Skip to content

Add privacy policy page - #65

Closed
github-actions[bot] wants to merge 6 commits into
mainfrom
i64-20260415-1252
Closed

Add privacy policy page#65
github-actions[bot] wants to merge 6 commits into
mainfrom
i64-20260415-1252

Conversation

@github-actions

Copy link
Copy Markdown

1. Target

2. Specification / Test Plan

(Text here)

3. Additional Instructions / Notes for Shipping (optional)

N/A

4. Check before Review Request

  • Self Review : I reviewed changes by myself and approved them.
    • Ensure there is no sensitive information, typos, unrelated changes, or debugging code.
  • Evidence : I attached evidences to prove the changes.
    • Record and attach a demo video. For minor changes, attaching an image is also acceptable.
    • Evidences should be updated to the latest version when further changes are made.

5. Evidence

(Attach here before request review)

Add OSBR privacy policy covering authentication, data handling,
third-party services, and user rights. Update sidebar config to
include the new page under Policies.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@sn0wm1ku sn0wm1ku mentioned this pull request Apr 15, 2026
4 tasks
…ness, and user decisions

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@sn0wm1ku
sn0wm1ku requested a review from RedEffandy April 15, 2026 04:31
@github-actions github-actions Bot added the ci-testing Enable a GitHub Action for unit testing on a pull request. label Apr 15, 2026
sn0wm1ku and others added 3 commits April 15, 2026 14:06
- Split into 4 pages: summary, company practices, PDPA compliance, systems
- Separate WHAT (company) from HOW (systems) for service user data
- Frame client data handling as governed by engagement agreements
- Remove false DNT compliance claim
- Set handbook GA4 retention to 2 months (verified default)
- Confirm 30-day auth log retention (Cloud Logging default)
- Soften over-commitments: manage gaps, don't fill them
- Update VitePress sidebar with nested navigation

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Reduce outstanding lawyer review scope by researching and addressing
items that can be resolved with public legal sources:

- privacy-pdpa.md §8: cite the 2013 Class of Data Users Order
  and 2016 Amendment by P.U.(A) reference; confirm OSBR does
  not fall within any designated class.
- privacy-pdpa.md §9: new Data Protection Officer section with
  PDPA Amendment Act 2024 thresholds (20,000 / 10,000 / systematic
  monitoring); note OSBR does not meet thresholds.
- privacy-pdpa.md §10: new Data Breach Notification section with
  the 72-hour statutory timeline and 2-year register requirement.
- privacy-company.md §6-3: add retention statement for meeting
  recordings where they occur.
- privacy-company.md §8-9: split sensitive personal data into a
  dedicated section covering all five Section 4 categories
  (including biometric data added by the 2024 Amendment);
  move general exclusions into §9.
- privacy-policy.md §8: add data portability right under the
  PDPA Amendment Act 2024.
- privacy-policy.md §11: update breach notification language to
  reference the statutory timeframe and link to the PDPA page.
3 items:
- Add 7-day data subject notification timeline (§10), clarifying
  that the countdown starts from notification to the Commissioner.
- Add [Act A1727] full citation on first substantive reference to
  the Personal Data Protection (Amendment) Act 2024 (§9).
- Add breach register record retention row to the §5 retention
  table (at least 2 years from notification to the Commissioner).
@sn0wm1ku sn0wm1ku mentioned this pull request Jul 2, 2026
@sn0wm1ku

sn0wm1ku commented Jul 3, 2026

Copy link
Copy Markdown
Member

Reviewed 2026-07-03 12:49 JST. This PR appears to fully satisfy the acceptance criteria of #64 — no scope gap found:

  • doc/privacy-policy.md created, covering all requested topics: authentication information & OAuth tokens (§7), data retention table (§7), Google API Services Limited Use Disclosure (§6, with the required verbatim reference to the Google API Services User Data Policy), and user rights (§8).
  • doc/.vitepress/config.mts updated — "Privacy Policy" added under the Policies section, with nested links to the supporting pages.
  • Beyond the ticket's scope, three supporting pages were added and wired into the sidebar and cross-linked: privacy-company.md, privacy-pdpa.md (per-principle PDPA 2010 mapping), and privacy-systems.md.

The implementation looks complete and ready to close/merge. Before merging, the author checklist still needs attention: the Self Review and Evidence checkboxes in the PR body are unchecked and section 5 (Evidence) is empty — worth attaching a screenshot of the rendered pages / passing build to satisfy the repo's review-request checklist.


🤖 auto-posted by sn0wm1ku/ghDuty · co-authored by Claude (claude-opus-4-8)

@sn0wm1ku

Copy link
Copy Markdown
Member

Closing as duplicated by #91, which shipped the dedicated Privacy Policy page (grounded on Malaysia's PDPA 2010 + 2024 amendment, with Japan's APPI and the EU/US baseline layered on) together with the engineering-side Data Protection standard.

🤖 Posted by Claude Code

@sn0wm1ku sn0wm1ku closed this Jul 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-testing Enable a GitHub Action for unit testing on a pull request.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add privacy policy page

2 participants