Draft / not legal advice

Privacy Policy

Scope

This draft describes Keyboard Workshop as it works today. The site information pages — this one, About, Editorial Standards, Terms and Contact — are open to anyone. The guides themselves are unpublished and can be opened only by signed-in editors and administrators. It is an outline for review, not a finished policy.

Data used for staff access

Staff sign in to the editorial system with an account that holds their email address, a password (stored hashed by the content-management software) and a role. The preview uses the role only to decide whether the page may be shown. Editorial actions record which account performed them.

Session cookies

Reading these information pages sets no cookie at all. Signing in as staff sets a session cookie namedpayload-token. It is HttpOnly (not readable by page scripts) and SameSite=Lax. The sign-in token it carries expires after two hours, and the session it belongs to is recorded on the staff account. No other cookies are set by these pages, and there is no analytics, advertising or tracking code.

Hosting and security

Depending on the address used, a request either reaches the server directly over HTTPS or passes through a content-delivery network first; where a network is in front, it also sees the request. The web server keeps a standard access log of each request: the connecting network address, time, requested path, response status and size, referring page and browser identification string.

Pending confirmation: how long access logs are kept, who operates the service, and which hosting providers process data.

Retention and requests

These pages do not offer public accounts, registration, newsletters or a contact form.

Pending confirmation: retention periods, how individuals can ask about or delete their data, and the legal basis for processing.

Changes

This outline will change before any public release and must be reviewed and approved first.