fix(content): state the true data-processing agreement position #130
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!130
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/compliance-copy-accuracy"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Ahead of a wide public announcement, an audit of every compliance claim on the site found
statements that are not true today. This corrects them. Merge before announcing.
The false claims
security.md— "We apply each sub-processor's standard GDPR Article 28 data-processingagreement, and these agreements are available on request." No signed Article 28 instrument
is held for any processor that touches user personal data. Both halves were wrong, and
"available on request" actively invited a request that could not be satisfied — which is
worse than the assertion, because this site's audience is precisely the sort to test it.
privacy.md— "A sub-processor is an external service we use to operate Bitborg under adata-processing agreement", immediately followed by four named suppliers. The definition
made every reader conclude all four were covered.
intro.md(the homepage) — "without code, data or personal information leaving thecountry." This was contradicted by our own privacy policy two clicks away, which lists
processors in France and Finland. A self-contradicting pair needs no investigation to
disprove, just two URLs.
privacy.md— "We make no transfers outside the EU/EEA." An unqualified absolutenegative, contradicted by the same page's own honest-exceptions list.
The approach
Rather than hedging everything into mush, this copies the discipline the security page
already uses for ISO 27001: state the goal, then explicitly disclaim the present tense
("we do not claim that all of these agreements are signed today"). That paragraph is proof the
site can state an unfinished position and still read as trustworthy.
So the DPA section now says two true things: each supplier's published Article 28 processor
terms apply to our use of the service, and signed agreements are being concluded and filed.
The contact line offers to say where an agreement stands, which is a promise we can keep.
Also corrected
docs.mdnarrowed to what holds: repositories hosted in Sweden, encryptedbackups and personal data within the EU/EEA.
honest-exceptions section instead of being quietly contradicted by it.
readable personal data. This is both accurate and a better selling point than listing them
as personal-data sub-processors.
service. It matters more here than in marketing because it is contract text.
security.descriptionno longer asserts GDPR compliance as fact where English says"posture"; aligned Swedish down to English.
Notes
backdated.
register rows on a public surface; one honest aggregate statement is both truthful and safer.
pnpm check0 errors,mdlint0 issues, eslint/stylelint clean, language detector clean(its one hit is a false positive — "arkiv" here means backup archive, matching existing
usage in
security.md, not a git repository).