Privacy
What the site stores about you, why, and for how long.
Maintainers: this describes what the software actually does. Before launch, confirm it against your deployment — reverse proxy logs in particular are outside the application — have it reviewed by the university's data protection officer, and fill in the placeholders.
The short version
You can use most of this site without an account and without being identified. No analytics, no advertising, no third-party requests: browsing a record page contacts this server and nothing else.
If you do not have an account
Reading, searching and downloading need no account. The web server records ordinary access logs — request time, path, status, user agent — for operational purposes such as diagnosing faults and detecting abuse. [RETENTION PERIOD].
If you have an account
Stored: your e-mail address, an optional display name and affiliation, your password as a salted hash (never in plain text), your group memberships, and the account's creation date.
Purpose: authenticating you, attributing deposits to you, and contacting you about data you have deposited. Legal basis: performance of the service you asked for, and our legitimate interest in maintaining a research resource.
Sign-in cookie. One cookie, holding your account id, signed so it cannot be tampered with. It is not used for tracking, and there is no other cookie.
API tokens
Stored: a label you choose, a public prefix, a hash of the secret, the scopes, the creation date and the date of last use. The secret itself is never stored in a recoverable form. Last-use dates exist so you can tell which token to revoke.
Legacy authentication logging
When a client authenticates with a username and password over the older API endpoints, we record that it happened: a timestamp, the username presented, the endpoint, and whether it succeeded. The password is never logged.
This exists for one purpose — to know whether the legacy authentication path is still in use before proposing a date to switch it off, so that the decision is based on a number rather than a guess. [RETENTION PERIOD].
What you deposit is public
Records you deposit are published under the licence you choose, along with the fact that you deposited them. That is the point of depositing. Consider what you attach to a record before you attach it.
What we do not do
- No third-party analytics, tag managers, or advertising.
- No fonts, scripts or stylesheets loaded from external hosts. The optional structure viewer, where enabled, is served from this domain.
- No sale or transfer of personal data.
- No profiling, and no automated decisions about you.
Your rights
Under the GDPR you may request access to your personal data, its correction or erasure, restriction of processing, portability, and you may object to processing. Deleting an account does not withdraw records already published under an open licence, and cannot — but the deposit can be dissociated from your account.
To exercise any of this, or to complain: [EMAIL]. You may also complain to [SUPERVISORY AUTHORITY].
Data controller: [ORGANISATION], [ADDRESS]. Data protection officer: [EMAIL].