PRIVACY · EFFECTIVE 27 SEP 2026

Privacy information for openrgd.org.

This notice describes the limited personal-data processing involved in operating the public OpenRGD website. The site currently has no user accounts, contact form or newsletter.

CONTROLLER & CONTACT

OpenRGD is currently operated as an open project.

For this public website, the current controller and privacy contact is Pasquale Ranieri, the project steward identified by the canonical OpenRGD governance record. OpenRGD is not presented on this website as a separate legal entity. If a dedicated legal entity becomes the controller, this notice will be updated.

To request a private privacy contact channel, open a minimal GitHub issue containing only [PRIVACY CONTACT REQUEST]. Do not place personal data or request details in the public issue.

WHAT IS PROCESSED

The site is intentionally data-light.

Website delivery & security

Requests to the site may generate technical data such as IP address, user agent, requested URL, timestamp, response status and security/operational logs needed to deliver and protect the service.

Consent preferences

ECM is used as the consent-management layer. It may store or process the choices needed to remember and apply privacy preferences across visits.

External links

Following links to GitHub or other external primary sources causes the destination service to process the request under its own privacy terms.

PURPOSES & LEGAL BASES

Processing is limited to operating the site and honoring privacy choices.

Site delivery, availability and abuse preventionLEGITIMATE INTERESTGDPR Art. 6(1)(f), where applicable.
Recording and applying privacy choicesCOMPLIANCE / LEGITIMATE INTERESTGDPR Art. 6(1)(c) and/or 6(1)(f), as applicable to the processing.
Optional analytics or advertising storageCONSENTGDPR Art. 6(1)(a) where optional processing is configured and enabled.

The public site initializes analytics and advertising consent states as denied. Optional categories are not required to read OpenRGD content.

TECHNICAL PROVIDERS

Infrastructure providers receive only the data needed for their role.

Vercel

OpenRGD.org is deployed on Vercel infrastructure, which provides hosting, edge delivery and operational/security services.

ECM

ECM at ecm.plus supplies the consent-management script and preference layer used by this site.

GitHub

GitHub hosts the canonical OpenRGD source and external contribution/disclosure surfaces. Data is sent to GitHub when a visitor follows those links.

Technical providers may process data from infrastructure outside the visitor's country. Where the GDPR applies, relevant provider transfer mechanisms and applicable safeguards govern those transfers.

RETENTION

Data is kept only as long as needed for its stated purpose.

Operational and security logs follow the retention settings of the hosting/infrastructure services and are retained only as needed for delivery, reliability, security and incident investigation. Consent records/preferences are kept only for the period needed to remember, apply and, where required, demonstrate the user's choices, and may be refreshed when those choices change or expire.

YOUR RIGHTS

GDPR rights remain available where they apply.

Depending on the circumstances, individuals may request access, rectification, erasure, restriction, portability or object to processing. Consent can be withdrawn at any time for future optional processing without affecting processing already carried out lawfully. A complaint may also be lodged with the competent supervisory authority; in Italy this is the Garante per la protezione dei dati personali.

AUTOMATED DECISIONS

The public website does not make decisions about visitors.

OpenRGD.org does not use visitor data for automated decision-making or profiling that produces legal or similarly significant effects.

CHANGE CONTROL

This notice follows the actual public website, not planned features.

If OpenRGD later adds accounts, forms, newsletters, analytics, advertising or a dedicated legal entity, this notice and the consent configuration must be updated before those changes become the new privacy baseline.