Legal

Privacy Policy

We teach data minimisation, so we practise it. This page describes every piece of personal data uwitz.org handles, why we have it, and how to make us delete it.

Legal status: Uwitz is currently unincorporated. We are preparing to legally register and operate under Estonia in the foreseeable future. All Stripe transactions are processed via our Financial Representative based in Malaysia.

Effective 30 July 2026 Last updated 30 July 2026

1. Who this covers

This policy applies to uwitz.org — this website, the donation flow, and the staff console behind it. It is published by Uwitz, established in Estonia ("Uwitz", "we", "us"), which is the data controller for everything described here.

Our two divisions run their own sites and publish their own policies:

If you follow a link to either, you leave the scope of this policy. Data handled inside a paid Uwitz Corporate engagement is governed by that engagement's contract, not by this page.

2. What we collect

Visiting the site

No account, no cookie banner, no tracking pixel. We set no cookies on ordinary visitors. Our web server keeps standard request logs — IP address, timestamp, requested path, user agent — because a server that logs nothing cannot be defended against abuse. These are kept short-term (see Retention) and are never used to profile you or joined to anything else.

Donating

Donations are processed by Stripe. Your card number never touches our servers; it goes straight from your browser to Stripe. We receive the amount, currency, whether it's one-time or monthly, and a Stripe reference. If you enter an email for a receipt, we get that too. All Stripe transactions are processed via our Financial Representative based in Malaysia.

Contacting us

If you email hello@uwitz.org or security@uwitz.org, or call us, we hold whatever you chose to send until the matter is closed. Security reports may be kept longer where a disclosure timeline requires it.

Staff sign-in

The blog console is staff-only. It stores a session record in your browser's localStorage under irys_admin_session. This is a functional sign-in mechanism, not analytics, and it never runs for ordinary visitors.

3. What we don't collect

Where our software is designed so that we cannot read your content, we cannot hand it over either — including to a government that asks. That is a property of the architecture, not a promise about our intentions.

4. Third parties

The complete list of external services this site touches:

That is the whole list. There is no third entry.

5. How long we keep things

6. Your rights

Depending on where you live, you can ask us to give you a copy of what we hold about you, correct it, delete it, restrict or object to our use of it, or send it to someone else. You can also withdraw consent where consent is what we relied on.

Email hello@uwitz.org. We will respond within 30 days. We do not charge for this, and we will not ask you to prove your identity with more data than we already hold.

If you think we have handled this badly, you can complain to your local data protection authority — in the EU/EEA, the supervisory authority in your country of residence; and because we are established in Estonia, our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). We would rather you told us first, but it is your call.

7. How we protect it

The site is served over HTTPS with post-quantum TLS 1.3 (ML-DSA-87). Payment data is isolated at Stripe. Access to donation records and the staff console is limited to the people who need it, behind authenticated sign-in. We apply the same standards we audit other people against, and we publish our own findings when we fall short.

Found a problem? security@uwitz.org. We will not threaten you for reporting in good faith.

8. Changes and contact

If we change this policy materially we will update the "last updated" date above and note the change on the site. We will not quietly broaden what we collect.

Questions: hello@uwitz.org. Security: security@uwitz.org.

This policy is governed by Estonian law and the EU General Data Protection Regulation.


Read the Terms of Use →