CGS Contact Forum Privacy Policy
Revision 1.4.1, Last Modified 05.11.2002 by Andrew West.
e-mail site.maintainer.Q2.2010@xcgs.org
The current revision of this document can always be found at:
http://xcgs.org/s/privacy.cgi
The CGS Contact Forum takes privacy and security very seriously. In this
Privacy Policy, this document will outline what measures have been taken
to address these issues.
Short:
The CGS Contact Forum does not give out details to any third party
(such as mailing lists, companies or organisations). Your details are kept
securely by the CGS Contact Forum and if you have any problems or queries,
contact the current Site Maintainer, Andrew West, at the e-mail address
site.maintainer@xcgs.org .
Long:
This policy applies to site pages that have URLs that begin with
'http://xcgs.org'
In this document the term "CGS CF" is used as a short form for the "CGS
Contact Forum". The sole person responsible for the CGS Contact Forum is
the Site Maintainer, which is currently Andrew West. ("The Site Maintainer").
The private site information is not accessible to any person other than the
Site Maintainer. The passphrases required to gain access to private information
are known only to the Site Maintainer.
The CGS Contact Forum makes five pledges to you:
1. The CGS CF Security will always be maintained to a level that protects
all information provided to the correct level, for example, messages on the
Message Forum can be read only by those who are allowed to. Unauthorised
access to files or members' accounts will be proactively denied.
2. The CGS CF protects any member details that are not intended for displaying
on the site ("private member information") with a high level of security
and ensures that this level of security is upheld at all times. The Site
Maintainer is the only person who has internal knowledge of the details of
the site security. Rather than relying on security by obscurity, the
system uses time-proven methods for member verification and access control.
3. Your personally identifiable information will not be released to any
third-parties, although a proportion of member information is displayed on
the site in good faith for its intended purpose. (Personally identifiable
information is information, like your name, e-mail address or other details
that can be used to uniquely identify you.)
4. You can manage and control the information that you have voluntarily
provided to the CGS CF. You can tell the Site Maintainer what your privacy
questions and security concerns are so that the Site Maintainer can
respond.
5. To ensure privacy is upheld at all times, all site scripting that runs on
the CGS CF has been programmed solely by the Site Maintainer. No third
party code or scripts are used at any point in the CGS CF code and scripts.
The CGS CF will not intentionally share any information about
the use of the site with third parties, however the web host Dreamhost
reserves the right to monitor access onto its servers, which includes the
CGS CF. The domain xcgs.org is hosted on their servers.
The CGS CF will NOT pass on e-mail addresses to third parties, or
provide any other member details to third parties. The nature of the site
is such that selected information can be viewed by any web client, but
the CGS CF presents the information in good faith and cannot exclude the
possibility of unwanted use by third parties of public readable material.
The Site Maintainer should be notified in the event of such abuse of details
by any third party so that the situation can be resolved as quickly as
possible.
The CGS CF records a variety of information about the site members that is
not publically readable, but this is done for security purposes or
site statistics purposes only. This may include IP addresses and member Sign-In
information for pages on which the security is important. The intention is to
ensure that the site security is not compromised at any point. Such private
information is never passed on to third parties. As stated above, the Site
Maintainer is the only person who has access to this information. As the
CGS CF is hosted on a UKLinux.net web server, the possibility that their
administrators access the information exists, but they will have appropriate
protocol to ensure their members' privacy.
The CGS CF maintains message discussion and interaction areas. Members using
some areas (such as the guest Message Forums, Polls facility, Forum Archive)
should note that textual and other information provided will usually be
displayed for any web client to see. The Message Forum allows for category
owners to mark their category as accessible to anyone, any logged-in member or
specific signed-in members or groups of members. The security system will
prevent unauthorised access to anyone not allowed to view messages as dictated
by the category owner's options.
The site Chat Room is only accessible to valid members of the site, and is
securely protected from intrusion by other persons. It is a requirement of
the Chat Room that messages are stored privately on the server, however
every single message is deleted when all members have exited the Chat Room.
The CGS CF has a facility for e-mail announcements of new features, which is
accessible only to the Site Maintainer. It is used extremely infrequently.
By becoming a 'minimalist member' or by contacting the Site Maintainer you can
opt-out of these announcements. Message Forum posts are used in almost all
cases to indicate improvements to the site.
You will not receive any e-mail from the CGS CF if you are not a full site
member or you have contacted the Site Maintainer expressing that you are to
be removed from all mailings. No e-mail correspondance from the CGS CF will
include advertisements for any third party. The CGS CF respects that members do
not welcome this form of announcement e-mail frequently or if it is larger
in length than is strictly necessary.
Member passwords are stored privately on the server in the second revision of
the Site Maintainer's proprietary one-way encryption format. The internal
details of current encryption method are not public. The current
cookie-based Sign-In system uses authentication information encoded in very
short strings of characters that are used to maintain authentication and
session information. There are security means to ensure that this does not
allow unauthorised access. The Site Maintainer does not have access to any
passwords other than the encrypted forms stored as part of a member's private
profile. It is for this reason that there are no "password request" forms
on the site, sites using two-way encryption to store such details provide
insufficient security.
If you have any concerns regarding this Privacy Policy, please contact the
Site Maintainer. This Privacy Policy may contain omissions or even errors,
it will be revised where necessary to clarify.
(Last revised to cover new web host 05.11.2002, previously updated 22.08.2001)
|