Data Governance Philosophy
At OpenListing, data minimization is our core engineering principle. We design our directory infrastructure to process only public repository metrics and essential session data. We do not monetize personal data or trade user behavioral data.
GDPR Compliance Framework
For European Economic Area (EEA) and UK users, we adhere to the General Data Protection Regulation (Regulation (EU) 2016/679):
- Lawful Basis: Public repository data is indexed under legitimate interest for developer tooling discovery. Newsletter emails are processed with explicit consent.
- Right to Erasure (Article 17): Maintainers and users can request full deletion of contact records and submitted profiles.
- Data Minimization (Article 5): We retain telemetry logs only for the minimum duration required for security debugging.
CCPA / CPRA Consumer Rights
For California residents under the California Consumer Privacy Act:
- We Do Not Sell Your Personal Information: OpenListing has never sold consumer data.
- Right to Know & Delete: Submit a verification request to view or purge personal records.
- Non-Discrimination: Exercising your privacy rights will never degrade your directory browsing access.
Data Storage & Encryption Standards
All data in transit is encrypted using modern TLS 1.3 cryptographic protocols with HSTS enforcement. Data at rest is encrypted with AES-256 standard encryption on ISO 27001-certified cloud infrastructure.
Data Subject Requests (DSR)
To submit a formal Data Subject Access Request (DSAR), deletion request, or maintainer verification query:
Send your request with the subject line "[DSR Request] OpenListing" to:
We acknowledge all DSR inquiries within 48 business hours and fulfill verified requests within 30 days.
Subprocessors & Infrastructure
We rely on trusted cloud infrastructure partners operating under strict Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs):
- Cloud Hosting & CDN: Edge networks for low-latency worldwide delivery.
- GitHub API: Official developer APIs for public star counts and repo tags.
- Email Dispatch: Transactional email service for opt-in digest delivery.
Data Breach Notification Protocol
In the event of a security incident affecting user credentials or submitted information, we will notify relevant supervisory authorities and affected users within 72 hours as mandated by GDPR.