---> DRAFT VERSION
This policy describes restrictions for websites managed by the ASF or hosted on ASF servers.
All analytics software embedded on a website needs to be confirmed by V.P. Data Privacy. Analytics software need to support the GDPR and a DPA need to be signed before it can be used.
Note: Google Analytics cannot be used on any ASF website because of Schrems-II.
YouTube content can be embedded only when the user gave consent before loading any file from YouTube.
No cookies are allowed, except the user gave consent before setting the cookie.
If the cookie is not used for tracking, but used for managing a so called session, no user content is necessary.
Assets (JS, Images, Fonts, CSS etc) from other domains cannot be loaded. Assets need to be hosted on ASF servers.
(Google) can usually be used, when the user gave consent before loading.
Social Media buttons (Facebook Like, showing Instagram embeds, Twitter pixel) can only be used when the user gave consent before loading.
ASF Projects cannot run Facebook pages due to Art. 5 ยง2 and Art. 26 of the GDPR.