Legal

Privacy Policy

Last updated: August 2026

1. Who we are

Griott ("we", "us", "our") is a community-curated archive of Zimbabwean and African history. Our platform allows contributors to submit historical accounts, curators to review them, and the public to read published entries. Our website is located at griott.org.

2. What data we collect

  • Account data: Email address, username, and password (hashed) when you register.
  • Profile data: Display name, biography, and any optional information you add to your contributor profile.
  • Contribution data: Historical texts, citations, and metadata you submit to the archive.
  • Usage data: Pages visited, features used, and interaction logs for analytics and abuse prevention.
  • Technical data: IP address, browser type, and device information collected automatically.
  • Cookies: Session cookies for authentication and optional analytics cookies (see Section 7).

3. How we use your data

  • To provide and maintain the Griott archive service.
  • To authenticate your account and keep it secure.
  • To display your contributions and profile to other users (unless you submit anonymously).
  • To send you notifications about your submissions (moderation decisions, corroborations).
  • To prevent spam, abuse, and fraudulent submissions.
  • To improve the platform through aggregated, anonymised analytics.

4. Legal basis for processing (GDPR)

If you are in the European Economic Area, we process your data under the following legal bases:

  • Contract: Processing necessary to provide the service you signed up for.
  • Legitimate interests: Security, fraud prevention, and service improvement.
  • Consent: Analytics cookies and marketing communications (you may withdraw consent at any time).

5. Data sharing

We do not sell your personal data. We share data only with:

  • Supabase: Our database and authentication provider, hosted in the EU.
  • Law enforcement: When required by applicable law or to protect the rights of others.

6. Data retention

We retain your account data for as long as your account is active. Published contributions are retained indefinitely as part of the historical archive. You may request deletion of your account and personal data at any time (see Section 8), though published contributions may be anonymised rather than deleted to preserve the integrity of the archive.

7. Cookies

We use the following types of cookies:

  • Essential cookies: Required for authentication and security. Cannot be disabled.
  • Analytics cookies: Help us understand how the platform is used. You can decline these via the cookie banner.

8. Your rights

Under GDPR and applicable data protection law, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Object to or restrict processing.
  • Data portability (receive your data in a machine-readable format).
  • Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at privacy@griott.org.

9. Security

We implement industry-standard security measures including encrypted connections (HTTPS), hashed passwords, and access controls. No system is completely secure; if you believe your account has been compromised, contact us immediately.

10. Changes to this policy

We may update this policy from time to time. We will notify registered users of material changes by email. Continued use of Griott after changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related questions or requests: privacy@griott.org