Privacy Policy

Last Updated: January 7, 2025

Table of Contents

  1. Introduction
  2. Data We Collect
  3. How We Use Your Data
  4. Data Storage and Retention
  5. Data Sovereignty
  6. Tenant Isolation
  7. Third-Party Services
  8. Cookies and Tracking
  9. Your Rights
  10. Security Measures
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact Us

1. Introduction

My Digital Sovereignty Community ("we," "us," or "our") is committed to protecting your privacy and giving you control over your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our multi-tenant community platform.

Our platform is built on the principle of data sovereignty - you own your data, and your community owns its collective data. We are merely custodians, providing secure infrastructure for your digital space.

Our Promise: We will never sell your data, use it for advertising, or access it without your explicit consent except as required for technical operations or legal compliance.

2. Data We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Information From Third-Party Services

3. How We Use Your Data

3.1 Platform Functionality

We use your data to:

3.2 Communication

3.3 Security and Compliance

3.4 Platform Improvement

What We DON'T Do: We never use your data for advertising, marketing to third parties, training AI models (except for your own voice transcriptions), or any purpose not explicitly listed here.

4. Data Storage and Retention

4.1 Where We Store Your Data

Your data is stored in European data centers to comply with GDPR and ensure data sovereignty. Specifically:

4.2 How Long We Keep Your Data

4.3 Backups and Disaster Recovery

We maintain daily automated backups of all data to protect against data loss. Backups are:

5. Data Sovereignty

5.1 You Own Your Data

Unlike traditional social platforms, you retain full ownership of all content you create. This includes:

5.2 Community Ownership

Your community (tenant) collectively owns the community's data. Community administrators can:

5.3 Data Portability

You have the right to export your personal data in machine-readable formats:

6. Tenant Isolation

6.1 Multi-Tenant Architecture

My Digital Sovereignty Community uses a multi-tenant architecture where each community is completely isolated:

6.2 Technical Enforcement

Tenant isolation is enforced through multiple layers:

Security Guarantee: We conduct regular audits to verify tenant isolation is maintained. Any breach of tenant isolation is treated as a critical security incident.

7. Third-Party Services

7.1 Matrix (Chat Integration)

7.2 Nextcloud (File Storage)

7.3 Jitsi (Video Calling)

7.4 OpenAI Whisper (Voice Transcription)

7.5 DeepL (Translation - Optional)

Self-Hosting Preference: We prioritize self-hosted services (Matrix, Nextcloud, Jitsi, Whisper) to minimize third-party data sharing and maintain full control over your data.

8. Cookies and Tracking

8.1 Essential Cookies

We use strictly necessary cookies for:

8.2 Functional Cookies

8.3 What We DON'T Use

8.4 Cookie Management

You can control cookie preferences in your browser settings. Note that blocking essential cookies will prevent you from logging in and using the platform.

9. Your Rights (GDPR Compliance)

Under GDPR and other privacy laws, you have the following rights:

9.1 Right to Access

Request a copy of all personal data we hold about you. We will provide this within 30 days in a machine-readable format.

9.2 Right to Rectification

Correct any inaccurate or incomplete personal data. You can update most information directly in your profile settings.

9.3 Right to Erasure ("Right to Be Forgotten")

Request deletion of your personal data. We will delete all data within 90 days unless legally required to retain it.

9.4 Right to Data Portability

Export your data in JSON format to migrate to another platform. Includes all content, files, and messages.

9.5 Right to Restrict Processing

Request that we limit how we use your data while you contest its accuracy or processing legality.

9.6 Right to Object

Object to processing of your data for specific purposes. We will stop processing unless we have compelling legitimate grounds.

9.7 Right to Withdraw Consent

Withdraw consent for any processing based on consent (e.g., marketing emails). Does not affect lawfulness of processing before withdrawal.

9.8 Right to Lodge a Complaint

File a complaint with your local data protection authority if you believe we have violated your privacy rights.

How to Exercise Your Rights: Email privacy@mysovereignty.digital with your request. We will respond within 30 days.

10. Security Measures

10.1 Data Encryption

10.2 Access Controls

10.3 Infrastructure Security

10.4 Incident Response

In the event of a data breach:

11. Children's Privacy

My Digital Sovereignty Community is not intended for children under 13 years old. We comply with the Children's Online Privacy Protection Act (COPPA):

For users aged 13-16 in the EU, we require parental consent as mandated by GDPR.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make changes:

We encourage you to review this policy periodically to stay informed about how we protect your data.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer

Email: privacy@mysovereignty.digital
Address: My Digital Sovereignty Ltd
Wellington, New Zealand

Response Time: We aim to respond to all privacy inquiries within 30 days.