Confidentiality Policy: Accessibility, Design & Technology

Purpose

The Accessibility, Design, & Technology Committee (“AD&T”) believes transparency and disclosure are key to maintaining a good rapport with Archive of Our Own (“AO3”) users as well as other Organization for Transformative Works (“OTW”) volunteers. However, we also recognize that some matters require confidentiality in order to protect our volunteers, users, and suppliers. Therefore, all members of AD&T are required to agree and adhere to this Confidentiality Policy in addition to their responsibilities under the Code of Conduct and Speaking About the OTW in Public policies. Note that this policy is intended to cover confidential information that may be available to volunteers in any AD&T role, including liaison positions. Confidential information that is only available to a specific role or subset of roles may require agreement to additional confidentiality policies.

Who does the AD&T Confidentiality Policy affect?

All AD&T chairs and volunteers (including Quality Assurance & Testing subcommittee volunteers), as well as inter-committee liaisons to AD&T (collectively, “AD&T volunteers”), are required to agree and adhere to this policy. This policy will apply during these individuals’ service on AD&T and will continue to bind those individuals after their service on AD&T has ended, including during any future service for the OTW in any other capacity.

AD&T volunteers must agree to this policy as part of induction and the agreement must be filed with Volunteers & Recruiting before the volunteer gains access to any of the Confidential Information defined below.

What is Confidential Information?

For the purposes of this policy, Confidential Information shall include:

  1. AO3 User Data. Some AD&T volunteers may have access to the personal information of AO3’s users (e.g. IP addresses or email addresses) through tools such as Sentry or Resque
  2. Supplier Information. AD&T volunteers may have access to private information about the suppliers for hardware and services used by the OTW for AO3. Private information may include the names of suppliers, including both the company name and the names of any contacts within the company, location of hardware, and the details of any contracts the suppliers hold with the OTW. Suppliers working exclusively with AD&T may choose to waive confidentiality with approval by AD&T chair(s).
  3. Contacts’ Personal Information. AD&T volunteers may have access to external contacts’ names, email addresses, and other personal information (e.g., place of employment) that is privately shared on OTW tools such as Google groups, Slack, and Jira. Contacts may be external code contributors, reporters of security issues or other external contacts AD&T interacts with in the course of their work. General information privately shared by external contributors, such as coding queries, may be shared in an anonymized form. If an email is received by AD&T that is best dealt with by another volunteer or committee, the entire email can be forwarded to the appropriate volunteer or committee with the AD&T chair(s)’ agreement, provided forwarding the email would not violate the Code of Conduct’s policy on outing. Names shared on public tools such as GitHub and Jira may be shared, including publicly in release notes.
  4. Security Issues. AD&T volunteers may become aware of security risks in AO3’s codebase. Details about security issues, including how to exploit or fix them, may only be shared according to the Security Fixes for AO3 policy. In situations where it is unclear whether an issue impacts the security of the AO3, the issue is to be treated as a security issue by default, unless determined by the AD&T chair(s) that the issue should not be considered a security issue.
  5. Committee Internal Discussion. Discussion held in private OTW-controlled spaces used for AD&T work such as Google Workspace, private code repositories including forks, or locked Slack channels.

Treatment of Confidential Information

This Confidentiality Policy requires that AD&T volunteers, as well as inter-committee liaisons to AD&T, must not share Confidential Information (as defined above) with any individual or group outside the AD&T Committee unless specifically authorised to do so by the AD&T chair(s).

If an AD&T volunteer receives a request for information which would breach this Confidentiality Policy, they should refer that request to the AD&T chair(s).

Enforcement

Failing to uphold the terms of this Confidentiality Policy while serving in the OTW will be addressed under the Constructive Corrective Action Procedure by AD&T chair(s) and Volunteers & Recruiting, and may result in a warning, suspension, or direct termination depending on the severity of the misconduct.