Privacy Policy

We’re updating our Privacy Policy on May 25, 2018. Our new and previous policies are outlined below.

This is our updated Privacy Policy which goes into effect on May 25, 2018.

——

Who We Are

 

Xanthe is the author of fanfiction in multiple fandoms. www.xanthe.org offers news and updates regarding any past, current and future works by Xanthe, and general news of interest.

 

This privacy policy applies to all visitors and members using or accessing the website www.xanthe.org. It also applies to the Newsletter service that we provide as part of our subscription service.

 

Xanthe is based in London, for any privacy-related questions, you can reach us a via email here.

 

Who We Share Your Data With

 

We use third-party services (data processors) across our sites. The extent to which your data is shared with these providers depends on your use of our services, and we list the specific third-parties in use (with links to their privacy policies) in the sections below.

 

Each third-party provider has been vetted by our security team to ensure that privacy policies and practices meet or exceed the same levels of compliance and standards that we follow in order to help ensure your data is safe and secure.

 

We disclose potentially personally-identifying and personally-identifying information only to our employees, contractors and affiliated organizations that (i) need to know that information in order to process it on our behalf or to provide services, and (ii) that have agreed, in writing, not to disclose it to others. Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using our websites and services, you consent to the transfer of such information to them. We will not rent or sell potentially personally-identifying and personally-identifying information to anyone.

 

We may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

If we ever were to engage in any onward transfers of your data with third parties for a purpose other than which it was originally collected or subsequently authorized, we would provide you with an opt-out choice to limit the use and disclosure of your personal data.

 

Cookies

 

A cookie is a string of information that a website stores on a visitor’s computer, and that the visitor’s browser provides to the website each time the visitor returns. We use cookies across our sites to help identify and track visitors, their usage of our services, and their website access preferences. We describe the specific cookies used in the sections below. Visitors who do not wish to have cookies placed on their computers should set their browsers to refuse cookies before using our websites, with the drawback that certain features may not function properly without the aid of cookies.

 

 

What Personal Data We Collect And Why We Collect It

Registered Users

  • If you create an account on one the site, you will be prompted to select a Username and provide your Email Address.
  • When choosing a Username, we strongly advise you not use or include your real name. Usernames cannot be changed by the member, you can contact the admin to request a username change.
  • Your Username and Email Address are stored in the website’s database. Your Email Address is used to send you an email with a link to set your password or to send you an email with a link to reset your password in the event you forget your password.
  • Once an account is created, you must contact us to have it deleted.
  • Accounts have a numeric User ID assigned to them when they are created. The User ID cannot be changed.
  • An anonymized string created from your email address (also called a hash) is provided to the Gravatar service to see if a Profile picture of you is available for display. The Gravatar service privacy policy is available here.
  • You may optionally complete your Profile by providing your First Name, Last Name, Website (URL) and/or Biographical info. These additional details are also saved in the website’s database. You may edit these details, and your Email Address, in your Profile at any time.
  • You may also choose how your name is displayed (your Display Name) to visitors to the site (e.g. in comments you create) in your Profile.
  • Your Username, First Name, Last Name and Email Address are accessible by employees on the site.
  • If you attempt to log in to our site, we will set a temporary cookie to determine if your browser accepts cookies at all. This cookie contains no personal data and is discarded when you close your browser.
  • If you have an account and you log in to a site, we will set up several cookies to save your login information and some of your screen options. The logged-in cookies last for two days, and the screen options cookies last for a year.
  • If you select “Remember Me” these cookies will persist for two weeks. If you log out of your account, the login cookies will be removed. It is important that you log out if you are using a public computer.
  • For users that register on one of our site, we also store the data they provide in their profile indefinitely. All registered users can see, change or delete most of that data at any time except their login name/nickname.

 

Publishing Content (Comments, Pages, Posts, Forums)

  • Your Profile Picture (Gravatar, or one uploaded by the member), Display Name, Website (URL) (if any) and Biographical Info (if any) may be visible to visitors to the website (e.g. if you leave a comment, forum post, or contribute an article/post).
  • If you author an article/post, your Username, User ID, Profile Picture (Gravatar), Display Name, Website (URL) (if any) and Biographical Info (if any) are provided to any visitor using the website’s REST API interface.
  • If you upload media (e.g. images) to the website (in forums, posts, or comments), you should avoid uploading images with EXIF GPS location data included. Visitors to the website can download and extract any location data included in images on the website.
  • Visitors using the website’s REST API interface can correlate uploaded media to a particular user. This may allow such visitors to map a user to a particular time and location if EXIF GPS location data was included in the uploaded media.
  • If you edit or publish an article/post, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
  • When visitors leave comments on one of our sites we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
  • Comments may require manual approval by one of our employees or site owners.
  • If you leave a comment on a site you may opt-in to saving your name, email address and website in cookies so we can recognise you as a commenter. These cookies will persist for one year.
  • Published content and comments are stored indefinitely unless deletion/removal is requested by the original author.

 

Email/Chat/Contact Forms

  • We use Google/G Suite to process all internal email and communication with our customers. Google’s privacy policy is available here.
  • Customers that email us, or use any of the contact forms on our websites, will have their email address, IP address, and any data provided in the contact form or body of the email stored in G Suite archives .
  • We keep all email and chat communication indefinitely to help us provide support and improve our services. Individuals can request copies of any previous correspondence with us at any time.

 

Embedded Content From Other Websites

Embeds are pieces from other websites that are shown from time to time on our websites. They behave in the exact same way as if the visitor has visited the other website and may use cookies or capture information. Typically embedded content is from websites that share videos, images, or other content. These services may collect your IP Address, your User Agent, store and retrieve cookies on your browser, embed additional third-party tracking, and monitor your interaction with that embedded content, including correlating your interaction with the content with your account with that service, if you are logged in to that service.

 

Links to the privacy policies of the most common services have been included below. Where a general privacy policy is not available, the applicable country is indicated.

 

Analytics

  • We use Google Analytics for tracking visitors and aggregating information about the traffic to our websites. The Google Analytics privacy policy can be found here:  https://policies.google.com/privacy. You can learn more about how to opt-out of tracking in Google Analytics here.

 

Marketing Campaigns

  • We use email marketing to communicate with customers and potential customers from time to time. All email lists and campaigns are “opt-in” meaning we will not send you these sorts of emails unless you indicated that you wish to receive them during signup or other interactions on our website.
  • We may send you “system” emails, such as password reset requests or payment notifications/receipts even if you have not opted-in to email marketing lists.
  • All marketing emails sent by us will include an unsubscribe link in the footer of the email. Emails sent to you may also include standard tracking, including open and click activities.
  • We use an external service for email marketing, MailChimp. Mailchimp’s privacy policy is found here.
  • We may utilize social media and web advertising campaigns. These service providers use cookies on our sites and/or pixel tracking to serve ads across the different platforms.

 

Hosting and API Services

  • All web servers and hosting are managed by our team on the Godaddy Web Services platform located in different regions around the world. This includes website hosting, backups, web database, file storage, APIs, and log files. Godaddy’s privacy policy can be found here.
  • Our ‘Tinypng’ services use the image compression serviceFiles and images served by the CDN may be stored and served from countries other than your own. Tinypng’s privacy policy can be found here.

 

What Rights You Have Over Your Data

If you are a registered user or have left comments on our site you can request to see or download the data we have about you.

 

Typically for visitors that have left comments, the data will be their email address, any IP addresses assigned to them at the time of leaving the comments and the user agent strings of the browsers they used. The rest of the data is public as published by the visitors.

For registered users, this will also include profile information and download, payment, and support ticket histories.

 

You can also request “to be forgotten” and we will erase any personally identifiable data we have about you. Of course, this excludes data we need for administrative or security purposes or if we are required by law to retain some of the data.

 

An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data, should direct his/her query to xanthewalter. We will respond within a reasonable timeframe, not to exceed one week.

 

How We Protect Your Data

The security and reliability of our service is our number one priority. We endeavour to ensure that best practices are followed in everything that we do.

 

See wordpress.org/about/security for details on the security of the WordPress core itself.

  • Prevention is best when it comes to security, and as a first step, we follow all WordPress Code Standards in the plugins that we build and use.
  • In addition, we internally review services and plugins specifically to prevent potential security vulnerabilities in those plugins and services.
  • All staff only have access to systems that are directly required to complete the functions of their job.
  • Staff stay informed of best practices and relevant trends. Staff review and agree, in writing, to all policies and procedures annually.  We need to get something formal between me and you here to protect us on this
  • We only use third-party services, such as Goddady Web Services, that are fully vetted and adhere to the highest levels of privacy and security practices.

 

What Data Breach Procedures We Have In Place

Should any event occur where customer data has been lost, stolen, or potentially compromised, our policy is to alert our customers via email no later than 48 hours of our team becoming aware of the event. We will also report such incident to any required data protection authority. We will work closely with any customers affected to determine next steps such as any end-user notifications, needed patches, and how to avoid any similar event in the future.

 

Privacy Policy Changes

Although most changes are likely to be minor, Xanthe may change its Privacy Policy from time to time, and in Xanthe’s sole discretion. Xanthe will notify clients by email when making changes.

 

Changelog

  • May 25, 2018 – Updated language of the policy to be more user-friendly, specifically outlining requirements in preparation for meeting the GDPR.

 

Previous Privacy Policy

What is this Privacy Policy for?

 

This privacy policy is for this website www.xanthe.org and served b xanthe.org and governs the privacy of its users who choose to use it.

The policy sets out the different areas where user privacy is concerned and outlines the obligations & requirements of the users, the website and website owners. Furthermore the way this website processes, stores and protects user data and information will also be detailed within this policy.

 

The Website

 

This website and its owners take a proactive approach to user privacy and ensure the necessary steps are taken to protect the privacy of its users throughout their visiting experience. This website complies to all UK national laws and requirements for user privacy.

Use of Cookies

 

This website uses cookies to better the users experience while visiting the website. Where applicable this website uses a cookie control system allowing the user on their first visit to the website to allow or disallow the use of cookies on their computer / device. This complies with recent legislation requirements for websites to obtain explicit consent from users before leaving behind or reading files such as cookies on a user’s computer / device.

 

Cookies are small files saved to the user’s computers hard drive that track, save and store information about the user’s interactions and usage of the website. This allows the website, through its server to provide the users with a tailored experience within this website.
Users are advised that if they wish to deny the use and saving of cookies from this website on to their computers hard drive they should take necessary steps within their web browsers security settings to block all cookies from this website and its external serving vendors.

This website uses tracking software to monitor its visitors to better understand how they use it. This software is provided by Google Analytics which uses cookies to track visitor usage. The software will save a cookie to your computers hard drive in order to track and monitor your engagement and usage of the website, but will not store, save or collect personal information. You can read Google’s privacy policy here for further information [http://www.google.com/privacy.html .

 

Other cookies may be stored to your computers hard drive by external vendors when this website uses referral programs, sponsored links or adverts. Such cookies are used for conversion and referral tracking and typically expire after 30 days, though some may take longer. No personal information is stored, saved or collected.

 

Contact & Communication

 

Users contacting this website and/or its owners do so at their own discretion and provide any such personal details requested at their own risk. Your personal information is kept private and stored securely until a time it is no longer required or has no use, as detailed in the Data Protection Act 1998. Every effort has been made to ensure a safe and secure form to email submission process but advise users using such form to email processes that they do so at their own risk.

 

This website and its owners use any information submitted to provide you with further information about the products / services they offer or to assist you in answering any questions or queries you may have submitted. This includes using your details to subscribe you to any email newsletter program the website operates but only if this was made clear to you and your express permission was granted when submitting any form to email process. Or whereby you the consumer have previously purchased from or enquired about purchasing from the company a product or service that the email newsletter relates to. This is by no means an entire list of your user rights in regard to receiving email marketing material. Your details are not passed on to any third parties.

 

Email Newsletter

 

This website operates an email newsletter program, used to inform subscribers about products and services supplied by this website. Users can subscribe through an online automated process should they wish to do so but do so at their own discretion. Some subscriptions may be manually processed through prior written agreement with the user.

 

Subscriptions are taken in compliance with UK Spam Laws detailed in the Privacy and Electronic Communications Regulations 2003. All personal details relating to subscriptions are held securely and in accordance with the Data Protection Act 1998. No personal details are passed on to third parties nor shared with companies / people outside of the company that operates this website. Under the Data Protection Act 1998 you may request a copy of personal information held about you by this website’s email newsletter program. A small fee will be payable. If you would like a copy of the information held on you please write to the business address at the bottom of this policy.

 

Email marketing campaigns published by this website or its owners may contain tracking facilities within the actual email. Subscriber activity is tracked and stored in a database for future analysis and evaluation. Such tracked activity may include; the opening of emails, forwarding of emails, the clicking of links within the email content, times, dates and frequency of activity [this is by no far a comprehensive list].
This information is used to refine future email campaigns and supply the user with more relevant content based around their activity.

In compliance with UK Spam Laws and the Privacy and Electronic Communications Regulations 2003 subscribers are given the opportunity to un-subscribe at any time through an automated system. This process is detailed at the footer of each email campaign. If an automated un-subscription system is unavailable clear instructions on how to un-subscribe will by detailed instead.

 

External Links

 

Although this website only looks to include quality, safe and relevant external links, users are advised adopt a policy of caution before clicking any external web links mentioned throughout this website. (External links are clickable text / banner / image links to other websites, similar to; Xanthe Walter.)

 

The owners of this website cannot guarantee or verify the contents of any externally linked website despite their best efforts. Users should therefore note they click on external links at their own risk and this website and its owners cannot be held liable for any damages or implications caused by visiting any external links mentioned.

 

Adverts and Sponsored Links

 

This website may contain sponsored links and adverts. These will typically be served through our advertising partners, to whom may have detailed privacy policies relating directly to the adverts they serve.

 

Clicking on any such adverts will send you to the advertisers website through a referral program which may use cookies and will track the number of referrals sent from this website. This may include the use of cookies which may in turn be saved on your computers hard drive. Users should therefore note they click on sponsored external links at their own risk and this website and its owners cannot be held liable for any damages or implications caused by visiting any external links mentioned.

 

Social Media Platforms

 

Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are custom to the terms and conditions as well as the privacy policies held with each social media platform respectively.

 

Users are advised to use social media platforms wisely and communicate / engage upon them with due care and caution in regard to their own privacy and personal details. This website nor its owners will ever ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.

This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using such social sharing buttons that they do so at their own discretion and note that the social media platform may track and save your request to share a web page respectively through your social media platform account.

 

 

Shortened Links in Social Media

This website and its owners through their social media platform accounts may share web links to relevant web pages. By default some social media platforms shorten lengthy urls [web addresses] (this is an example: http://bit.ly/zyVUBo).

 

Users are advised to take caution and good judgement before clicking any shortened urls published on social media platforms by this website and its owners. Despite the best efforts to ensure only genuine urls are published many social media platforms are prone to spam and hacking and therefore this website and its owners cannot be held liable for any damages or implications caused by visiting any shortened links.

Show Buttons
Hide Buttons