Privacy Policy

Hed-Core Academic Commons Privacy Policy

Effective Date: June 12, 2026

1. Introduction

The Hed-Core Academic Commons (“the Commons”) is committed to protecting the privacy and personal data of its members. This Privacy Policy explains how we collect, use, store, and safeguard information, and outlines members’ rights regarding their data. By joining or using the Commons, you consent to the practices described here.

2. Information We Collect

We collect only the information necessary to provide services and maintain community integrity:

  • Personal Information: Name, email address, institutional affiliation, membership category.
  • Profile Information: Areas of expertise, interests, and optional biographical details.
  • Usage Data: Activity logs, forum participation, repository uploads, and event attendance.
  • Technical Data: Browser type, device information, and IP address (for security and analytics).

3. How We Use Your Information

Your information is used to:

  • Manage membership accounts and provide access to Commons resources.
  • Facilitate collaboration through forums, working groups, and networking tools.
  • Communicate updates, events, and opportunities relevant to your membership.
  • Improve platform functionality and ensure accessibility.
  • Maintain security and prevent misuse of the Commons.

4. Data Sharing

  • Internal Use: Data is shared only within the Commons for operational purposes.
  • Third Parties: We do not sell or disclose member data to external parties without explicit consent.
  • Legal Compliance: Data may be disclosed if required by law or to protect the rights and safety of the Commons and its members.

5. Data Protection

  • All personal data is stored securely using encryption and access controls.
  • Regular audits are conducted to ensure compliance with international data protection standards.
  • Only authorized staff have access to sensitive information.

6. Member Rights

Members have the right to:

  • Access: Request a copy of the personal data held about them.
  • Correction: Update or amend inaccurate information.
  • Deletion: Request removal of personal data, subject to legal and operational requirements.
  • Restriction: Limit processing of their data under certain circumstances.
  • Portability: Receive their data in a structured, machine‑readable format.

7. Cookies and Tracking

  • The Commons uses cookies to enhance user experience, such as remembering login sessions and preferences.
  • Analytics tools may track usage patterns to improve services.
  • Members can manage cookie preferences through their browser settings.

8. Data Retention

  • Personal data is retained for as long as membership is active.
  • Upon termination, data is archived or deleted in accordance with legal and ethical standards.
  • Research datasets and publications may remain in the repository under open access licensing, unless otherwise specified.

9. International Compliance

The Commons operates globally and complies with relevant data protection laws, including the EU General Data Protection Regulation (GDPR) and other international frameworks.

10. Updates to This Policy

  • This Privacy Policy may be updated periodically to reflect changes in practices or legal requirements.
  • Members will be notified of significant updates.
  • Continued use of the Commons constitutes acceptance of revised policies.

11. Contact

For questions or concerns regarding privacy, members may contact the Commons’ Data Protection Officer via the official support channel.

12. Acceptance

By registering as a member, you acknowledge that you have read, understood, and agreed to this Privacy Policy, along with the Terms of Use, Community Guidelines, Accessibility Statement, and Data Management Policy.

Privacy Policy and Data Governance Statement

Effective Date: June 12, 2026

Platform: Hed-Core Academic Commons

The Independent Academic Commons is committed to protecting the privacy, identity, and intellectual safety of our global scholarly community. This policy explains how we collect, handle, and secure your personal data in compliance with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

  1. Data Controller & Governance Contact
    For the purposes of data protection regulations, the platform infrastructure is managed by the network administrative team. For any data inquiries, erasure requests, or compliance questions, please contact our Data Privacy Liaison via text at: privacy@[yourdomain.com].
  2. Information We Collect and How We Use It
    We limit data collection to the minimum required to verify professional academic credentials and maintain platform security.
    2.1 Information You Provide to Us:
    Account Basics (All Users): Display name, account username, and professional email address.
    Academic Verification Footprints: ORCID iD numbers, external Google Scholar URLs, professional titles, institutional/organizational affiliations, and research fields.
    User-Generated Metadata: Text-based abstracts, citation records, and reference keys linked to your repository uploads.
    2.2 Information Collected Automatically (System Protection):
    Security Logs: IP addresses and basic browser metadata are collected at login. This data is strictly used by our security firewalls (Cloudflare/Akismet) to block malicious traffic, bots, and brute-force attacks from crashing our shared hosting environment.
  3. Data Storage, Security, and Cloud Offloading
    To ensure high performance on our server infrastructure, we use a decentralized data pipeline:
    Database Isolation: Profile information, forum text posts, and membership registries are stored securely in local, optimized MySQL tables on our host.
    Asset Offloading: Any research documents, preprints, or briefs you upload bypass our primary server and are immediately stored in an encrypted external cloud storage bucket.
    No Commercial Data Processing: We do not track your browsing history across the web. We do not use third-party marketing trackers or ad pixels.
  4. Data Retention & The 72-Hour Purge Rule
    Verified Accounts: We store your profile data for as long as your account remains active on the network.
    Unverified/Incomplete Accounts: To keep our databases lean and prevent data hoarding, any registration profile that fails to verify or remains in “Pending” status will be permanently purged from our database after 72 hours.
  5. Your Global Rights (GDPR & CCPA Compliance)
    Regardless of your geographic location, the platform extends the following data protections to all registered scholars:
    The Right to Know / Access: You can request a clear, text-only export of all personal data points currently linked to your WordPress user profile.
    The Right to Correction / Rectification: You can update, change, or clear any custom profile metadata at any time through your account settings dashboard.
    The Right to Erasure (“Right to be Forgotten”): Upon receiving a deletion request from your verified account email, we will permanently purge your database records, forum profiles, and delete your associated repository uploads within 14 business days.
    Non-Discrimination: We do not, and will never, sell or monetize your professional data. Access to all open research tiers remains equal and free.
  6. Third-Party Links & Integrations
    Our network connects directly with trusted academic infrastructure APIs, such as the ORCID Registry and the Zotero Reference Manager. When pulling data from these platforms, your access tokens are handled using industry-standard OAuth protocols and are never stored as raw text in our backend.
    If you want to finish the data workflow setup, let me know:
    Would you like me to draft the Submission Guidelines and disclaimer text that scholars see right before uploading files?