Legal
Privacy Policy
Last updated: 2 July 2026
This Privacy Policy explains how the Processing Foundation (“we”, “us”, “our”) collects, uses, and protects personal data in connection with the Processing Community Day website at day.processing.org (the “Site”). We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable data-protection laws.
1. Who we are (Data Controller)
The data controller responsible for your personal data is:
Processing Foundation Email: day@processing.org
For any privacy-related question or to exercise your rights, contact us at the address above.
2. What data we collect and why
We deliberately keep data collection to a minimum. We collect personal data in two ways:
2.1 Event organizer information (data you submit to us)
When you volunteer to host a Processing Community Day event, you submit information about yourself and your event through our public GitHub repository and/or the Processing Discourse forum. This information may include:
- Your name and the names of co-organizers;
- A primary contact email address;
- Your organization’s name, website, and type;
- Event details (city, country, venue address or location, date, time, description, activities, and related links);
- Your GitHub username.
How this data is used: This information is published on the Site so that the public can discover and attend Processing Community Day events near them. The organizer name(s) and the primary contact email address are displayed publicly on the event map and event pages, and are made available through a public data feed at /data.json.
Legal basis (GDPR Art. 6): Consent. By submitting your event, you consent to the public display of the information you provide. You can withdraw consent at any time (see Section 6).
Please note: Because this data is submitted through, and stored in, a public GitHub repository and public forum, it is publicly visible by design and may be cached, copied, indexed by search engines, or archived by third parties beyond our control. Do not submit information you are not comfortable making public. Where possible, consider using a role-based or shared email address rather than a personal one.
2.2 Server logs (data collected automatically)
The Site is hosted on Netlify. Like any web host, Netlify’s servers automatically receive and may log standard request information — including your IP address, browser user agent, and the pages requested — for the purpose of delivering the Site, ensuring its security, and preventing abuse.
- Legal basis (GDPR Art. 6): Legitimate interest in operating, securing, and delivering the Site.
- Netlify’s privacy policy: netlify.com/privacy
2.3 Website analytics (data collected automatically)
We use Fathom Analytics to understand how the Site is used (for example, which pages are visited and which events are popular). Fathom is a privacy-focused, cookieless analytics service that does not collect or store personal data, does not use cross-site tracking, and does not create personal profiles. No personal data is sold or used for advertising.
Fathom aggregates data anonymously and does not identify individual visitors. We also record a small number of anonymous, aggregate interaction events (for example, when the “Submit an Event” flow is used) to help us improve the Site. None of these events are tied to your identity.
- Legal basis (GDPR Art. 6): Legitimate interest in understanding and improving our Site, balanced against your privacy. Because Fathom does not use cookies or collect personal data, no consent banner is required.
- Fathom’s own privacy policy: usefathom.com/legal/privacy
3. Third-party services and data sharing
We do not sell your personal data. We rely on the following third-party services, each with its own privacy practices:
| Service | Purpose | Privacy policy |
|---|---|---|
| Netlify | Hosting and serving the Site; its servers process request data (including IP addresses) to deliver pages | netlify.com/privacy |
| Fathom Analytics | Cookieless, anonymous website analytics | usefathom.com/legal/privacy |
| GitHub (Microsoft) | Hosting the repository where event submissions and site content are stored | docs.github.com/privacy |
| Discourse forum (discourse.processing.org) | Community forum used to coordinate events | Discourse privacy |
| CARTO / OpenStreetMap | Map tiles used to display the event map | CARTO · OpenStreetMap |
When you load the event map, your browser requests map tiles directly from CARTO’s servers, which means your IP address is necessarily shared with them to deliver the map imagery.
Some of these providers are located outside the European Economic Area (for example, in the United States). Where personal data is transferred internationally, we rely on the providers’ own safeguards (such as Standard Contractual Clauses) as described in their respective privacy policies.
4. How long we keep data
- Event organizer information remains published for as long as the event listing is relevant, and persists in the public GitHub repository’s history unless removed. You may request removal at any time (see Section 6). Note that because Git retains history, complete erasure may require rewriting repository history.
- Analytics data is retained by Fathom in aggregate, anonymous form only, per Fathom’s retention practices.
5. Cookies
The Site does not set tracking or advertising cookies. Fathom Analytics operates without cookies. We may use only strictly necessary browser storage required for the Site to function (for example, remembering your language or theme preference); this is not used to track you.
6. Your rights
Depending on where you live, you have rights over your personal data, including the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”);
- Restrict or object to processing;
- Withdraw consent at any time (for example, to have your event listing and contact details removed);
- Data portability;
- Lodge a complaint with a supervisory authority (in the EU/UK) or your local data-protection regulator.
Under the CCPA/CPRA, California residents also have the right to know what personal information is collected and to request its deletion. We do not sell or “share” personal information as defined by the CCPA.
To exercise any of these rights, email us at day@processing.org. To remove or edit an event listing, you may also open a request in our GitHub repository. We will respond within the timeframe required by applicable law (generally within 30 days).
7. Children’s privacy
The Site is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
8. Security
We take reasonable technical and organizational measures to protect personal data. However, please remember that information submitted through public channels (GitHub, the forum) is public by nature, and no method of transmission over the internet is completely secure.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above. Continued use of the Site after changes take effect constitutes acceptance of the revised policy.
10. Contact
Questions about this Privacy Policy or our data practices:
Processing Foundation — day@processing.org