Website Privacy Policy: Difference between revisions

From Wikimedia UK
Jump to navigation Jump to search
Tags: New redirect Visual edit
 
(21 intermediate revisions by 6 users not shown)
Line 1: Line 1:
{{notice|This policy is currently being drafted. It is based on the [[:wmf:Privacy policy|Wikimedia Foundation's Privacy policy]].}}
#REDIRECT [[https://wikimedia.org.uk/wiki/Privacy policy]]{{BoardApproved | Minutes 11May13#Proposed_Privacy_Policy | 11 May 2013 | lastid = 38921
| history  = {{BoardApprovedHistory | Minutes 11May13#Proposed_Privacy_Policy | 11 May 2013 | Initial adoption | 38921 | lastid = }}
}}


==General Scope==
This policy describes what happens to personal information that we obtain from your interactions with the websites hosted at uk.wikimedia.org and wikimedia.org.uk. For details of other processing and storage of data personal information the Chapter undertakes outside the functioning of these websites, please see our [[Data Protection Policy]] and [[Donor Privacy Policy]] This policy will be updated periodically subject to approval by the Charity's board of Trustees.
This policy covers personally identifiable information collected or stored by Wikimedia UK on its servers as of March 2013. Wikimedia UK collects and retains the least amount of personally identifiable information needed to fulfil the operational needs of the projects and activities that it runs, and will update both this policy and its Data Registration with the Information Commissioners Officer on a periodical basis to reflect any changes in its hosting or data processing arrangements.


==The public and collaborative nature of the projects==
There are some technical terms used in this policy. Clicking a highlighted technical term will link you to a webpage with an explanation.  
The majority of the Wikimedia projects that Wikimedia UK supports with its resources are collaboratively developed by users using the MediaWiki software. Anyone with Internet access (and not otherwise restricted from doing so) may edit the publicly editable pages of these sites with or without logging in as a registered user. By doing this, editors create a published document, and a public record of every word added, subtracted, or changed. This is a public act, and editors are identified publicly as the author of such changes. All contributions made to a Project, and all publicly available information about those contributions, are irrevocably licensed and may be freely copied, quoted, reused and adapted by third parties with few restrictions.


Wikimedia UK currently does not host the UK wiki (this site) - this is hosted on the servers of the Wikimedia Foundation and subject to the remit of [http://wikimediafoundation.org/wiki/Privacy_policy their privacy policy]. The details of the sites hosted by Wikimedia UK hosts are detailed [[IT_Development/Infrastructure|here]] and are subject to the terms of this policy.
==Who are you?==


==Activities on Wikimedia UK sites==
We are Wikimedia UK, and we are responsible for the websites hosted at uk.wikimedia.org and wikimedia.org.uk.
In general, this Policy only applies to private information stored or held by Wikimedia UK on its servers, which is not publicly available (i.e. it does not include publicly logged version histories of editing activity, but would include server log files of when an editor had logged into his/her account)


Interactions with Wikimedia Foundation projects not covered by this Policy include, but are not limited to, aspects of browsing and editing pages, use of the wiki "email user" function, subscribing and posting to Wikimedia UK hosted email lists, and corresponding with volunteers via Wikimedia UK's ticketing system ("OTRS"). These interactions may reveal a contributor's IP address, and possibly other personal information, indiscriminately to the general public, or to specific groups of volunteers acting independently of Wikimedia UK.
We are the local UK chapter of the Wikimedia Foundation, and we share its cultural and educational objectives. However, we are a separate organisation. Thus, we have no control over personal information collected through websites for Wikipedia or other Wikimedia Foundation projects.


Users may also interact with one another outside of Wikimedia UK sites, via email, IRC or other chat, or independent websites, and should assess the risks involved, and their personal need for privacy, before using these methods of communication.
==What type of personal information do you collect?==


==User accounts and authorship==
We collect certain information automatically when your computer or other device visits our websites. This will be things like:


Wikimedia UK does not require editors to register with any wiki or website it hosts. Anyone can edit without logging in with a username, in which case they will be identified by network IP address. Users that do register are identified by their chosen username. Users select a password, which is confidential and used to verify the integrity of their account.
* your [http://en.wikipedia.org/wiki/IP_address IP address]
* the date and time of your visit
* the pages from our websites that you view
* the browser that you use


Except insofar as it may be required by law, no person should disclose, or knowingly expose, either user passwords and/or cookies generated to identify a user. Once created, user accounts will not be removed. It may be possible for a username to be changed, depending on the policies of individual sites. Wikimedia UK does not guarantee that a username will be changed on request.
We also collect certain additional information in connection with the following activities (and note that some of this will be made automatically public):


==Purpose of the collection of private information==
{| class="wikitable" style="text-align: left;"
! Activity !! Information collected !! Public/private
|-
| editing pages on our websites || all your editing and contributions (recorded by reference to your username, or by reference to your IP address if you are not logged in) || public <br />
|-
| anything you do while logged in as a registered user || all your activities on our websites, including the content of any messages sent through our websites || private (but messages sent to the mailing list for a project or event will be public)<br />
|-
| adding your email address to the mailing list for a project or event || your email address || public <br />
|-
| sending an email to one of our email accounts (such as volunteering@wikimedia.org.uk) ||
* your email address
* the content of your message
* the date and time of your message
* your IP address
|| private <br />
|-
| registering to become a member of Wikimedia UK || this is subject to a separate policy || please click [[Data_Protection_Policy| this link]] for further details <br />
|-
|}


Wikimedia UK limits the collection of personally identifiable user data to purposes which serve the well-being of its projects, including but not limited to the following:
==What do you do with my personal information?==


* To enhance the public accountability of the projects. Wikimedia UK recognises that any system that is open enough to allow the greatest possible participation of the general public will also be vulnerable to certain kinds of abuse and counterproductive behaviour. Wikimedia UK and the project communities have established a number of mechanisms to prevent or remedy abusive activities. For example, when investigating abuse on its sites, including the suspected use of malicious “sockpuppets” (duplicate accounts), vandalism, harassment of other users, or disruptive behaviour, the IP addresses of users (derived either from those logs or from records in the database) may be used to identify the source(s) of the abusive behaviour. This information may be shared by users with administrative authority who are charged by their communities with protecting the projects.
We use your personal information for the following purposes:
* To provide site statistics. Wikimedia UK statistically samples raw log data from users' visits. These logs are used to produce the site statistics pages; the raw log data is not made public.
* To solve technical problems. Log data may be examined by developers in the course of solving technical problems and in tracking down badly-behaved web spiders that overwhelm the site.


== Data Retention ==
* identifying and terminating abuse of our websites or other disruptive behaviour (this could be things like the use of 'sockpuppets' or duplicate accounts, vandalism, or harassment of others);
Wikimedia UK, consistent with its long-standing commitment to minimising the unnecessary data retention of users and editors, adopts the policy of retaining the least of amount personally identifiable information consistent with its Data Protection registration, this privacy policy, or as required by United Kingdom law.
* protecting the safety of individuals;
* investigating and responding to requests or complaints from users of our websites;
* identifying and resolving technical problems with our websites;
* improving the operation or features of our websites;
* bringing or defending legal proceedings.


==Details of data retention==
==Who will have access to my personal information?==
===General expectations===
====IP and other technical information====
* When a visitor requests or reads a page hosted by the Wikimedia UK server, or sends email via a Wikimedia UK server hosted account. No more information is collected than is typically collected by web sites - as standard this will be limited to -
:*requested url
:* HTTP method
:* HTTP answer status code
:* client IP
:* client browser user agent
:* date


*The Wikimedia UK may keep raw logs of such transactions, which are only accessible by contracted staff who have signed confidentiality agreements. Logs will not be published, though aggregregate data to provide insight into site usage may. Invidual log records will not be reviewed to track legitimate uses of the sites.
The following persons may have access to your personal information for the purposes described above (and will be obliged to keep that information confidential):
* When a Wikimedia UK hosted project page is edited by a logged-in editor, the server confidentially stores related IP information for a limited period of time. This information is automatically deleted after a set period. For editors who do not log in, the IP address used is publicly and permanently credited as the author of the edit. It may be possible for a third party to identify the author from this IP address in conjunction with other information available. Logging in with a registered username allows for better preservation of privacy.
* registered users who have been elected by the community to support the activities of the community (you can read more about these users [http://meta.wikimedia.org/wiki/CheckUser_policy#Everywhere here])
* our employees or contractors
* our trustees
* our software developers
* our legal and business advisers
* [https://en.wikipedia.org/wiki/Internet_service_provider ISPs] (and similar types of carriers and service providers)
* the other claimants and defendants to legal proceedings involving us


====Cookies====
Where required to do so under a court order or other legally compulsory request, we will also provide your personal information to the person or entity specified in that order or request.
* The sites set a temporary session cookie on a visitor's computer whenever a Wikimedia UK hosted site page is visited. Readers who do not intend to log in or edit may deny this cookie; it will be deleted at the end of the browser's session. More cookies may be set when one logs in to maintain logged-in status. If one saves a user name or password in one's browser, that information will be saved for up to 30 days, and this information will be resent to the server on every visit to the same site. Contributors using a public machine who do not wish to show their username to future users of the machine should clear these cookies after use.


====Page history====
We also make public the usage statistics for our websites. These statistics are anonymised before publication to ensure that you (and your activities) cannot be identified or tracked. For this reason, IP addresses and usernames do not form part of statistics information that we publish.
* Edits or other contributions to a Project on its articles, user pages and talk pages are generally retained forever. Removing text from a project does not permanently delete it. Normally, in projects, anyone can look at a previous version of an article and see what was there. Even if an article is "deleted", a user entrusted with higher level of access may still see what was removed from public view. Information can be permanently deleted by individuals with access to Wikimedia UK servers, but aside from the rare circumstance when Wikimedia UK is required to delete editing-history material in response to a court order or equivalent legal process, there is no guarantee any permanent deletion will happen.


====User contribution====
==What are cookies, and how do you use them?==
* User contributions are also aggregated and publicly available. User contributions are aggregated according to their registration and login status. Data on user contributions, such as the times at which users edited and the number of edits they have made, are publicly available via user contributions lists, and in aggregated forms published by other users.


=====Reading projects=====
Cookies are small text files that are placed on your computer or other device by websites. Cookies are used for a wide variety of purposes. Some help websites perform properly, such as keeping you logged in as you move from page to page. Others collect information on your browsing activities within that website or more generally across the internet. You can find more information on cookies (including how to block or delete them) on [http://www.allaboutcookies.org/ this website]
* No more information on users and other visitors reading pages is collected than is typically collected in server logs by web sites. Aside from the above raw log data collected for general purposes, page visits do not expose a visitor's identity publicly. Sampled raw log data may include the IP address of any user, but it is not reproduced publicly.


=====Editing Wikimedia UK hosted sites=====
To see an up to date list of the cookies used by our sites please visit [[Cookies Log]].
* Edits to Wikimedia UK hosted site pages are identified with the username or network IP address of the editor, and editing history is aggregated by author in a contribution list. Such information will be available permanently on the projects.
* Logged in registered users:
* Logged in users do not expose their IP address to the public except in cases of abuse, including vandalism of a wiki page by the user or by another user with the same IP address. A user's IP address is stored on the wiki servers for a period of time, during which it can be seen by server administrators and by users who have been granted CheckUser access.
* IP address information, and its connection to any usernames that share it, may be released under certain circumstances (see below).
* Editors using a company mail server from home or telecommuting over a DSL or cable Internet connection, are likely to be easy to identify by their IP address; in which case it may be easy to cross-identify all contributions to various sites made by that IP. Using a username is a better way of preserving privacy in this situation.
* Unlogged-in registered users and unregistered users:
* Editors who have not logged in may be identified by network IP address. Depending on one's connection, this IP address may be traceable to a large Internet service provider or more specifically to a school, place of business or home. It may be possible to use this information in combination with other information, including editing style and preferences, to identify an author completely.


=====Discussions=====
==Where do you hold my personal information? Can I find out what personal information you hold about me?==
* On wiki discussion pages:
* Any editable page can theoretically be the location of a discussion. In general, discussions on Wikimedia UK projects occur on user talk pages (associated with particular users), on article talk pages (associated with particular articles) or in pages specially designated to function as forums (e.g., the Water Cooler). Privacy expectations apply to discussion pages in the same way as they do elsewhere.
* Via email:
* Users are not required to list an email address when registering. Users who provide a valid email address can enable other logged-in users to send email to them through the wiki. When receiving an email from other users through this system, one's email address is not revealed to them. When choosing to send an email to other users, one's email is displayed as the sender.
* The email address put into one's user preferences may be used by Wikimedia UK for communication. Users whose accounts do not have a valid email address will not be able to reset their password if it is lost. In such a situation, however, users may be able to contact one of the Wikimedia UK server administrators to enter a new e-mail address. A user can remove the account's email address from his preferences at any time to prevent it from being used. Private correspondence between users may be saved at those users' discretion and is not subject to Wikimedia UK policy.
* On mailing lists:
* The email addresses used to subscribe and post to Project mailing lists are exposed to other subscribers. The list archives of most such mailing lists are public, and searches of public archives may be performed on the Web. Subscribers' addresses may also be quoted in other users' messages. These email addresses and any messages sent to a mailing list may be archived and may remain available to the public permanently.
* Via OTRS:
* Some e-mail addresses (such as info at wikimedia dot org dot uk) forward mail to a team of volunteers trusted by Wikimedia UK to use a ticket system, such as OTRS, to respond. Mail sent to this system is not publicly visible, but volunteers selected by Wikimedia UK will have access to it. The ticket system team may discuss the contents of received mail with other contributors in order to respond effectively. Mail to private addresses of members of Board of Trustees and to staff of Wikimedia UK may also be forwarded to the OTRS team. These messages and e-mail addresses may be saved by members of the OTRS team and any email service they use, and may remain available to them.
* On IRC:
* IRC channels are not officially part of the Wikimedia UK and are not operated on Wikimedia UK controlled servers. The IP address of users who chat over such a service may be exposed to other participants. IRC users' privacy on each channel can only be protected according to the policies of the respective service and channel. Different channels have different policies on whether logs may be published.


==Access to and release of personally identifiable information==
Our [[Data Protection Policy]] details how Wikimedia UK stores your personal information and how you can find out what personal information we hold about you."
Access:


Wikimedia UK hosted sites are primarily run by volunteer contributors. Some dedicated users are chosen by the community to be given privileged access. For example, on the UK wiki (uk.wikimedia.org), user access levels are determined by the user's presence in various 'user groups'. User group rights and group members are reachable in every project from the [[Special:ListGroupRights]] page.
==What else should I be aware of?==


Other users who may have access to private identifiable information include, but are not limited to, users who have access to OTRS, or to the CheckUser and Oversight functions, users elected by project communities to serve as stewards or Arbitrators, Wikimedia UK employees, trustees, appointees, and contractors and agents employed by Wikimedia UK, and developers and others with high levels of server access.
Some of your activities on our websites will be public acts that will result in your personal information being permanently and publicly available. You must ensure that you feel comfortable with this before engaging in these activities:


Access to and publication of this information is governed by the [[Access control approval guidelines]], as well as [[IT Security Policy| specific policies]] covering some of the functions in question. Sharing information with other privileged users is not considered "distribution."
{| class="wikitable" style="text-align: left;"
! Activity !! Public availability 
|-
| editing pages on our websites ||
* every word that you add, remove or change becomes part of the public record for that page
* your IP address (or your username if your are logged in as a registered user) also becomes part of the public record as the source of those edits
* all edits under your IP address (or your username) across all pages become linked together as part of the public record <br />
|-
| adding your email address to the mailing list for a project or event || your email address becomes part of the public record for that project or event <br />
|-
| sending a message to the mailing list for a project or event || your email address and the content of your message becomes part of the public record for that project or event <br />
|-
|}


Release: Policy on Release of Data
==Where can I find more information in relation to my rights?==


It is the policy of Wikimedia UK that personally identifiable data collected in the server logs, or through records in the database via the CheckUser feature, or through other non-publicly-available methods, may be released by Wikimedia UK volunteers or staff, in any of the following situations:
The Information Commissioner's Office is the UK's independent authority that is responsible for upholding data privacy for individuals. You can find additional information on your rights under the Data Protection Act 1998 on [http://www.ico.org.uk/ the Information Commissioner's website].
# In response to a valid court order or other valid, compulsory legal request,
# With permission of the affected user,
# When necessary for investigation of abuse complaints,
# Where the information pertains to page views generated by a spider or bot and its dissemination is necessary to illustrate or resolve technical issues,
# Where the user has been vandalizing articles or persistently behaving in a disruptive way, data may be released to a service provider, carrier, or other third-party entity to assist in the targeting of IP blocks, or to assist in the formulation of a complaint to relevant Internet Service Providers,
# Where it is reasonably necessary to protect the rights, property or safety of the Wikimedia UK, its users or the public.


Except as described above, Wikimedia UK policy does not permit distribution of personally identifiable information under any circumstances. All provisions as described above can only be applied within the terms set out in the Data Protection Act 1998 and Privacy and Electronic Communications Regulations 2003 guidance.
[[Category:Constitution]]
 
Third-party access and notifying registered users when receiving legal process:
 
As a general principle, the access to, and retention of, personally identifiable data in all projects should be minimal and should be used only internally to serve the well-being of the projects. Occasionally, however, Wikimedia UK may receive a valid court order or other valid, compulsory legal request that requests the disclosure of information about a registered user, and may be compelled by law to comply with the request. In the event of such a legally compulsory request, Wikimedia UK will attempt to notify the affected user within three business days after the arrival of such request by sending a notice by email to the email address (if any) that the affected user has listed in his or her user preferences.
 
Wikimedia UK cannot advise a user receiving such a notification regarding the law or an appropriate response. Wikimedia UK does note, however, that such users may have the legal right to resist or limit that information in their response. Users who wish to oppose a valid court order or other valid, compulsory legal request should seek legal advice concerning applicable rights and procedures that may be available.
 
Registered users are not required to provide an email address. However, when an affected registered user does not provide an email address, Wikimedia UK will not be able to notify the affected user in private email messages when it receives requests from law enforcement to disclose personally identifiable information about the user.
 
==Disclaimer==
The Wikimedia UK believes that maintaining and preserving the privacy of user data is an important value. This Privacy Policy, together with other policies, resolutions, and actions by Wikimedia UK, represents a committed effort to safeguard the security of the limited user information that is collected and retained on our servers. Nevertheless, Wikimedia UK cannot guarantee that user information will remain private. We acknowledge that, in spite of our committed effort to protect private user information, determined individuals may still develop data-mining and other methods to uncover such information and disclose it. For this reason, Wikimedia UK can make no guarantee against unauthorized access to information provided in the course of participating in Wikimedia UK sites or related communities.

Latest revision as of 15:24, 13 May 2024

This document was approved by the Board on 11 May 2013 . (approved revision, subsequent changes)
Changes to this document are subject to board approval, and should be proposed either on the talk page or the Engine room

Approval history:

11 May 2013 - Initial adoption (approved revision)

This policy describes what happens to personal information that we obtain from your interactions with the websites hosted at uk.wikimedia.org and wikimedia.org.uk. For details of other processing and storage of data personal information the Chapter undertakes outside the functioning of these websites, please see our Data Protection Policy and Donor Privacy Policy This policy will be updated periodically subject to approval by the Charity's board of Trustees.

There are some technical terms used in this policy. Clicking a highlighted technical term will link you to a webpage with an explanation.

Who are you?

We are Wikimedia UK, and we are responsible for the websites hosted at uk.wikimedia.org and wikimedia.org.uk.

We are the local UK chapter of the Wikimedia Foundation, and we share its cultural and educational objectives. However, we are a separate organisation. Thus, we have no control over personal information collected through websites for Wikipedia or other Wikimedia Foundation projects.

What type of personal information do you collect?

We collect certain information automatically when your computer or other device visits our websites. This will be things like:

  • your IP address
  • the date and time of your visit
  • the pages from our websites that you view
  • the browser that you use

We also collect certain additional information in connection with the following activities (and note that some of this will be made automatically public):

Activity Information collected Public/private
editing pages on our websites all your editing and contributions (recorded by reference to your username, or by reference to your IP address if you are not logged in) public
anything you do while logged in as a registered user all your activities on our websites, including the content of any messages sent through our websites private (but messages sent to the mailing list for a project or event will be public)
adding your email address to the mailing list for a project or event your email address public
sending an email to one of our email accounts (such as volunteering@wikimedia.org.uk)
  • your email address
  • the content of your message
  • the date and time of your message
  • your IP address
private
registering to become a member of Wikimedia UK this is subject to a separate policy please click this link for further details

What do you do with my personal information?

We use your personal information for the following purposes:

  • identifying and terminating abuse of our websites or other disruptive behaviour (this could be things like the use of 'sockpuppets' or duplicate accounts, vandalism, or harassment of others);
  • protecting the safety of individuals;
  • investigating and responding to requests or complaints from users of our websites;
  • identifying and resolving technical problems with our websites;
  • improving the operation or features of our websites;
  • bringing or defending legal proceedings.

Who will have access to my personal information?

The following persons may have access to your personal information for the purposes described above (and will be obliged to keep that information confidential):

  • registered users who have been elected by the community to support the activities of the community (you can read more about these users here)
  • our employees or contractors
  • our trustees
  • our software developers
  • our legal and business advisers
  • ISPs (and similar types of carriers and service providers)
  • the other claimants and defendants to legal proceedings involving us

Where required to do so under a court order or other legally compulsory request, we will also provide your personal information to the person or entity specified in that order or request.

We also make public the usage statistics for our websites. These statistics are anonymised before publication to ensure that you (and your activities) cannot be identified or tracked. For this reason, IP addresses and usernames do not form part of statistics information that we publish.

What are cookies, and how do you use them?

Cookies are small text files that are placed on your computer or other device by websites. Cookies are used for a wide variety of purposes. Some help websites perform properly, such as keeping you logged in as you move from page to page. Others collect information on your browsing activities within that website or more generally across the internet. You can find more information on cookies (including how to block or delete them) on this website

To see an up to date list of the cookies used by our sites please visit Cookies Log.

Where do you hold my personal information? Can I find out what personal information you hold about me?

Our Data Protection Policy details how Wikimedia UK stores your personal information and how you can find out what personal information we hold about you."

What else should I be aware of?

Some of your activities on our websites will be public acts that will result in your personal information being permanently and publicly available. You must ensure that you feel comfortable with this before engaging in these activities:

Activity Public availability
editing pages on our websites
  • every word that you add, remove or change becomes part of the public record for that page
  • your IP address (or your username if your are logged in as a registered user) also becomes part of the public record as the source of those edits
  • all edits under your IP address (or your username) across all pages become linked together as part of the public record
adding your email address to the mailing list for a project or event your email address becomes part of the public record for that project or event
sending a message to the mailing list for a project or event your email address and the content of your message becomes part of the public record for that project or event

Where can I find more information in relation to my rights?

The Information Commissioner's Office is the UK's independent authority that is responsible for upholding data privacy for individuals. You can find additional information on your rights under the Data Protection Act 1998 on the Information Commissioner's website.