Scope and controller
Andyl, Inc., a Delaware corporation (ANDYL, we, us, or our), controls the personal information covered by this supplement. It applies to cla.andyl.org, the contributor-facing functions of api.andyl.org, and related administrative functions (collectively, the CLA Service).
The general ANDYL Privacy Notice also applies. This supplement controls if the two notices differ with respect to contributor-agreement information.
Information we collect
Agreement and contributor information
When you accept an agreement, we collect your legal name, email address, contact address, authenticated stable GitHub user ID, GitHub login at acceptance, acceptance time, agreement version and exact text, agreement digest, explicit assent, unique acceptance identifier, and current authorization status. We receive your GitHub identifier and login from GitHub when you authenticate.
Security and evidence information
We create keyed hashes of the source IP address and user-agent value associated with an acceptance. We also record the service revision, evidence digest, archive state, and administrative status history. The hashes help distinguish evidence and investigate abuse without storing the underlying IP address or user-agent value in the acceptance record.
Sessions and administration
Session records contain an opaque-token digest, authenticated principal, and expiration time. Contributor sessions include GitHub identity information. Administrative sessions may include an authorized Google Workspace email and the result of an access check. We receive those details from GitHub or Google when the relevant person authenticates.
Private contact requests
The contributor contact form collects the name, email address, subject, message, submission time, expiration time, and private reference number needed to answer the request.
Cookies and browser storage
The CLA Service uses strictly necessary, secure, HTTP-only cookies for OAuth state, OAuth verifier data, and authenticated sessions. OAuth preparation cookies are valid for up to ten minutes and are cleared after the callback. An authenticated CLA session is valid for up to twelve hours. These cookies are scoped to the API paths that need them.
During an acceptance attempt, your browser temporarily stores an opaque retry identifier and a local fingerprint in session storage. This allows an interrupted submission to resume without creating duplicate evidence. It is removed after successful acceptance and otherwise expires with the browser session.
Vercel serves the frontend but does not receive the API session cookie or OAuth access tokens. The CLA Service does not use advertising cookies, advertising pixels, or session-replay technology.
Purposes and legal bases
We use the information described above to:
- authenticate contributors and authorized administrators;
- display and verify the exact active agreement;
- record and prove unambiguous acceptance;
- administer authorization for future contributions;
- preserve the licenses granted for accepted contributions;
- prevent duplicate records, fraud, and abuse;
- respond to contributor, privacy, security, and legal requests; and
- establish, exercise, or defend legal claims and comply with law.
Where European data-protection law applies, we rely on steps requested before and performance of the contributor agreement, our legitimate interests in administering open-source licensing and preserving reliable evidence, compliance with legal obligations, and the establishment, exercise, or defense of legal claims.
How we disclose information
Google Cloud processes the CLA API, Firestore query records, and Cloud Storage evidence archive. GitHub processes contributor authentication. Google processes administrator authentication and authorization checks. Vercel hosts the contributor-facing frontend. These providers receive only the information needed for their role.
Access to private acceptance and contact records is limited to authorized service, security, and legal administrators. We may also disclose information to professional advisers, authorities, or transaction participants when reasonably necessary to comply with law, protect rights and security, or complete a business reorganization subject to appropriate safeguards. Acceptance records are not committed to a public repository.
Retention and legal evidence
- The operational acceptance record remains in Firestore while needed to administer contribution authorization and the licenses already granted.
- A create-only evidence copy is retained privately in a retention-locked Google Cloud Storage archive for at least seven years. After that minimum, it remains until an authorized records process determines deletion is appropriate.
- Contributor and administrator sessions cease to be valid after twelve hours. Expired records are removed under the database lifecycle process.
- Private contact requests expire after 180 days.
- Short-lived OAuth state, verifier, and browser retry data expires as described in the Cookies and browser storage section.
Disabling or superseding authorization changes whether a contributor is authorized for future contributions. It does not erase or revoke licenses already granted, and it does not rewrite the historical evidence.
Your rights
Depending on where you live and whether the relevant law applies, you may request access to, correction of, deletion of, restriction of, or a portable copy of your personal information, or object to certain processing. You may also have a right to appeal our response or complain to the data-protection authority where you live or work.
These rights are subject to legal exceptions. In particular, we may retain agreement evidence needed to administer or prove licenses, comply with law, or establish or defend legal claims. A correction that affects legal evidence is recorded through a new acceptance or supplemental record rather than by rewriting immutable evidence.
We may ask for information reasonably necessary to verify your identity and authority. We do not sell CLA information or use it for advertising, targeted advertising, or profiling that produces legal or similarly significant effects.
Security and international processing
We use administrative and technical safeguards designed to protect CLA information, including restricted access, keyed hashing of limited transport metadata, scoped authentication cookies, create-only evidence, and a private retention archive. No system is completely secure.
ANDYL is based in the United States, and the providers named above may process information in the United States or other countries. Where applicable law requires a transfer mechanism, we use an approved legal mechanism or another permitted basis.
The CLA Service is intended only for people who are at least 18 years old, or the age of legal majority where they live, and have legal capacity to enter the contributor agreement.
Changes and contact
We may update this supplement as the CLA Service or applicable requirements change. We will post the revised version, update the effective date, and provide additional notice when appropriate. A change to this supplement does not change an agreement already accepted or a license already granted.
To ask a privacy question or exercise an applicable right, use the private contributor contact form. Questions about general ANDYL privacy practices may also be sent to privacy@andyl.com. Use of the CLA Service is subject to the ANDYL Terms of Use.