TLS cipher version), request and error rates, DDoS attack patterns and mitigation data, aggregated analytics data about website usage, security threat intelligence data.

Purpose of processing: content delivery network (CDN) services, DDoS attack protection and mitigation, traffic routing and optimization, security monitoring and threat detection, performance analytics to improve website speed and user experience.

The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).

Legitimate interests: strong economic interest in secure, reliable, and functioning operation of the website, protection against cyber attacks, and optimization of service performance.

Data are transmitted: to the data processor Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (https://www.cloudflare.com).

This may also mean a transfer of personal data to a country outside the European Union. The data are transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).

Please read Cloudflare's full privacy policy for more information.

We may disclose data when required by law or to protect the rights and safety of users.

8. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Hashing and salting of passwords
  • Regular security updates
  • Access controls and authentication
  • The full encryption of all backups made

8.1 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
  • Notify affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms
  • Document all breaches in accordance with GDPR requirements

9. Automated Decision-Making

We do not engage in automated decision-making that produces legal or similarly significant effects. Our anti-spam tools (hCaptcha) involve automated processing but:

  • Do not produce significant effects on users
  • Allow for easy appeals via email or Discord

We do not engage in profiling activities as defined under GDPR.

10. Children's Privacy

The CRW is not intended for children under 16. We do not knowingly collect personal data from children. If we become aware of such collection, we will promptly delete the data.

11. Cookies

We do not use tracking cookies. The wiki may use strictly necessary session cookies for authentication, which are deleted when you close your browser.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last Updated" date will always reflect the most recent version.

Previous versions of the policy can be seen by viewing the Privacy Policy page history.

13. Data Protection Queries

For any questions about this Privacy Policy or our data practices, please contact:

Data Protection Contact Email: data@consumerrights.wiki FULU Foundation FULU Foundation, Austin, Texas 78705


14. Complaint Rights

If you are unsatisfied with our response to your data protection query, you have the right to lodge a complaint with your local data protection authority. For EU residents, you can find your local authority at: https://edpb.europa.eu/about-edpb/board/members_en

---

By using the Consumer Rights Wiki, you acknowledge that you have read and understood this Privacy Policy.

Filed under