PRIVACY POLICY
Last updated: 14-01-2025
Welcome to Project EDI Limited’s (“Project EDI,” “we,” “us,” or “our”) Privacy Policy. We operate the Open Source Sign Language (OSSL) platform, which enables users to submit and share sign language videos to advance research, preserve sign languages, and foster inclusivity.
This Privacy Policy explains how we collect, use, store, and share your personal data when you interact with our website or services (“Platform”), and outlines your rights under the UK General Data Protection Regulation (UK GDPR) and other applicable laws.
1. Who We Are
- Data Controller: Project EDI Limited
- Company Number: 15253340
- Data Protection Contact: [email protected]
We are responsible for the personal data we collect and process. If you have any questions about this Privacy Policy, or if you wish to exercise your rights, please contact us at [email protected].
2. Age Restriction
Our Platform is intended for users who are at least 18 years old. We do not knowingly collect or process data from individuals under 18. If we discover that someone under 18 has provided us with personal data, we will delete it promptly.
3. What Data We Collect
3.1 User-Provided Data
- Email Address (Optional)
- You may choose to provide an email address when uploading sign language videos or creating an account. - Providing your email allows us to (a) verify your identity if you later request deletion of your content, (b) send you feature updates or newsletters if you consent to receive them.
- Optional Attributes
- We may ask for your approximate location (e.g., country/region for dialect purposes), gender, or age group to support sign language research. This information is strictly optional.
- Sign Language Videos
- Public Videos: If you choose to make your video “Public,” it will be subject to community review and ultimately released under a Creative Commons CC0 (public domain) licence.
- Private Videos: If you choose “Private,” your original video is not shared publicly. We extract sign language features (e.g., body or hand pose data) internally for research, but the raw video remains inaccessible to the public.
3.2 Automatically Collected Data
- Cookies and Similar Technologies
- We use essential cookies for authentication and session management. - We may use analytics cookies (e.g., Google Analytics) to understand user interactions. - Please see Section 6 for more information on how cookies operate and how you can manage them.
- Video Fingerprinting (Security/Spam Prevention)
- We may generate a “fingerprint” or hash of uploaded videos to detect duplicates, spam, or misuse. This fingerprint is used for security purposes and does not store or reveal personal identifiers like faces.
4. How We Use Your Data
- Platform Operation: - Allowing you to upload and manage your sign language videos (public or private).
- Research and Feature Extraction: - If you select “Private,” we extract anonymised features (e.g., hand or body pose data) to support research and algorithmic improvements.
- Community Engagement: - Public videos may be reviewed, rated, or flagged by other users for moderation or community feedback.
- Communication: - Sending updates, newsletters, or feature announcements if you have opted in (consented) to receive them. - Responding to your inquiries, feedback, or deletion requests.
- Security and Fraud Prevention: - Using basic analytics, logs, and fingerprinting to detect suspicious activity or misuse of the Platform.
- Legal Compliance: - We may retain or disclose data if required by law or to respond to legal processes (e.g., subpoenas or court orders).
5. Legal Basis for Processing
5.1 Consent
- Video Upload and Processing: We rely on your explicit consent when you choose to upload a sign language video (public or private). You can withdraw this consent at any time by contacting [email protected], subject to the limitations described in Section 7.
- Newsletter/Updates: We also rely on consent for sending you newsletters or updates. You can unsubscribe at any time.
5.2 Legitimate Interests
Security: We may process minimal data (e.g., video fingerprints or IP addresses) to protect our Platform from spam and fraud. We believe this is necessary for our legitimate interest in maintaining a secure, user-friendly environment.
5.3 Legal Obligations
Compliance with Laws: We may process or retain certain data if required to comply with applicable laws and regulations (e.g., law enforcement requests).
6. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Authenticate and Maintain Sessions: These are essential cookies required for the Platform to function properly.
- Analyze Usage: We may use Google Analytics or similar tools to collect anonymized usage statistics that help us improve the Platform.
You can control or delete cookies within your browser settings. Note that blocking essential cookies may affect certain features of the Platform. For more details, please see our separate Cookie Policy (if applicable) or contact us at [email protected].
7. Data Retention and Deletion
- Public Videos
- Once a public video is released under CC0, it is irretrievable from the public domain, and we cannot remove it post-release. - We generally prepare public datasets every few months. You may request deletion before your video is included in the dataset.
- Private Videos
- We store private videos for internal research and feature extraction. You may request deletion at any time by emailing [email protected]. - Extracted Features: Once anonymised or aggregated, the features no longer contain personally identifiable information and may be retained indefinitely for research. These features cannot be linked back to you.
- Email Address and Other Personal Data
- We keep your email address as long as you maintain your account or subscription for updates. If you opt out or request deletion, we will remove or anonymise your email, except where legal obligations require retention.
- No Email Provided
- If you did not provide an email address, we cannot verify your identity to process deletion requests. As a result, we may be unable to remove specific videos that were uploaded anonymously.
8. Data Sharing and International Transfers
- Public Datasets
- Public (CC0) videos are distributed globally for sign language research. We do not include email addresses or other personal data in these datasets.
- Service Providers
- We may use hosting (e.g., R2 buckets) or analytics services (e.g., Google Analytics) that could process data in regions outside the UK. Where feasible, we store data in the user’s region (e.g., BSL data in the UK) to maintain data residency.
- Legal or Regulatory Requirements
- We may disclose personal data if required by law (e.g., to comply with a legal obligation or valid governmental request).
- Safeguards
- When transferring data internationally, we use appropriate safeguards (such as Standard Contractual Clauses) to protect your personal data in compliance with the UK GDPR.
9. Data Security
We take the security of your data seriously and implement appropriate technical and organisational measures to protect it. These measures include:
- Encryption (SSL/TLS) for data transmission.
- Secure Storage in R2 buckets with restricted access.
- Strict Access Controls ensuring only authorised staff can handle private videos or personal data.
- 2FA for Staff Logins to reduce the risk of unauthorised access.
- Cyber Essentials or similar security frameworks that we aim to adhere to.
10. Your Data Protection Rights
Under the UK GDPR, you have the right to:
- Access: Request a copy of your personal data.
- Rectify: Have inaccurate data corrected.
- Erase: Request deletion of your data (subject to the limitations outlined in Section 7).
- Restrict Processing: Ask us to pause or limit how we use your data.
- Data Portability: Obtain a copy of your data in a structured, commonly used format.
- Object: Object to data processing based on legitimate interests or direct marketing.
- Withdraw Consent: If processing relies on your consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
If you wish to exercise any of these rights, please email us at [email protected]. We may need you to verify your identity (e.g., by confirming the same email used during registration or upload).
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your rights have been violated.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make significant changes, we will:
- Post a notice on the Platform, and/or
- Send an email notification to registered users.
The “Last Updated” date at the top of this document indicates when the latest modifications were made.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact: Data Protection Officer at [email protected]