Pegasus Fleet Privacy Policies


Revision as of 23:36, 28 May 2018 by Emily Quinn (talk | contribs) (Created page with "{{Icons|pfo}} Here, the official Pegasus Fleet Privacy Policies are listed, including the issue date and any further relevant dates (such as revision/voiding dates). Due to th...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

This page has been adopted by the PFA as an official policy.

Here, the official Pegasus Fleet Privacy Policies are listed, including the issue date and any further relevant dates (such as revision/voiding dates). Due to the complexity of the Fleet Privacy Policy in order to comply with privacy regulations, the Fleet Privacy Policy has been separated into separate policies.

Privacy Policy

Pegasus Fleet takes the privacy of its members seriously, and shall take steps in order to protect that privacy. Fleet members should be able to expect a certain measure of privacy, both of their personal data and communications. The Fleet will not tolerate illegal access or sharing of such information.

  1. Private communications are to be accessible, modifiable, or shareable only be the sender and the recipient(s). Only the sender and recipient(s) are permitted to share these communications with others. Communications pertaining to Fleet business will be shared with the appropriate parties for the purpose of conducting said Fleet business, but must be treated as private communications for parties other than the Fleet, original sender, and original recipient(s). Accessing, modifying, or sharing communications without the permission of these parties, whatever the means, are grounds for immediate expulsion from the Fleet. This does not apply to public communications, such as posts, logs, news items, or Fleet announcements.
  2. The access, modification, or sharing of personal data, including contact data such as emails and IP addresses, provided to the Fleet for administrative purposes of the Fleet and communications required for the operation of the Fleet, for reasons other than conducting Fleet business, is prohibited without permission of the person of whom the data belongs.
  3. Members must be made aware of any and all personal data that is collected by Pegasus Fleet, and have the right to request removal of that personal data. See the Pegasus Fleet Data Management and Retention Policy for more information.
  4. In compliance with the Children's Online Privacy Protection Act of 1998 (COPPA), Pegasus Fleet and its member sims do not accept players under the age of 13. Any player found to be under the age of 13 will be immediately removed without question.
  5. For a player to apply for membership of a Pegasus Fleet sim, the player must provide their informed consent of their personal data to be used for the purpose of conducting Fleet business and providing Fleet related communication through the Fleet mailing list or sim manifest. The sign up terms must provide an acknowledgement that the user has read and agrees to your privacy policy and is agreeing to receive communications related to your sim and the Fleet. These terms should include a clause affirming that the user has the full right and authority to enter into this agreement based on their age, or allow a parent or legal guardian to enter into the agreement.
  6. In the event of a data breach, Pegasus Fleet is required to notify members within 72 hours of the discovery of the data breach. This notification will be sent over the Fleet mailing list used for special announcements and monthly updates.

Issue Date: 25th May 2018

Data Management and Retention Policy

In the process of conducting Fleet business, Pegasus Fleet collects various types of user data for all visitors, registered members, and banned members. They type of data collected, and how it is stored, is detailed below.

  1. Pegasus Fleet records the following information about any visitor:
    1. Web Browser (from UserAgent string) - saved as an anonymized statistic
    2. Operating System (from UserAgent string) - saved as an anonymized statistic
    3. IP Address (from connection data) - saved in session cookie for the purposes of session management
    4. Server Logs record the UserAgent string and IP Address of all visitors for the purposes of diagnosing technical problems with Fleet services. Server access logs may also be used to ban an individual found to be acting inappropriately with Fleet services, including but not limited to violating the rules of the Fleet, placing an undue burden on Fleet services, or violating applicable laws ("Inappropriate Use")
    5. Google Analytics additionally records a range of data about users via a script included on the Pegasus Fleet website to enable the Fleet to analyze the effectiveness of Fleet services. Specific information on this recorded data can be obtained from Google Analytics, and is not controlled by Pegasus Fleet.
  2. Pegasus Fleet records the following information on logged-in users, Fleet members, and Fleet applicants:
    1. Username. A pseudonym can be provided in place of a real name. Defaults to the name of the first character added under the user’s email address on the main site; is set manually by users when registering on the forums or wiki. The username is used to assist in identifying users on the sites, and is displayed next to forum posts and on wiki edit logs. Users can update their username via the relevant user profile pages.
    2. Email Address. Provided either by the user on registration or by the sim CO when adding users who have signed-up via a Pegasus Fleet sim website directly. Users have control over updating their email address on their user account, but require Webmaster support to update or remove some historical records of email addresses in the database. Email addresses are used to facilitate communications with the user about fleet or sim-related matters.
    3. Month and Day of Birth. Not collected by default. Users may choose if they wish to provide this information and have control to reset it. Birth year is not collected.
    4. Instant Messenger Details. Optionally provided by user when submitting an application. Requires Webmaster support to remove from previous application records. This information may be used by sim cos and fleet staff members when contacting users about their application.
    5. Age. Requires Webmaster to remove it from the database for each application submitted. This is used to ensure that users meet the minimum age requirements for the fleet and for the sim they are applying to join.
  3. Pegasus Fleet records the following information for banned users to enable the Fleet to ensure that the ban is enforceable.
    1. IP Address - optional, manually entered by staff member issuing the ban
    2. Email Address - optional, manually entered by staff member issuing the ban, or automatically by system for 90-day command cool-down bans.
  4. Pegasus Fleet retains collected data permanently, or until it is manually deleted, with the following exception:
    1. Server logs only retain the last seven (7) days of data.

All visitors, members, and other users of the Pegasus Fleet site are entitled to access of their, and only their, personal data. Users who wish to see what data has been collected and stored on them can do so by contacting the Pegasus Fleet Webmaster at webmaster@pegasusfleet.net. Users should provide the search terms for the data they are requesting (i.e. email address and/or IP address) to improve the response time of the request. Data collected by Google Analytics is aggregated and anonymized, and is not accessible by Pegasus Fleet in any way that can be associated with individual users.

Personal data collected by the Fleet is only shared within Pegasus Fleet for the purpose of conducting Fleet business. Data is shared in the following ways:

  1. User email addresses are visible to the commanding officer of any sim of which that user is a member and of any sim of which the user has applied, and to Fleet staff members with appropriate IFS privileges for the purpose of Fleet administration.
  2. Crew email addresses are visible in sim monthly reports submitted to Fleet staff
  3. Email addresses of users who nominate another user for an award is recorded against that nomination and is available only to Fleet staff.
  4. IFS usernames, or character name if not changed from the default, is visible to Fleet staff and website administrators.
  5. Wiki and Forum usernames are publicly visible and used to attribute wiki edits and/or forum posts to that user.
  6. User IP addresses are visible to server administrators
  7. User name, age, email address, and instant messenger details, if provided, are visible to recipients of any application submitted through the Pegasus Fleet site.
  8. Banned user IP and/or email addresses are visible as public information

Users of the Pegasus Fleet site have the right to request deletion of personal data from the Pegasus Fleet database. Such requests should be made to the Pegasus Fleet Webmaster (webmaster@pegasusfleet.net).

Issue Date: 25th May 2018

Do Not Track Policy

Pegasus Fleet servers operate through the use of Apache, and as such server logs will follow Apache 2 standards in regards to Do Not Track requests.

Cookies are set to expire after seven (7) days. Cookies are scoped only to pegasusfleet.net and will only be set if the connection is https.

If Do Not Track settings are active, Pegasus Fleet does not track the OS and Browser of visitors. Google Analytics is also no longer included in the page. Pegasus Fleet does still record the IP address under Do Not Track, but only for session purposes to enable login.

Issue Date: 25th May 2018

California Privacy Rights Policy

Your California Privacy Rights: If you are a California resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of your personal information by Pegasus Fleet or a member sim to third parties for the third parties’ direct marketing purposes. To make such a request, please contact the Pegasus Fleet Webmaster at webmaster@pegasusfleet.net.

Issue Date: 25th May 2018

Sim Privacy Compliance Policy

All member sims of Pegasus Fleet must maintain a privacy policy meeting the minimum requirements of the Fleet Privacy Policy, as shown below, substituting the sim for the Fleet, where appropriate. Commanding Officers not complying with this policy will be subject to disciplinary action. Due to the sensitivity of the Fleet Privacy Policy, periodic random audits will be conducted of the member sim sites to ensure that the policy is followed. These audits may be conducted by the Pegasus Fleet Admiralty without prior warning.

  1. Pegasus Fleet sims must include a separate page for each of the following policies, accessible by a link on the sim Privacy Policy page. The sim Privacy Policy should be easily accessible from any page of the sim site. The footer is an acceptable location for this link. Each of the listed sim policies must comply with at least the minimum requirements of the corresponding Pegasus Fleet Policy. References to the Pegasus Fleet staff should be replaced with the sim staff, where appropriate.
    1. Privacy Policy
    2. Data Management and Retention Policy
    3. Do Not Track Policy
    4. California Privacy Rights Policy
  2. For a player to apply for membership of a Pegasus Fleet sim, the player must provide their informed consent of their personal data to be used for the purpose of conducting Fleet business and providing Fleet related communication through the Fleet mailing list or sim manifest. The sign up terms must provide an acknowledgement that the user has read and agrees to your privacy policy and is agreeing to receive communications related to your sim and the Fleet. These terms should include a clause affirming that the user has the full right and authority to enter into this agreement based on their age. Pegasus Fleet sims should include the statements below in their sign up terms. These terms will be reviewed as part of the privacy policy audits.
    1. The following clause should be included in the sim sign up terms:
      1. By agreeing to these terms, I acknowledge that I have read and agree to the [SIM NAME] Privacy Policy, which can be found here [PROVIDE LINK TO SIM PRIVACY POLICY], and that I agree to receive communications from the sim and from Pegasus Fleet regarding updates pertaining to this sim and Pegasus Fleet. I understand that my contact information will not be shared internally for any reason other than conducting [SIM NAME] and Pegasus Fleet business, and will not be shared externally for any reason without my permission. By agreeing to these terms, I affirm that I have the full right and authority to enter into this Agreement, including that I am of the age of majority in [WEB HOST COUNTY; for Fleet-hosted sims the web host country will be the United Kingdom] and my own country.
    2. Additionally, if the rating allows for users younger than the age of consent, an additional clause may be included:
      1. If I do not have the full right and authority to enter into this Agreement for any reason, up to and including not having reached the age of consent, a Parent or Legal Guardian may enter the Agreement on my behalf. In compliance with the Children's Online Privacy Protection Act of 1998 (COPPA), I, or my Legal Guardian, affirm that I am above the age of 13.
  3. Pegasus Fleet sims using Nova must update to Nova version 2.5 or later. Nova version 2.5 contains additional functionality to comply with privacy regulations.
  4. During a random audit, if a sim is discovered to not be in compliance with the above requirements following the initial sim creation grace period, the sim Commanding Officer will be subject to a Yellow Demerit. The Commanding Officer will be given two (2) weeks from the date of notification to make the appropriate corrections to the sim policies. If the Commanding Officer has not made the noted corrections within that time, they will be subject to a second Yellow Demerit and an additional two (2) weeks will be given to make the necessary corrections. If the Commanding Officer fails to meet the requirements after receiving two Yellow Demerits, they will receive a third Yellow Demerit and a Red Demerit, per the Pegasus Fleet Disciplinary Policy. A Red Demerit will result in a loss of command.

Issue Date: 25th May 2018