Skip to content

Update privacy policy for GDPR compliance#4634

Closed
Yndira-E wants to merge 5 commits intomainfrom
yndira/privacy-policy-update
Closed

Update privacy policy for GDPR compliance#4634
Yndira-E wants to merge 5 commits intomainfrom
yndira/privacy-policy-update

Conversation

@Yndira-E
Copy link
Copy Markdown
Contributor

@Yndira-E Yndira-E commented Mar 4, 2026

Description

This PR updates the privacy policy to accurately reflect our current tracking implementation and to strengthen our compliance with GDPR

Key Changes

  • Tool Transparency: Clearly describes our use of third-party tools, including Google Analytics, HubSpot, PostHog, warmly.ai, and advertising pixels (Google, Meta, LinkedIn).
  • Cookie Alignment: Aligns policy descriptions with our actual site configuration (e.g., distinguishing between strictly necessary security cookies like reCAPTCHA and optional tracking).
  • Notice to European Users: Added a dedicated section for EEA, UK, and Swiss visitors covering Legal Bases for processing (Consent, Contractual Necessity, Legitimate Interest) and explicit GDPR rights (Erasure, Portability, Restriction).
  • International Transfers: Discloses the use of Standard Contractual Clauses (SCCs) and our preference for EU-based data centers (e.g., HubSpot EU1) to protect data transferred to the US.

Related Issue(s)

Checklist

  • I have read the contribution guidelines
  • I have considered the performance impact of these changes
  • Suitable unit/system level tests have been added and they pass
  • Documentation has been updated
  • For blog PRs, an Art Request has been created (instructions)

@netlify
Copy link
Copy Markdown

netlify bot commented Mar 4, 2026

Deploy Preview for flowforge-website ready!

Name Link
🔨 Latest commit e97de97
🔍 Latest deploy log https://app.netlify.com/projects/flowforge-website/deploys/69c2b9406875f17eaee80eb8
😎 Deploy Preview https://deploy-preview-4634--flowforge-website.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 91 (no change from production)
Accessibility: 81 (no change from production)
Best Practices: 100 (no change from production)
SEO: 91 (no change from production)
PWA: -
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

Copy link
Copy Markdown
Contributor

@UnicornGunnerz UnicornGunnerz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Yndira-E Is there a reason we added the European Economic Area (EEA) section? Shouldn't we cover all regions in our privacy policy? Let me know if I'm missing anything.

@Yndira-E
Copy link
Copy Markdown
Contributor Author

Yndira-E commented Mar 4, 2026

That section covers a GDPR requirement. GDPR doesn't cover all regions, so it's only a requirement where listed there. It was a recommendation made by Gemini.

The intention wasn’t to exclude other regions; the general privacy policy still applies globally, but to clarify the rights and legal framework that are specific to GDPR.

Also worth noting that the website behaviour itself is the same globally: no cookies are installed without consent except for strictly necessary ones.

That said, if you think the structure should be different or have more accurate legal guidance, happy for it to be adjusted.

@UnicornGunnerz
Copy link
Copy Markdown
Contributor

Makes sense. thank you!

Comment thread src/privacy-policy.md Outdated
Comment thread src/privacy-policy.md Outdated
Comment thread src/privacy-policy.md
Comment on lines +138 to +162
## <span name="european-users">Additional Information for European Users</span>

If you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, the following additional information applies to you.

**Legal Bases for Processing**
We process your personal information on the following legal bases:
* **Consent:** For marketing communications and the use of non-essential cookies (Analytics, Functional, and Advertising).
* **Contractual Necessity:** To provide the Service and support you have requested.
* **Legitimate Interests:** To protect our Service, prevent fraud (such as via reCAPTCHA), and improve our product offerings.

**Your Rights**
Under the GDPR, you have the following rights:
* **Right to Access/Portability:** Request a copy of your data in a structured format.
* **Right to Erasure:** Request that we delete your personal information.
* **Right to Object/Restrict:** Object to our processing of your data for legitimate interests or request we limit how we use it.
* **Right to Withdraw Consent:** Withdraw your consent for cookies or marketing at any time.
* **Right to Complain:** You have the right to lodge a complaint with your local Data Protection Authority.

To exercise any of these rights, please follow the instructions in the [How to contact us](#how-to-contact-us) section below. We will respond to your request within 30 days.

**International Transfers**
When we transfer data to the United States, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
* **Standard Contractual Clauses (SCCs):** We use specific contracts approved by the European Commission.
* **Data Center Selection:** We utilize EU-based data centers (e.g., HubSpot EU1 region) where available to minimize transfer risks.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Yndira-E If you now misexplain rights, do users obtain new rights? Do we want to update this, or do you extend the liability for the company inadvertently?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Definitely not looking to extend liability. This was an attempt to make GDPR-specific rights more explicit based on a recommendation, but I agree this goes into legal territory.

I’m not a legal expert, so we could either remove or simplify this section for now and handle it separately with proper legal review.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As the previous one was legally reviewed, lets stick with it.

@ZJvandeWeg ZJvandeWeg closed this Apr 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants