Legal

Privacy Policy

What this website does with data, in plain language: static hosting, self-hosted fonts, no cookies set by this site and no tracking of any kind.

Last updated
Applies to
This website only — not a Peoplevate instance running on your own infrastructure.
  1. 01

    Controller

    The controller responsible for the processing of personal data on this website is Orbivort, the maintainer of the open-source Peoplevate project.

    Enquiries are answered through the project channel — Ask a question on GitHub (opens in a new tab) — and the answer stays available to the next person who asks.

  2. 02

    What this site does with data

    This website is the static product page for Peoplevate. It has no forms, no user accounts and no tracking scripts, it sets no cookies of its own, and it collects no personal data of its own.

    It is not the Peoplevate application. An instance of Peoplevate runs on infrastructure its operator controls, and the employee data inside it is governed by that operator — this policy covers this website and nothing else.

    One kind of data is still processed automatically, by the provider that serves these pages. It is described next.

  3. 03

    Hosting — Cloudflare Pages

    This website is hosted on Cloudflare Pages, a service provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).

    When you open a page, Cloudflare processes the following data as a processor on our behalf:

    • Your IP address
    • Request headers — browser type, operating system and referrer URL
    • The date and time of the request
    • The pages requested

    The data is processed to deliver the site to your browser and to keep it secure and available. Cloudflare handles it under its privacy policy (opens in a new tab) and under the data processing agreement (opens in a new tab) in place with us.

    Legal basis Article 6(1)(f) GDPR — legitimate interest in operating and securing this website.

  4. 04

    Transfers outside the EEA

    Cloudflare, Inc. is established in the United States, so serving these pages can involve a transfer of personal data outside the European Economic Area. The transfer relies on the safeguards Cloudflare offers: its certification under the EU-U.S. Data Privacy Framework, and the Standard Contractual Clauses in its data processing agreement (opens in a new tab) with us.

    No other recipient receives data from this site, because nothing else is contacted when a page is opened.

  5. 05

    How long data is kept

    This website keeps no server logs of its own. The request data listed above is held by Cloudflare under the retention schedule for its own service, which its privacy policy (opens in a new tab) sets out. We hold no separate copy and cannot extend that period.

    Nothing else is stored, so there is no other retention period to state: no account to expire, no message log and no analytics record.

  6. 06

    Analytics

    This site is built without analytics: no measurement script, no tag manager and no cookie of our own. Nothing on a visit is profiled or joined to a visitor.

    Because no visitor-level data is collected here, there is nothing on this site to consent to or to opt out of.

    Nothing on this site profiles a visitor, and no decision about you is taken automatically, because no visitor-level data is collected in the first place.

  7. 07

    Fonts

    This website sets three typefaces — Playfair Display, Source Sans 3 and Roboto Condensed — all of them self-hosted as part of the build.

    No font is requested from Google Fonts or any other font service, so opening these pages sends nothing to a third party in order to render text.

  8. 09

    Your rights under the GDPR

    If you are in the European Economic Area, the General Data Protection Regulation gives you the following rights over personal data about you:

    • Right of access (Art. 15 GDPR) — ask whether your personal data is processed, and request a copy of it.
    • Right to rectification (Art. 16 GDPR) — have inaccurate personal data corrected.
    • Right to erasure (Art. 17 GDPR) — have your personal data deleted.
    • Right to restriction of processing (Art. 18 GDPR) — have processing limited in certain circumstances.
    • Right to data portability (Art. 20 GDPR) — receive your data in a structured, commonly used format.
    • Right to object (Art. 21 GDPR) — object to processing carried out on the basis of legitimate interests.

    This site keeps no personal data of its own, so most requests would concern data processed by the hosting provider. No processing described in this policy relies on your consent, so there is no consent to withdraw.

    A request can be made through the contact route at the end of this page. That route is public, so name the right you are exercising and nothing else — clause 12 sets out why.

  9. 10

    Right to lodge a complaint

    If you believe that the processing of your personal data breaches the GDPR, you have the right to lodge a complaint with a supervisory authority — in particular in the EEA member state of your habitual residence, your place of work, or the place where the alleged infringement took place.

  10. 11

    Changes to this policy

    This page is the current version of the policy. Any change is published here with a new revision date at the top, so the register above describes the site as it stands.

  11. 12

    Contact

    Questions about this policy, or about how this site handles data, go to the open project channel:

    Ask a question on GitHub (opens in a new tab)

    That channel is public, and it is the only contact route this project publishes — there is no contact address. Do not post personal data there, your own or anyone else’s. If you are exercising a right under clause 09, name the right and nothing more: this site holds no personal data of its own, and the answer comes back on the same public thread.