Consumer Rights Wiki:Privacy policy
Contents34
- Consumer Rights Wiki Privacy Policy
- 1. Data Controller
- 2. Legal Basis for Processing
- 2.1 Data Minimization
- 2.2 Special Categories of Data
- 3. PII and other data We Collect
- 3.1 Account Information
- 3.2 Contribution Data
- 3.3 Technical Data
- 3.4 Analytics Data (via Plausible Analytics)
- 3.5 Security Services
- 4. Data Retention and Backup Schedule
- 4.1 Primary Data Retention
- 4.2 Backup and Recovery Schedule
- 5. International Data Transfers
- 6. Your Rights Under GDPR
- 6.1 Right of Access (Article 15)
- 6.2 Right to Rectification (Article 16)
- 6.3 Right to Erasure (Article 17)
- 6.4 Right to Restriction (Article 18)
- 6.5 Right to Object (Article 21)
- 6.6 Right to Data Portability (Article 20)
- 6.7 Right to Lodge a Complaint
- 7. Data Sharing and Third Parties
- 7.1 Service Providers (Data Processors)
- 7.2 Legal Requirements
- 8. Data Security
- 8.1 Data Breach Notification
- 9. Automated Decision-Making
- 10. Children's Privacy
- 11. Cookies
- 12. Changes to This Policy
- 13. Data Protection Queries
- 14. Complaint Rights
Consumer Rights Wiki Privacy Policy
Last Updated: January 20, 2026
This Privacy Policy explains how the Consumer Rights Wiki ("CRW," "we," "us," or "our"), our service providers, and our partners, collect, use, share, and protect Personally Identifying Information (PII), and other data, in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
FULU Foundation Fulu Foundation, Austin, Texas 78705 Email: data@consumerrights.wiki
2. Legal Basis for Processing
We process personal data based on the following legal grounds under Article 6 of the GDPR:
Contract (Article 6(1)(b)) Data used for:
- Account registration and management
- User authentication and login
- Enabling wiki contributions and editing
Legitimate Interests (Article 6(1)(f)) Data used for:
- IP address processing for security and anti-spam protection
- Privacy-preserving analytics through Plausible Analytics
- Maintaining the integrity and security of the wiki
- Prevention of abuse and vandalism
2.1 Data Minimization
We adhere to the principle of data minimization, collecting only the personal data that is necessary for the specific purposes outlined in this policy. We do not collect excessive or irrelevant data.
2.2 Special Categories of Data
We do not intentionally collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation). If such data is inadvertently collected through user-generated content, it is not processed by us for any purpose.
3. PII and other data We Collect
3.1 Account Information
When you create an account, we collect:
- Username - Stored indefinitely, or until account deletion request
- Email address - Stored indefinitely, or until account deletion request
- Hashed and salted password - Stored indefinitely, or until account deletion request
3.2 Contribution Data
- Edit history and contributions - Stored indefinitely as necessary for wiki functionality and attribution under legitimate interest
- Timestamps of edits - Stored indefinitely as part of contribution history
- Discussion posts and comments - Stored indefinitely as part of wiki content
3.3 Technical Data
- IP addresses - Stored in server logs and backups for 90 days for security purposes, and indefinitely in edit history for attribution and anti-vandalism purposes
- Browser type and version - Processed temporarily for technical compatibility and for generation of anonymized analytics
- Device information - Processed temporarily for technical compatibility and for generation of anonymized analytics
3.4 Analytics Data (via Plausible Analytics)
Our self-hosted Plausible Analytics instance collects:
- Page views and navigation patterns
- Referrer information
- Country of origin (derived from IP addresses, which are immediately discarded)
- Device type and browser information
Important: Plausible does not use cookies or persistent identifiers, or create profiles. All data is aggregated and anonymous.
3.5 Security Services
hCaptcha processes the following when you interact with protected forms:
- Technical connection data (IP address, timestamp)
- Interaction data with the captcha interface
CloudFlare processes the following when you connect to the site:
- Technical connection data (Traffic routing data, HTTP request metadata)
4. Data Retention and Backup Schedule
4.1 Primary Data Retention
| Data Type | Retention Period | Justification |
|---|---|---|
| Account data (username, email, hashed and salted password) | Indefinitely until deletion request | Necessary to perform contract |
| Contribution history | Indefinitely | Legitimate interest in maintaining wiki integrity and attribution |
| IP addresses in server logs | 30 days | Security and anti-abuse purposes |
| IP addresses in edit history | Indefinitely until deletion request | Attribution and anti-vandalism |
| Analytics data (aggregated) | Indefinitely | Legitimate interest in service improvement |
4.2 Backup and Recovery Schedule
| Backup Type | Frequency | Retention Period | Data Included |
|---|---|---|---|
| Daily backups | Every 24 hours | 7 days | Full database, user accounts, contribution history, configuration |
| Monthly backups | 1st of each month | 6 months | Full database, user accounts, contribution history, configuration |
| Server logs | Continuous | 30 days rolling | Access logs, error logs, security logs |
Important Notes on Backups:
- All backups are fully encrypted
- Deleted data may persist in backups until the backup retention period expires
- Maximum possible retention through backups: 6 months for monthly backups
- After backup expiration, data is permanently deleted unless specifically retained under section 4.1
5. International Data Transfers
Our servers are hosted by Hetzner in the United States. This constitutes an international data transfer from the EU/EEA. We ensure appropriate safeguards through:
- EU-US Data Privacy Framework: Our hosting providers participate in the EU-US Data Privacy Framework, ensuring adequate protection for your personal data
- hCaptcha transfers: Data may be transferred to Intuition Machines, Inc. in the USA under the EU-US Data Privacy Framework (European Commission adequacy decision C(2023) 4745)
6. Your Rights Under GDPR
You have the following rights regarding your personal data:
6.1 Right of Access (Article 15)
You can request a copy of your personal data we hold.
6.2 Right to Rectification (Article 16)
You can request correction of inaccurate personal data.
6.3 Right to Erasure (Article 17)
You can request deletion of your personal data, subject to legal obligations and legitimate interests (e.g., contribution history may be retained for attribution).
6.4 Right to Restriction (Article 18)
You can request restriction of processing in certain circumstances.
6.5 Right to Object (Article 21)
You can object to processing based on legitimate interests.
6.6 Right to Data Portability (Article 20)
You can request your data in a structured, machine-readable format.
6.7 Right to Lodge a Complaint
You have the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact us at: data@consumerrights.wiki
7. Data Sharing and Third Parties
We do not sell or rent your personal data. We share data only with:
7.1 Service Providers (Data Processors)
| Service Provider | Data Types Processed | Location | Purpose |
|---|---|---|---|
| Hetzner | Server infrastructure, web application data, user data, backups | US/EU | Primary hosting infrastructure |
| CloudFlare | Analytics data, traffic patterns, security logs, attack mitigation data | USA | DDoS protection, CDN, security analytics |
| hCaptcha | IP addresses, interaction data | USA | Spam prevention |
7.1.1 Privacy statement for the service hCaptcha
When accessing some sub-services of our website, additional information is processed.
Processed data categories: technical connection data of the server access (IP address, date, time, requested page, browser information), data about the use of the website, and the logging of clicks on individual elements.
Purpose of processing: avoid non-human and automated input.
The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).
Legitimate interests: strong economic interest in safe and functioning operation of the technical systems.
Data are transmitted: to the data processor Intuition Machines, Inc., 1065 SW 8th St #704, Miami FL 33130, USA (https://www.hcaptcha.com).
This may also mean a transfer of personal data to a country outside the European Union. The data are transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).
Please read the hCaptcha's full privacy policy for more information.
7.1.2 Privacy statement for the service Hetzner
Our website infrastructure and web application are hosted on servers provided by Hetzner.
Processed data categories: Web application data, server infrastructure data, technical connection data (IP address, date, time, requested page, browser information), server configuration and usage metrics, network traffic data.
Purpose of processing: provision of hosting infrastructure for the web application, ensuring system availability and performance.
The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).
Legitimate interests: strong economic interest in reliable and functioning operation of the technical systems and infrastructure.
Data are transmitted: to the data processor Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (https://www.hetzner.com).
Hetzner operates servers in both the European Union and the United States. When US servers are used, data transfers are covered under standard contractual clauses.
Please read Hetzner's full privacy policy for more information.
7.1.3 Privacy statement for the service CloudFlare
Our website uses CloudFlare services for content delivery, security, and performance optimization. CloudFlare processes analytics and security-related data, but does not have access to user account data or personal information stored in our databases.
Processed data categories: Traffic routing data, HTTP request metadata (HTTP headers, user agent, query-string, path, host, HTTP method, HTTP version, TLS cipher version), request and error rates, DDoS attack patterns and mitigation data, aggregated analytics data about website usage, security threat intelligence data.
Purpose of processing: content delivery network (CDN) services, DDoS attack protection and mitigation, traffic routing and optimization, security monitoring and threat detection, performance analytics to improve website speed and user experience.
The legal basis for processing: a legitimate interest that overrides the rights and freedoms of the data subject (Art. 6 (1) f GDPR).
Legitimate interests: strong economic interest in secure, reliable, and functioning operation of the website, protection against cyber attacks, and optimization of service performance.
Data are transmitted: to the data processor Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (https://www.cloudflare.com).
This may also mean a transfer of personal data to a country outside the European Union. The data are transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).
Please read Cloudflare's full privacy policy for more information.
7.2 Legal Requirements
We may disclose data when required by law or to protect the rights and safety of users.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Hashing and salting of passwords
- Regular security updates
- Access controls and authentication
- The full encryption of all backups made
8.1 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
- Notify affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms
- Document all breaches in accordance with GDPR requirements
9. Automated Decision-Making
We do not engage in automated decision-making that produces legal or similarly significant effects. Our anti-spam tools (hCaptcha) involve automated processing but:
- Do not produce significant effects on users
- Allow for easy appeals via email or Discord
We do not engage in profiling activities as defined under GDPR.
10. Children's Privacy
The CRW is not intended for children under 16. We do not knowingly collect personal data from children. If we become aware of such collection, we will promptly delete the data.
11. Cookies
We do not use tracking cookies. The wiki may use strictly necessary session cookies for authentication, which are deleted when you close your browser.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last Updated" date will always reflect the most recent version.
Previous versions of the policy can be seen by viewing the Privacy Policy page history.
13. Data Protection Queries
For any questions about this Privacy Policy or our data practices, please contact:
Data Protection Contact Email: data@consumerrights.wiki FULU Foundation FULU Foundation, Austin, Texas 78705
14. Complaint Rights
If you are unsatisfied with our response to your data protection query, you have the right to lodge a complaint with your local data protection authority. For EU residents, you can find your local authority at: https://edpb.europa.eu/about-edpb/board/members_en
---
By using the Consumer Rights Wiki, you acknowledge that you have read and understood this Privacy Policy.