Privacy Policy
Effective Date: 01.08.2025
Last Updated: 01.08.2025
Version: 2.0
1. Introduction and Scope
Welcome to Reliability Board Community ("we," "our," "us," or "the Company"). This Privacy Policy describes how we collect, use, process, store, and protect your personal information when you use our platform, website, and services (collectively, the "Service").
This Privacy Policy applies to all users of the Reliability Board Community platform, including registered users, visitors, and anyone who interacts with our services. By using our Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
This policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
2. Data Controller Information
Data Controller: Reliability Board Community
Address: United Kingdom
Email: hello@reliabilityboard.com
Data Protection Officer: hello@reliabilityboard.com
For the purposes of GDPR, Reliability Board Community is the data controller responsible for your personal data.
3. Types of Personal Data We Collect
3.1 Personal Identification Information
- Account Information: Name, surname, email address, username, password (encrypted)
- Profile Information: Professional title, company, industry, years of experience, certifications
- Contact Information: Address, country, postcode, phone number (optional)
- Professional Details: Job title, industry sector, maintenance discipline, years of experience
- Certifications: Professional certifications, training records, qualification documents
3.2 Technical and Machine Data
- Machine Information: Machine names, types, specifications, operational parameters
- Sensor Data: Vibration readings, acceleration data, velocity measurements, acoustic data, magnetic flux readings
- Diagnostic Data: Analysis results, predictions, fault diagnoses, severity assessments
- Media Files: Machine photos, diagnostic images, uploaded documents, certificates
- Data Files: CSV files, graph images, digitized data, analysis reports
3.3 Community and Social Data
- Social Content: Posts, comments, discussions, knowledge articles, job postings
- Professional Network: Friend connections, mentorship relationships, professional contacts
- Communication Data: Private messages, conversation history, file attachments
- Engagement Data: Likes, shares, follows, board memberships, event participation
3.4 Usage and Technical Data
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Analytics: Pages visited, features used, time spent, interaction patterns
- Performance Data: Competition results, prediction accuracy, points earned, rankings
- Technical Logs: Error reports, system logs, security events, access timestamps
3.5 Special Categories of Data
We may process the following special categories of personal data with your explicit consent:
- Professional Certifications: Industry-specific qualifications and training records
- Biometric Data: Only in the context of machine vibration analysis (not human biometrics)
- Location Data: Only for event management and professional networking purposes
4. How We Collect Your Data
4.1 Data You Provide Directly
- Account registration and profile creation
- Machine data uploads and sensor readings
- Social posts, comments, and community contributions
- Job postings and event announcements
- Private messages and communications
- Feedback and support requests
4.2 Data Collected Automatically
- Usage analytics and platform interactions
- Technical logs and system performance data
- Competition participation and scoring data
- Network connections and social interactions
- Device and browser information
4.3 Data from Third Parties
- Invitations from existing community members
- Professional networking connections
- Event registrations and participation
- Certification verification (with consent)
5. Legal Basis for Processing Personal Data
We process your personal data based on the following legal grounds under GDPR:
5.1 Consent (Article 6(1)(a) GDPR)
- Marketing communications and promotional activities
- Data sharing with third parties for research purposes
- Processing of special categories of data
- Use of cookies and tracking technologies
- Participation in competitions and tournaments
5.2 Contract Performance (Article 6(1)(b) GDPR)
- Account creation and platform access
- Provision of core platform services
- Processing payments and transactions
- Fulfillment of user agreements and terms of service
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
- Platform security and fraud prevention
- Service improvement and development
- Community moderation and content management
- Analytics and performance monitoring
- Professional networking and community building
5.4 Legal Obligations (Article 6(1)(c) GDPR)
- Compliance with applicable laws and regulations
- Response to legal requests and court orders
- Tax and accounting requirements
- Data protection and privacy law compliance
6. Purposes of Data Processing
6.1 Core Platform Services
- Account management and user authentication
- Machine data storage, analysis, and visualization
- Prediction competitions and scoring systems
- Social networking and professional connections
- Knowledge sharing and community discussions
6.2 Community Features
- Mentorship program facilitation
- Job board and career opportunities
- Event management and professional development
- Discussion boards and knowledge hubs
- Private messaging and communication tools
6.3 Analytics and Improvement
- Platform performance monitoring and optimization
- User experience improvement and feature development
- Community engagement analysis
- Research and industry insights generation
- Machine learning model development and training
6.4 Security and Compliance
- Fraud detection and prevention
- Content moderation and community safety
- Legal compliance and regulatory reporting
- Data backup and disaster recovery
- Security incident response and investigation
7. Data Sharing and Third-Party Disclosures
7.1 Data Sharing Within the Platform
- Public Sharing: When you choose to share machines or data publicly, it becomes visible to all community members
- Friend Sharing: Data shared with friends is visible to your connected professional network
- Community Features: Social posts, knowledge articles, and discussions are visible to the community
- Competitions: Prediction results and scores may be visible to other participants
7.2 Service Providers and Processors
We may share data with the following categories of service providers:
- Cloud Infrastructure: AWS, Azure, or similar cloud hosting services
- Analytics Services: Google Analytics, Mixpanel, or similar analytics tools
- Email Services: Email delivery and marketing automation services
- Payment Processors: Stripe, PayPal, or similar payment services
- Security Services: Fraud detection, DDoS protection, and security monitoring
7.3 Research and Industry Partners
- Anonymized data may be shared with research institutions and industry partners
- Aggregated insights and trends may be published for industry benefit
- Machine learning models may be developed using anonymized community data
- All research sharing is done with appropriate safeguards and anonymization
7.4 Legal and Regulatory Disclosures
- Compliance with court orders, subpoenas, or legal requests
- Response to government investigations or regulatory inquiries
- Protection of rights, property, or safety of users or the public
- Enforcement of our Terms of Service or other agreements
8. Data Retention and Deletion
8.1 Retention Periods
- Account Data: Retained while account is active, anonymized upon deletion
- Machine Data: Retained indefinitely for community benefit and competition integrity
- Social Content: Retained while relevant, may be anonymized upon user deletion
- Technical Logs: Retained for 12 months for security and debugging purposes
- Backup Data: Retained for up to 6 months for operational continuity
8.2 Anonymization Policy
Important: If a user or a machine or data is deleted, it will not be hard delete, but everything will be anonymized. Because tournaments, tests, points, etc. are performed based on these data.
- Tournaments and competitions rely on historical data for integrity
- Community statistics and leaderboards require persistent data
- Research and analytics depend on comprehensive datasets
- Platform features and machine learning models require training data
- Points systems and scoring algorithms depend on historical performance data
- Community knowledge and expertise is preserved for future users
8.3 Deletion Requests
- Users may request account deactivation and data anonymization
- Personal identifying information will be removed during anonymization
- Community contributions will be preserved in anonymized form
- Complete data removal is not possible due to platform dependencies
9. Your Data Protection Rights
Under GDPR and other applicable data protection laws, you have the following rights:
9.1 Right of Access (Article 15 GDPR)
- Request confirmation of whether we process your personal data
- Obtain a copy of your personal data in a structured, machine-readable format
- Receive information about the purposes, categories, and recipients of your data
- Learn about the retention period and your rights
9.2 Right to Rectification (Article 16 GDPR)
- Request correction of inaccurate personal data
- Request completion of incomplete personal data
- Update your profile information and preferences
9.3 Right to Erasure (Article 17 GDPR)
- Request deletion of your personal data in certain circumstances
- Note: Complete deletion is not possible due to platform dependencies
- Data will be anonymized instead of permanently deleted
9.4 Right to Restrict Processing (Article 18 GDPR)
- Request limitation of data processing in certain circumstances
- Temporarily suspend data processing while disputes are resolved
9.5 Right to Data Portability (Article 20 GDPR)
- Receive your personal data in a structured, commonly used format
- Transmit your data to another controller
- Export your profile information and contributions
9.6 Right to Object (Article 21 GDPR)
- Object to processing based on legitimate interests
- Object to direct marketing communications
- Object to automated decision-making and profiling
9.7 Right to Withdraw Consent
- Withdraw consent for data processing at any time
- Withdrawal does not affect the lawfulness of processing before withdrawal
- May impact certain platform features that require consent
9.8 Right to Lodge a Complaint
- File a complaint with your local data protection authority
- Contact us first to resolve any privacy concerns
- We will respond to complaints within 30 days
10. Data Security Measures
10.1 Technical Security
- Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Role-based access control and multi-factor authentication
- Network Security: Firewalls, intrusion detection, and DDoS protection
- Data Backup: Regular encrypted backups with disaster recovery procedures
- Security Monitoring: 24/7 security monitoring and incident response
10.2 Organizational Security
- Employee Training: Regular privacy and security training for staff
- Data Protection Officer: Dedicated DPO for privacy compliance
- Incident Response: Documented procedures for security incidents
- Vendor Management: Security assessments of third-party providers
11. International Data Transfers
11.1 Cross-Border Transfers
Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards are in place:
- EU-US Transfers: Use of Standard Contractual Clauses (SCCs)
- Adequacy Decisions: Transfers to countries with adequate data protection
- Certification Schemes: Privacy Shield or similar certification where applicable
- Binding Corporate Rules: Internal policies for multinational operations
11.2 Data Localization
- Primary data storage in the European Economic Area (EEA)
- Backup and disaster recovery may involve international transfers
- CDN and performance optimization may use global servers
- All transfers comply with applicable data protection laws
12. Cookies and Tracking Technologies
12.1 Types of Cookies We Use
- Essential Cookies: Required for platform functionality and security
- Performance Cookies: Analytics and performance monitoring
- Functional Cookies: User preferences and settings
- Marketing Cookies: Advertising and promotional content (with consent)
12.2 Cookie Management
- Cookie consent banner for non-essential cookies
- Browser settings can be used to control cookie preferences
- Cookie policy available in footer with detailed information
- Regular review and update of cookie usage
13. Automated Decision-Making and Profiling
13.1 Prediction Systems
- Machine learning models for failure prediction and analysis
- Automated scoring systems for competitions and tournaments
- Recommendation engines for content and connections
- All automated decisions are subject to human review and appeal
13.2 Your Rights Regarding Automated Decisions
- Right to request human review of automated decisions
- Right to contest automated decisions and request explanation
- Right to opt-out of certain automated processing
- Transparency about how automated systems work
14. Children's Privacy
Our platform is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete such information promptly.
15. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant data protection authority within 72 hours
- Notify affected users without undue delay
- Provide information about the breach and mitigation measures
- Take immediate steps to contain and remediate the breach
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify users via email or in-app notification for material changes
- Provide advance notice for significant changes affecting user rights
- Obtain consent for changes that require it under applicable law
17. Contact Information and Complaints
17.1 Data Protection Officer
For privacy-related inquiries, data subject requests, or complaints:
Data Protection Officer
Reliability Board Community
Email: hello@reliabilityboard.com
Address: United Kingdom
Response Time: Within 30 days for data subject requests
17.2 Supervisory Authority
You have the right to lodge a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ICO)
- EU: Your local EU data protection authority
- Other Jurisdictions: Relevant local privacy regulator
18. Platform-Specific Privacy Information
18.1 Machine Data Privacy
- Machine data may be shared publicly when you choose to share with the community
- Data is anonymized for research and analytics purposes
- You control sharing settings for each machine and dataset
- Historical data is preserved for competition and research integrity
18.1.1 Public Sharing of Machine Data
Important: If a machine with data is shared with community, it will be available to all community members. This means data and machine is public.
- When you choose to share a machine publicly, it becomes visible to all community members
- Public sharing makes both the machine information and associated data publicly accessible
- Once shared publicly, data cannot be made private again
- Public data contributes to community knowledge and research
- Users should carefully consider the implications before sharing data publicly
18.2 Community Features Privacy
- Social posts and discussions are visible to the community
- Private messaging is encrypted and secure
- Professional connections are visible to your network
- Event participation may be visible to other attendees
18.3 Competition and Scoring Privacy
- Competition results and rankings are publicly visible
- Individual predictions may be shared for learning purposes
- Scoring algorithms are transparent and documented
- Performance data contributes to community analytics
18.3.1 Points System and Algorithm Transparency
Important: Earning and losing points are performed based on documented algorithms. Management will perform best effort to make this process with fairness. Contact with us if there is any bug. Reliability Board developers and managers are not responsible with wrong calculations.
- Points are awarded based on transparent, documented algorithms
- Management makes best efforts to ensure fairness in the scoring process
- Users should report any suspected bugs or errors in the scoring system
- No compensation will be provided for points lost due to system errors or algorithm bugs
- Scoring algorithms may be updated to maintain fairness and accuracy
18.3.2 Failure Predictions and Expert Opinions
Important: Failure predictions for machine data are mainly selected and confirmed by community members. Experts in the community are making their best for the predictions to be as good as possible. But eventually these are just predictions and even different experts have different opinions. Community developers and management is not responsible for wrong predictions.
- Predictions are made by community experts, not by the platform itself
- Different experts may have different interpretations of the same data
- Predictions are not guaranteed to be accurate and should not be solely relied upon
- Platform developers and management are not liable for incorrect predictions
- Users should always verify predictions with qualified professionals
19. Glossary of Terms
- Data Controller: The entity responsible for determining the purposes and means of processing personal data
- Data Processor: The entity that processes personal data on behalf of the controller
- Personal Data: Any information relating to an identified or identifiable natural person
- Special Categories: Sensitive personal data requiring enhanced protection
- Anonymization: Process of removing identifying information from data
- Pseudonymization: Process of replacing identifying information with pseudonyms