Tim Nash
Global Moderator Community Supporter?
Internet Junkie
Posts: 2173
5036 credits Members referred : 2
Venture Skills - New Media & IT group
« on: Mar 02, 2007, 12:11:02 PM »
So you have built your first web site but have you made a privacy policy? Its important that you write a policy both in Europe and the US you can leave your self up for either Fines and or being taken to court by individuals if you do not have a policy in place. But don't worry because I have done the hard work for you!
Before you start you will need to know: Does your site use cookies? Does your site use third party javascript (Google analytics/visitor counters etc) Do you pass any information to any other company? Do you accept payments through the site? Do you use a third party payment system that takes users off site (paypal etc)? Do you host your own server?
Once you have that your good to go, Our policy is divided into sections the first and last sections are compulsory the middle sections are only required if you answered yes to the above. oh and replace the bold with the correct words
Webdigity Privacy sample policy -------Section 1 --------- Introduction This site is governed by all the rules and regulation of the country of The Country of Business and is hosted in Country server is hosted. The site is owned and maintained by Company or Individual name and any enquires regarding privacy should in the first instance be directed to Email Address. Please note we hold all data for the minimum period of time prescribed by law for our country of origin any personal data that is held in a public facing part of the site can be removed if request in writing is made to the address below, please note a small administration charge may be applied.
Tracking of data This site tracks data in accordance with laws of of Country server is hosted this site collects logs which include IP address but does not collect personally identifiable data from visitors, the server logs are used to track problems within the site however the information is made available to police and other authorities in the country of Country server is hosted as dictated by local laws.
------Section 2 Optional------- Cookies & Sessions - For tracking The site uses cookies and sessions for tracking identifiable data about a machine this can include browser type amongst other information, however only personal identifiable information that you give can be placed in the cookie, the cookie resides in the machine that visited the site for a period of time. The following Cookies are used on the site List cookies
------Section 3 optional-------- 3rd Party information While we do not sell information to third parties, we do pass information on to other parties to provide a richer experience the following third parties have access to some or all of our data. List third parties + Reason use Example - Google Analytics cookies, Google analytics is our primary web statistics software no identifiable data is sent to Google analytics but rough geographic locations are included where available.
-------Section 4 Payments----- Payment Systems Our payment system are handled in a secure manner using SSL and all payments are made through our merchant provider Merchant provider The payments are handled on/off site. -------On site------ On site payments are done is a secure area This area has been verified through the following provider XXXX and any data collected there will be stored securely the following identifiable data is collected from you at the time of purchase: List data Example - Name & Address, Credit card numbers etc After a transaction is completed we Store your credit card details to make future purchases easier/never store your credit card details to prevent misuse -----Off site------ All payments are handled by our third party merchant provider at the following address URL you can get in touch with them via [/b]Email address[/b] The following information is kept on our site: List details Example - Name, delivery address If you have any concerns please get in touch with us regarding orders via the phone XXXXXXXXX
------Section 5 optional----- Server Hosting details As the owners of the server for this ste we are legally obliged to retain information regarding traffic entering and leaving the site in relation to the laws governing the use of computers in the country of origin.
---------Section 6 Compulsory--- Disputes If you require information or believe an error has been made within this document you should in the first instance contact Email or via a letter to Address If you feel the matter has not be dealt with correctly you can contact the following organisations XXXXX & XXXXX We take your privacy seriously and do not sell or use your data in a way that could be considered inappropriate both morally and in the eyes of the governing laws.
« Last Edit: Mar 07, 2007, 10:44:49 AM by ventureskills »
Global Moderator Community Supporter?
Jedai Sword Master
Gender:
Posts: 6440
39464 credits Members referred : 374
It's time to use PHP5!
« Reply #2 on: Mar 02, 2007, 12:27:52 PM »
Thanks Tim, I think we need to follow this guideline with all of our websites...
I remember that I did some investigations for privacy / disclaimer here in the Netherlands and I talked to some of the people from bigger ISP's. The problem is that here is almost no regulation for internet privacy on regular websites.
Most of the website owners didn't know the difference between disclaimer and internet privacy statement. ... and there was a seminar about this Item given by the chamber of commerce, the result was that the event was canceled because of a lack joining people
Tim Nash
Global Moderator Community Supporter?
Internet Junkie
Posts: 2173
5036 credits Members referred : 2
Venture Skills - New Media & IT group
« Reply #3 on: Mar 02, 2007, 01:22:53 PM »
Not sure about the rest of Europe but the UK has started enforcing the EU legislation on data privacy, other countries probably are as well, so it is a legal requirement (in most of europe) to have an identifiable privacy policy, which provides a method for disputes, and its a good idea to avoid conflicts.
Not sure about the rest of Europe but the UK has started enforcing the EU legislation on data privacy, other countries probably are as well, so it is a legal requirement (in most of europe) to have an identifiable privacy policy, which provides a method for disputes, and its a good idea to avoid conflicts.
you're absolutely right (and I don't like to run after the facts)
the next part is a gallery of screenshots or a kind of directory, using this form the user has to enter much more information, f.e. the e-mail address. Do I need additional information?
what about the information is collected by Adsense? do I need to mention that?
Tim Nash
Global Moderator Community Supporter?
Internet Junkie
Posts: 2173
5036 credits Members referred : 2
Venture Skills - New Media & IT group
« Reply #15 on: Mar 26, 2007, 12:27:23 AM »
Adsense should be included as a third party, in this case the third party is Google who tracks click through to advertisements placed on the site, this click through rate is shared by the site and in some cases limited third party advertisers however no individual click through are recorded and any enquires should be directed to Google TOS documents.
Adsense should be included as a third party, in this case the third party is Google who tracks click through to advertisements placed on the site, this click through rate is shared by the site and in some cases limited third party advertisers however no individual click through are recorded and any enquires should be directed to Google TOS documents.
Ok sounds good, what about the question about data entered by the user during the submission process?