top of page
OCP Large.png

OCP Private Policy

OpenCognition Protocol Private Policy

1. Introduction and Purpose


This Privacy Policy describes how the OpenCognition Protocol project — including the opencognition.org website, the GitHub repository at github.com/opencognitionprotocol, the Discord community server, and the documentation at docs.opencognitionprotocol.org (collectively, the "OCP Project") — collects, uses, stores, and protects personal data relating to contributors, community members, and website visitors.

This Privacy Policy does not govern the use of OCP by Deploying Organisations in their own systems. Each Deploying Organisation is independently responsible for its own privacy obligations under applicable law. Deploying Organisations should refer to the Responsible Use Addendum in Document I for their obligations with respect to personal data in OCP deployments.



2. Data We Collect and Why


2.1 Website Visitors

When you visit opencognitionprotocol.org or docs.opencognitionprotocol.org, we collect:

  • Standard web server logs, including IP addresses, browser type, referring URL, and page visit timestamps. These are collected automatically for security, performance monitoring, and aggregate analytics purposes. Log data is retained for 90 days and then permanently deleted. We do not use IP addresses for individual tracking or profiling.

  • If you voluntarily submit a contact form or email inquiry, we collect the name and email address you provide for the sole purpose of responding to your inquiry. Contact form submissions are retained for 12 months and then permanently deleted unless you have requested ongoing correspondence.


2.2 GitHub Contributors

Contributions to the OCP repository at github.com/opencognitionprotocol are subject to GitHub's own privacy policy (github.com/privacy). By contributing to the OCP repository, you acknowledge that your GitHub username, contribution history, and any personal information included in commits, pull requests, or issues will be permanently recorded in the public repository history as part of the open-source record.

If you wish to contribute without disclosing your identity, you may use a pseudonymous GitHub account, provided your contribution complies with the License Agreement and all other project guidelines.


2.3 Discord Community Members

Participation in the OCP Discord community is governed by Discord's own privacy policy (discord.com/privacy). The OCP Project moderates the server but does not independently collect, store, or process personal data from Discord interactions beyond what Discord itself retains. Server moderation logs — records of moderation actions taken against specific accounts — are retained for 24 months for the purpose of maintaining community safety.


2.4 OpenCognition Protocol Foundation Members (Upon Establishment)

When the OCP Foundation is established, individuals who apply for membership, governance roles, or working group participation will be asked to provide their name, professional affiliation, contact details, and relevant background information. This information will be used exclusively for governance administration, communication, and public transparency purposes (such as publishing the names and affiliations of Foundation board members). Foundation member data will be handled in accordance with this Privacy Policy and the Foundation's own data governance framework, to be published upon the Foundation's establishment.



3. What We Do Not Collect


The OCP Project does not:

  • Collect financial information of any kind from website visitors or community members

  • Use tracking cookies, advertising pixels, or third-party analytics services that track individuals across websites

  • Sell, rent, or otherwise commercialise any personal data

  • Use personal data for automated decision-making or profiling that produces legal or similarly significant effects on individuals

  • Collect data about minors. Our services are directed at professionals and are not intended for individuals under 18 years of age. If we become aware that we have collected personal data from a minor, we will delete it promptly.



4. Legal Basis for Processing (GDPR)


For individuals in the European Economic Area, the United Kingdom, or other jurisdictions where a legal basis for processing personal data is required, we rely on the following bases:
 

Processing Activity             Legal Basis

Web server logs                 Legitimate interest (security and                                      performance monitoring)

Contact form responses          Consent (you provided the information                                  voluntarily)

GitHub contribution records     Consent (you chose to contribute                                      publicly)

Discord moderation logs         Legitimate interest (community safety)

Foundation governance records   Contractual necessity (membership                                      agreement)



5. Data Sharing and Disclosure


We do not share personal data with third parties except:

  • Service providers acting as data processors on our behalf (including GitHub, Discord, and web hosting providers), who are contractually bound to process data only on our instructions and to maintain appropriate security measures

  • Legal requirements where we are compelled to disclose by applicable law, court order, or regulatory authority, in which case we will notify the affected individual where legally permitted to do so

  • Safety emergencies where disclosure is necessary to prevent serious harm to a person


We do not share personal data with any commercial partner, advertiser, data broker, or AI training service.



6. International Data Transfers


The OCP Project operates globally. Data collected through the project may be processed in countries outside your own jurisdiction, including countries whose data protection laws differ from your home country. Where personal data of EEA or UK residents is transferred outside those regions, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) or equivalent mechanisms recognised under applicable law.



7. Data Retention


Data Type                        Retention Period

Web server logs                  90 days, then permanently deleted

Contact form submissions         12 months from last correspondence

GitHub repository records        Perm retained open-source history

Discord moderation logs          24 months from the moderation action

Foundation governance records    Duration of membership plus 7 years



8. Your Rights


Depending on your jurisdiction, you may have the following rights with respect to your personal data:

  • Right of access — to request a copy of the personal data we hold about you

  • Right to rectification — to request correction of inaccurate personal data

  • Right to erasure — to request deletion of personal data (subject to our legal obligations and legitimate interests, including the permanent nature of public open-source contribution records)

  • Right to data portability — to receive your personal data in a structured, machine-readable format

  • Right to object — to object to processing based on legitimate interests

  • Right to restrict processing — to request that we limit our use of your data pending resolution of a complaint or query

  • Right to withdraw consent — where processing is based on consent, to withdraw that consent at any time

To exercise any of these rights, please contact privacy@opencognitionprotocol.org. We will respond within 30 days of receiving your request. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.



9. Security


We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include access controls on administrative systems, encrypted storage of contact information, and regular security reviews of our infrastructure. However, no system is completely secure. We cannot guarantee the absolute security of data transmitted over the internet.



10. Changes to This Privacy Policy


We will notify the community of material changes to this Privacy Policy through a prominent notice on opencognition.org and a post in the OCP GitHub repository and Discord server at least 30 days before the changes take effect. Your continued use of the OCP Project following the effective date of a material change constitutes your acceptance of the revised policy.

bottom of page