Privacy and cookies
What this site stores, where it goes, and how to have it removed.
Last updated 5 September 2026
1. Who we are
This site is the petition to free Bogdan Syrotiuk. It is operated by World Socialist Web Site, Inc., which is the data controller for the petition and for the processing it determines through this site. Addresses for writing to us, our Data Protection Officer, and our representatives in the European Union and the United Kingdom are at the end of this page.
Our email is signed Committee to Free Bogdan Syrotiuk, which is what the campaign calls itself and how you will have met it. Where this page says “the committee”, that is who it means. World Socialist Web Site, Inc. is still the data controller, and answers for everything here either way.
2. What we collect
To sign the petition, we ask for your name, email address, country and visibility choice. Everything else is optional.
We also store a salted hash of your IP address alongside what you agreed to. We do not store the address itself, and the hash cannot be turned back into one.
Our own mailing system. Your name, email address, country, city and phone are copied into the mailing system we run ourselves for every signature, not only if you ask for updates. It is how the campaign sends anything at all, including the confirmation email you asked for. Ticking the update boxes does not change what is held there, only which tags are put on it and therefore what you are sent. If you write a statement, its text is copied there too, and replaced or removed when you change or withdraw it. If you do receive campaign updates, it also records whether you opened each one and which links you clicked in it. See section 8.
If you do more than sign, we hold what you sent us.
A record of changes. Every time a signature is created, changed or removed we write one line saying which record it was, which fields moved, and when. It keeps no values: not your name, not your address, not a word of what you wrote. The exception is a short list of switches that carry nothing personal, such as whether a statement was approved and whether a name is published. It exists so that if somebody broke into an account we could say what they touched, which is the one question a stolen password makes urgent. It survives the deletion in section 11, holding a reference to a record that no longer has your details in it. Section 10 says how long we keep it.
Signatures gathered before this site. The petition ran on change.org first, and those signatures are counted here alongside the ones made on this site. They are held as private: counted, never listed. The only names shown from that group belong to people who posted a public statement with their signature at the time. If you signed then and want your record changed or removed, write to us at freebogdan@wsws.org.
3. Why we process your data and our legal bases
Different uses of your data have different purposes and legal bases.
Signing the petition and managing your signature. We process the information needed to record and manage your signature on the basis of your explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR. Signing a political petition can reveal a political opinion, which the GDPR treats as special category data. This is also the basis for the copy held in the mailing system we run ourselves, described in section 2. That copy is made for every signature, whether or not you ask for campaign updates, because it is how the record of your signature reaches you: it is part of recording and managing the signature rather than a purpose of its own.
Publishing your name or statement. If you choose Public, you deliberately make your name, country and any city you provide publicly available as part of the petition. We process this information under Article 6(1)(a) and Article 9(2)(e) GDPR. The same applies if you choose to publish a statement, a letter or a video statement. You can change your visibility choice or remove your statement at any time.
Campaign updates. We send campaign email or text messages only if you separately ask for them, on the basis of your explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR. The same consent covers measuring what happens to those messages — whether you opened one, and which links you clicked in it — which section 8 describes. You can withdraw that consent at any time, and withdrawing it ends the measuring as well as the sending.
Security and abuse prevention. We process limited technical data to keep the site secure, prevent automated or fraudulent submissions, apply rate limits and maintain necessary security logs. We do this on the basis of our legitimate interests under Article 6(1)(f) GDPR.
Analytics. If you allow optional analytics, we use limited information about how the site is used to understand whether the site and signing process work as intended. We do this on the basis of your consent under Article 6(1)(a) GDPR and, where the information may reveal a political opinion, Article 9(2)(a) GDPR. See section 7.
Donations. If you make a donation, we process the information needed to receive and administer it. We do this on the basis of our legitimate interests under Article 6(1)(f) GDPR. We also keep records where required by accounting or tax law under Article 6(1)(c) GDPR.
4. How your name appears, and the safety default
You choose one of three:
What happens if you do not choose. In Australia, New Zealand, Singapore and the United States the default is public: those are the countries the campaign is run from and where most of this list already is. Everywhere else the form asks you to choose, and a signature that still reaches us with no choice made is held private: counted, not listed. Holding your signature and publishing your name are two different things, and we would rather ask than assume the second. It is a default and not a rule, either way, and all three options are open to everyone.
Signatures from Russia, Ukraine and Belarus default to private: counted, not listed, with no country shown. People in those countries have been arrested and imprisoned for opposing the war, Bogdan Syrotiuk among them, and a name given publicly can be used against the person who gave it. The default is applied on our server rather than in your browser, so it holds even if scripts fail to load. It is a default and not a rule: if you are in one of those countries and want your name published, you can choose that, and we will honor it.
Your email address and phone number are never published, whatever visibility you choose. Statements are read by a moderator before they appear.
You can change any of this at any time in your signature portal, without asking us.
5. Who else handles your data
We use the following service providers and systems. The table shows what data each service receives or processes for this site.
Our mailing system is not on this list because it is not somebody else’s. We run it ourselves, so what it holds is described in section 2 as data we hold rather than data we hand to a company.
We do not sell your personal data or share it with advertisers. Each service above says which role it holds. The ones acting as our processors may use subprocessors of their own under their data-processing terms, and the list of those is linked on each row. Separately from any of that, we may disclose information where the law requires it of us.
The primary database is hosted in the United States. Transfers from the EEA are protected as described in section 9.
6. Cookies
Ours are these, and each holds a random value or your own choice rather than anything about you.
Stripe sets its own cookies for payment security, and only when the donation form is opened. Nothing from Stripe loads until you begin a donation. Stripe publishes the two it uses to judge whether a payment is fraud: __stripe_mid, which it keeps for a year, and __stripe_sid, which it keeps for 30 minutes. Its cookie settings page is where those durations come from.
Cloudflare Turnstile runs on our forms to tell people apart from automated programs. Cloudflare’s Turnstile Privacy Addendum explains what it collects. It does not say how long anything is kept, and neither does Cloudflare’s general policy, so we cannot give you a figure for Turnstile the way we can for the other two. We would rather say that than print a number we cannot stand behind.
PostHog sets one analytics cookie, and only if you allow it. Nothing analytics-related is fetched or run before you do. The cookie is named ph_ followed by our project code, and PostHog publishes it as lasting a year. Switch analytics off and it is deleted.
YouTube, on the donation page. The appeal video there is a picture with a play button on it, and nothing more until you press it. The picture is served from this site, so loading the page asks YouTube and Google for nothing and tells them nothing. Pressing play is what opens the video, from youtube-nocookie.com, YouTube’s privacy-enhanced player, and that is the moment YouTube sets its own cookies and learns your address. Google publishes two of them: YSC, which lasts as long as the visit, and VISITOR_INFO1_LIVE, which it keeps for 180 days. There may be more than two, and we would rather say so than print a list we cannot stand behind; Google’s cookie list is where it describes them. Closing the video does not take them off your machine again; your browser’s own settings do. If you never press play, none of this happens.
Cookies set by wsws.org. This site is part of wsws.org. Cookies that the main site sets are sent to this one as well, including its Google Analytics and Matomo cookies. We do not use them, read them, or send anything to Google or Matomo from this site. They are covered by the World Socialist Web Site’s own privacy statement.
7. Analytics
We use PostHog, hosted in the European Union, to understand how the site is used: which pages people read, where they leave, and whether the sign form works.
It runs only if you allow it. Nothing is measured before you choose, and you can change your mind at any time from the Cookies link in the footer.
We do not record your screen or what you type. Session recording is switched off and will stay off.
How long it is kept. Seven years.
8. Email
There are four kinds, and they follow different rules.
The first three carry no tracking. The record of your signature, the sign-in link and the confirmation request do not record whether you opened them or which links you clicked, and they do not rewrite their links, so the address you see is the address you go to. On the sign-in link we can show it: open tracking, link rewriting and the subscription footer are all switched off in the request that sends it.
Campaign updates do record whether you opened the message and which links you clicked in it. That happens in the mailing system we run ourselves rather than at another company, and it is how the campaign can tell whether an update was read and which parts of it people followed. It applies to campaign updates and to nothing else. You are sent them only if you asked for them and confirmed, every one carries an unsubscribe link, and unsubscribing takes effect immediately.
9. Sending data outside Europe
Some of the providers described above process personal data in the United States. For transfers from the European Economic Area, we rely on the EU-US Data Privacy Framework where the recipient is certified under it. Where that framework does not apply, we use the European Commission’s Standard Contractual Clauses under Article 46 GDPR or another legally recognized safeguard. You may contact us for information about the safeguard used for a particular provider and, where applicable, for a copy of the relevant clauses.
10. How long we keep things
What happens when the campaign ends. Everything here is held for one purpose: the campaign for Bogdan Syrotiuk’s release. When that purpose ends, most of this has no reason to exist and will not be kept.
The campaign ends when the Committee to Free Bogdan Syrotiuk says publicly that it has, and this section starts running from that announcement. Within twelve months of it, we delete every email address, phone number and city, and remove every name from the public list. What survives is the count of how many people signed and from which countries, which names nobody, and the statements and letters people deliberately published. Those stay part of the public record of the case, and you can still ask us to take yours down.
None of this waits for the campaign to end. You can delete your petition record at any time, today, from your signature portal. Section 11 sets out what that covers, and what survives it.
11. Your rights, and how to use them
Every signature has a signature portal, a page of your own where you can see and manage the petition data we hold about you. You can do all of the following there yourself, immediately, at your signature portal. Getting in takes a link we email you, so there is no password to remember or lose.
What deletion actually does. It removes your signature, your statement, any letter or video you sent, everything queued to be sent about you, and your contact in the mailing system, and it asks Stripe to redact your donor details. A donation stays on file as an amount and a date with nothing attached to it, because the campaign has to account for money it received. The record of changes described in section 2 also survives, holding a reference to a record that no longer has your details in it.
If you would prefer us to make these changes for you, or you no longer have access to the email address you signed with, write to freebogdan@wsws.org. If we have reasonable doubts about your identity, we may ask for additional information reasonably necessary to confirm that the request relates to your signature.
You also have the right, where applicable, to restrict processing, object to processing based on legitimate interests, and receive data you provided in a portable format. The portal covers seeing, changing, downloading and deleting; for the others, write to the address above. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
12. If you are in the United States
Where a state privacy law applies to us, residents of that state have rights to see, correct and delete their data, and to opt out of its sale or sharing. You can exercise all of those in your signature portal or by writing to us, wherever you live. We do not ask which state you are in before honoring a request.
We do not sell personal information, share it for targeted advertising, or use it for targeted advertising.
We honor the Global Privacy Control signal. If your browser sends it, we treat that as an instruction to switch off anything non-essential, and we do not ask you again.
13. Complaints
If you think we have handled your data wrongly, you are welcome to tell us first at freebogdan@wsws.org. Most things are quicker to fix directly.
You also have the right to complain to a data protection authority. In the EU that is the authority where you live, where you work, or where the problem happened. In the UK it is the Information Commissioner’s Office.
14. Changes to this policy
When we change something material we will say so on this page.
15. How this sits alongside the WSWS policy
This policy covers processing specific to the petition at freebogdan.wsws.org. The World Socialist Web Site’s general privacy statement covers other processing on wsws.org and the existing wsws.org cookies referred to in section 6.
16. How to contact us
About your signature, or anything to do with this campaign. Changing how your name appears, deleting your record, or a question about the petition: freebogdan@wsws.org
Our Data Protection Officer, for anything about data protection generally, or to make a formal request or complaint. This is our own accountability role under Article 37 of the GDPR, and it is not the same thing as the two representatives below:
Andrew Petrov, Data Protection Officer
World Socialist Web Site, Inc.
PO Box 48377
Oak Park, MI 48237
United States
comments@wsws.org
Our representatives under Article 27. We are established outside the European Union and the United Kingdom, so we appoint a representative in each. A representative is a point of contact, in particular for the supervisory authority of that territory, and you may contact the one for where you are instead of contacting us. Article 27 requires each representative to be established in the territory they represent, so these are two separate appointments and one person cannot hold both.
European Union representative, appointed under Article 27 of the EU GDPR:
Christoph Vandreier
c/o SGP
Neuenburgerstr. 13
10969 Berlin
Germany
free-bogdan@gleichheit.de
United Kingdom representative, appointed under Article 27 of the UK GDPR:
Richard Turner
Socialist Equality Party
Suite 106, 88 Queen Street
Sheffield S1 2FW
United Kingdom
richard.turner@socialistequalityparty.uk