Legal

Privacy Policy

Last updated: 2 July 2026

This Privacy Policy explains how the Processing Foundation (“we”, “us”, “our”) collects, uses, and protects personal data in connection with the Processing Community Day website at day.processing.org (the “Site”). We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable data-protection laws.

1. Who we are (Data Controller)

The data controller responsible for your personal data is:

Processing Foundation Email: day@processing.org

For any privacy-related question or to exercise your rights, contact us at the address above.

2. What data we collect and why

We deliberately keep data collection to a minimum. We collect personal data in two ways:

2.1 Event organizer information (data you submit to us)

When you volunteer to host a Processing Community Day event, you submit information about yourself and your event through our public GitHub repository and/or the Processing Discourse forum. This information may include:

How this data is used: This information is published on the Site so that the public can discover and attend Processing Community Day events near them. The organizer name(s) and the primary contact email address are displayed publicly on the event map and event pages, and are made available through a public data feed at /data.json.

Legal basis (GDPR Art. 6): Consent. By submitting your event, you consent to the public display of the information you provide. You can withdraw consent at any time (see Section 6).

Please note: Because this data is submitted through, and stored in, a public GitHub repository and public forum, it is publicly visible by design and may be cached, copied, indexed by search engines, or archived by third parties beyond our control. Do not submit information you are not comfortable making public. Where possible, consider using a role-based or shared email address rather than a personal one.

2.2 Server logs (data collected automatically)

The Site is hosted on Netlify. Like any web host, Netlify’s servers automatically receive and may log standard request information — including your IP address, browser user agent, and the pages requested — for the purpose of delivering the Site, ensuring its security, and preventing abuse.

2.3 Website analytics (data collected automatically)

We use Fathom Analytics to understand how the Site is used (for example, which pages are visited and which events are popular). Fathom is a privacy-focused, cookieless analytics service that does not collect or store personal data, does not use cross-site tracking, and does not create personal profiles. No personal data is sold or used for advertising.

Fathom aggregates data anonymously and does not identify individual visitors. We also record a small number of anonymous, aggregate interaction events (for example, when the “Submit an Event” flow is used) to help us improve the Site. None of these events are tied to your identity.

3. Third-party services and data sharing

We do not sell your personal data. We rely on the following third-party services, each with its own privacy practices:

ServicePurposePrivacy policy
NetlifyHosting and serving the Site; its servers process request data (including IP addresses) to deliver pagesnetlify.com/privacy
Fathom AnalyticsCookieless, anonymous website analyticsusefathom.com/legal/privacy
GitHub (Microsoft)Hosting the repository where event submissions and site content are storeddocs.github.com/privacy
Discourse forum (discourse.processing.org)Community forum used to coordinate eventsDiscourse privacy
CARTO / OpenStreetMapMap tiles used to display the event mapCARTO · OpenStreetMap

When you load the event map, your browser requests map tiles directly from CARTO’s servers, which means your IP address is necessarily shared with them to deliver the map imagery.

Some of these providers are located outside the European Economic Area (for example, in the United States). Where personal data is transferred internationally, we rely on the providers’ own safeguards (such as Standard Contractual Clauses) as described in their respective privacy policies.

4. How long we keep data

5. Cookies

The Site does not set tracking or advertising cookies. Fathom Analytics operates without cookies. We may use only strictly necessary browser storage required for the Site to function (for example, remembering your language or theme preference); this is not used to track you.

6. Your rights

Depending on where you live, you have rights over your personal data, including the right to:

Under the CCPA/CPRA, California residents also have the right to know what personal information is collected and to request its deletion. We do not sell or “share” personal information as defined by the CCPA.

To exercise any of these rights, email us at day@processing.org. To remove or edit an event listing, you may also open a request in our GitHub repository. We will respond within the timeframe required by applicable law (generally within 30 days).

7. Children’s privacy

The Site is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.

8. Security

We take reasonable technical and organizational measures to protect personal data. However, please remember that information submitted through public channels (GitHub, the forum) is public by nature, and no method of transmission over the internet is completely secure.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above. Continued use of the Site after changes take effect constitutes acceptance of the revised policy.

10. Contact

Questions about this Privacy Policy or our data practices:

Processing Foundationday@processing.org