Privacy notice

What happens to the personal data of those who read the portal and of those who open an account on it.

Data controller

Determines the purposes and means of the processing carried out through this portal:

PCS di Ambrosio Espedito
Via Luigi Maradei 15, 87026 Mormanno (CS), Italia
www.pcsai.it
redazione@example.it

Scientific direction of the content is separate from technical operation of the portal: whoever builds the infrastructure does not answer for scientific merit, and vice versa.

Reading the portal

Reading the portal requires no account and involves no behavioural tracking. These are statements verifiable in the source code, not generic commitments:

  • no web analytics or audience measurement tool is installed;
  • the fonts are served by the application itself: reading a page involves no requests to external domains;
  • neither the browser’s local storage nor its session storage is used;
  • the only cookie set is the session cookie, and only after a login: cookie page.

Entries translated from other people’s works display figures that remain hosted on the source site: to show them the reader’s browser contacts that site directly, which therefore receives their IP address. The portal does not tell it which page was being read. The reason for this choice is explained on the Licences and attribution page.

Opening an account

The registration form asks for:

Identification
first name, last name, email address
Credentials
a password, which is not stored in clear text
Acceptances
terms of service and acknowledgement of this notice, each with its date and time

The email address is used to confirm the account and to send service messages, such as the password reset link. No promotional messages: the portal sends none and keeps no mailing lists.

The form also contains a hidden field that must stay empty: it serves to recognise automated submissions and collects nothing from someone filling the form by hand.

The professional profile

It is optional and concerns only those who wish to propose content: the editorial team must be able to verify that whoever signs an article is who they claim to be. The profile collects profession, institution, optional department, city and country, ORCID identifier, institutional profile URL, a biography and — if declared — the type, number and region of the professional register entry.

The register number is never public: it serves the verification and stays visible to the editorial team alone. The profile asks for no date of birth, no tax code and no health data.

The dates of the actions that make up the verification are stored as well: profile submission, email confirmation, outcome, any reason for refusal or suspension, and who decided.

The verification documents

Anyone requesting professional verification uploads a supporting document. The document is stored in a private space — never in the public media store — and can be downloaded only through an endpoint that checks the identity of the requester; the storage path is exposed by no API.

Alongside the document are recorded its declared type, the original filename, the content type, the size, the upload date, the review outcome with its note, who reviewed it and when, the date until which it must be retained and, if removed, the deletion date.

If the private space is not configured the feature stays closed: an identity document cannot be kept in a public store, and the portal would rather switch verification off than accept it.

IP address and service protection

The IP address of anyone submitting a sensitive request — registration, login, password recovery, a question to the assistant — is used as the key of the counter that limits request frequency. It serves to prevent repeated password guessing and resource exhaustion; it is kept for the duration of the counting window and is not associated with the account or with the editorial records.

The session of a logged-in user is held by a technical cookie that JavaScript cannot read, lasting seven days.

The assistant

When the installation enables it, the portal offers an assistant that answers questions about the published content. The question and the previous messages of the same conversation are sent to an external language-model provider, which processes them to produce the answer. The portal keeps no conversations: neither question nor answer reaches the database.

Anyone who does not want a question to leave the portal can simply not ask it: the assistant is an extra and reading the portal does not depend on it. The identity of the provider belongs in the list of processors, which is among the missing information at the top of this page.

Why this data

  • to allow access to the reserved area and the recovery of credentials;
  • to verify the credentials of those proposing scientific content, which underpins the reliability declared on every article;
  • to publicly attribute authorship of articles, when the author chooses to make their profile public;
  • to protect the service from abusive access and from automated use that would make it unavailable.

The legal basis for each of these purposes is not yet declared: it is among the missing information listed at the top of the page, and must be stated before the notice can be considered complete.

Who else sees the data

The portal does not sell, transfer or exchange personal data. To operate, however, it relies on technical providers — whoever hosts the application, the database, delivers the email, stores the documents, and the language-model provider when the assistant is active — who process data on behalf of the controller.

The named list of those providers, their location and the safeguards for any transfers outside the European Economic Area depend on how the installation is configured: they are among the missing information.

For how long

Every verification document carries a date until which it must be retained, decided case by case at review time. For the other categories — account, professional profile, record of editorial decisions — the retention policy has not yet been set, and it is among the missing information.

The rights of data subjects

Anyone holding an account on this portal may request access to their data, its correction or erasure, the restriction of or objection to its processing, and to receive it in a machine-readable format. They may also lodge a complaint with the competent supervisory authority: in Italy, the Garante per la protezione dei dati personali.

Requests should be addressed to redazione@example.it, the only contact the project has published. Until the data controller is declared, this address is the de facto point of contact but does not amount to a formal one.

How the data is protected

  • the session cookie cannot be read by JavaScript and, in production, travels only over an encrypted connection;
  • verification documents live in a private space and are served by an endpoint that checks who is requesting them;
  • repeatedly failed logins temporarily lock the account, and sensitive requests are rate-limited.

Updates

This page carries no last-updated date because it is not yet a final document: it will carry one once the missing information has been supplied. The rules for reusing content are instead on the Terms page.