Website & Project Participation Privacy Notice
Conduck
Last Updated: 2026-07-24
Data Controller: GigaDuck OÜ Tornimäe tn 5, 10145 Tallinn, Estonia Registry code: 17501858 (Estonian Business Register) Email: [email protected] · General: [email protected]
1. What This Notice Covers
The Conduck app sends nothing to us — it has no backend, no accounts, and no analytics, so GigaDuck collects nothing through it. How the app handles data on your device and with the providers you configure is described in our Privacy Policy. This notice covers everything around the app: the ways you might choose to interact with us, GigaDuck OÜ (“we,” “us,” “our”), the company behind Conduck. Specifically:
- the conduck.com website (including the gigaduck.ai domain, which serves no content of its own and only redirects there);
- participating in the open-source project — issues, pull requests, and code contributions on GitHub;
- emailing us — support, privacy, legal, and security reports;
- our community channels, currently a Discord server.
This notice describes how data is handled in those channels. It is a notice, not a contract — it does not create contractual terms, and our Terms of Service do not change what it says.
2. The Website
conduck.com is a static site with no analytics and no tracking. We run no analytics product, no tag manager, no advertising or tracking cookies, no fingerprinting, and no third-party embeds. The site sets no cookies of its own, loads no third-party scripts or fonts, and contains no forms — there is nothing on it that asks you for personal data.
Hosting. The site is served by Cloudflare (Cloudflare, Inc.), our hosting and content-delivery provider, acting as our processor. Like any web server, Cloudflare’s infrastructure processes your IP address and technical request data (the page requested, browser type, timestamps) for the moment it takes to deliver the page and to protect the site against attacks and abuse. We do not enable or collect visitor request logs ourselves; what we can see is aggregate, non-identifying traffic statistics and, for site-protection purposes, a short rolling window of sampled security events (about 24 hours on our current plan). As part of its protection against automated abuse, Cloudflare may in rare cases set a strictly necessary security cookie (for example, during a bot challenge); such cookies serve no tracking purpose and are not used to profile you.
The same practices apply to gigaduck.ai, which hosts nothing of its own and only redirects to conduck.com.
Outbound links (the App Store, GitHub, Discord, social networks) are plain links. Nothing loads from those services until you click, and once you do, their privacy policies apply.
3. Emailing Us
When you email us — info@, privacy@, legal@, or [email protected] — we receive whatever you choose to send: your email address, your message, and any attachments. We use it to answer you and to handle whatever the message is about, and for nothing else. No marketing lists, no newsletters, no selling of your data — and no disclosure to anyone beyond the processors named in this notice, unless the law requires it.
Our email runs on Google Workspace (Google), acting as our processor: Google’s servers store and transmit the mail on our behalf under Google’s data-processing terms.
A small ask: please don’t include sensitive personal data (health, beliefs, and similar), credentials, or personal data about other people unless it is genuinely needed for your message. If we receive third-party or sensitive data we don’t need, we minimize or delete it rather than keep it — and where the GDPR requires us to inform a person whose data reached us this way, we do. We do not intentionally process special categories of personal data (GDPR Art. 9); if such data is genuinely needed to handle a specific matter — for example, as evidence in a legal claim — we keep it only under an applicable Art. 9 condition and delete it as soon as that need ends.
4. Security Reports
Vulnerability reports sent to [email protected] are handled as described in our Vulnerability Disclosure Policy: we use your report solely to triage, fix, and document the issue — including, where the law requires it, evidencing our handling to authorities — and we treat it confidentially. We do not share your details without your permission, except where disclosure is required by law or by security authorities, and even then we keep your identity out of it wherever possible.
Public credit is opt-in. We name you as the discoverer of a vulnerability only with your consent, which you can decline or withdraw at any time without affecting how your report is handled.
5. Participating in the Project on GitHub
Conduck’s source code lives in public repositories on GitHub (github.com/GigaDuckAI). If you open an issue, comment, submit a pull request, star, or fork, that activity is public — visible to anyone, on a platform operated by GitHub.
Two distinct roles. We are the controller for what we do with project content: reviewing, accepting, publishing, and moderating contributions, issues, and comments on our repositories. GitHub is a separate, independent controller for the platform itself — your GitHub account, platform logs, and everything its Privacy Statement covers. For your account and GitHub’s own processing, exercise your rights with GitHub.
Code contributions and the DCO — read this before your first commit. Every commit in a contribution must carry a Signed-off-by: Name <email> line certifying the Developer Certificate of Origin. If your contribution is accepted, that name and email — along with the git author metadata of the commit — become part of the repository’s published version history, where they are normally retained for as long as the project is maintained. You should understand what that means before contributing:
- Git history is distributed by design: anyone in the world may clone, fork, or mirror the repository, and every copy carries the full history, including your sign-off. Copies made by others are outside our control.
- Published git history is not ordinarily rewritten: rewriting it changes every subsequent commit identifier, breaks signatures and references, and disrupts every fork and clone — and still cannot recall copies already made.
- You choose the identifier. You control which name and which email address you embed. You may use a GitHub-provided
noreplyaddress or another address you are comfortable seeing published permanently — we ask only that the sign-off genuinely identifies you as the accountable contributor. Before a contribution is merged, you can freely amend the name or email on your commits; ask in the pull request if you need help. - Providing a sign-off is required to contribute. Without it we cannot accept the contribution — that is the only consequence of not providing it.
We retain the author and sign-off metadata of accepted commits for as long as the project and its licensing history are maintained, because it is what proves who wrote the code and under what right it was contributed — the project’s authorship and license provenance. Section 9 explains how erasure requests are handled against this backdrop, honestly.
6. Community Channels
We run one community Discord server (linked from conduck.com). Discord is an independent controller for the platform — your account, your messages, and everything its Privacy Policy covers. We are the controller for what we do as the server’s operator: like any member, we see the usernames, messages, attachments, and reports posted there, and we use them to run, moderate, and answer questions in the community — nothing is exported or used elsewhere. We may keep minimal moderation records (for example, the reason for a removal or ban) for as long as they are needed to keep the community usable and fair.
7. Why We May Process Your Data (Legal Bases)
| Processing | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Serving and securing the website (technical request data via Cloudflare) | (f) legitimate interest — delivering the pages you request and protecting the site against attacks and abuse |
| Answering email and handling support | (f) legitimate interest — ordinary correspondence you initiated; (b) contract, where you are personally entering into or performing a contract with us |
| Responding to privacy-rights requests | (c) legal obligation — the GDPR itself |
| Handling security reports | (f) legitimate interest — securing our software and coordinating fixes; (c) legal obligation, where a statutory incident-reporting duty applies to a specific incident |
| Crediting a security researcher publicly | (a) consent — always optional |
| Reviewing, publishing, and moderating project content (issues, PRs, comments) | (f) legitimate interest — operating, documenting, securing, and improving an open-source project |
| Retaining commit author and DCO sign-off metadata | (f) legitimate interest — preserving the authorship and license provenance of the code and the ability to establish or defend legal claims about it |
| Running and moderating the community (content we see as server operators; minimal moderation records) | (f) legitimate interest — operating a safe, usable community |
Your right to object. Where we rely on legitimate interest, you have the right to object at any time, on grounds relating to your particular situation (GDPR Art. 21) — email [email protected]. We then stop the processing unless compelling legitimate grounds override, or the data is needed for legal claims. We highlight this here, separately, because most of the processing above rests on legitimate interest.
We do no profiling and make no automated decisions about anyone.
8. How Long We Keep Things (Retention)
- Website technical data: we retain none ourselves; Cloudflare’s transient processing is described in Section 2.
- General email: kept while the conversation and whatever it concerns are live, then reviewed periodically and deleted once no longer needed — unless the thread became part of a contract, a dispute, or a statutory record (accounting records are kept seven years under Estonian law).
- Security reports: correspondence is kept only as long as needed to triage, fix, and document the issue — including any legally required evidencing to authorities — then deleted, as our Vulnerability Disclosure Policy says. A minimal case record (what was wrong, what we fixed) may be kept longer; your identity is removed from it where not needed.
- Privacy-rights and legal correspondence: a minimal record is kept for as long as needed to demonstrate compliance or while a claim could still arise, then deleted.
- Commit and DCO metadata: for as long as the project and its licensing history are maintained (Section 5). Copies held by third parties who cloned or forked the repository persist independently of us.
- Issues, PRs, comments: for as long as they remain relevant to the project’s operation, security, or history; subject to the rights below.
- Moderation records: for as long as the moderation action is relevant (for an active ban, its duration), then deleted.
9. Your Rights
You have the rights the GDPR provides, subject to its conditions: access to the personal data we hold about you, rectification, erasure, restriction of processing, objection (see Section 7 — highlighted there because it applies to most of this notice), and data portability where applicable. Email [email protected]; we respond within a month. Exercising your rights is free.
Honesty about git history. Erasure has real limits in a public, distributed version history, and we would rather tell you now than surprise you later:
- We assess every erasure or objection request individually — there is no blanket refusal.
- We can edit, anonymize, or remove content under our control — issue and PR text, comments, and moderation records — and where a request is justified, we do. Accidentally published secrets, private information, or unlawful content we remove even where doing so is disruptive.
- The author and sign-off metadata of accepted commits, however, we normally retain in the published history. That retention rests on our legitimate interest in preserving the code’s authorship and license provenance (Section 7), weighed against your rights in each individual assessment; where the metadata is additionally needed to establish, exercise, or defend a legal claim about the code, the GDPR’s own exception for legal claims (Art. 17(3)(e)) applies to that extent.
- Where erasure is legally required despite that, we take reasonable steps in the repositories we control and inform recipients where the GDPR requires it — but rewriting our repository cannot recall the copies independent forks, mirrors, and clones have already made, and those copies are held by parties who are not us. For data held by GitHub itself (your account, platform records), contact GitHub.
The practical advice worth repeating: choose the name and email you contribute under with the permanence of public git history in mind (Section 5).
10. International Transfers
We are an Estonian company, and the services we use are operated by U.S.-based providers:
- Cloudflare (hosting, processor) and Google (email, processor) process data for us under their data-processing agreements, with transfers safeguarded by the EU–U.S. Data Privacy Framework and, where that does not apply, the European Commission’s Standard Contractual Clauses, as set out in each provider’s data-processing terms.
- GitHub and Discord are independent controllers (Sections 5 and 6); their own transfer safeguards are described in their privacy documents.
- Public project content — including git history — is, by its open-source nature, published to the world and may be copied and processed anywhere. No transfer mechanism can recall data you have chosen to make public through a contribution; Section 5 is our way of making sure you know that before it happens.
Details of the safeguards each processor relies on are available in that provider’s published data-processing terms, or from us at [email protected].
11. Complaints
If you think we have handled your personal data wrongly, please contact us first at [email protected] — we read and answer. You also have the right to lodge a complaint with a supervisory authority at any time. Our lead authority is the Estonian Data Protection Inspectorate:
Andmekaitse Inspektsioon — Tatari 39, 10134 Tallinn, Estonia · [email protected] · +372 627 4135 · aki.ee
If you live or work in another EU/EEA country, you may instead complain to the supervisory authority there.
12. Changes to This Notice
We may update this notice as our website, project, or channels change. We will update the “Last Updated” date and publish the current version at conduck.com. Material changes will be announced on the website.
13. Contact
Privacy: [email protected] Data Controller: GigaDuck OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia · Registry code 17501858 · General: [email protected]