General Data Protection Regulation

The General Data Protection Regulation (GDPR) is a European Union law intended to promote the protection of privacy and personal information. It’s main goal to give users more control over their personal data.

To that end, we have taken steps to make NodeBB compliant with GDPR for any user who wishes to use it. Upon registering for an account, all users will be presented with a page outlining their rights, along with what data is collected. A request for their consent will be presented, and only upon receipt of affirmative consent, will their account be created.

With regards to compliance with GDPR in terms of our hosting service, please contact us at the mail or email addresses below to receive correspondence and documentation regarding our services. Specifically, you can retrieve a copy of our Data Processing Agreement for your records by clicking the following link:

Download NodeBB Data Protection Addendum (DPA)

Please also review our list of subprocessors.

For more information on GDPR and how it affects you (either as a customer or a website host using NodeBB), please see our blog article on GDPR.

Frequently Asked Questions

What types of data is collected and processed by NodeBB?

The complete list of data categories collected and processed by a vanilla NodeBB install can be found in our Data Protection Addendum (DPA), the download link of which is located above. Feel free to contact us for more details regarding our GDPR implementation.

Third-party plugins and themes have the capability to collect additional information, and are thus not covered by the existing DPA. You may wish to contact appropriate plugin authors to verify GDPR compliance.

All users are able to review their list of rights and consent status via the “Your Rights & Consent” page, accessible via the user settings page in NodeBB. Your existing users are able to provide consent here as well.

In order to facilitate receipt of consents for all users, you can elect to download and install the NodeBB GDPR plugin, which will allow you to require users to provide consent upon login, and view a list of users who have not provided consent yet.

Contacting us

If you have any questions about compliance with GDPR and NodeBB, please contact us at:

https://nodebb.org
support@nodebb.org

This document was last updated on March 11, 2025