DRAFT waiting for feedback from Privacy

Privacy is a core element of trust within Apache projects.
This guide explains how podlings should handle personal information, follow ASF policies, and align with privacy expectations such as the GDPR, while staying true to ASF values of transparency, respect, and openness.


1. Purpose and Scope

This guide applies to everyone involved in Apache Incubator projects:

It covers how to protect privacy in communications, data handling, and project governance.


1.1 Key Definitions


2. Why Privacy Matters

Apache projects operate in public, but contributors still deserve privacy and respect. Maintaining appropriate safeguards:

Balancing transparency with privacy means sharing enough information for open governance while avoiding unnecessary disclosure of personal data.


3. ASF Privacy Policy

The ASF Privacy Policy governs how the ASF handles personal information. Podlings automatically inherit this policy.

Key points:


4. Personal Information in Public Archives

ASF participation is inherently public, and contributors consent to this by using ASF systems.

Avoid posting private contact details or other sensitive information. Discuss confidential matters only on the private@podling.apache.org list.

Important: Individual Contributor License Agreements (ICLAs) contain personal data and must never be sent to project or podling mailing lists.
They should only be submitted directly to the ASF Secretary as described at https://www.apache.org/licenses/icla.pdf.

ASF does not remove historical archives except in exceptional cases handled by the Privacy Team.



5. Mailing Lists and Moderation

Mailing lists are the foundation of ASF collaboration. Never forward or quote messages from a podling’s private@ list to public lists without consent.

Messages on private@ lists are accessible to PPMC members, mentors, and all ASF Members and are subject to ASF privacy and retention rules.


6. GDPR and International Privacy Obligations

The General Data Protection Regulation (GDPR) and similar laws protect personal data. Although the ASF is a U.S. non-profit, it follows GDPR principles:

Podlings must not collect or process personal data outside ASF infrastructure. If unsure, contact privacy@apache.org before using any external service.

Podlings that temporarily collect voluntary data (such as survey results or event registrations) must delete it once no longer needed and never reuse it for unrelated purposes.


7. Podling Websites and External Services

Podling websites must respect ASF infrastructure and privacy standards:


7.1 Allowed and Prohibited Tools

✅ Allowed

⚠️ Allowed with Review

🚫 Not Allowed

Rule of thumb: if it sets cookies, contacts an external server, or tracks users then it’s not allowed on ASF infrastructure.


7.2 Website Privacy and Analytics

Podling websites must be static, privacy-respecting, and under the control of the PPMC.

⚠️ Reminder: Google Analytics, Tag Manager, and all third-party analytics are strictly prohibited. ASF-hosted Matomo is the only approved solution.

Requesting Matomo Access

  1. Email privacy@apache.org with your podling site URL and reporting contact.
  2. The privacy team will coordinate setup.
  3. You’ll receive a tracking snippet to include in your site footer.

7.3 Data Processing Agreements (DPAs)

ASF may sign Data Processing Agreements (DPAs) with trusted providers when required by law (for example, Algolia for internal search).

Podlings:

This ensures consistent privacy terms and legal protection across all ASF projects.


8. ASF Values and Privacy Culture

ASF privacy expectations reflect the same cultural principles that guide governance:


9. Contacts

For questions or concerns about privacy or data handling, contact: privacy@apache.org