Jitsu Privacy Policy

Introduction

This privacy policy (“Privacy Policy”) applies to all visitors and users of the Jitsu hosted services and websites (collectively, the “Website” or “Websites”, the “Services” or “Service”) which are offered by Jitsu Labs Inc and/or any of its affiliates ("Jitsu" or "we" or "us"). Please read this Privacy Policy carefully. By accessing or using any part of the Websites or self-managed installations, you acknowledge you have been informed of and consent to our practices with regard to your personal information and data.

Websites:

Services:

Jitsu is an open-source project and collaborative community, as well as a company. This means that many portions of our Websites, including information you voluntarily provide, will be public-facing for the open sharing of innovative developments, ideas, and information that make our collaborative community so great. While we are committed to open sharing, we strive to respect the privacy of individual community members and will minimize the information we collect and share. If you do not want to share your information, including personally identifiable information, with other community members and the public, please be thoughtful as to how you interact with our Websites and what information you provide through the Websites (for example, through creating a public profile, project contributions, comments, and blog posts).

Data Protection

Oversight of Data Security is handled by Jitsu's respective Data Protection Officers. Should you wish to make modifications, deletions, or additions to any personal data you believe to be captured by Jitsu, or if you have any general security concerns, please contact us at privacy@jitsu.com.

Compliance with the EU-U.S. Data Privacy Framework (DPF) and UK Extension

Jitsu Labs Inc complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce. Jitsu Labs Inc has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov.

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, Jitsu Labs Inc commits to cooperate and comply with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.

How to Contact Jitsu About Privacy or Complaints

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, Jitsu Labs Inc commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF should first contact Jitsu Labs Inc at:

privacy@jitsu.com

What Information Jitsu Collects and Why

Information from Website Visitors

Like most website operators, Jitsu collects basic non-personally-identifying information from Website visitors of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. We collect this information to better understand how visitors use the Website, to improve our Websites and experience for visitors, and to monitor the security of the Websites. From time to time, Jitsu may publicly release non-personally-identifying information collected from Website visitors in the aggregate, e.g., by publishing a report on trends in the usage of the Website.

Jitsu also collects potentially personally-identifying information, such as Internet Protocol (IP) addresses, and uses an anonymized cookie to track user events for product analytics. While Jitsu does not use this information to personally identify individual visitors, we do use it to understand how visitors interact with the Websites, improve performance and content, and monitor the security of the Websites. The anonymized data is later used for aggregate reporting to help us enhance the overall user experience.

Opt-Out for Tracking

Visitors can opt out of any personal tracking or cookies by adjusting their browser settings to refuse cookies, using the Do Not Track option in their browser, or selecting their cookie preferences available on our website at jitsu.com/cookie-preferences. Visitors may also contact us at privacy@jitsu.com to request removal of any personally-identifiable tracking information.

Personally-Identifying Information

Users of the Websites may choose to interact with Jitsu in ways that provide us with their personally-identifying information. In some instances, a User ID is generated for form and URL tracking, page views, page pings, and usage counts to ascertain product performance and development. The amount and type of information that Jitsu gathers depends on the nature of your interaction with us, as well as the amount of information you choose to share. For example, we ask visitors who use our community Slack group to provide a username and email address. We will also collect the information you provide with us in connection with creating an account on the Website. Profile information is shared publicly, as well as activity under your profile. If you report a security vulnerability to Jitsu and request public acknowledgment, we may publicly disclose the personal information you provided to us in connection with the report, including your name to fulfill your request for acknowledgment. In each case, Jitsu collects such personally-identifiable information only insofar as is necessary or appropriate to fulfill the purpose of the user’s interaction with or request of Jitsu. We will not disclose personally-identifying information other than as described in this Privacy Policy.

Visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent you from engaging in certain Website-related activities or being able to access and use certain features and services.

Information Jitsu Does Not Collect

Jitsu does not intentionally collect sensitive personal information, such as social security numbers, genetic data, health information, or religious information. Although Jitsu does not request or intentionally collect any sensitive personal information, we realize that users might store this kind of information in a Jitsu instance by pushing it to us through our libraries or API. If you store any sensitive personal information on Jitsu’s servers, you are consenting to our storage of that information on our servers, which are located in the United States.

If you're a child under the age of 13, you may not have an account on the Website. Jitsu does not knowingly collect information from or direct any of our Website or content specifically to children under 13. If we learn or have reason to suspect that a user is under the age of 13, we will close the child’s account.

Other countries may have different minimum age limits. If you are below the minimum age for providing consent for data collection in your country, you may not use Jitsu.

Basis for Processing Your Information

Performance of a contract. The use of your information may be necessary to perform the contract that you have with us. For example, if you use our Websites to purchase Jitsu product subscriptions or services, contribute to a project, create a profile, post and comment through our Websites, or request information through our Websites, we will use your information to carry out our obligation to complete and administer that contract or request.

Legitimate interests. We use your information for our legitimate interests, such as to provide you with the best content through our Websites and communications with users and the public, to improve and promote our products and services, and for administrative, security, fraud prevention, and legal purposes.

Consent. We may rely on your consent to use your personal information for certain direct marketing purposes, such as sending you newsletter updates about Jitsu products. You may withdraw your consent at any time through the unsubscribe feature provided with each marketing email or by contacting us at the addresses given at the end of this Privacy Policy.

How Jitsu Uses and Protects Personally-Identifying Information

Sharing Your Information

Jitsu only discloses potentially personally-identifying and personally-identifying information to those of its employees, contractors, and affiliated organizations that (i) need to know that information in order to process it on Jitsu's behalf or to provide services available on the Website, and (ii) that have agreed not to disclose it to others.

Jitsu will not rent or sell potentially personally-identifying and personally-identifying information to anyone. Other than to its employees, contractors, and affiliated organizations, as described above, Jitsu discloses potentially personally-identifying and personally-identifying information only when required to do so by law, or when Jitsu believes in good faith that disclosure is reasonably necessary to protect the property or rights of Jitsu, third parties, or the public at large.

Jitsu takes measures reasonably necessary to protect against the unauthorized access, use, alteration, or destruction of potentially personally-identifying and personally-identifying information.

Onward Transfers and Accountability

When Jitsu transfers personal data to third parties (e.g., service providers or partners), we ensure that such transfers comply with the Accountability for Onward Transfer principle. This includes requiring third parties to maintain the same level of data protection, using contractual agreements such as Standard Contractual Clauses (SCCs).

International Transfer of Information

The Website is hosted in the United States, and information we collect will be stored and processed on our servers in the United States. Our employees, contractors, and affiliated organizations that process information for us, as described above, may be located in the United States or in other countries outside of your home country. By using the Website, you consent to the international transfer of your information by Jitsu in compliance with applicable data protection laws, including the EU-U.S. Data Privacy Framework and UK Extension.

FTC Enforcement and Binding Arbitration

Jitsu Labs Inc is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC) regarding the EU-U.S. Data Privacy Framework Principles.

Under certain conditions, individuals may invoke binding arbitration for complaints regarding our processing of personal data in accordance with Annex I of the EU-U.S. DPF Principles. For more information, individuals should follow the procedures set forth in Annex I of the Principles.

Disclosure in Response to Lawful Requests

Jitsu Labs Inc may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Data Retention and Deletion

If you already have an account on the Websites, you may access, update, alter, or delete your basic user profile information by logging into your account and updating profile settings.

Jitsu will retain your information for as long as your account is active or as needed to perform our contractual obligations, provide you services through the Website, to comply with legal obligations, resolve disputes, preserve legal rights, or enforce our agreements.

Please note that due to the open-source nature of our products, services, and community, we may retain limited personally-identifiable information indefinitely in order to ensure transactional integrity and nonrepudiation. For example, if you provide your information in connection with a blog post, GitHub issue, or comment, we may display that information even if you have deleted your account as we do not automatically delete community posts. Also, as described in our Terms of Use, if you contribute to a Jitsu project and provide your personal information in connection with that contribution, that information (including your name) will be embedded and publicly displayed with your contribution, and we will not be able to delete or erase it because doing so would break the project code.

Privacy Policy Changes

Although most changes are likely to be minor, Jitsu may change its privacy policy from time to time, and in Jitsu's sole discretion.

We may also provide notification to users who have provided us email addresses of material changes to this Privacy Policy through our Website. Jitsu encourages visitors to frequently check this page for any minor changes to its Privacy Policy. Your continued use of this site after any change in this Privacy Policy will constitute your acceptance of such change.