Skip to content

Instantly share code, notes, and snippets.

@kemitchell
Created April 20, 2018 16:05
Show Gist options
  • Save kemitchell/4aa53f008fa91b2d2706b1760ec2f420 to your computer and use it in GitHub Desktop.
Save kemitchell/4aa53f008fa91b2d2706b1760ec2f420 to your computer and use it in GitHub Desktop.
\documentclass[]{article}
\usepackage{lmodern}
\usepackage{amssymb,amsmath}
\usepackage{ifxetex,ifluatex}
\usepackage{fixltx2e} % provides \textsubscript
\ifnum 0\ifxetex 1\fi\ifluatex 1\fi=0 % if pdftex
\usepackage[T1]{fontenc}
\usepackage[utf8]{inputenc}
\else % if luatex or xelatex
\ifxetex
\usepackage{mathspec}
\else
\usepackage{fontspec}
\fi
\defaultfontfeatures{Ligatures=TeX,Scale=MatchLowercase}
\fi
% use upquote if available, for straight quotes in verbatim environments
\IfFileExists{upquote.sty}{\usepackage{upquote}}{}
% use microtype if available
\IfFileExists{microtype.sty}{%
\usepackage[]{microtype}
\UseMicrotypeSet[protrusion]{basicmath} % disable protrusion for tt fonts
}{}
\PassOptionsToPackage{hyphens}{url} % url is loaded by hyperref
\usepackage[unicode=true]{hyperref}
\hypersetup{
pdftitle={GitHub Privacy Statement},
pdfborder={0 0 0},
breaklinks=true}
\urlstyle{same} % don't use monospace font for urls
\usepackage{longtable,booktabs}
% Fix footnotes in tables (requires footnote package)
\IfFileExists{footnote.sty}{\usepackage{footnote}\makesavenoteenv{long table}}{}
\IfFileExists{parskip.sty}{%
\usepackage{parskip}
}{% else
\setlength{\parindent}{0pt}
\setlength{\parskip}{6pt plus 2pt minus 1pt}
}
\setlength{\emergencystretch}{3em} % prevent overfull lines
\providecommand{\tightlist}{%
\setlength{\itemsep}{0pt}\setlength{\parskip}{0pt}}
\setcounter{secnumdepth}{0}
% Redefines (sub)paragraphs to behave more like sections
\ifx\paragraph\undefined\else
\let\oldparagraph\paragraph
\renewcommand{\paragraph}[1]{\oldparagraph{#1}\mbox{}}
\fi
\ifx\subparagraph\undefined\else
\let\oldsubparagraph\subparagraph
\renewcommand{\subparagraph}[1]{\oldsubparagraph{#1}\mbox{}}
\fi
% set default figure placement to htbp
\makeatletter
\def\fps@figure{htbp}
\makeatother
\title{GitHub Privacy Statement}
\date{}
\begin{document}
\maketitle
Effective date: \textbf{May 25, 2018}
Thanks for entrusting GitHub with your source code, your projects, and
your personal information. Holding onto your private information is a
serious responsibility, and we want you to know how we're handling it.
\subsubsection{The short version}\label{the-short-version}
We only collect the information you choose to give us, and we process it
with your consent, or on another legal basis; we only require the
minimum amount of personal information that is necessary to fulfill the
purpose of your interaction with us; we don't sell it to third parties;
and we only use it as this Privacy Statement describes. If you're
visiting us from the EU, please see our
\protect\hyperlink{githubs-global-privacy-practices}{global privacy
practices}: we comply with the
\href{https://www.privacyshield.gov/participant?id=a2zt000000001K2AAI}{Privacy
Shield framework} and we are compliant with the General Data Protection
Regulation (GDPR). No matter where you are, where you live, or what your
citizenship is, we provide the same standard of privacy protection to
all our users around the world, regardless of their country of origin or
location.
Of course, the short version doesn't tell you everything, so please read
on for more details!
\subsubsection{Summary}\label{summary}
\begin{longtable}{|p{2in}|p{2in}|}
\toprule
Section & What can you find there? \\
\midrule
\endhead
\protect\hyperlink{what-information-github-collects-and-why}{What
information GitHub collects and why}
&
GitHub collects basic information from visitors to our website, and some
personal information from our users. We only require the minimum amount
of personal information necessary from you. This section gives
details.\\
\protect\hyperlink{what-information-github-does-not-collect}{What
information GitHub does not collect}
&
We don't collect information from children under 13, and we don't
collect sensitive data.\\
\protect\hyperlink{how-we-share-the-information-we-collect}{How we share
the information we collect}
&
We share information to provide the service to you, to comply with your
requests, or with our vendors. We do not host advertising on GitHub and
we do not sell your personal information. You can see a list of the
vendors that access your personal information.\\
\protect\hyperlink{how-you-can-access-and-control-the-information-we-collect}{How
you can access and control the information we collect}
&
We provide ways for you to access, alter, or delete your profile
information. You can also contact Support for more help.\\
\protect\hyperlink{our-use-of-cookies-and-tracking}{Our use of cookies
and tracking}
&
We use cookies for the overall functionality of our website, and we use
a small number of tracking and analytics services on a few parts of our
site. We offer a page that makes this very transparent. Please see this
section for more information.\\
\protect\hyperlink{how-github-secures-your-information}{How GitHub
secures your information}\strut
&
We take all measures reasonably necessary to protect the
confidentiality, integrity, and availability of your personal
information on GitHub and to protect the resiliance of our servers as
they host your information.\\
\protect\hyperlink{githubs-global-privacy-practices}{GitHub's global
privacy practices}
&
GitHub complies with both the EU-US Privacy Shield Framework and the
General Data Protection Regulation. Please see this section for more
specific information.\\
\protect\hyperlink{how-we-respond-to-compelled-disclosure}{How we
respond to compelled disclosure}
&
We may share your information in response to a warrant, subpoena, or
other court action, or if disclosure is necessary to protect our rights
or the rights of the public at large. We strive for transparency, and
will notify you when possible.\\
\protect\hyperlink{how-we-communicate-with-you}{How we communicate with
you}
&
We communicate with you by email. You can control the way we contact you
in your account settings.\\
\protect\hyperlink{resolving-complaints}{Resolving complaints}
&
In the unlikely event that we are unable to resolve a privacy concern
quickly and thoroughly, we provide a path of dispute resolution through
external arbiters.\\
\protect\hyperlink{changes-to-our-privacy-statement}{Changes to our
Privacy Statement}
&
We will notify you of material changes to this Privacy Statement 30 days
in advance of any such changes becoming effective. You may also track
changes in our Site Policy repository.\\
\protect\hyperlink{contacting-github}{Contacting GitHub}\strut
&
Please feel free to contact us if you have questions about our Privacy
Statement.\\
\bottomrule
\end{longtable}
\subsubsection{GitHub Privacy Statement}\label{github-privacy-statement}
\hypertarget{what-information-github-collects-and-why}{\subsubsection{What
information GitHub collects and
why}\label{what-information-github-collects-and-why}}
\paragraph{Information from website
browsers}\label{information-from-website-browsers}
If you're \textbf{just browsing the website}, we collect the same basic
information that most websites collect. We use common internet
technologies, such as cookies and web server logs. This is stuff we
collect from everybody, whether they have an account or not.
The information we collect about all visitors to our website includes
the visitor's browser type, language preference, referring site,
additional websites requested, and the date and time of each visitor
request. We also collect potentially personally-identifying information
like Internet Protocol (IP) addresses.
\subparagraph{Why we collect this}\label{why-we-collect-this}
We collect this information to better understand how our website
visitors use GitHub, and to monitor and protect the security of the
website.
\paragraph{Information from users with
accounts}\label{information-from-users-with-accounts}
If you \textbf{create an account}, we require some basic information at
the time of account creation. You will create your own user name and
password, and we will ask you for a valid email address. You also have
the option to give us more information if you want to, and this may
include ``User Personal Information.''
``User Personal Information'' is any information about one of our users
which could, alone or together with other information, personally
identify him or her. Information such as a user name and password, an
email address, a real name, and a photograph are examples of ``User
Personal Information.'' User Personal Information includes Personal Data
as defined in the General Data Protection Regulation.
User Personal Information does not include aggregated, non-personally
identifying information. We may use aggregated, non-personally
identifying information to operate, improve, and optimize our website
and service.
\subparagraph{Why we collect this}\label{why-we-collect-this-1}
\begin{itemize}
\tightlist
\item
We need your User Personal Information to create your account, and to
provide the services you request, including to provide the GitHub
service, the Marketplace service, or to respond to support requests.
\item
We use your User Personal Information, specifically your user name, to
identify you on GitHub.
\item
We use it to fill out your profile and share that profile with other
users if you ask us to.
\item
We will use your email address to communicate with you, if you've said
that's okay, \textbf{and only for the reasons you've said that's
okay}. Please see our section on
\protect\hyperlink{how-we-communicate-with-you}{email communication}
for more information.
\item
We use User Personal Information to make recommendations for you, such
as to suggest projects you may want to follow or contribute to. For
example, when you fill out your biography in your Account Settings, we
learn from it --- as well as from your public behavior on GitHub ---
to determine your coding interests. These recommendations are
automated decisions, but they have no legal impact on your rights.
\item
We use your User Personal Information for internal purposes, such as
to maintain logs for security reasons, for training purposes, and for
legal documentation.
\item
We limit our use of your User Personal Information to the purposes
listed in this Privacy Statement. If we need to use your User Personal
Information for other purposes, we will ask your permission first. You
can always see what information we have, how we're using it, and what
permissions you have given us in your
\href{https://github.com/settings/admin}{user profile}.
\end{itemize}
\subparagraph{Our legal basis for processing
information}\label{our-legal-basis-for-processing-information}
Under certain international laws (including GDPR), GitHub is required to
notify you about the legal basis on which we process User Personal
Information. GitHub processes User Personal Information on the following
legal bases:
\begin{itemize}
\tightlist
\item
When you create a GitHub account, you provide your user name and an
email address. We require those data elements for you to enter into
the Terms of Service agreement with us, and we process those elements
on the basis of performing that contract. We also process your user
name and email address on other bases. If you have a GitHub Hosted,
GitHub Enterprise, or other paid account with us, there will be other
data elements we must collect and process on the basis of performing
that contract. GitHub does not collect or process a credit card
number, but our third-party payment processor does.
\item
When you fill out the information in your
\href{https://github.com/settings/profile}{user profile}, you have the
option to provide User Personal Information such as your full name, an
avatar which may include a photograph, your biography, your location,
your company, and a URL to a third party website. You have the option
of setting a publicly visible email address here. We process this
information on the basis of consent. All of this information is
entirely optional, and you have the ability to access, modify, and
delete it at any time (while you are not able to delete your email
address entirely, you can set it private).
\item
Generally, the remainder of the processing of personal information we
perform is necessary for the purposes of our legitimate interests. For
example, for security purposes, we must keep logs of IP addresses that
access GitHub, and in order to respond to legal process, we are
required to keep records of users who have sent and received DMCA
takedown notices.
\item
If you would like to request erasure of data we process on the basis
of consent or object to our processing of personal information, please
use our \{\{ site.data.variables.contact.contact\_privacy \}\}.
\end{itemize}
\hypertarget{what-information-github-does-not-collect}{\subsubsection{What
information GitHub does not
collect}\label{what-information-github-does-not-collect}}
We do not intentionally collect \textbf{sensitive personal information},
such as social security numbers, genetic data, health information, or
religious information. Although GitHub does not request or intentionally
collect any sensitive personal information, we realize that you might
store this kind of information in your account, such as in a repository.
If you store any sensitive personal information on our servers, you are
responsible for complying with any regulatory controls regarding that
data.
If you're a \textbf{child under the age of 13}, you may not have an
account on GitHub. GitHub does not knowingly collect information from or
direct any of our content specifically to children under 13. If we learn
or have reason to suspect that you are a user who is under the age of
13, we will unfortunately have to close your account. We don't want to
discourage you from learning to code, but those are the rules. Please
see our \href{/articles/github-terms-of-service/}{Terms of Service} for
information about account termination. Other countries may have
different minimum age limits, and if you are below the minimum age for
providing consent for data collection in your country, you may not use
GitHub without obtaining your parents' or legal guardians' consent.
We do not intentionally collect User Personal Information that is
\textbf{stored in your repositories} or other free-form content inputs.
Information in your repositories belongs to you, and you are responsible
for it, as well as for making sure that your content complies with our
\href{/articles/github-terms-of-service/}{Terms of Service}. Any
personal information within a user's repository is the responsibility of
the repository owner.
\paragraph{Repository contents}\label{repository-contents}
GitHub employees
\href{/articles/github-terms-of-service/\#e-private-repositories}{do not
access private repositories unless required to} for security reasons, to
assist the repository owner with a support matter, or to maintain the
integrity of the service. Our Terms of Service provides
\href{/articles/github-terms-of-service/\#e-private-repositories}{more
details}.
If your repository is public, anyone (including us and unaffiliated
third parties) may view its contents. If you have included private or
sensitive information in your public repository, such as email addresses
or passwords, that information may be indexed by search engines or used
by third parties. In addition, while we do not generally search for
content in your repositories, we may scan our servers for certain tokens
or security signatures, or for known active malware.
Please see more about
\protect\hyperlink{public-information-on-github}{User Personal
Information in public repositories}.
\hypertarget{how-we-share-the-information-we-collect}{\subsubsection{How
we share the information we
collect}\label{how-we-share-the-information-we-collect}}
We do share User Personal Information with your permission, so we can
perform services you have requested or communicate on your behalf. For
example, if you purchase an integration or other Developer Product from
our Marketplace, we will share your account name to allow the integrator
to provide you services. Additionally, you may indicate, through your
actions on GitHub, that you are willing to share your User Personal
Information. For example, if you join an organization, the owner of the
organization will have the ability to view your activity in the
organization's access log. We will respect your choices.
We \textbf{do not} share, sell, rent, or trade User Personal Information
with third parties for their commercial purposes, expect where you have
specifically told us to (such as by buying an integration from
Marketplace).
We \textbf{do not} host advertising on GitHub. We may occasionally embed
content from third party sites, such as YouTube, and that content may
include ads. While we try to minimize the amount of ads our embedded
content contains, we can't always control what third parties show. Any
advertisements on individual GitHub Pages or in GitHub repositories are
not sponsored by, or tracked by, GitHub.
We \textbf{do not} disclose User Personal Information outside GitHub,
except in the situations listed in this section or in the section below
on \protect\hyperlink{how-we-respond-to-compelled-disclosure}{Compelled
Disclosure}.
We \textbf{do} share certain aggregated, non-personally identifying
information with others about how our users, collectively, use GitHub,
or how our users respond to our other offerings, such as our conferences
or events. For example, we may
\href{https://github.com/blog/1964-open-source-license-usage-on-github-com}{compile
statistics on the usage of open source licenses across GitHub}. However,
we do not sell this information to advertisers or marketers.
We \textbf{do} share User Personal Information with a limited number of
third party vendors who process it on our behalf to provide or improve
our service, and who have agreed to privacy restrictions similar to our
own Privacy Statement by signing data protection agreements. Our vendors
perform services such as payment processing, customer support ticketing,
network data transmission, and other similar services. When we transfer
your data to our vendors under
\href{/articles/github-privacy-statement/\#githubs-global-privacy-practices}{Privacy
Shield}, we remain responsible for it. While GitHub processes all User
Personal Information in the United States, our third party vendors may
process data outside of the United States or the European Union. If you
would like to know who our third party vendors are, please see our page
on \href{/articles/github-subprocessors-and-cookies/}{Subprocessors}.
We do share aggregated, non-personally identifying information with
third parties. For example, we share the number of stars on a
repository, or in the event of a security incident, we may share the
number of times a particular file was accessed.
We may share User Personal Information if we are involved in a merger,
sale, or acquisition. If any such change of ownership happens, we will
ensure that it is under terms that preserve the confidentiality of User
Personal Information, and we will notify you on our website or by email
before any transfer of your User Personal Information. The organization
receiving any User Personal Information will have to honor any promises
we have made in our Privacy Statement or in our Terms of Service.
\hypertarget{public-information-on-github}{\paragraph{Public information
on GitHub}\label{public-information-on-github}}
Much of GitHub is public-facing. If your content is public-facing, third
parties may access and use it in compliance with our Terms of Service,
such as by viewing your profile or repositories or pulling data via our
API. We do not sell that content; it is yours. However, we do allow
third parties, such as research organizations or archives, to compile
public-facing GitHub information. Other third parties, such as data
brokers, have been known to scrape GitHub and compile data as well.
Your Personal Information, associated with your content, could be
gathered by third parties in these compilations of GitHub data. If you
do not want your Personal Information to appear in third parties'
compilations of GitHub data, please do not make your Personal
Information publicly available and be sure to
\href{https://github.com/settings/emails}{configure your email address
to be private in your user profile}. We set current users' email address
private by default, but legacy GitHub users may need to update their
settings.
If you would like to compile GitHub data, you must comply with our Terms
of Service regarding
\href{/articles/github-terms-of-service/\#5-scraping}{scraping} and
\href{/articles/github-terms-of-service/\#6-privacy}{privacy}, and you
may only use any public-facing Personal Information you gather for the
purpose for which our user has authorized it. For example, where a
GitHub user has made an email address public-facing for the purpose of
identification and attribution, do not use that email address for
commercial advertising. We expect you to reasonably secure any Personal
Information you have gathered from GitHub, and to respond promptly to
complaints, removal requests, and ``do not contact'' requests from
GitHub or GitHub users.
Similarly, projects on GitHub may include publicly available Personal
Information collected as part of the collaborative process. In the event
that a GitHub project contains publicly available Personal Information
that does not belong to GitHub users, we will only use that Personal
Information for the limited purpose for which it was collected, and we
will secure that Personal Information as we would secure any User
Personal Information. If you have a complaint about any Personal
Information on GitHub, please see our section on
\protect\hyperlink{resolving-complaints}{resolving complaints}.
\paragraph{Third party applications}\label{third-party-applications}
You have the option of enabling or adding third party applications,
known as ``Developer Products,'' to your account. These Developer
Products are not necessary for your use of GitHub. We will share your
User Personal Information to third parties when you ask us to, such as
by purchasing a Developer Product from the Marketplace; however, you are
responsible for your use of the third party Developer Product and for
the amount of User Personal Information you choose to share with it. You
can check our \href{https://developer.github.com/v3/users/}{API
documentation} to see what information is provided when you authenticate
into a Developer Product using your GitHub profile.
\paragraph{GitHub applications}\label{github-applications}
You also have the option of adding applications from GitHub, such as our
Desktop app, our Mobile app, or other account features, to your account.
These applications each have their own terms and may collect different
kinds of User Personal Information; however, all GitHub applications are
subject to this Privacy Statement, and we will always collect the
minimum amount of User Personal Information necessary, and use it only
for the purpose for which you have given it to us.
\hypertarget{how-you-can-access-and-control-the-information-we-collect}{\subsubsection{How
you can access and control the information we
collect}\label{how-you-can-access-and-control-the-information-we-collect}}
If you're already a GitHub user, you may access, update, alter, or
delete your basic user profile information by
\href{https://github.com/settings/profile}{editing your user profile} or
contacting \{\{ site.data.variables.contact.contact\_support \}\}. You
can control the information we collect about you by limiting what
information is in your profile, by updating out of date information, or
by contacting \{\{ site.data.variables.contact.contact\_support \}\}.
\paragraph{Data retention and
deletion}\label{data-retention-and-deletion}
Generally, GitHub will retain User Personal Information for as long as
your account is active or as needed to provide you services.
We may retain certain User Personal Information indefinitely, unless you
delete it or request its deletion. For example, we don't automatically
delete inactive user accounts, so unless you choose to delete your
account, we will retain your account information indefinitely.
If you would like to cancel your account or delete your User Personal
Information, you may do so in your
\href{https://github.com/settings/admin}{user profile}. We will retain
and use your information as necessary to comply with our legal
obligations, resolve disputes, and enforce our agreements, but barring
legal requirements, we will delete your full profile (within reason)
within 90 days. You may contact \{\{
site.data.variables.contact.contact\_support \}\} to request the erasure
of the data we process on the basis of consent within 30 days.
\hypertarget{our-use-of-cookies-and-tracking}{\subsubsection{Our use of
cookies and tracking}\label{our-use-of-cookies-and-tracking}}
\paragraph{Cookies}\label{cookies}
GitHub uses cookies to make interactions with our service easy and
meaningful. We use cookies (and similar technologies, like HTML5
localStorage) to keep you logged in, remember your preferences, and
provide information for future development of GitHub. We also use
cookies to identify a device, for security reasons. By using our
website, you agree that we can place these types of cookies on your
computer or device. If you disable your browser or device's ability to
accept cookies, you will not be able to log in or use GitHub's services.
We provide a web page on
\href{/articles/github-subprocessors-and-cookies/}{cookies and tracking}
that describes the cookies we set, the needs we have for those cookies,
and the types of cookies they are (temporary or permanent). It also
lists our third party analytics and service providers and details
exactly which parts of our website we permit them to track.
\paragraph{Tracking and analytics}\label{tracking-and-analytics}
We use a number of third party analytics and service providers to help
us evaluate our users' use of GitHub; compile statistical reports on
activity; and improve our content and website performance. We only use
these third party analytics providers on certain areas of our website,
and all of them have signed data protection agreements with us that
limit the type of personal information they can collect and the purpose
for which they can process the information. In addition, we use our own
internal analytics software to provide features and improve our content
and performance.
We do not currently respond to your browser's Do Not Track signal, and
we do not permit third parties other than our analytics and service
providers to track GitHub users' activity over time on GitHub. We do not
track your online browsing activity on other online services over time.
\hypertarget{how-github-secures-your-information}{\subsubsection{How
GitHub secures your
information}\label{how-github-secures-your-information}}
GitHub takes all measures reasonably necessary to protect User Personal
Information from unauthorized access, alteration, or destruction;
maintain data accuracy; and help ensure the appropriate use of User
Personal Information.
GitHub enforces a written security information program. Our program:
\begin{itemize}
\tightlist
\item
aligns with industry recognized frameworks;\\
\item
includes security safeguards reasonably designed to protect the
confidentiality, integrity, availability, and resilience of our users'
data;
\item
is appropriate to the nature, size, and complexity of GitHub's
business operations;
\item
includes incident response and data breach notification processes; and
\item
complies with applicable information security related laws and
regulations in the geographic regions where GitHub does business.
\end{itemize}
In the event of a data breach that affects your User Personal
Information, we will act promptly to mitigate the impact of a breach and
notify any affected users.
Transmission of data on GitHub is encrypted using SSH, HTTPS, and
SSL/TLS. While our data is not encrypted at rest, we manage our own
cages and racks at top-tier data centers with excellent physical and
network security, and when data is stored with a third party storage
provider, it is encrypted.
No method of transmission, or method of electronic storage, is 100\%
secure. Therefore, we cannot guarantee its absolute security. For more
information, see our \href{/articles/github-security/}{security
disclosures}.
\hypertarget{githubs-global-privacy-practices}{\subsubsection{GitHub's
global privacy practices}\label{githubs-global-privacy-practices}}
\textbf{We store and process the information that we collect in the
United States} in accordance with this Privacy Statement (our
subprocessors may store and process data outside the United States).
However, we understand that we have users from different countries and
regions with different privacy expectations, and we try to meet those
needs even when the United States does not have the same privacy
framework as other countries'.
We provide the same standard of privacy protection --- as described in
this Privacy Statement --- to all our users around the world, regardless
of their country of origin or location, and we are proud of the levels
of notice, choice, accountability, security, data integrity, access, and
recourse we provide. We have appointed a Privacy Counsel and we work
hard to comply with the applicable data privacy laws wherever we do
business, and we also expect to appoint a Data Protection Officer to
oversee our compliance efforts. Additionally, if our vendors or
affiliates have access to User Personal Information, they must sign
agreements that require them to comply with our privacy policies and
with applicable data privacy laws.
In particular: - GitHub provides clear methods of unambiguous, informed
consent at the time of data collection, when we do collect your personal
data using consent as a basis. - We collect only the minimum amount of
personal data necessary for our purposes, unless you choose to provide
more. We encourage you to only give us the amount of data you are
comfortable sharing. - We offer you simple methods of accessing,
correcting, or deleting the User Personal Information we have collected.
- We provide our users notice, choice, accountability, security, and
access, and we limit the purpose for processing. We also provide our
users a method of recourse and enforcement. These are the Privacy Shield
Principles, but they are also just good practices.
\paragraph{Cross-border data
transfers}\label{cross-border-data-transfers}
For cross-border data transfers from the European Union (EU) and the
European Economic Area (EEA), GitHub adheres to the
\href{https://www.privacyshield.gov/}{Privacy Shield Framework}. You may
view our entry in the
\href{https://www.privacyshield.gov/participant?id=a2zt000000001K2AAI}{Privacy
Shield List}.
In addition to providing our users methods of unambiguous, informed
consent and control over their data, we participate in and comply with
the Privacy Shield framework, and we are committed to subject any
Personal Information we receive from the EU and EEA to the Privacy
Shield Principles. In addition, we continue to participate in the Safe
Harbor Framework for Swiss data transfers to the US. Please read more
about \href{/articles/global-privacy-practices/}{GitHub's international
privacy commitments}.
\hypertarget{how-we-respond-to-compelled-disclosure}{\subsubsection{How
we respond to compelled
disclosure}\label{how-we-respond-to-compelled-disclosure}}
GitHub may disclose personally-identifying information or other
information we collect about you to law enforcement in response to a
valid subpoena, court order, warrant, or similar government order, or
when we believe in good faith that disclosure is reasonably necessary to
protect our property or rights, or those of third parties or the public
at large.
In complying with court orders and similar legal processes, GitHub
strives for transparency. When permitted, we will make a reasonable
effort to notify users of any disclosure of their information, unless we
are prohibited by law or court order from doing so, or in rare, exigent
circumstances.
For more information, see our
\href{/articles/guidelines-for-legal-requests-of-user-data/}{Guidelines
for Legal Requests of User Data}.
\subsubsection{How we, and others, communicate with
you}\label{how-we-and-others-communicate-with-you}
We will use your email address to communicate with you, if you've said
that's okay, \textbf{and only for the reasons you've said that's okay}.
For example, if you contact our Support team with a request, we will
respond to you via email. You have a lot of control over how your email
address is used and shared on and through GitHub. You may manage your
communication preferences in your
\href{https://github.com/settings/emails}{user profile}.
By design, the Git version control system associates many actions with a
user's email address, such as commit messages. We are not able to change
many aspects of the Git system. If you would like your email address to
remain private, even when you're commenting on public repositories, you
can \href{https://github.com/settings/emails}{create a private email
address in your user profile}. You should also
\href{/articles/setting-your-commit-email-address-on-github/}{update
your local Git configuration to use your private email address}. This
will not change how we contact you, but it will affect how others see
you. We set current users' email address private by default, but legacy
GitHub users may need to update their settings. Please see more about
email addresses in commit messages
\href{https://help.github.com/articles/about-commit-email-addresses/}{here}.
Depending on your email settings, GitHub may occasionally send
notification emails about changes in a repository you're watching, new
features, requests for feedback, important policy changes, or offer
customer support. We also send marketing emails, but only with your
consent, if you opt in to our list. There's an unsubscribe link located
at the bottom of each of the marketing emails we send you. Please note
that you can not opt out of receiving important communications from us,
such as mails from our Support team or system emails, but you can
configure your notifications settings in your profile.
Our emails might contain a pixel tag, which is a small, clear image that
can tell us whether or not you have opened an email and what your IP
address is. We use this pixel tag to make our email more effective for
you and to make sure we're not sending you unwanted email.
\hypertarget{resolving-complaints}{\subsubsection{Resolving
complaints}\label{resolving-complaints}}
If you have concerns about the way GitHub is handling your User Personal
Information, please let us know immediately. We want to help. You may
contact us by filling out the \{\{
site.data.variables.contact.contact\_privacy \}\}. You may also email us
directly at [email protected] with the subject line ``Privacy
Concerns.'' We will respond promptly --- within 45 days at the latest.
In the coming weeks, GitHub expects to appoint a Data Protection Officer
who will be responsible for oversight over our compliance with the GDPR.
We will provide our Data Protection Officer's contact information here.
In the meantime, you may contact our Privacy Team via any of the methods
above.
\paragraph{Dispute resolution process}\label{dispute-resolution-process}
In the unlikely event that a dispute arises between you and GitHub
regarding our handling of your User Personal Information, we will do our
best to resolve it. If we cannot, we have selected JAMS, an independent
dispute resolution provider, to handle unresolved Privacy Shield
complaints. If we are unable to resolve your concerns after a good faith
effort to address them, you may
\href{https://www.jamsadr.com/file-an-eu-us-privacy-shield-or-safe-harbor-claim}{contact
JAMS and submit a Privacy Shield claim}. JAMS is a US-based private
alternate dispute resolution provider, and we have contracted with JAMS
to provide an independent recourse mechanism for any of our users for
privacy concerns \textbf{at no cost to you.} You do not need to appear
in court; you may conduct this dispute resolution process via telephone
or video conference. If you are not based in the EU or EEA, but you
would still like to use the JAMS arbitration process to resolve your
dispute, please let us know and we will provide access to you.
\paragraph{Independent arbitration}\label{independent-arbitration}
Under certain limited circumstances, European Union individuals may
invoke binding Privacy Shield arbitration as a last resort if all other
forms of dispute resolution have been unsuccessful. To learn more about
this method of resolution and its availability to you, please read more
about
\href{https://www.privacyshield.gov/article?id=ANNEX-I-introduction}{Privacy
Shield}. Arbitration is not mandatory; it is a tool you can use if you
choose to.
We are subject to the jurisdiction of the Federal Trade Commission.
\hypertarget{changes-to-our-privacy-statement}{\subsubsection{Changes to
our Privacy Statement}\label{changes-to-our-privacy-statement}}
Although most changes are likely to be minor, GitHub may change our
Privacy Statement from time to time. We will provide notification to
Users of material changes to this Privacy Statement through our Website
at least 30 days prior to the change taking effect by posting a notice
on our home page or sending email to the primary email address specified
in your GitHub account. We will also update our
\href{https://github.com/github/site-policy/}{Site Policy} repository,
which tracks all changes to this policy. For changes to this Privacy
Statement that do not affect your rights, we encourage visitors to check
our Site Policy repository frequently.
\subsubsection{License}\label{license}
This Privacy Statement is licensed under this
\href{https://creativecommons.org/publicdomain/zero/1.0/}{Creative
Commons Zero license}. For details, see our
\href{https://github.com/github/site-policy\#license}{site-policy
repository}.
\hypertarget{contacting-github}{\subsubsection{Contacting
GitHub}\label{contacting-github}}
Questions regarding GitHub's Privacy Statement or information practices
should be directed to our \{\{
site.data.variables.contact.contact\_privacy \}\}.
\end{document}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment