<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Trust, Legal &amp; Safety on Documentation</title><link>https://docs.opencommit.eu/trust/</link><description>Recent content in Trust, Legal &amp; Safety on Documentation</description><generator>Hugo</generator><language>en-us</language><copyright>&amp;copy; 2025-2026, OpenCommit Foundation. This work is licensed under [CC BY-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/")&lt;img src="https://docs.opencommit.eu/cc.svg" alt="" style="max-width: 1em;max-height:1em;margin-left: .2em;"&gt;&lt;img src="https://docs.opencommit.eu/by.svg" alt="" style="max-width: 1em;max-height:1em;margin-left: .2em;"&gt;&lt;img src="https://docs.opencommit.eu/nc.svg" alt="" style="max-width: 1em;max-height:1em;margin-left: .2em;"&gt;&lt;img src="https://docs.opencommit.eu/static/sa.svg" alt="" style="max-width: 1em;max-height:1em;margin-left: .2em;"&gt;</copyright><atom:link href="https://docs.opencommit.eu/trust/index.xml" rel="self" type="application/rss+xml"/><item><title/><link>https://docs.opencommit.eu/trust/coc/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.opencommit.eu/trust/coc/</guid><description>&lt;h1 id="code-of-conduct--opencommit"&gt;Code of Conduct — OpenCommit&lt;a class="anchor" href="#code-of-conduct--opencommit"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;Effective Date: 2026-01-31&lt;/em&gt;&lt;br/&gt;
&lt;em&gt;Last Updated: 2026-03-25&lt;/em&gt;&lt;/p&gt;
&lt;h2 id="1-purpose"&gt;1. Purpose&lt;a class="anchor" href="#1-purpose"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;OpenCommit exists to support open source development and responsible software collaboration. This Code of Conduct defines the standards of behavior expected from all users of the OpenCommit platform (the “Service”).&lt;/p&gt;
&lt;p&gt;Our goal is to foster a &lt;strong&gt;stable, inclusive, professional, and non-abusive environment&lt;/strong&gt; for developers, organizations, and contributors.&lt;/p&gt;
&lt;p&gt;This Code of Conduct applies to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All users of the OpenCommit platform&lt;/li&gt;
&lt;li&gt;All public and private repositories hosted on the Service&lt;/li&gt;
&lt;li&gt;Issues, pull/merge requests, comments, profiles, and other user-generated content&lt;/li&gt;
&lt;li&gt;Communications that take place through the platform&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Violation of this Code may result in enforcement actions as described below.&lt;/p&gt;</description></item><item><title/><link>https://docs.opencommit.eu/trust/dpa/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.opencommit.eu/trust/dpa/</guid><description>&lt;h1 id="data-processing-addendum-dpa--opencommit"&gt;Data Processing Addendum (DPA) — OpenCommit&lt;a class="anchor" href="#data-processing-addendum-dpa--opencommit"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;Effective Date: 2026-01-31&lt;/em&gt;&lt;br/&gt;
&lt;em&gt;Last Updated: 2026-04-04&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This Data Processing Addendum (“DPA”) forms part of the Terms of Service (“Agreement”) between &lt;strong&gt;Stichting OpenGit&lt;/strong&gt;, operating as OpenCommit (OpenCommit Foundation), (“Processor”) and the entity subscribing to the Service (“Controller”).&lt;/p&gt;
&lt;h2 id="1-definitions"&gt;1. Definitions&lt;a class="anchor" href="#1-definitions"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;“Data Protection Laws”&lt;/strong&gt; means the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;“Personal Data”&lt;/strong&gt; means any information relating to an identified or identifiable natural person processed by Processor on behalf of Controller within the Service.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;“Sub-processor”&lt;/strong&gt; means any third party appointed by Processor to process Personal Data.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="2-scope-and-role"&gt;2. Scope and Role&lt;a class="anchor" href="#2-scope-and-role"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This DPA applies where OpenCommit processes Personal Data as a &lt;strong&gt;Processor&lt;/strong&gt; on behalf of the Controller in the course of providing git hosting services. This typically includes data contained within private repositories, issue trackers, and pull requests.&lt;/p&gt;</description></item><item><title/><link>https://docs.opencommit.eu/trust/privacy-policy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.opencommit.eu/trust/privacy-policy/</guid><description>&lt;h1 id="privacy-policy--opencommit"&gt;Privacy Policy — OpenCommit&lt;a class="anchor" href="#privacy-policy--opencommit"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;Effective Date: 2026-01-31&lt;/em&gt;&lt;br/&gt;
&lt;em&gt;Last Updated: 2026-04-04&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;OpenCommit Foundation&lt;/strong&gt; (&lt;em&gt;Stichting OpenGit, a foundation (stichting)&lt;/em&gt;) (“OpenCommit”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our git hosting service at &lt;a href="https://opencommit.eu"&gt;opencommit.eu&lt;/a&gt; (the “Service”).&lt;/p&gt;
&lt;p&gt;OpenCommit is a foundation established in the Netherlands and is subject to the &lt;strong&gt;General Data Protection Regulation (GDPR)&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title/><link>https://docs.opencommit.eu/trust/security-overview/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.opencommit.eu/trust/security-overview/</guid><description>&lt;h1 id="security-overview--opencommit"&gt;Security Overview — OpenCommit&lt;a class="anchor" href="#security-overview--opencommit"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;Last Updated: 2026-04-04&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;OpenCommit aims to protect the confidentiality, integrity, and availability of the Service and user data. This Security Overview describes the technical and organizational measures we use to secure the platform. It is provided for transparency and does not form part of the Terms of Service.&lt;/p&gt;
&lt;h2 id="1-infrastructure-and-hosting"&gt;1. Infrastructure and Hosting&lt;a class="anchor" href="#1-infrastructure-and-hosting"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;EEA-based hosting&lt;/strong&gt;: Core infrastructure is hosted within the European Economic Area (EEA).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hosting provider&lt;/strong&gt;: Infrastructure is hosted with &lt;strong&gt;Hetzner Online GmbH&lt;/strong&gt; in &lt;strong&gt;Germany and Finland&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data center security&lt;/strong&gt;: We rely on Hetzner’s data center security controls and certifications (including ISO/IEC 27001 where applicable) and industry-standard physical security measures.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="2-network-security"&gt;2. Network Security&lt;a class="anchor" href="#2-network-security"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Segmentation&lt;/strong&gt;: We segment services to limit unnecessary access between components.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Firewalls&lt;/strong&gt;: Inbound access is restricted to required ports and services.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Administrative access&lt;/strong&gt;: Administrative access is limited and protected using strong authentication and encrypted connections.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="3-encryption"&gt;3. Encryption&lt;a class="anchor" href="#3-encryption"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;In transit&lt;/strong&gt;: Traffic between clients (web browsers and git clients) and OpenCommit is encrypted using modern TLS.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;At rest&lt;/strong&gt;: We use encryption where appropriate for backups and sensitive configuration material.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="4-authentication-and-account-security"&gt;4. Authentication and Account Security&lt;a class="anchor" href="#4-authentication-and-account-security"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Passwords&lt;/strong&gt;: Passwords are stored using strong, one-way hashing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2FA&lt;/strong&gt;: We support and may require two-factor authentication (2FA) for accounts or organizations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SSH&lt;/strong&gt;: Git access supports SSH keys; users are encouraged to use modern key types (e.g., Ed25519).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="5-application-and-dependency-security"&gt;5. Application and Dependency Security&lt;a class="anchor" href="#5-application-and-dependency-security"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Forge software&lt;/strong&gt;: The Service is based on &lt;strong&gt;Forgejo&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Patching&lt;/strong&gt;: We monitor upstream security advisories and apply relevant security updates in a timely manner.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hardening&lt;/strong&gt;: We aim to minimize the attack surface by disabling or restricting non-essential services and features.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="6-monitoring-and-logging"&gt;6. Monitoring and Logging&lt;a class="anchor" href="#6-monitoring-and-logging"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Operational monitoring&lt;/strong&gt;: We monitor service health and availability to detect incidents and outages.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Status monitoring&lt;/strong&gt;: We may use third parties (e.g., &lt;strong&gt;Uptime Robot&lt;/strong&gt;) for status/availability checks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security logging&lt;/strong&gt;: We maintain logs relevant to security and abuse prevention. Access to logs is restricted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="7-backups-and-recovery"&gt;7. Backups and Recovery&lt;a class="anchor" href="#7-backups-and-recovery"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Backups&lt;/strong&gt;: We perform regular backups of repository and database data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Recovery&lt;/strong&gt;: We maintain recovery procedures to restore service after incidents.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;User responsibility&lt;/strong&gt;: Users remain responsible for maintaining independent backups of their repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="8-incident-response"&gt;8. Incident Response&lt;a class="anchor" href="#8-incident-response"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Response&lt;/strong&gt;: We investigate suspected security incidents and take appropriate steps to contain and remediate issues.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Notification&lt;/strong&gt;: Where required by law or contract (for example under a DPA), we will notify affected parties of relevant incidents.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="9-vulnerability-reporting"&gt;9. Vulnerability Reporting&lt;a class="anchor" href="#9-vulnerability-reporting"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;If you believe you have found a security vulnerability in OpenCommit, please contact:&lt;/p&gt;</description></item><item><title/><link>https://docs.opencommit.eu/trust/sub-processors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.opencommit.eu/trust/sub-processors/</guid><description>&lt;h1 id="sub-processors--opencommit"&gt;Sub-processors — OpenCommit&lt;a class="anchor" href="#sub-processors--opencommit"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;Last Updated: 2026-04-04&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;To provide our Service, OpenCommit engages the following third-party sub-processors to perform specific processing activities. All sub-processors are bound by Data Processing Agreements (DPAs) to ensure the protection of your personal data.&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th style="text-align: left"&gt;Entity&lt;/th&gt;
 &lt;th style="text-align: left"&gt;Activity&lt;/th&gt;
 &lt;th style="text-align: left"&gt;Location&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;&lt;strong&gt;Hetzner Online GmbH&lt;/strong&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;Cloud Infrastructure &amp;amp; Hosting&lt;/td&gt;
 &lt;td style="text-align: left"&gt;Germany / Finland (EEA)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;&lt;strong&gt;Soverin&lt;/strong&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;Email&lt;/td&gt;
 &lt;td style="text-align: left"&gt;The Netherlands (EEA)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;&lt;strong&gt;Uptime Robot&lt;/strong&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;Status page (if accessed by user)&lt;/td&gt;
 &lt;td style="text-align: left"&gt;Slovak Republic (EEA)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;</description></item><item><title/><link>https://docs.opencommit.eu/trust/tos/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.opencommit.eu/trust/tos/</guid><description>&lt;h1 id="terms-of-service--opencommit"&gt;Terms of Service — OpenCommit&lt;a class="anchor" href="#terms-of-service--opencommit"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;Effective Date: 2026-01-31&lt;/em&gt;&lt;br&gt;
&lt;em&gt;Last Updated: 2026-04-04&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;These Terms of Service (“Terms”) constitute a legally binding agreement between the &lt;strong&gt;OpenCommit Foundation&lt;/strong&gt; (&lt;em&gt;Stichting OpenGit, a foundation (stichting)&lt;/em&gt;) established under the laws of The Netherlands, with its statutory seat in Leiden, the Netherlands (“OpenCommit”, “we”, “us”, “our”), and you (“User”, “you”).&lt;/p&gt;
&lt;p&gt;These Terms govern your access to and use of the OpenCommit platform available at &lt;a href="https://opencommit.eu"&gt;https://opencommit.eu&lt;/a&gt; and related services (the “Service”).&lt;/p&gt;</description></item></channel></rss>