Privacy Policy

Last Updated: December 2024

At Digital Prison, we practice what we preach. This privacy policy outlines our commitment to protecting your personal information while providing you with essential surveillance awareness resources.

Minimal Collection

We collect only what's absolutely necessary for website functionality

Maximum Security

Industry-leading encryption and security measures protect all data

Full Transparency

Clear information about what we collect, why, and how long we keep it

1. Overview and Scope

Digital Prison ("we," "our," or "us") is committed to protecting your privacy and promoting digital privacy awareness. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website digitalprison.com and use our services.

Our Privacy Philosophy

As advocates for digital privacy and surveillance awareness, we operate under the principle of privacy by design. We collect minimal data, implement strong security measures, and give you full control over your personal information.

This policy applies to all information collected through our website, mobile applications, and any related services, sales, marketing, or events. By accessing our website, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Information Collected Automatically

When you visit our website, we may automatically collect certain information:

  • Technical Information: IP address (anonymized), browser type, operating system, device information
  • Usage Data: Pages visited, time spent on pages, referring websites, exit pages
  • Performance Data: Website performance metrics and error logs (anonymized)

Privacy-First Analytics

We use privacy-friendly analytics that don't track individual users, don't use cookies for tracking, and don't collect personally identifiable information. All data is aggregated and anonymized.

Information You Provide Voluntarily

You may choose to provide us with certain information when you:

  • Contact Us: Name, email address, and message content through our contact forms
  • Newsletter Signup: Email address for updates and resources
  • Community Participation: Comments, poll responses, or contributions to our platform
  • Resource Downloads: Email address when accessing gated educational materials

Information We Don't Collect

In line with our privacy-first approach, we explicitly do NOT collect:

  • Detailed Personal Profiles: Comprehensive behavioral tracking or profiling
  • Cross-Site Tracking: We don't track you across other websites
  • Sensitive Personal Data: Financial information, health data, or government IDs
  • Biometric Data: Fingerprints, facial recognition, or similar biometric identifiers

3. How We Use Information

We use collected information only for specific, legitimate purposes:

Primary Uses

  • Website Operation: Ensure proper functioning and security
  • Communication: Respond to inquiries and provide support
  • Content Delivery: Provide requested resources and information
  • Security: Protect against fraud, abuse, and security threats

Secondary Uses

  • Improvement: Analyze usage patterns to improve our services
  • Education: Send relevant privacy and security educational content
  • Research: Conduct privacy-focused research (anonymized data only)
  • Compliance: Meet legal obligations and regulatory requirements

Legal Basis for Processing (GDPR)

For users in the European Union, we process your data based on:

  • Legitimate Interests: Website operation and improvement
  • Consent: Newsletter subscriptions and optional communications
  • Contract Performance: Providing requested services
  • Legal Compliance: Meeting regulatory requirements

4. Data Sharing and Disclosure

We believe in data minimalism and rarely share personal information. When we do, it's only in these specific circumstances:

Trusted Service Providers

We may share limited data with carefully vetted service providers who help us operate our website:

Current Providers:

  • Web hosting service (encrypted data only)
  • Email service provider (for communications)
  • Privacy-friendly analytics (anonymous data)

Provider Requirements:

  • Privacy-focused business models
  • Strong data protection agreements
  • No data sharing with third parties

Legal Compliance

We may disclose information if required by law or to:

  • Comply with legal processes (subpoenas, court orders)
  • Protect our rights, property, or safety
  • Prevent fraud, abuse, or illegal activities

Our Commitment

We will always notify you of legal requests for your data unless prohibited by law. We challenge overly broad or unjustified requests and use legal means to protect your privacy.

What We Never Share

  • Personal data for advertising or marketing purposes
  • Data with data brokers or aggregators
  • Information with social media platforms for tracking
  • Data for commercial profiling or targeting

5. Cookies and Tracking

Our approach to cookies reflects our commitment to privacy - we use minimal tracking and give you full control.

Essential Cookies (Always Active)

These cookies are necessary for the website to function properly:

  • Session Management: Maintaining your preferences during your visit
  • Security: CSRF protection and basic security measures
  • Performance: Load balancing and basic functionality

Optional Cookies (Your Choice)

You can control these optional cookies:

Analytics (Privacy-Friendly)

  • Anonymous usage statistics
  • Aggregated visitor counts

Preferences

  • Dark/light mode selection
  • Language preferences

Tracking We Reject

We explicitly refuse to use:

  • Google Analytics (replaced with privacy-friendly alternatives)
  • Facebook Pixel or similar tracking pixels
  • Cross-site tracking cookies
  • Advertising or remarketing cookies

6. Your Privacy Rights

European Union (GDPR) Rights

Right to Access

Request copies of your personal data

Right to Rectification

Request correction of inaccurate data

Right to Erasure

Request deletion of your data

Right to Restrict Processing

Limit how we use your data

Right to Portability

Receive your data in a usable format

Right to Object

Object to certain types of processing

California (CCPA) Rights

California residents have additional rights:

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale (we never sell data)
  • Right to non-discrimination for exercising rights

How to Exercise Your Rights

To exercise any of your privacy rights:

Contact Form

Use our secure contact form

Response Time

Within 30 days maximum

7. Data Security

We implement industry-leading security measures to protect your data from unauthorized access, use, or disclosure:

Technical Safeguards

  • SSL/TLS Encryption: All data transmission encrypted with 256-bit SSL
  • Data Encryption: All stored data encrypted at rest
  • Firewalls: Multi-layer firewall protection
  • Access Controls: Strict access controls and authentication

Administrative Safeguards

  • Staff Training: Regular security and privacy training
  • Principle of Least Privilege: Minimal access to data
  • Regular Audits: Periodic security assessments
  • Incident Response: Documented breach response procedures

Security Limitations

While we implement strong security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but commit to using industry best practices and notifying you promptly of any security incidents.

8. Data Retention

We retain personal information only as long as necessary for the purposes outlined in this policy:

Retention Periods

Contact Form Data

Retained for 2 years or until you request deletion

Newsletter Subscriptions

Until you unsubscribe or request deletion

Analytics Data

Aggregated data retained for 25 months maximum

Technical Logs

Anonymized logs kept for 90 days for security

Legal Requirements

Some data may be retained longer if required by law

Secure Deletion

All data securely deleted when no longer needed

9. International Users

Data Processing Location

Your information may be processed in countries other than your own. We ensure adequate protection regardless of location:

  • Primary Servers: Located in privacy-friendly jurisdictions
  • EU-US Data Flows: Using Standard Contractual Clauses
  • Encryption: All international transfers encrypted

10. Contact Information

Privacy Questions or Concerns?

Secure Contact

Use our encrypted contact form

Response Time

Within 48-72 hours

Policy Updates

We may update this privacy policy periodically. When we do:

  • We'll update the "Last Updated" date at the top
  • For significant changes, we'll notify you by email
  • You'll be encouraged to review the updated policy

Our Commitment to Your Privacy

At Digital Prison, privacy isn't just a policy—it's our core mission. We're committed to protecting your personal information while empowering you with the knowledge and tools to protect yourself in the digital age.