Privacy Policy
Last Updated: January 1, 2025
Effective Date: January 1, 2025
1. Introduction
The Fides Standard Foundation ("Foundation", "we", "us", or "our") is a non-profit organization dedicated to establishing global standards for information verification. We respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable international data protection laws.
This Privacy Policy outlines how we collect, use, process, and safeguard your information when you interact with our website (fidesstandard.com), use our verification API, or submit data to the Global Source Index.
2. Data Controller
For the purposes of the GDPR, the Data Controller is:
Fides Standard Foundation
Singapore
Email: privacy@fidesstandard.com
3. Information We Collect
We adhere to the principle ofdata minimization. We only collect data that is strictly necessary for the operation of the Fides Standard.
3.1 Information You Provide Voluntarily
- Contact Information:Name, email address, and organizational affiliation provided via contact forms or API access requests.
- Source Metadata:URLs, RSS feeds, and editorial policy documents submitted for verification.
- Dispute Evidence:Links and descriptions provided when contesting a Trust Score.
3.2 Information Collected Automatically
- Log Data:Internet Standard (IP) address, browser type, operating system, and timestamp of your visit. This data is used solely for security auditing and DDoS mitigation.
- API Usage Data:Call frequency, endpoint access, and error rates associated with your API Key.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Legitimate Interests:Maintaining the integrity of the Fides Registry, preventing fraud, and ensuring network security.
- Contractual Performance:Creating API keys and processing verification applications at your request.
- Consent:When you explicitly subscribe to our updates or waitlists.
5. How We Use Your Data
We do not sell, trade, or rent your personal identification information to others. Your data is used to:
- Verify the authenticity of media sources applying for the Global Source Index.
- Generate immutable cryptographic hashes for information assets (Note: Only public metadata is hashed on-chain; personal emails are not).
- Communicate regarding standard updates, API status, or dispute resolutions.
6. International Data Transfers
As a global standard organization, your data may be transferred to and processed in countries other than your country of residence, including Singapore and the United States. We ensure that appropriate safeguards, such as Standard Contractual Clauses (SCCs), are in place to protect your data during these transfers.
7. Data Retention & Immutability
We adhere to the principle ofstorage limitation. We distinguish between two types of data:
- Personal Identification Data:Emails and contact details are retained only for as long as necessary (e.g., until an inquiry is resolved) and can be fully deleted upon request.
- Protocol Metadata (Hashes):To maintain the integrity of the Fides Registry, cryptographic hashes and timestamps of information assets are stored permanently.
Note on GDPR: Cryptographic hashes are considered pseudonymized data that do not contain PII (Personally Identifiable Information). Once generated, these hashes are immutable to prevent historical revisionism, which is a core function of the Protocol.
8. Your Rights
Under GDPR, CCPA, and similar laws, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate personal data.
- Request erasure of your personal data ("Right to be Forgotten"). Please note that while we can delete your account and contact information, thecryptographic hashes already minted to the public registry remain as part of the immutable historical record to ensure the auditability of the information ecosystem.
- Object to processing based on legitimate interests.
To exercise these rights, please contactprivacy@fidesstandard.com.
9. Security
We implement industry-standard technical and organizational measures (TOMs) to protect your data, including TLS 1.3 encryption for data in transit and AES-256 encryption for sensitive data at rest.
10. Updates to This Policy
We may update this Privacy Policy to reflect changes in our standard or legal requirements. The "Last Updated" date at the top of this page indicates when the latest changes were made.