fix(content): state the true data-processing agreement position #130

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/compliance-copy-accuracy in i main 2026-07-31 23:06:31 +00:00
Ägare

Ahead of a wide public announcement, an audit of every compliance claim on the site found
statements that are not true today. This corrects them. Merge before announcing.

The false claims

  1. security.md — "We apply each sub-processor's standard GDPR Article 28 data-processing
    agreement, and these agreements are available on request."
    No signed Article 28 instrument
    is held for any processor that touches user personal data. Both halves were wrong, and
    "available on request" actively invited a request that could not be satisfied — which is
    worse than the assertion, because this site's audience is precisely the sort to test it.
  2. privacy.md — "A sub-processor is an external service we use to operate Bitborg under a
    data-processing agreement"
    , immediately followed by four named suppliers. The definition
    made every reader conclude all four were covered.
  3. intro.md (the homepage) — "without code, data or personal information leaving the
    country."
    This was contradicted by our own privacy policy two clicks away, which lists
    processors in France and Finland. A self-contradicting pair needs no investigation to
    disprove, just two URLs.
  4. privacy.md — "We make no transfers outside the EU/EEA." An unqualified absolute
    negative, contradicted by the same page's own honest-exceptions list.

The approach

Rather than hedging everything into mush, this copies the discipline the security page
already uses for ISO 27001: state the goal, then explicitly disclaim the present tense
("we do not claim that all of these agreements are signed today"). That paragraph is proof the
site can state an unfinished position and still read as trustworthy.

So the DPA section now says two true things: each supplier's published Article 28 processor
terms apply to our use of the service, and signed agreements are being concluded and filed.
The contact line offers to say where an agreement stands, which is a promise we can keep.

Also corrected

  • Homepage and docs.md narrowed to what holds: repositories hosted in Sweden, encrypted
    backups and personal data within the EU/EEA.
  • Transfers section scoped to user content and account data, cross-linking the
    honest-exceptions section instead of being quietly contradicted by it.
  • Glesys and Hetzner re-described as receiving client-side-encrypted archives containing no
    readable personal data. This is both accurate and a better selling point than listing them
    as personal-data sub-processors.
  • Terms' extraterritorial-law absolute scoped to the hosting infrastructure, not the whole
    service. It matters more here than in marketing because it is contract text.
  • "every sub-processor" → the ones listed in the privacy policy.
  • Swedish security.description no longer asserts GDPR compliance as fact where English says
    "posture"; aligned Swedish down to English.

Notes

  • Every change is made in both languages.
  • Last-updated dates bumped on all five changed pages, so a corrected page does not read as
    backdated.
  • Deliberately not included: a per-supplier status table. That would reproduce internal
    register rows on a public surface; one honest aggregate statement is both truthful and safer.
  • pnpm check 0 errors, mdlint 0 issues, eslint/stylelint clean, language detector clean
    (its one hit is a false positive — "arkiv" here means backup archive, matching existing
    usage in security.md, not a git repository).
Ahead of a wide public announcement, an audit of every compliance claim on the site found statements that are not true today. This corrects them. **Merge before announcing.** ## The false claims 1. **`security.md` — "We apply each sub-processor's standard GDPR Article 28 data-processing agreement, and these agreements are available on request."** No signed Article 28 instrument is held for any processor that touches user personal data. Both halves were wrong, and "available on request" actively invited a request that could not be satisfied — which is worse than the assertion, because this site's audience is precisely the sort to test it. 2. **`privacy.md` — "A sub-processor is an external service we use to operate Bitborg under a data-processing agreement"**, immediately followed by four named suppliers. The definition made every reader conclude all four were covered. 3. **`intro.md` (the homepage) — "without code, data or personal information leaving the country."** This was contradicted by our own privacy policy two clicks away, which lists processors in France and Finland. A self-contradicting pair needs no investigation to disprove, just two URLs. 4. **`privacy.md` — "We make no transfers outside the EU/EEA."** An unqualified absolute negative, contradicted by the same page's own honest-exceptions list. ## The approach Rather than hedging everything into mush, this copies the discipline the security page **already** uses for ISO 27001: state the goal, then explicitly disclaim the present tense ("we do not claim that all of these agreements are signed today"). That paragraph is proof the site can state an unfinished position and still read as trustworthy. So the DPA section now says two true things: each supplier's published Article 28 processor terms apply to our use of the service, and signed agreements are being concluded and filed. The contact line offers to say where an agreement *stands*, which is a promise we can keep. ## Also corrected - Homepage and `docs.md` narrowed to what holds: repositories hosted in Sweden, encrypted backups and personal data within the EU/EEA. - Transfers section scoped to user content and account data, cross-linking the honest-exceptions section instead of being quietly contradicted by it. - Glesys and Hetzner re-described as receiving client-side-encrypted archives containing no readable personal data. This is both accurate and a better selling point than listing them as personal-data sub-processors. - Terms' extraterritorial-law absolute scoped to the hosting infrastructure, not the whole service. It matters more here than in marketing because it is contract text. - "every sub-processor" → the ones listed in the privacy policy. - Swedish `security.description` no longer asserts GDPR compliance as fact where English says "posture"; aligned Swedish down to English. ## Notes - Every change is made in **both** languages. - Last-updated dates bumped on all five changed pages, so a corrected page does not read as backdated. - Deliberately **not** included: a per-supplier status table. That would reproduce internal register rows on a public surface; one honest aggregate statement is both truthful and safer. - `pnpm check` 0 errors, `mdlint` 0 issues, eslint/stylelint clean, language detector clean (its one hit is a false positive — "arkiv" here means backup archive, matching existing usage in `security.md`, not a git repository).
supernaut lade till 1 incheckning 2026-07-31 22:59:27 +00:00
fix(content): state the true data-processing agreement position
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m11s
5fd51584d5
The security page asserted that each sub-processor's GDPR Article 28
agreement is applied and that copies are "available on request", and the
privacy policy defined a sub-processor as one used "under a data-processing
agreement". No signed Article 28 instrument is held for any processor that
touches user personal data, so all three claims were false, and the
"available on request" offer invited a request that could not be met.

Replace them with what is true today: each supplier's published Article 28
processor terms apply, and signed agreements are being concluded and filed.
This copies the discipline the same page already uses for ISO 27001, which
states the goal and explicitly disclaims the present tense.

Also correct four related overstatements:

- The homepage claimed the whole chain runs "without code, data or personal
  information leaving the country", which the privacy policy contradicted
  two clicks away by listing processors in France and Finland. Narrowed to
  repositories hosted in Sweden, encrypted backups and personal data within
  the EU/EEA.
- The privacy policy's absolute "no transfers outside the EU/EEA" is scoped
  to user content and account data, and cross-links the honest-exceptions
  section rather than being silently contradicted by it.
- Glesys and Hetzner are described as receiving client-side-encrypted
  archives with no readable personal data, which is what actually happens.
- The terms' extraterritorial-law absolute is scoped to the hosting
  infrastructure rather than the whole service.

Smaller alignments: "every sub-processor" becomes the ones listed in the
privacy policy; the Swedish security description no longer asserts GDPR
compliance as fact where English says "posture"; the documentation intro
says the service is hosted in Sweden rather than everything.

Last-updated dates bumped on every page changed, so a corrected page does
not read as backdated.
supernaut sammanfogade incheckning 47c068b421 till main 2026-07-31 23:06:31 +00:00
supernaut tog bort grenen fix/compliance-copy-accuracy 2026-07-31 23:06:31 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web!130
Ingen beskrivning angiven.