gwift-book/chapters/gdpr.tex

431 lines
29 KiB
TeX
Executable File
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

\chapter{Politique de protection des données}
\begin{quote}
Le règlement général sur la protection des données (RGPD) responsabilise les organismes publics et privés qui traitent leurs données.
Vous collectez ou traitez des données personnelles ? Adoptez les bons réflexes !
-- \url{https://www.cnil.fr/fr/comprendre-le-rgpd}
\end{quote}
\section{TL;DR}
Aka "Les six bons conseils" de la CNIL:
\begin{enumerate}
\item \textbf{Ne collectez que les données vraiment nécessaires}
\item \textbf{Soyez transparents}
\item \textbf{Pensez au droit des personnes}
\item \textbf{Gardez la maîtrise de vos données}
\item \textbf{Identifiez les risques}
\item \textbf{Sécurisez vos données}
\end{enumerate}
\url{https://www.cnil.fr/sites/default/files/atoms/files/bpi-cnil-rgpd_guide-tpe-pme.pdf}
Le cas de \href{https://discord.com/privacy}{Discord} est éloquent et spécifie:
\begin{enumerate}
\item
Un message de bienvenue (c'est toujours plus sympa), pour dire qu'ils sont nos meilleurs copains, qu'ils ne veulent que notre bien et que leur priorité se trouve au niveau de la sécurité et de l'autonomie de leurs utilisateurs.
\item
Une description de la plateforme et des services qu'elle offre, mais aussi des moyens (déjà) par lesquels ils pourraient récupérer des données personnelles: enquêtes, courriels ou réseaux sociaux.
\item
Les informations collectées, selon trois catégories:
\begin{enumerate}
\item Directement fournies par l'utilisateur
\item Celles qui sont collectées automatiquement
\item Celles qui sont recueillies à partir d'autres sources.
\end{enumerate}
\item
Comment les informations sont utilisées
\item
Comment les informations sont partagées
\item
Quelle est la rétention des données
\item
Comment les informations sont protégées
\item
Comment la vie privée est contrôlée
\item
Les transferts de données internationaux
\item
Les services offerts par les tierces parties
\item
Comment contacter le DPO
\item
Les informations spécifiques à certains utilisateurs (Brésil, UK, EEA)
\item
Les informations spécifiques aux utilisateurs habitant en Californie
\item
La liste des changements
\item
Comment les contacter
\end{enumerate}
La lecture de ces quelques éléments montre que ceux-ci doivent immédiatement faire partie de votre description fonctionnelle et technique.
Ils peuvent être regroupés en quatre catégories bien précises:
\begin{enumerate}
\item La collecte des informations
\item L'utilisation des informations
\item Le partage des informations
\end{enumerate}
\section{Collecte des informations}
Comme indiqué ci-dessus, trois types de collectes différentes sont identifiées:
\begin{enumerate}
\item Directement fournies par l'utilisateur
\item Celles qui sont collectées automatiquement
\item Celles qui sont recueillies à partir d'autres sources.
\end{enumerate}
Chacune des informations collectée doit pouvoir avoir sa raison d'être.
Une fois que cette raison est identifiée, cela peut être considéré comme suffisant.
Mais on ne peut pas demander la date de naissance d'une personne (qui permettrait de l'identifier en croisant les informations avec d'autres plateformes) sans une bonne raison.
Une bonne raison (comme nous le verrons ci-dessous) consiste simplement à autoriser certaines fonctionnalités pouvant nécessité un âge minimal.
\subsection{Informations fournies par l'utilisateur}
Les informations fournies par l'utilisateur sont de plusieurs types également:
\begin{enumerate}
\item Identifiants
\item Contenu créé
\item Informations de paiements
\item Actions effectuées
\item Confirmation d'options facultatives
\end{enumerate}
\subsubsection{Identifiants}
\begin{quote}
\textit{When you create a Discord account, you can come up with a username and password, and provide a way of contacting you (such as an email address and/or phone number).
Youll also need to provide your birthday.
To access certain features or communities, you may need to verify your account or add other information (like a verified phone number) to your account.
You may also have the option to add your name or nicknames.}
\end{quote}
Les informations suivantes sont identifiées:
\begin{tabular}{c|c}
Informations & Raison \\
\hline
Nom d'utilisateur et mot de passe & Connexion à la plateforme \\
\hline
Adresse email ou numéro de téléphone & Un moyen de vous contacter \\
\hline
Une date de naissance & Pour vérifier l'accès à certaines fonctionnalités \\
\end{tabular}
\begin{itemize}
\item
\textbf{Account information}.
When you create a Discord account, you can come up with a username and password, and provide a way of contacting you (such as an email address and/or phone number).
Youll also need to provide your birthday.
To access certain features or communities, you may need to verify your account or add other information (like a verified phone number) to your account.
You may also have the option to add your name or nicknames.
\item
\textbf{Content you create}.
This includes any content that you upload to the service.
For example, you may write messages (including drafts), create custom emojis, or upload and share files through the services.
This also includes your profile information and the information you provide when you create servers.
We generally do not store the contents of video or voice calls or channels.
If we were to change that in the future (for example, to facilitate content moderation), we would disclose that to you in advance.
We also dont store streaming content when you share your screen, but we do retain the thumbnail cover image for the stream for a short period of time.
\item
\textbf{Purchase information}.
If you buy any paid services through Discord, you may need to submit a valid payment method and associated billing information, including your full name and billing address.
Our payment processors, like Stripe and PayPal, receive and process your payment information.
Depending on the processor, we may also receive and store certain billing information, including the last four digits of the credit card number associated with the transaction.
If we decide to process our own payments in the future, we would receive and process this information ourselves.
\item
\textbf{Information from actions you take}.
We collect information about your use of and activities on the services.
This includes the friends you add, the servers or other communities you join, your roles in servers, content moderation decisions you make, and other related actions.
\item
\textbf{Information used to enable optional features}.
Certain features, like contact syncing, may require that you provide additional information (or grant us access to such information) to make them work.
This also includes information about third party integrations you choose to enable and the data you authorize those third party services to share with us.
For example, when you link a music streaming account, we may collect information about that account such as the song you are listening to in order to display that information on your profile or as your status (if you have chosen to do so).
\item
\textbf{Other information you provide directly to us}.
You may have the option to submit additional information as you use Discord.
For example, you may choose to participate in our verified server program, which requires that you provide additional information about yourself or your company.
Or, you may participate in surveys where you can provide feedback on the product, or submit information to our Discord Support teams.
\end{itemize}
\subsection{Informations collectées automatiquement}
We also collect information automatically from you when you use Discord. This includes:
\begin{itemize}
\item
\textbf{Information about your device}.
We collect information about the device you are using to access the services.
This includes information like your IP address, operating system information, browser information, and information about your device settings, such as your microphone and/or camera.
\item
\textbf{Information about your use of the apps or websites}.
We collect log and event information related to how and when you use our services (such as the pages, servers, and channels you visit).
\item
\textbf{Other information that we collect automatically}.
When you take certain actions on other sites, we may receive information about you.
For example, when we advertise for Discord on third party platforms, if you click on the ad, we may receive information about which ad you saw and on which platform.
Similarly, we may also receive certain information when you click on a referral link, such as which website you came from.
\end{itemize}
We may receive information from cookies (small text files placed on your computer or device) and similar technologies. First-party cookies are placed by us (and our third-party service providers) and allow you to use the services and to help us analyze and improve your experience and the services. You can control cookies as described in the “How to control your privacy” section below. The services use the following types of cookies:
\begin{itemize}
\item
\textbf{Strictly Necessary Cookies}: These are required for services to function. If you try to use tools to disable these cookies, parts of the services may not work properly.
\item
\textbf{Functional Cookies}: These help us provide enhanced functionality on the services like remembering language preferences. Disabling these could affect some service functionality.
\item
\textbf{Performance Cookies}: These allow us or our third-party analytics providers to learn how you and others use and engage with the services so we can understand and improve them.
\end{itemize}
\section{Utilisation des informations}
Nous revenons à présent au contenu et aux informations apportées par l'utilisateur.
Un point important est qu'il est précisé que "le contenu est à vous, mais vous accordez une licence d'utilisation à l'entreprise".
Cette licence d'utilisation leur permet de :
\begin{itemize}
\item
Utiliser, copier, stocker, distribuer ou communiquer ce contenu
\item
Publier de manière publique et rendre ce contenu visible à d'autres personnes ou utilisateurs, sous réserve que le propriétaire l'ait rendu visible.
\item
Monitorer, modifier, traduire ou reformater le contenu
\item
Sous-licencier le contenu pour le faire fonctionner sur la plateforme ou avec d'autres fournisseurs.
\end{itemize}
Cette licence est mondiale, non-exclusive, sans aucun frais, transférable et perpétuelle.
C'est également le cas avec un éventuel retour d'idées que nous pourrions leur communiquer, dans la mesure où \textit{by sending us feedback, you grant us a non-exclusive, perpetual, irrevocable, transferable license to use the feedback and ideas generated from the feedback without any restrictions, attribution, or compensation to you}.
Bref, ils sont couverts, et vous ne savez pas exactement tout ce qu'ils pourraient faire avec vos données.
De leur côté, ils proposent également du contenu, mais ils en restent propriétaires :-)
Pour le contenu que les autres personnes pourraient publier ou rendre disponibles, il n'est pas permis de le réutiliser sans leur consentement.
\subsection{Pour remplir leur contrat avec l'utilisateur}
\begin{itemize}
\item
\textbf{To provide you with the services}.
We use your information to provide you with the Discord services.
For example, when you start a video call, we process your images and audio to make that work.
We similarly collect and store the messages you send and display them as you direct.
We also use the information you provide to us to create and manage your account and to facilitate purchases.
When you enable optional features (like connecting your Discord account to other platforms), we use information from those services to power the feature (like displaying what song you are listening to on another service within the Discord app).
\item
\textbf{To meet our commitments to the Discord community}.
We work hard to try to make Discord a safe, positive, and inclusive place.
To do so, we use your information to monitor for and take action against users and content that violate our Terms of Service, Community Guidelines, and other policies.
This includes responding to user reports, detecting fraud and malware, and proactively scanning attachments and other content for illegal or harmful content.
We also use certain information, which may include content reported to us and public posts, to develop and improve systems and models that can be automated to more swiftly detect, categorize, and take action against prohibited content or conduct.
\item
\textbf{To personalize the product}.
We use your information to provide, personalize and improve our services.
This information powers our discovery surfaces (so that you see relevant communities or content first), and it helps us surface Discord features and promotions from us and our partners that may be of interest to you.
As discussed in the “How to control your privacy” section below, you can choose whether to allow us to personalize your Discord experience.
\item
\textbf{To contact you}.
We use your information to contact you in connection with your account, such as to verify or secure it with two-factor authentication.
We may also use your information to contact you about important product or policy changes, to send you information about products you have purchased, or just to let you know about new products or features we think youll like.
You may opt-out of receiving marketing communications.
Where local law requires, we will obtain your consent before sending such communications.
\item
\textbf{To provide customer service}.
We use your information to respond to your questions about our products and services, and to investigate bugs or other issues.
\end{itemize}
\subsection{Dans leur propre intérêt}
\begin{itemize}
\item
\textbf{To protect our services}.
We use information to keep our services secure, to prevent misuse, and to enforce our Terms of Service and other policies against users who violate them.
\item
\textbf{To report on our companys performance}.
We use your information to track the fundamental metrics of our business, to perform financial reporting, to respond to regulatory obligations, and to debug billing issues.
\item
\textbf{To improve our services}.
We use your information to help us understand how users interact with our services, what features or products users may want, or to otherwise understand and improve our services.
This includes information about how you use our services and how servers are structured.
We may also use public posts to better understand, for example, what topics public servers cover and what content is most interesting within those servers.
As discussed in the ”How to control your privacy” section below, you can control whether your data is used for these purposes.
\item
\textbf{To advertise our services on other platforms}.
We are proud of the product we've built and spend money advertising it on other platforms in order to bring more users to Discord.
As part of that, we use certain information to assist in the delivery of our advertising, to measure the effectiveness of advertisements for our own products, and to improve such advertisements in the future.
\end{itemize}
\subsection{Pour tout ce qui touche aux contraintes légales}
We retain and use your information in connection with potential legal claims when necessary and for compliance, regulatory, and auditing purposes. For example, we retain information where we are required by law or if we are compelled to do so by a court order or regulatory body. Also, when you exercise any of your applicable legal rights to access, amend, or delete your personal information, we may request identification and verification documents from you for the purpose of confirming your identity.
\subsection{Avec votre consentement}
We may also collect and use personal information with your consent. You can revoke your consent at any time (mostly through our services directly), though note that you might not be able to use any service or feature that requires collection or use of that personal information.
\subsection{Pour protéger les intérêts vitaux d'un tiers}
We may collect or share personal data if we think someones life is in danger—for example, to help resolve an urgent medical situation.
\section{Arrêt}
Your right to terminate. Youre free to stop using Discords services at any time and for any reason. You can delete your Discord account through the User Settings page in the Discord app. You can also disable your account, which restricts the processing of your personal information as described in our Privacy Policy. Disabling your account does not terminate this agreement.Our right to terminate. Subject to applicable law, we reserve the right to suspend or terminate your account and/or your access to some or all of our services with or without notice, at our discretion, including if:
You breach these terms, our policies, or additional terms that apply to specific products.
Were required to do so to comply with a legal requirement or court order.
We reasonably believe termination is necessary to prevent harm to you, us, other users, or third parties.
Your account has been inactive for more than two years.
However, we will give you advance notice if reasonable to do so or required by applicable law. You can appeal any enforcement action we take under these terms here: https://dis.gd/request.
\section{Partage des informations}
\begin{itemize}
\item
\textbf{When you tell us to}.
When you add your content to the services, you are telling us to share that content with certain communities, people, or in the case of public spaces, with anyone who accesses it.
Who can access that information is determined by who can access a particular community.
Server owners or admins set those permissions, and they control whether a server requires an invite link or is open and accessible to anyone.
And these permissions, like the size of the server, may change over time.
Similarly, if you link your Discord account with a third-party service (like a music-streaming service) or participate in a server that has third-party features like bots enabled, you may be telling us to share certain information with that service, or with other Discord users.
You can control this sharing as described in the "How to control your privacy" section below.
We may also share your information as you otherwise instruct us or provide us your consent to do so.
\item
\textbf{With our vendors}.
We may share information with vendors we hire to carry out specific work for us.
This includes payment processors like Stripe and PayPal that process transactions on our behalf and cloud providers like Google that host our data and our services.
We may also share limited information with advertising platforms to help us reach people that we think will like our product and to measure the performance of our ads shown on those platforms.
We do this to help bring more users to Discord, and provide only the information required to facilitate these services.
This may include information like the fact that you installed our app or registered to use Discord.
\item
\textbf{To comply with the law}.
We may share information in response to a request for information if we believe disclosure is required by law, including meeting national security or law enforcement requirements.
Where allowed and feasible, we will attempt to provide you with prior notice before disclosing your information in response to such a request.
Our Transparency Report has additional information about how we respond to requests from governments and law enforcement entities.
\item
\textbf{In an emergency}.
We may share information if we believe in good faith that it's necessary to prevent serious harm to a person.
\item
\textbf{To enforce our policies and rights}.
We may share information if needed to enforce our Terms of Service, Community Guidelines, or other policies, or to protect the rights, property, and safety of ourselves and others.
\item
\textbf{With our related companies}.
We may share information with our related companies, including parents, affiliates, subsidiaries, and other companies under common control and ownership.
\item
\textbf{Sale, Acquisition, or Transfer of Assets}.
We may share information if Discord is evaluating and/or engaging in a merger, acquisition, reorganization, bankruptcy, or sale, transfer, or change in ownership of Discord or any of its assets.
\item
\textbf{Aggregated or de-identified information}.
We may share information about you that has been aggregated or anonymized such that it cannot reasonably be used to identify you.
For example, we may share aggregated user statistics in order to describe our business to partners or the public.
\end{itemize}
\section{Rétention des données}
We retain personal information for as long as it is needed for the purposes for which we collected it. If your account is inactive for more than two years, we may delete it, and we may delete or anonymize any personal information associated with your account.If you submit an ID for an age verification appeal, we will delete it within sixty days after the age appeal ticket is closed.
\section{Protection des informations}
We take a number of steps to help protect your information.
All information sent within our services is encrypted both in transit and at rest.
For example, we use Transport Layer Security (“TLS”) to encrypt text and images in transit.
We also enforce technical and administrative access controls to limit which of our employees and contractors have access to nonpublic personal information.
You can help maintain the security of your account by configuring two-factor authentication.
\section{Contrôle de la vie privée}
We believe that users should be able to tailor their Discord experience to their preferences, including privacy.
And while local laws may require different things, we believe that our users should have the same basic ability to shape their experience no matter where they are in the world.
Heres how you can control how we process your information and how to request access to your information:
\subsection{Be aware of the Discord spaces you choose to participate in}
You can always choose what communities to participate in and what information you add to our services. You can choose what messages to send or post, who to engage with (e.g., one or more particular users or a potentially unlimited group of users), what information to include in your profile, whether to connect any third party services to your Discord account, and more. For example, if you share content in public spaces, it may be accessed by anyone. Public content may also be subject to fewer restrictions under your local laws.
\subsection{Customize your personal Discord settings}
We offer a number of settings that allow you to tailor your experience within Discord. Some of these relate to specific features: for example, you can choose whether to display your current activity in your status via the Activity Status tab in your User Settings page (this is the gear icon next to your name).
You can also access privacy-specific settings in the Privacy \& Safety section of your User Settings. For example, you can decide which types of direct messages are scanned for explicit content, who can add you as a friend, and more. This is also where you can restrict certain types of processing of your information:
\begin{itemize}
\item
\textbf{Restrict our ability to use your data to improve our products. }
If you turn off the “Use data to improve Discord” setting, we will stop collecting and using certain event and log information to help us understand how users use our services, what features or products they may want, or to otherwise improve our services.
\item
\textbf{Restrict our ability to personalize Discord for you}.
If the “Use data to customize my Discord experience” setting is disabled, we will stop collecting and using certain event and log information to help us offer you relevant recommendations for in-app content and features.
\end{itemize}
You can also disable or delete your account via the “My Account” tab on the settings page.
Disabling your account stops the processing of new data, but allows you to reactivate your account without interruption to you.
Deleting your account permanently deletes identifying information and anonymizes other data.
\subsection{Manage your content and servers}
You may edit or erase specific pieces of information within the services:
\begin{itemize}
\item
You can edit or delete any message you have sent or content you have posted if you still have access to the space where you posted it.
\item
You can edit or delete a Discord server if you have the permissions needed to do so.
\item
You can edit or delete a channel from a Discord server if you have the permissions needed to do so.
\end{itemize}
Public posts may be retained by Discord for use as described elsewhere in this policy.
Also, in limited circumstances, we may have a legal obligation to retain certain information, even if you delete the information or your account.
If you want to see what information we have collected about you, you can request a copy of your data by selecting Request Data in the Privacy \& Safety section of your User Settings.
You should receive your data packet within 30 days.
Data is delivered in common digital formats including CSV, JSON, and any other file format you used when uploading attachments to the services.
\subsection{Cookies}
To control how information is collected and used from cookies on the services, you can take one or more of the following steps.
\begin{itemize}
\item
You can disable and manage some cookies through your browser settings. You will need to manage your settings for each browser you use. You can find instructions for how to manage Cookies in popular browsers such as Internet Explorer, Firefox, Chrome, Safari (iOS), Safari (Mac), and Opera.
\item
To disable analytics cookies, you can use the browser controls discussed above or, for certain providers, you can use their individual opt-out mechanisms, such as Google Analytics Opt-Out.
\item
Your mobile device may also include browser settings to manage the use of cookies. Your device may also have settings to control the collection and use information in your apps.
\item
Third party groups also enable you to limit how cookies are used for advertising purposes by participating third parties. You can learn more at Network Advertising Initiative, the Digital Advertising Alliance, and for users in the EU, the European Interactive Digital Advertising Alliance.
\item
Depending on where you are accessing our services, you may be able to adjust your cookie preferences at any time through a cookies banner or by selecting “Cookie Settings” from the footer or menu on our website.
\end{itemize}
If you disable or remove cookies, some parts of the services may not function properly. Information may be collected to remember your opt-out preferences.Questions or concerns about your privacy? You can email us at privacy@discord.com.
\section{Services tiers}
We allow third party developers to build certain features or other services and offer them within the Discord services.
For example, server administrators can add “bots” created by third party developers that provide features like content moderation and interactive games.
Similarly, you may have access to games or activities built by third parties within the services.
These third-party services need to follow all policies that apply to them (including often our Developer Terms of Service and Developer Policy).
As part of these policies, we require developers to have a privacy policy that makes clear what they do with your information.
Please review these privacy policies, as they describe what bots and apps may do with your information.
We also require that certain popular bots apply for access to certain data. But because these services are operated by third parties, we dont control them or what information they collect.
Its up to you whether to participate in a server that uses bots, and whether to engage with third-party services in general.
\section{Conclusions}
la structure proposée est la suivante:
\begin{enumerate}
\item
\end{enumerate}