8 ms·
>... we have not restricted contractors’ own use or disclosure of that information or data. We are not responsible for the conduct or policies of Stripe, or oth
by computerex 3y ago
>... we have not restricted contractors’ own use or disclosure of that information or data. We are not responsible for the conduct or policies of Stripe, or other contractors.
I mean this seems pretty suspect for anyone privacy focused.
- rusk 3y agoAlso not legal in Europe where you absolutely are responsible for the actions of your processors
- CaptArmchair 3y ago> Section 8.6 GDPR > Part b. omg.lol does not believe its processing of limited personal data of those outside the United States (if any) brings it within the jurisdiction of these laws. That's a hard disclaimer if there's any. I read that as: if you're a European user, we do not believe you can legally enforce us to honor your rights, even though we operate within the EEA.
- ykonstant 3y agoThis is very disappointing, and automatically dismisses omg.lol as an option for me as a researcher and educator.
- jacquesm 3y agoAnd is illegal to boot. If that's their attitude they should not allow Europeans to register in the first place because all it will do is set them up for a confrontation with the various Data Privacy Offices. And such wilful language rules out any apologies.
- CaptArmchair 3y agoMore to the point, the GDPR is quite explicit on here as well: > Article 3.2 goes even further and applies the law to organizations that are not in the EU if two conditions are met: the organization offers goods or services to people in the EU, or the organization monitors their online behavior. (Article 3.3 refers to more unusual scenarios, such as in EU embassies.) https://gdpr.eu/companies-outside-of-europe/ https://gdpr.eu/companies-outside-of-europe/ Which is pretty much what happens given that they allow EU citizens to buy a 20 USD subscription.
- niemandhier 3y agoIf you are affected file a complaint with the DPA. If enough people do it they will act. https://commission.europa.eu/law/law-topic/data-protection/reform/rights-citizens/redress/what-should-i-do-if-i-think-my-personal-data-protection-rights-havent-been-respected_en https://commission.europa.eu/law/law-topic/data-protection/r... If one does not like EU law, one should just not do business here.
- rusk 3y agoWorth a shot I suppose
- hnbad 3y agoThat's also a sovereign citizen level of legalese. It doesn't matter what omg.lol states it believes. If anything, this demonstrates clear intent to violate users' privacy and be non-compliant with international data protection laws. This is largely a moot point as long as omg.lol remains some guy's side project but given that the ToS explicitly mentions the possibility of a merger or buyout, this feels like it's poisoning the well a bit. If there's any upside to this, it's that this makes a buyout far less likely because he's essentially saying "yeah, we collect a ton of personal information but we don't have the legal consent for any of it and explicitly told users we're not complying with their regional data protection laws when it comes to gathering, processing or storing their personal information". Fair enough for the MySpace era of Web 2.0 privacy abuse but no longer workable in a world with the GDPR and its many regional equivalents.
- agos 3y agoyour comment is spot on. an acquisition is also the perfect time to have someone trigger an investigation by the local privacy authority for breach of GDPR and I can tell with reasonable certainty that the wording on that ToS is enough to get fined. Until they have a legal presence in the EU they might get away with it, though.
- cderpz 3y ago>omg.lol does not believe its processing of limited personal data of those outside the United States (if any) brings it within the jurisdiction of these laws. Oh dear. That is definitely not correct. The only way for omg.lol to not fall under the jurisdiction of the GDPR is to not offer their services to people living where it applies.
- amne 3y agoAnd how would the owner go about that? Implement expensive geo-fences and KYC processes for a market they are not interested in? If they (EU people) want to use it .. they should be able to without expecting the same protections as if the business operates in EEA. How did we get here? To where If I spin up a webserver and charge for access now I'm suddenly forced to lick your middle finger because you have laws in your country saying so?
- deleted 3y ago[deleted]
- sverhagen 3y agoI'll include the mandatory ianal, but they could even ask people to indemnify them, or put up a banner saying: you must be in the US, blah-blah. But they're straight up saying: don't care about your laws. That seems untenable.
- Towaway69 3y agoHangon, if go to another country I most certainly have to follow the laws that apply there. If I surf over to another (Internet surfing) country because the server is physically located in that country, I again am forced to follow the laws that apply there. It does seem illogical to have such setup especially since physical I haven't moved. Now it seems that I can take my laws with me when I visit a server in another country. Making everything even more confusing. Unfortunately that does not apply to physically traveling to another country: that country doesn't care two bobs for my countries laws. Edit: INAL.
- 3y ago