Skip to content
HomeNode MapNodesHardwareFAQHelpGet LicensedAboutCommunity

GDPR & Data Protection

Version 1.0 · Effective & last reviewed 2026-05-23

This is the authoritative statement of the Open Radio Linking Project’s data-protection obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR. It complements our Privacy Policy.

Data controller

The OpenRLP Project is the data controller for personal data processed through orlp.io. Contact: privacy@orlp.io. A formal Data Protection Officer is not required at our current scale (the Article 37 thresholds are not met), but a designated privacy contact answers all data-subject requests within 30 days (Article 12).

Lawful basis for processing (Article 6)

We process the minimum data necessary under the following lawful bases:

Your rights (Articles 15–22)

EU/UK data subjects may exercise the following rights by emailing privacy@orlp.io:

Requests are answered within 30 days and free of charge (Article 12).

Data minimisation (Article 5(1)(c))

Only data strictly necessary for the stated purpose is collected; nothing is collected speculatively.

Storage limitation (Article 5(1)(e))

Security & privacy by design (Article 25)

Data protection is built into the architecture, not bolted on afterwards:

International transfers (Chapter V)

Breach notification (Articles 33–34)

Right to complain (Article 77)

You may lodge a complaint with your national supervisory authority — for example, the UK Information Commissioner’s Office (ICO), Ireland’s Data Protection Commission, Germany’s BfDI, or France’s CNIL.