Privacy Policy
Last Updated: September 5, 2026
New Media Arts Inc ("NMA," "we," "us," or "our") is a small foundation under IRC 501(c)(3).
This Privacy Policy explains how we collect, use, and protect information across our website, our OpenSim virtual world grid ("the Grid"), and our Nextcloud file server, and applies regardless of where you are located, including visitors in the European Economic Area (EEA), the UK, and elsewhere.
This policy covers three groups of people:
- Visitors to our website and;
- Users of our OpenSim grid, including those arriving via hypergrid from other grids and;
- Visitors to our Discord server and;
- Authorized personnel (staff, board members, and volunteers) with Nextcloud logins, or with local user accounts on our grid.
1. Who We Are
Data Controller: New Media Arts Inc
Address:
New Media Arts Inc
2001 Addison Street, Suite 300
Berkeley, CA
94704
United States
Contact: privacy@newmediaarts.org
For visitors from the EEA or the UK, we act as the "data controller" for the purposes described below.
2. Information We Collect
2.1 Website Visitors
We do not use cookies or tracking pixels at this time. Our web server (Apache, self-hosted on our VPS) automatically logs standard technical data for every request, including:
- IP address
- Date/time of access
- Pages requested and referring URL
- Browser/user-agent string
These logs exist for security, abuse prevention, and troubleshooting. They are not cross-referenced with any tracking or advertising service, because we use none.
Future note: if we introduce accessibility preference settings (e.g., font size, contrast mode), these will be stored locally in your browser via cookies or local storage, used only to remember your preference, and this policy will be updated accordingly before that feature launches.
2.2 Nextcloud file server
Publicly shared files: When we deliberately share a file or folder publicly (e.g., a report or resource), anyone with the link can view it through Nextcloud's file viewer without logging in. Standard web server-style access logs (IP address, timestamp) may be recorded for that request in the same way as ordinary website visits, described in §2.1.
Authorized personnel: Staff, board members, and volunteers with Nextcloud accounts have their name, email, and login activity logged for account administration and security. Access to content is restricted using Team Folders and role based access controls, so personnel only see files relevant to their role; the ability to create public share links is limited to a small number of administrative roles.
2.3 OpenSim Grid Users
We provide an OpenSim grid for visitors to interact with some of our projects, including the Arcadia Asylum Asset Archive (AAAA). Access to this grid for the general public is via the hypergrid.
- Visitors from other grids may teleport in; we may log their avatar name, home grid, and avatar UUID, as is standard for the hypergrid protocol.
- Your data is only subject to our privacy policy for the time you are in our grid. We do not continue to collect data after you leave, either through logging out or teleporting to another grid.
Authorized Personnel: We only create local accounts for authorized personnel (staff, AAAA conservators, volunteers). For these members, we collect their avatar name and password (stored in hashed form). The special "god mode" is only granted to grid administrators and select AAAA conservators.
2.4 Discord Server
We maintain a Discord Community Server. Any activity by visitors is stored by Discord according to their policies. Administrators on the server have the usual access to perform security actions such as muting, kicking, and banning accounts. We reserve the right to delete content from our server that violates our rules.
2.4 Information You Provide Directly
If you contact us by email, we collect whatever information you choose to include (e.g., name, email, message content) solely to respond to you.
3. Why We Process This Data (Legal Basis)
These points refer to types of data we collect, and the legal basis under which we collect this data. This legal basis is general in some cases, and in others refers to articles of the General Data Protection Regulation (GDPR).
- Mandatory IRS public disclosures (see §6): Legal obligation (Art. 6(1)(c))
- Server/security logs: Legitimate interest (Art. 6(1)(f)) — maintaining site security and integrity.
- Nextcloud account management: Legitimate interest / contractual necessity (staff & volunteer administration).
- OpenSim account & session data: Legitimate interest — grid security and service delivery
- Responding to inquiries: Legitimate interest / consent, as applicable
4. Hosting, Security & Data Processors
Our website and Grid are hosted on infrastructure managed by a third-party VPS provider, Contabo GmbH. We have a Data Processing Agreement (DPA) in place with this host consistent with Article 28 GDPR, requiring them to process data only on our documented instructions and to implement appropriate technical and organizational security measures.
We do not sell, rent, or share personal data with advertisers or data brokers. We do not use third-party analytics or advertising cookies.
5. International Data Transfers
Our online content is accessible worldwide, and our infrastructure is hosted by Contabo GmbH, in their United States West data center, located in Seattle, Washington. Your data will be processed in this data center.
Where this involves transfers out of the EEA/UK, we rely on our host's contractual safeguards (including the DPA referenced above) to ensure an adequate level of protection.
6. Mandatory Public Disclosures
(Nonprofit Transparency)
As a 501(c)(3) organization, U.S. law requires certain documents to be made publicly available upon request or disclosure, including our Form 1023 application, IRS Determination Letter, and Form 990/990-PF filings. These filings name our board members as a matter of federal law. This disclosure is a legal obligation independent of consent, and it cannot be opted out of or erased upon request, since it reflects public record requirements imposed on nonprofit organizations.
These disclosures can be accessed from our IRS Disclosures page.
7. Data Retention
- Server logs: retained for 6 months, then deleted or anonymized.
- Nextcloud accounts: retained for the duration of an individual's role with NMA; deactivated and removed within 30 days of offboarding.
- OpenSim accounts: retained until the user requests deletion.
- IRS-mandated disclosures: retained indefinitely, per federal recordkeeping requirements.
8. Your Rights
If you are located in the EEA, UK, or a jurisdiction with similar protections, you have the right to:
- Request the personal data we hold about you.
- Rectify inaccurate data
- Erase your data ("right to be forgotten"), except where retention is legally required (see §6)
- Restrict or object to certain processing
- Data portability, where technically applicable
- Lodge a complaint with your local data protection supervisory authority
To exercise these rights, contact us at privacy@newmediaarts.org. We will respond within the timeframes required by applicable law.
9. Children's Privacy
Our website, Grid, and Nextcloud services are not directed at children under 13 (or 16, where applicable local law requires), and we do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this policy as our practices evolve (for example, if we introduce cookies for accessibility preferences). Material changes will be noted with a revised "Last Updated" date at the top of this page.
11. Contact Us
Questions about this policy or your data can be directed to:
New Media Arts Inc
2001 Addison Street, Suite 300
Berkeley, CA
94704
United States