OS-ERIN hosted proof

Privacy Notice Draft

Status: draft placeholder pending institutional/legal review. This page is provided for SRAM/OIDC registration review and internal preparation only. It is not an approved production privacy notice, does not prove hosted readiness, and does not imply permission to invite external users.

Draft Control

This notice must not be treated as legal approval, production readiness, live SRAM login proof, DNS/TLS/firewall proof, security review completion, penetration testing, or permission to process confidential or sensitive manuscripts.

External users must not be invited until controller/processor roles, contact addresses, retention, hosting jurisdiction, support and security routes, policy approval, and operational configuration are confirmed.

Scope

This notice is for the OS-ERIN registration surface and later hosted proof-of-concept. The hosted proof is intended to test federated access and controlled scholarly-review collaboration, not to provide a production research service.

OS-ERIN is not a truth engine, ranking system, misconduct detector, compliance score, or automated peer-review replacement. Parser, model, provider, and retrieval outputs remain proposals or provenance-bearing intermediate records unless accepted through explicit OS-ERIN owner and reviewer workflows.

Authentication And Access

The hosted proof is expected to use SRAM/OpenID Connect through a confidential or restricted browser web application or trusted OIDC proxy. The exact login and callback origins remain subject to the deployed OIDC contract; login is not enabled on this registration surface.

OIDC information remains pending external input. Missing OIDC facts block hosted identity and external-user claims, but do not by themselves block local UI completion work.

Authentication alone does not grant project access. Project access and reviewer/admin authorization must come from OS-ERIN project membership, invitation or allowlist rules, or SRAM collaboration/group/entitlement claims mapped into OS-ERIN authorization.

Personal Data Expected In The Proof

Secrets And Internal Services

The proof must not put client secrets, access tokens, ID tokens, refresh tokens, bearer tokens, session cookies, private keys, raw identity-provider responses, organisation API tokens, raw OIDC claim dumps, or equivalent secrets into chat, git, Markdown artifacts, screenshots, ordinary logs, proof JSON, exports, or public pages.

The hosted runtime should expose the application only through the public HTTPS/OIDC proxy. Internal services such as the API, Postgres, object storage, parser/GROBID, fallback workers, model/provider services, and MinIO console are not intended to be directly public.

Required Before External Users Are Invited

Rights, Retention, And Contact Route

Registration contact: Peter Tamas, Wageningen University & Research. The formal privacy-rights process, controller/processor roles, institutional data-protection route, retention/deletion schedule and final policy approval remain to be confirmed before external users are invited.

Until those roles and routes are approved, contact through this page is a project inquiry and should not be treated as a substitute for a formal institutional privacy request.