Legal / privacy / v1 · current
Privacy notice
- version
- v1
- effective from
- 2026-09-02
- permalink
-
/legal/privacy/v1 - issuer
- Purpose Source Association
This notice covers purposesource.org and the public edge API at api.purposesource.org. It is written to satisfy the Swiss Federal Act on Data Protection (FADP), the EU and UK General Data Protection Regulations (GDPR), and the principle behind all three: say what you collect, why, for how long, and who else sees it — and collect as little as possible. Here, the honest summary is that this site collects almost nothing.
1. Controller
Purpose Source Association, an association under Art. 60 ff. ZGB with its seat in the
canton of Aargau, Switzerland (the imprint carries the register
status). Contact for anything in this notice: legal@purposesource.org, or the
data-request route.
Representatives. The Association is established in Switzerland and has a Swiss-domiciled representative under Art. 69 Abs. 2 ZGB. A representative in the European Union under Art. 27 GDPR (and in the United Kingdom under the UK GDPR) is appointed before the Association itself processes personal data of an EU- or UK-based Entitlement purchaser — at v0 the merchant of record is the seller and the Association’s processing of purchaser data is occasional — and is named in the next version of this notice.
2. What this site collects from a visitor: nothing
- No cookies are set on anonymous browsing. No local storage, no fingerprinting.
- No analytics script exists on any page, first- or third-party. Aggregate traffic figures (requests per path, per country, per day) come from the hosting provider’s server-side zone metrics, which your browser contributes to only by making the request.
- No consent banner, because there is nothing to consent to. Introducing any technology that would need one is a change to the site’s requirements, never a banner bolted on.
- One third-party script: the bot-protection challenge widget on the contact forms, loaded on that page only. It sees its own challenge and your browser’s request to it; it sets no cookie usable elsewhere on this site.
Edge request logs. Like every website, this one is served by a provider whose edge records the request: IP address, path, user agent, timestamp, response code. These logs are retained briefly under the provider’s terms, are not exported or retained by the Association, and are not linked to any person — there are no accounts on this site.
3. What you can send us
Forms. The contact, abuse-report, and data-request forms send what you type — your reply address, a subject, a message — through the challenge widget to the edge Worker, which verifies the challenge server-side, forwards the submission as one email to the steward inbox through the transactional-email provider, and stores nothing. There is no database on this site’s request path. Your message then lives in the steward mailbox for the retention period in section 8.
Email. Mail to the published addresses is routed at the edge to the steward inbox. It is handled like a form submission.
What is never in a URL. Organisation names in a coverage lookup are sent by POST, never as a query string, so a third party’s name never lands in a shareable link, a proxy log, or a cached URL. No personal data appears in any URL on this site, and the verification page sends a certificate identifier to the edge API and nowhere else.
4. Entitlement purchasers
Entitlements are sold through a merchant of record, which is the seller to you and an independent controller of your checkout and payment data under its own notice. Card and bank details never reach the Association.
The Association receives and processes, as controller: the purchasing organisation’s name and verified domain; the purchaser contact’s name and email; the revenue-band self-certification (one binding, timestamped tick); usage declarations (which registered projects you use); and the settlement record. From this it produces the signed entitlement record and the certificate, and it screens the organisation against sanctions lists.
Public by design: an organisation that buys an Entitlement is recorded in the public registry by organisation name and, if verified, domain — that is the credential’s whole function. The contact person’s name and email are never published.
5. Registry, contributors, and public artifacts
The registry, the waiver list, the allocation ledger, the certificate status records, and the transparency log are public. They contain repository identifiers, organisation names, and — from the phase in which contributors can claim their attribution — a contributor’s public platform login and opaque account identifier, displayed only if the contributor opted in. They never contain email addresses, because the Association never collects contributors’ email addresses. The transparency log contains hashes, type codes, and timestamps only. The ledger contains aggregates, repositories, and organisations — no personal data by schema.
Anyone may permanently exclude their identity from attribution processing through the exclusion list, which stores a salted hash only — see section 9.
6. Certificates
A certificate names its subject as the subject elected to be named (an organisation, or a contributor’s platform login or supplied name — never an email address) and is published as a status record at its verification URL. Revocation is prospective and leaves the record’s historical window readable. After revocation a minimal issuance record is retained for ten years for the Association’s accounting and legal defence.
7. Why we may process this: lawful bases
| Processing | Basis (GDPR Art. 6(1)) |
|---|---|
| Serving the site; edge logs; abuse prevention | (f) legitimate interests — running a public website securely |
| Answering a form or an email | (f) legitimate interests — responding to you; (b) where you are a purchaser |
| Purchaser records, entitlement records, certificates | (b) performance of the Entitlement contract |
| Accounting records, sanctions screening, VAT | (c) legal obligation (Swiss Code of Obligations Art. 958f; Swiss and international sanctions law) |
| Public registry entries of purchasing organisations | (b) contract; (f) legitimate interests — the credential’s public function |
| Contributor attribution display | (a) consent (opt-in), withdrawable at any time; the underlying computation over public repository data rests on (f), with the balancing test on file |
| Opt-in email | (a) consent, double opt-in, withdrawable at any time |
Under the FADP, the same processing is justified by contract, legal obligation, or overriding interest, and by consent where a consent is asked for.
8. Retention
| Data | Retained |
|---|---|
| Edge request logs | Briefly, by the provider under its terms; not retained by the Association |
| Form submissions and email | 24 months in the steward mailbox, then deleted; data-subject-request correspondence for the request plus one year |
| Purchaser and entitlement records, invoices, band self-certifications | 10 years (Swiss Code of Obligations Art. 958f) |
| Usage declarations | Life of the account, or 10 years where money-relevant |
| Certificate issuance records | Life of the certificate plus 10 years after revocation or expiry, as a minimal record |
| Transparency-log entries and ledger rows | Permanent — they contain no personal data |
| Exclusion-list hashes | Permanent — honouring an objection requires remembering it |
| Sanctions-screening records | 10 years |
9. Your rights, and how to use them
You have the rights of access, rectification, erasure, restriction, objection, and data portability, the right to withdraw a consent at any time without affecting earlier processing, and the right to complain to a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC); in the EU or UK, your local authority.
The route: the data-request form or legal@purposesource.org. We verify
your identity proportionately (for a request about attribution data, by having you sign in
with the same platform account), answer within 30 days — usually much sooner — and charge
nothing. Erasure never reaches the ledger or the transparency log (they contain no personal
data) and never reaches accounting records within their statutory retention; it does reach
display identity, contact data, tokens, and opt-in emails, and it revokes certificates issued
to you on request.
The right to object to attribution. If you never want your contributions attributed, displayed, or used to direct funds, you may be placed on the exclusion list permanently. The list stores a salted hash of your account identifier — no login, no reason text — and the exclusion is irreversible by design, so that no future operator can quietly undo it.
No automated decision-making with legal or similarly significant effect takes place. The coverage function computes an answer from published records; a person reviews any dispute.
10. Recipients and transfers
The recipients of personal data are the subprocessors listed, with purposes, data categories, and residency, on the Trust Center overview. That list is part of this notice: a change to it publishes as a new version of this notice at a new URL.
The Association’s own stores are in Switzerland. Where a subprocessor processes data in the United States (edge logs, email delivery, error telemetry, source hosting), the transfer rests on standard contractual clauses and, where the provider is certified, the Swiss–US Data Privacy Framework. Switzerland is recognised as adequate by the European Union. The full residency statement lists every exception.
11. Children
This site is not directed at children and the Association does not knowingly process personal data of anyone under 16. A contributor’s attribution is displayed only after an opt-in from an account the contributor controls.
12. Changes
This notice is versioned at a permanent URL. A new version is a new URL, announced on the Trust Center; this one stays readable here forever. Version 2 will add the EU/UK representative and the register details once published.