Privacy Notice Draft
Draft control
This notice must not be treated as evidence of:
- legal approval;
- production readiness;
- complete SRAM/OIDC configuration;
- complete DNS, TLS, firewall, or hosted-ingress validation;
- security-review completion;
- penetration testing;
- an approved retention schedule;
- permission to process confidential manuscripts or sensitive personal data;
- permission to invite additional external users.
Before invitations expand, the following must be confirmed:
- controller, processor, or joint-controller roles;
- the responsible policy owner;
- institutional privacy, support, and security contacts;
- legal basis;
- data categories and purposes;
- retention and deletion;
- hosting location and jurisdiction;
- subprocessors and support access;
- incident procedures;
- approved operational configuration.
Scope
The current OS-ERIN service operator is Biometris, Wageningen University & Research.
This notice concerns the public registration surface and the restricted hosted research demonstrator. The hosted demonstrator is intended to test federated access and controlled scholarly-review collaboration. It is not a production research service or long-term repository.
OS-ERIN is not a truth engine, ranking system, misconduct detector, compliance score, or automated peer-review replacement.
Parser, retrieval, model, and provider outputs remain proposals or provenance-bearing intermediate records unless an authorised reviewer explicitly accepts, edits, or replaces them within the OS-ERIN workflow.
Authentication and access
The current hosted demonstrator uses SURF SRAM and OpenID Connect through a restricted browser application and trusted OIDC proxy.
The reviewed public callback is: https://os-erin.eu/oauth2/callback
Login is limited to approved SRAM application-group membership.
The current operator-validation account has completed the bounded SRAM sign-in route. This does not establish:
- the complete registered redirect inventory;
- final claim and scope configuration;
- membership-removal propagation timing;
- final policy approval;
- permission to invite additional external users.
Authentication alone does not grant access to a project or its documents. Authorisation depends on OS-ERIN project membership, invitation or allowlist rules, assigned roles, or approved SRAM collaboration, group, or entitlement claims mapped into OS-ERIN permissions.
Personal data expected in the demonstrator
Authentication and identity data
- identity-provider issuer;
- persistent subject identifier;
- internal OS-ERIN user identifier;
- display name;
- email address;
- minimal attributes required for authentication and access decisions.
Collaboration and authorisation data
- group or collaboration membership;
- entitlement claims;
- project membership;
- assigned role;
- invitation or allowlist status;
- access-control decisions.
Application and review data
- documents uploaded or selected by the user;
- extracted document text;
- source and citation metadata;
- reviewer actions;
- selected passages;
- interpreted claims;
- proposed and accepted relationships;
- reviewer-authored judgements;
- confidence and concern;
- annotations and notes;
- provenance and revision records;
- audit and export records.
Operational and security data
- non-secret runtime status;
- request and security events required to operate the demonstrator;
- error reports;
- degraded-state indicators;
- redacted diagnostic and validation artefacts.
Secrets and internal services
Client secrets, access tokens, ID tokens, refresh tokens, bearer tokens, session cookies, private keys, raw identity-provider responses, organisation API tokens, unredacted OIDC claim dumps, and equivalent credentials must not be placed in:
- chat systems;
- source control;
- Markdown records;
- screenshots;
- ordinary application logs;
- proof or diagnostic JSON;
- review exports;
- public pages.
The hosted runtime should expose the application only through the approved HTTPS and OIDC boundary.
Internal components—including the application API, databases, object storage, parser services, GROBID, fallback workers, model or provider services, and administrative consoles—must not be directly exposed as public services.
Required before additional external users are invited
- Confirm institutional controller, processor, or joint-controller roles.
- Confirm the accountable policy owner.
- Confirm institutional data-protection, administrative, support, and security contacts.
- Confirm the legal or approved institutional basis for demonstrator processing.
- Confirm the SRAM issuer, scopes, released claims, callback inventory, and entitlement or group mapping.
- Confirm the hosting provider, location, jurisdiction, support access, and required processing agreements.
- Confirm retention and deletion for identity data, documents, extracted text, review records, logs, audit records, exports, and backups.
- Confirm cookie and session behaviour.
- Confirm support-ticket data handling.
- Confirm incident and breach-response responsibilities.
- Confirm which categories of manuscripts and source material may be processed.
- Obtain final institutional and legal approval before sending additional invitations.
Rights, retention, and contact route
Registration contact: Peter Tamas, Wageningen University & Research.
The formal privacy-rights process, controller and processor roles, institutional data-protection route, retention and deletion schedule, and final policy approval remain to be confirmed before invitations expand.
Until those routes are approved, contact through this page is a project enquiry and should not be treated as a substitute for a formal institutional privacy request.