Contact
Five mailboxes and four forms, each with a published response target. Every form submission is forwarded as a single email and stored nowhere — there is no database on this site's request path. The targets below are targets, not service-level commitments: the operating team is small, and printing a promise we cannot staff would be the first thing on this site that was not true.
The mailboxes
These work without JavaScript, without the challenge widget, and without this page. All of them route to the steward inbox; none of them is a person, which is deliberate — a role outlives whoever is holding it.
Published addresses, what each is for, and the response target.
| Address | For | Response target |
|---|---|---|
| hello@purposesource.org | General enquiries — adoption, the licence, the schedule, the registry, anything on this site. | 5 business days |
| legal@purposesource.org | Legal notices and service, data-subject requests, the right to object, takedown, trademark and claim-language matters. | 30 days (statutory maximum; usually much sooner) for a data request; 5 business days otherwise |
| security@purposesource.org | Vulnerability reports only. Coordinated disclosure, scope, and safe-harbour wording are on the security page. | 3 business days to acknowledge, 10 business days to triage |
| press@purposesource.org | Media enquiries. We will decline to confirm anything the published record does not show, including figures. | 5 business days |
| billing@purposesource.org | Invoices, receipts, renewals, refunds, band corrections, and merchant-of-record questions. | 5 business days |
Security reports have their own policy, scope, and safe-harbour wording: the security page and security.txt. Do not use the forms below for a vulnerability report.
General contact
Questions about the licence, adoption, the schedule, or anything on this site. Include a repository or organisation name if it helps us answer precisely. We cannot give legal or tax advice, and we cannot pre-approve your reading of the licence — but we can point at the operative clause.
Response target: 5 business days. Submissions are stored nowhere; rate limit five per hour per address of origin, on top of the challenge.
Abuse and moderation report
Report a misrepresented certificate, a false coverage claim, a sold waiver, a repository misusing the marks, or any content on this site you believe is wrong. Include the URL, the certificate identifier, or the repository so the report is actionable.
Response target: 5 business days. Submissions are stored nowhere; rate limit five per hour per address of origin, on top of the challenge.
Data request
Exercise access, rectification, erasure, restriction, objection, or portability, or withdraw a consent. This site stores nothing about anonymous visitors and has no accounts, so most requests concern a message you previously sent us or, in a later phase, attribution data. We verify identity proportionately, charge nothing, and answer within the statutory maximum.
Response target: 30 days (statutory maximum; usually much sooner). Submissions are stored nowhere; rate limit five per hour per address of origin, on top of the challenge.
Right to object to attribution
A standing objection: if you never want your contributions attributed, displayed, or used to direct funds, ask to be placed on the exclusion list. It stores a salted hash of your account identifier — no login, no reason text — and the exclusion is irreversible by design, so that no future operator can quietly undo it. Tell us the platform account you mean.
Response target: 30 days (statutory maximum; usually much sooner). Submissions are stored nowhere; rate limit five per hour per address of origin, on top of the challenge.
Data requests and the right to object, in more detail
The route is the data-request form or legal@purposesource.org. We answer within 30 days (statutory maximum; usually much sooner), verify identity proportionately — for a request about attribution data, by having you sign in with the same platform account — and charge nothing.
- What erasure reaches: display identity, contact data, tokens, opt-in emails, and certificates issued to you on request.
- What it does not reach: the allocation ledger and the transparency log, which contain no personal data by schema, and accounting records inside their statutory retention period. Saying so up front is better than promising erasure and then explaining an exception.
- The exclusion list is permanent on purpose: honouring an objection requires remembering it, so a salted hash stays even though nothing else does.
- Complaints go to a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner; in the EU or UK, your local authority.
What we cannot help with
We cannot give legal, tax, or accounting advice, and we cannot pre-approve your interpretation of the licence — an interpretation from us would not bind a court and would mislead you about how much comfort you had. What we can do is point at the operative clause and the published record. For a procurement or programme-office review, the OSPO and legal pack is written for exactly that, and the annotated licence answers the three questions reviews ask most.