Privacy

What the site stores about you, why, and for how long.

Maintainers: this describes what the software actually does. Before launch, confirm it against your deployment — reverse proxy logs in particular are outside the application — have it reviewed by the university's data protection officer, and fill in the placeholders.

The short version

You can use most of this site without an account and without being identified. No analytics, no advertising, no third-party requests: browsing a record page contacts this server and nothing else.

If you do not have an account

Reading, searching and downloading need no account. The web server records ordinary access logs — request time, path, status, user agent — for operational purposes such as diagnosing faults and detecting abuse. [RETENTION PERIOD].

If you have an account

Stored: your e-mail address, an optional display name and affiliation, your password as a salted hash (never in plain text), your group memberships, and the account's creation date.

Purpose: authenticating you, attributing deposits to you, and contacting you about data you have deposited. Legal basis: performance of the service you asked for, and our legitimate interest in maintaining a research resource.

Sign-in cookie. One cookie, holding your account id, signed so it cannot be tampered with. It is not used for tracking, and there is no other cookie.

API tokens

Stored: a label you choose, a public prefix, a hash of the secret, the scopes, the creation date and the date of last use. The secret itself is never stored in a recoverable form. Last-use dates exist so you can tell which token to revoke.

Legacy authentication logging

When a client authenticates with a username and password over the older API endpoints, we record that it happened: a timestamp, the username presented, the endpoint, and whether it succeeded. The password is never logged.

This exists for one purpose — to know whether the legacy authentication path is still in use before proposing a date to switch it off, so that the decision is based on a number rather than a guess. [RETENTION PERIOD].

What you deposit is public

Records you deposit are published under the licence you choose, along with the fact that you deposited them. That is the point of depositing. Consider what you attach to a record before you attach it.

What we do not do

Your rights

Under the GDPR you may request access to your personal data, its correction or erasure, restriction of processing, portability, and you may object to processing. Deleting an account does not withdraw records already published under an open licence, and cannot — but the deposit can be dissociated from your account.

To exercise any of this, or to complain: [EMAIL]. You may also complain to [SUPERVISORY AUTHORITY].

Data controller: [ORGANISATION], [ADDRESS]. Data protection officer: [EMAIL].