This notice describes the project-specific handling of personal data used to record explicit acceptance of the e-dialect Individual Contributor License Agreement (ICLA). It supplements, and does not replace, the notices of GitHub or the hosted service.
e-dialect uses the third-party hosted CLA Assistant service and its GitHub authentication. The service is provided by SAP. Its source repository describes the hosted service, including its use of Microsoft Azure infrastructure in Europe, and provides operational details: https://github.com/cla-assistant/cla-assistant. SAP's CLA Assistant privacy statement is available at https://gist.github.com/CLAassistant/3a73e4cd729c9d0a6e30.
The project-specific signature record may contain:
- the GitHub-authenticated identity and username;
- legal name supplied as the only project-requested text custom field;
- agreement version and revision;
- acceptance date and time and related pull-request identifiers; and
- a separate cross-border-processing confirmation.
e-dialect does not ask a signer to re-enter a GitHub username or supply a current email address as a project custom field. GitHub, CLA Assistant, or SAP may independently process account email, contact, authentication, or technical information under their own notices and service operation; this notice does not claim otherwise.
The information is used to confirm ICLA acceptance, maintain an auditable contribution rights chain, conduct a compliance audit, and handle a related dispute when necessary. Project maintainers may view or export records only for those purposes. Exported records must be access-controlled and available only to authorized maintainers or professional advisers who need them.
e-dialect will not publish a signer's legal name, email address, consent or signature record in a GitHub issue, public spreadsheet, or public back-signature list. Public reports may state aggregate or repository-level coverage without naming individual signers.
Using CLA Assistant may provide or make the signature information available to an overseas service provider. SAP provides CLA Assistant. Current public materials state that hosted signer data is stored on Microsoft Azure infrastructure in Europe, but e-dialect does not promise that all processing or transfers are confined exclusively to the European Union.
The information processed overseas may include the GitHub-authenticated identity and username, legal name, agreement version and revision, signature timestamp, related pull-request identifiers, the separate confirmation record, and information that the hosted service itself processes lawfully or under its privacy statement. The purposes are to confirm CLA acceptance, maintain an auditable contribution rights chain, conduct compliance audits, and handle necessary related disputes. Information about the overseas service provider and its current contact channel is provided in SAP's CLA Assistant privacy statement, including [email protected].
A signer in mainland China will be separately required in the signing flow to confirm this cross-border processing. That confirmation is separate from acceptance of the ICLA and must be affirmative before the configured workflow can complete.
Records should be retained only as long as reasonably necessary to demonstrate the rights associated with accepted contributions and meet applicable legal or audit needs. To request access, correction, or deletion of a project-held export, contact [email protected]. Requests concerning the hosted CLA Assistant service may also be directed as described in SAP's privacy statement.
Deletion or loss of a signature record may prevent the project from verifying the affected contributor's eligibility for future merges or alternative licensing; it does not revoke an open-source license already granted to the public. Beijing Taju Technology Co., Ltd. is responsible for appropriate access control and retention of project-held exports. The public CLA personal-information protection impact assessment records the present lightweight assessment. Professional legal advice should be obtained before personal-data processing materially scales, sensitive personal information is introduced, or the records become material to commercial licensing or dispute handling.
本文说明 e-dialect 为记录个人贡献者许可协议(ICLA)的显式接受而进行的项目侧个人 信息处理。本文是对 GitHub 及托管服务自身告知的补充,并不取代其告知。
e-dialect 使用由 SAP 提供的第三方托管服务 CLA Assistant 及其 GitHub 身份验证。服务当前公开资料说明 其使用位于欧洲的 Microsoft Azure 基础设施;运行信息见 CLA Assistant 源仓库,SAP 的 CLA Assistant 隐私声明 继续适用。
项目侧签署记录可能包含:
- 经 GitHub 验证的身份与用户名;
- 作为项目唯一主动要求的文本自定义字段提供的法定姓名;
- 协议版本与修订;
- 签署日期时间及相关 Pull Request 标识;
- 单独的境外处理确认记录。
e-dialect 不要求签署者再次手填 GitHub 用户名,也不要求将当前邮箱作为项目自定义 字段。GitHub、CLA Assistant 或 SAP 仍可能依其自身告知和服务运行需要,独立处理账户 邮箱、联系方式、身份验证或技术信息;本文不作相反声明。
上述信息仅用于确认 ICLA 接受、维护可审计的贡献权利链、合规审计,以及在必要时处理 相关争议。项目维护者只可为这些目的查看或导出记录;导出副本必须受访问控制,只提供 给确有必要的授权维护者或专业顾问。
e-dialect 不会在 GitHub Issue、公开表格或公开补签名单中披露签署者实名、邮箱、同意 记录或签署记录;公开报告只能披露不识别个人的汇总或仓库级覆盖状态。
使用 CLA Assistant 可能会向境外服务方提供签署信息,或使其可以处理这些信息。CLA Assistant 由 SAP 提供。当前公开资料说明托管签署数据存储在位于欧洲的 Microsoft Azure 基础设施上,但 e-dialect 不承诺所有处理或传输仅限于欧盟境内。
境外处理的信息可能包括经 GitHub 验证的身份和用户名、法定姓名、协议版本与修订、 签署时间、相关 Pull Request 标识、单独确认记录,以及托管服务依法或依其隐私声明 自行处理的信息。处理目的为确认 CLA 接受、维护可审计的贡献权利链、合规审计和必要 的相关争议处理。境外服务方信息及当前公开联系渠道见 SAP 的 CLA Assistant 隐私声明, 包括 [email protected]。
中国境内签署者将在签署流程中被单独要求确认上述境外处理。该确认独立于对 ICLA 的 接受,并须在已配置的签署流程完成前作出肯定确认。
记录只应在证明已接受贡献的权利、满足适用法律或审计需要所合理必要的期限内保留。 申请访问、更正或删除项目持有的导出副本,请联系 [email protected];涉及托管服务的请求也可按 SAP 隐私声明提出。
删除或遗失签署记录可能使项目无法验证该贡献者后续 PR 或替代许可资格,但不会撤销 公众已经取得的开源权利。北京塔聚科技有限责任公司应对项目自行导出的签署记录实施 适当的访问控制与保留管理。公开的 CLA 个人信息保护影响评估记录 记录了当前的轻量评估。当个人信息 处理规模显著扩大、涉及敏感个人信息,或相关记录开始实质支撑商业授权或争议处理时, 应取得专业法律意见。