1. Who this covers
This policy applies to uwitz.org — this website, the donation flow, and the staff console behind it. It is published by Uwitz, established in Estonia ("Uwitz", "we", "us"), which is the data controller for everything described here.
Our two divisions run their own sites and publish their own policies:
- Uwitz Juniors — juniors.uwitz.org
- Uwitz Corporate — corp.uwitz.org
If you follow a link to either, you leave the scope of this policy. Data handled inside a paid Uwitz Corporate engagement is governed by that engagement's contract, not by this page.
2. What we collect
Visiting the site
No account, no cookie banner, no tracking pixel. We set no cookies on ordinary visitors. Our web server keeps standard request logs — IP address, timestamp, requested path, user agent — because a server that logs nothing cannot be defended against abuse. These are kept short-term (see Retention) and are never used to profile you or joined to anything else.
Donating
Donations are processed by Stripe. Your card number never touches our servers; it goes straight from your browser to Stripe. We receive the amount, currency, whether it's one-time or monthly, and a Stripe reference. If you enter an email for a receipt, we get that too. All Stripe transactions are processed via our Financial Representative based in Malaysia.
Contacting us
If you email hello@uwitz.org or security@uwitz.org, or call us, we hold whatever you chose to send until the matter is closed. Security reports may be kept longer where a disclosure timeline requires it.
Staff sign-in
The blog console is staff-only. It stores a session record in your browser's localStorage under irys_admin_session. This is a functional sign-in mechanism, not analytics, and it never runs for ordinary visitors.
3. What we don't collect
- No analytics, no page-view tracking, no session recording, no heatmaps.
- No advertising or marketing trackers, and no data sold or shared with brokers.
- No profiling, scoring, or automated decision-making about you.
- No card numbers, CVVs, or bank credentials on our servers.
- No attempt to link a donation to a site visit.
Where our software is designed so that we cannot read your content, we cannot hand it over either — including to a government that asks. That is a property of the architecture, not a promise about our intentions.
4. Third parties
The complete list of external services this site touches:
- Stripe — card processing. Receives your card details and payment metadata directly. Acts as its own controller for that data under its own privacy policy.
- Fonts — none. The Geist typefaces are served from our own origin, not from Google Fonts, so loading a page here does not hand your IP address to a third party.
- Our hosting provider — Contabo GmbH, Germany. Processes traffic on our behalf as a processor, under a data processing agreement and on our instructions only.
That is the whole list. There is no third entry.
5. How long we keep things
- Server logs — 30 days, then deleted.
- Donation records — 7 years, as the Estonian Accounting Act requires for accounting source documents. We cannot delete these on request; the legal obligation overrides it.
- Emails — until the matter is closed, then deleted on our next review cycle.
- Security reports — until the disclosure is public and the fix has shipped.
- Staff sessions — until sign-out or expiry. Clearing your browser storage removes them immediately.
6. Your rights
Depending on where you live, you can ask us to give you a copy of what we hold about you, correct it, delete it, restrict or object to our use of it, or send it to someone else. You can also withdraw consent where consent is what we relied on.
Email hello@uwitz.org. We will respond within 30 days. We do not charge for this, and we will not ask you to prove your identity with more data than we already hold.
If you think we have handled this badly, you can complain to your local data protection authority — in the EU/EEA, the supervisory authority in your country of residence; and because we are established in Estonia, our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). We would rather you told us first, but it is your call.
7. How we protect it
The site is served over HTTPS with post-quantum TLS 1.3 (ML-DSA-87). Payment data is isolated at Stripe. Access to donation records and the staff console is limited to the people who need it, behind authenticated sign-in. We apply the same standards we audit other people against, and we publish our own findings when we fall short.
Found a problem? security@uwitz.org. We will not threaten you for reporting in good faith.
8. Changes and contact
If we change this policy materially we will update the "last updated" date above and note the change on the site. We will not quietly broaden what we collect.
Questions: hello@uwitz.org. Security: security@uwitz.org.
This policy is governed by Estonian law and the EU General Data Protection Regulation.