Legal / privacy
Privacy notice
- version
- v1
- effective from
- 2026-10-02
- issuer
- Purpose Source Association
This notice covers purposesource.org and the public edge API at api.purposesource.org. It is written to satisfy the Swiss Federal Act on Data Protection (FADP), the EU and UK General Data Protection Regulations (GDPR), and the principle behind all three: say what you collect, why, for how long, and who else sees it — and collect as little as possible. Here, the honest summary is that this site collects almost nothing.
1. Controller
Purpose Source Association, an association under Art. 60 ff. ZGB with its seat in
Aarau, canton of Aargau, Switzerland (the imprint carries the register
status). Postal address: Purpose Source Association, Altstadtbüro, Zollrain 2, 5000 Aarau,
Switzerland. Contact for anything in this notice: legal@purposesource.org, or the
data-request route.
If the Association is dissolved. The registry, the ledger, the key set and the transparency log are archived and handed to the archive custodian named on the wind-down page, which is the controller of that archive from that day. Before the signing keys are retired the archive is minimised — a listed organisation’s name becomes a status-only record unless the organisation asked to stay listed — and the data-request route becomes the custodian’s published contact.
Representatives. The Association is established in Switzerland and has a Swiss-domiciled representative under Art. 69 Abs. 2 ZGB. A representative in the European Union under Art. 27 GDPR (and in the United Kingdom under the UK GDPR) is appointed before the Association itself processes personal data of an EU- or UK-based Entitlement purchaser — Paddle, our merchant of record, is the seller to purchasers, and the Association’s own processing of purchaser data is occasional — and is named in the next version of this notice.
2. What this site collects from a visitor: nothing
- No cookies are set on anonymous browsing. No local storage, no fingerprinting. Paddle’s checkout, once you continue to payment, may set Paddle’s own cookies under Paddle’s privacy notice.
- No analytics script exists on any page, first- or third-party. Aggregate traffic figures (requests per path, per country, per day) come from the hosting provider’s server-side zone metrics, which your browser contributes to only by making the request.
- No consent banner, because there is nothing to consent to. Introducing any technology that would need one is a change to the site’s requirements, never a banner bolted on.
- Two third-party scripts:
- the bot-protection challenge widget on the contact forms, loaded on that page only. It sees its own challenge and your browser’s request to it; it sets no cookie usable elsewhere on this site.
- Paddle.js on the pricing page, loaded only when you continue to payment; it opens Paddle’s checkout, which Paddle runs under its own privacy notice.
Edge request logs. Like every website, this one is served by a provider whose edge records the request: IP address, path, user agent, timestamp, response code. These logs are retained briefly under the provider’s terms, are not exported or retained by the Association, and are not linked to any person — there are no accounts on this site.
3. What you can send us
Forms. The contact, abuse-report, and data-request forms send what you type — your reply address, a subject, a message — through the challenge widget to the edge Worker, which verifies the challenge server-side, forwards the submission as one email to the steward inbox through the transactional-email provider, and stores nothing. There is no database on this site’s request path. Your message then lives in the steward mailbox for the retention period in section 8.
Email. Mail to the published addresses is routed at the edge to the steward inbox. It is handled like a form submission.
What is never in a URL. Organisation names in a coverage lookup are sent by POST, never as a query string, so a third party’s name never lands in a shareable link, a proxy log, or a cached URL. No personal data appears in any URL on this site, and the verification page sends a certificate identifier to the edge API and nowhere else.
4. Entitlement purchasers
Entitlements are sold through Paddle (Paddle.com Market Ltd; Paddle.com Inc. for buyers in the United States; Paddle.com (Canada) Ltd. for buyers in Canada), our merchant of record, which is the seller to you and an independent controller of your checkout and payment data under its own privacy notice. Card and bank details never reach the Association.
The Association receives and processes, as controller: the purchasing organisation’s name and verified domain; the purchaser contact’s name and email; the revenue-band self-certification (one binding, timestamped tick); whether the organisation asked to be listed by name; for the Pass, any registered repositories the organisation chose to name; and the settlement record. From this it produces the signed entitlement record and the certificate, and it screens the organisation against sanctions lists.
Named only if you ask. An organisation that buys an Entitlement is named in the public registry only if it ticks List our organisation’s name publicly at checkout; otherwise it appears as Unlisted organisation under an opaque company identifier. Unlisted is not anonymous: the identifier, the lane, what the Entitlement covers, its term dates, its status and the fee amount of each purchase are published in the registry and the ledger, and a domain the organisation verifies resolves publicly to that identifier. The contact person’s name and email are never published. If an organisation’s registered name is a person’s name — a sole trader’s, for instance — ticking the box publishes that name. The name is shown on the list of covered organisations, in the signed entitlement record and on the certificate’s public record, and is never written into the ledger rows themselves, so asking to be unlisted removes it from every page the Association publishes; copies others have already made are outside its reach.
5. Registry, contributors, and public artifacts
The registry, the waiver list, the list of covered organisations, the allocation ledger, the certificate status records, and the transparency log are public. They contain repository identifiers, company identifiers, the names of organisations that asked to be listed and of organisations covered by a waiver, and — from the phase in which contributors can claim their attribution — a contributor’s public platform login and opaque account identifier, displayed only if the contributor opted in. They never contain email addresses, because the Association never collects contributors’ email addresses. The transparency log contains hashes, type codes, and timestamps only. The ledger contains aggregates, repositories and company identifiers — no personal data by schema; a listed organisation’s name is shown beside its ledger rows on the transparency pages, never inside them.
Anyone may permanently exclude their identity from attribution processing through the exclusion list, which stores a salted hash only — see section 9.
6. Certificates
A certificate names its subject as the subject elected to be named (an organisation, or a contributor’s platform login or supplied name — never an email address). Its status record at the verification URL is public; it carries that name only for an organisation that asked to be listed and for a contributor who chose to display it, and for every other organisation it carries the status alone, while the signed certificate goes only to the organisation. Revocation is prospective and leaves the record’s historical window readable. After revocation a minimal issuance record is retained for ten years for the Association’s accounting and legal defence.
7. Why we may process this: lawful bases
| Processing | Basis (GDPR Art. 6(1)) |
|---|---|
| Serving the site; edge logs; abuse prevention | (f) legitimate interests — running a public website securely |
| Answering a form or an email | (f) legitimate interests — responding to you; (b) where you are a purchaser |
| Purchaser records, entitlement records, certificates | (b) performance of the Entitlement contract |
| Accounting records, sanctions screening, VAT | (c) legal obligation (Swiss Code of Obligations Art. 958f; Swiss and international sanctions law) |
| Public registry entries of purchasing organisations (identifier, lane, scope, term, status, fee amounts; the name only on request) | (b) contract; (f) legitimate interests — the credential’s public function; a sole trader’s name only on (a) the consent the listing tick gives, withdrawable at any time |
| Contributor attribution display | (a) consent (opt-in), withdrawable at any time; the underlying computation over public repository data rests on (f), with the balancing test on file |
| Opt-in email | (a) consent, double opt-in, withdrawable at any time |
Under the FADP, the same processing is justified by contract, legal obligation, or overriding interest, and by consent where a consent is asked for.
8. Retention
| Data | Retained |
|---|---|
| Edge request logs | Briefly, by the provider under its terms; not retained by the Association |
| Form submissions and email | 24 months in the steward mailbox, then deleted; data-subject-request correspondence for the request plus one year |
| Purchaser and entitlement records, invoices, band self-certifications | 10 years (Swiss Code of Obligations Art. 958f) |
| Usage declarations | Life of the account, or 10 years where money-relevant |
| Certificate issuance records | Life of the certificate plus 10 years after revocation or expiry, as a minimal record |
| Transparency-log entries and ledger rows | Permanent — they contain no personal data |
| Exclusion-list hashes | Permanent — honouring an objection requires remembering it |
| The archive after a dissolution | Permanent, held by the archive custodian as its controller; minimised before the keys are retired (§1) |
| Sanctions-screening records | 10 years |
9. Your rights, and how to use them
You have the rights of access, rectification, erasure, restriction, objection, and data portability, the right to withdraw a consent at any time without affecting earlier processing, and the right to complain to a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC); in the EU or UK, your local authority.
The route: the data-request form or legal@purposesource.org. We verify
your identity proportionately (for a request about attribution data, by having you sign in
with the same platform account), answer within 30 days — usually much sooner — and charge
nothing. Erasure never reaches the ledger or the transparency log (they contain no personal
data) and never reaches accounting records within their statutory retention; it does reach
display identity, contact data, tokens, and opt-in emails, and it revokes certificates issued
to you on request.
The right to object to attribution. If you never want your contributions attributed, displayed, or used to direct funds, you may be placed on the exclusion list permanently. The list stores a salted hash of your account identifier — no login, no reason text — and the exclusion is irreversible by design, so that no future operator can quietly undo it.
No automated decision-making with legal or similarly significant effect takes place. The coverage function computes an answer from published records; a person reviews any dispute.
10. Recipients and transfers
The recipients of personal data are the subprocessors listed, with purposes, data categories, and residency, on the Trust Center overview. That list is part of this notice: a change to it publishes as a new version of this notice at a new URL.
The Association’s own stores are in Switzerland. Where a subprocessor processes data in the United States (edge logs, email delivery, error telemetry, source hosting), the transfer rests on standard contractual clauses and, where the provider is certified, the Swiss–US Data Privacy Framework. Switzerland is recognised as adequate by the European Union. The full residency statement lists every exception.
11. Children
This site is not directed at children and the Association does not knowingly process personal data of anyone under 16. A contributor’s attribution is displayed only after an opt-in from an account the contributor controls.
12. Changes
When this notice changes, the new version is published on this site and announced on the Trust Center. Every version, this one included, stays permanently readable at its own numbered address; this one’s is /legal/privacy/v1. Version 2 will add the EU/UK representative and the register details once published.