Jonathan Haack, doing business as Haack’s Networking (hereafter the “supplier,” “we,” “us”), is committed to protecting the privacy and security of paying clients and of people who use our voluntary community services. This Privacy Policy describes how we collect, store, use, and disclose personal information in connection with paid work under Haack’s Networking Terms of Service and voluntary services such as the PubGLUG instances and their respective terms.
Haack’s Networking is based in New Mexico, United States. Primary infrastructure is co-located at Brown Rice Internet, Taos, New Mexico. Secondary infrastructure is a dedicated host rented from Pebble Host in the United Kingdom. Data on the UK host is stored with that provider in the United Kingdom.
What personal information we collect
There are two categories of data we may hold:
- Customer data – is data held to communicate with you as a purchaser, prospective purchaser, or as a voluntary participant, which we use to perform estimates and projects.
- User data – is data which you or your users provide through systems we host, build, or administer, including voluntary community services.
Either category may contain personal information.
Customer data
May include:
- Name, username, and email address
- Phone number or other contact details you provide
- Notes on your organization’s structure and roles, as needed to do the work
- History of communication with us, including email (our TOS treats email as written notice)
- Recordings or transcripts of meetings, only where participants have agreed
- Data received through payments or other financial transactions (see Financial information)
- Invoices, estimates, and notes we record in order to provide the service
- Technical details you send us for support (logs, configs, hostnames), which may include IP addresses or account identifiers
User data
May include:
- Data entered into applications we host or administer for you, including backups
- Internet connection details in server logs (for example browser signature, IP address, timestamps)
- Where a service is end-to-end encrypted, we store ciphertext and not user keys (e.g., Nextcloud’s E2EE).
- Third party apps or integrations you use, e.g., external storage, APIs, public share points
- Account identifiers on voluntary services such as PubGLUG
- Where a given service is end-to-end encrypted, ciphertext stored on our servers, not the users’ keys.
User data in transit is encrypted using TLS. User data at rest on systems we control is protected with full-disk encryption (FDE). We do not control every application we install or support; we cannot guarantee that no staff member can ever access application-level data when administration requires it. Holding user data is a responsibility and protecting its integrity and privacy is part of the work.
How we use personal information
- Billing and invoicing
- Customer support and project delivery
- Confirmation of identity where needed to grant access
- Notice of changes to services, estimates, or this policy
- Configuring accounts for access to systems we operate
- Internal record-keeping and capacity planning
If the purpose of collection changes in a material way, we will update this policy and notify paying customers via email and voluntary users will be notified via Mastodon and/or Delta Chat. It is the paying clients’ and/or voluntary users’ responsibility to stay apprised of these changes.
Monitoring and analytics
If we run analytics on our own marketing sites, we prefer self-hosted tools under our control (e.g., Matomo). Those tools may record page views, approximate unique visitors, time on page, and entry/exit paths, used to size infrastructure and decide what to publish. We do not sell that data, nor release or publish it.
We do not sell, rent, or trade personal information. The only exceptions to this are:
- To provide the agreed service (for example a registrar, upstream host, or payment processor you authorized by paying an invoice)
- With contractors or volunteers working under confidentiality consistent with the Haack’s Networking TOS and/or the PubGLUG’s varying terms and this Privacy Policy
- When required by applicable US federal law and/or New Mexico law
- When required by UK law, to the extent is applies to systems hosted in the United Kingdom
Links to other websites
This policy covers sites we operate for Haack’s Networking. It does not automatically cover customer sites we host, or third-party sites linked from ours. Read those sites’ own policies.
Cookies and similar techniques
Our sites and hosted applications may use cookies or equivalent storage to keep a session, remember a login, or apply security controls. That is ordinary web practice, not marketing surveillance. Transactional email we send may include standard delivery logs (bounce, accept).
Financial information
Hardware, labor, and project payments are described in the TOS. If you pay by card, the processor (Stripe) has its own privacy policy. We do not store full card numbers, CVVs, or bank account numbers on our systems when our processor (Stripe) handles the charge. Access to financial records we do keep (invoices, amounts, purchaser identity) is limited to people who need them to bill, account, or comply with tax and record-retention rules.
Where we store personal information
Primary production systems are at Brown Rice Internet in Taos, New Mexico. Secondary systems are on a dedicated host at Pebble Host in the United Kingdom. Financial and project records may also live in ordinary US business tools (email, bookkeeping) that we use to run the company. We do not promise that no packet or backup ever leaves those sites.
How long we hold personal information
We keep information only as long as needed for the purpose collected, except:
- Invoices, business records, and confidential project information are retained for five years past the estimate/project date
- Voluntary service records for the PubGLUG are retained for five years past the sign-up and/or beginning of the utilization of the service
- Tax, company, and financial documents may require longer retention in specific situations
When information is no longer required and no legal hold applies, we delete or irreversibly destroy the information.
Access, correction, and deletion
You may request access to customer data we hold about you, or ask us to update, correct, or delete it, by emailing the contact below.
We will respond within a reasonable time. We may refuse or limit a request when:
- Deletion would break the five-year record obligation in the TOS or other law
- We cannot authenticate that you are the person concerned
- The data is needed to complete a project, invoice a balance, or defend a dispute
- The service or instance does not contain the information the voluntary user believes it does
- The paid offering or contract does not include the information the customer believes it does
If we refuse, we will say why. This is a policy commitment. It is not a claim that every CCPA, GDPR, HIPAA, FERPA, and/or other statutory right(s) apply/applies to every request.
When we may disclose personal information
We will not publish, sell, trade, or rent personal information except as this policy and the TOS allow.
We may disclose information:
- To contractors and processors who need it to perform the work, under confidentiality
- If we reasonably believe disclosure is required by a valid US or New Mexico legal process
- If we reasonably believe disclosure is necessary to prevent or lessen a serious and imminent threat to someone’s life or safety
- In connection with a good-faith legal claim, including the collection remedies in any of our published terms
New Mexico’s Data Breach Notification Act requires notice to affected New Mexico residents when unencrypted personal identifying information is acquired in a security breach, subject to the statute’s definitions and timing. We will follow that law if it applies. Paying clients will be notified via email when notice is required and voluntary users will be notified via Mastodon and/or Delta Chat.
Changes to this policy
We may change this policy. Continued use of our sites and/or services after a posted change is acceptance of the change. If you do not agree, stop using the services and contact us. Material changes that affect an active project will also be handled under the terms’ amendment rules where those rules apply.
Contact
Questions and/or Inquiries: webmaster@haacksnetworking.org
If you are not satisfied
If you are not satisfied with our response:
- First, email us in good-faith negotiation; most issues can resolved by communicating. If you communicate enough, you are in danger of actually communicating.
- If you are not satisfied with good-faith communications and/or serving process and/or want to begin good-faith legal discussions, contact our counsel: Fuqua Law & Policy.
- For a suspected New Mexico data breach or unfair practice, you may also contact the New Mexico Attorney General.
This policy does not create rights beyond those already provided by applicable US and New Mexico law and by our various terms.
Attribution
This Privacy Policy used Isaac Freeman and Magnificent’s Privacy Policy (CC-BY-SA) as a jumping off point.
Terms of Service
Updated
09-13-26 – First major draft released publicly