Data & Compliance
Transparency, security, and regulatory adherence form the foundation of Aevum Encyclopedia. This document outlines how we collect, process, protect, and govern your data in accordance with global standards.
Last Updated: October 24, 2025Data Privacy & Collection
We collect and process data strictly for service delivery, platform improvement, and compliance purposes. All data handling follows a privacy-by-design methodology.
๐น Account Data
Email, username, profile preferences, and authentication tokens required for account creation and session management.
๐น Usage Analytics
Aggregated, anonymized telemetry including page views, search queries, and feature interactions to optimize content delivery.
๐น Contribution Metadata
Editorial history, revision timestamps, IP anonymization hashes, and contribution verification signatures for academic integrity.
๐น Communication Logs
Support tickets, feedback submissions, and opt-in newsletter preferences retained for service continuity.
Legal Basis: Data collection is grounded in explicit consent, contractual necessity, legitimate interest, and legal obligation, documented in our Data Processing Register.
Security Infrastructure
Aevum Encyclopedia employs defense-in-depth security architecture, regularly audited by independent third parties.
| Control Domain | Implementation | Status |
|---|---|---|
| Data Encryption | AES-256 at rest, TLS 1.3 in transit, zero-knowledge where applicable | Active |
| Access Management | RBAC + MFA, principle of least privilege, automated session revocation | Active |
| Infrastructure Monitoring | 24/7 SOC, SIEM integration, anomaly detection, automated incident response | Active |
| Vulnerability Management | Quarterly penetration testing, continuous CVE scanning, patch SLA <72hrs | Scheduled |
Regulatory Compliance
We maintain continuous alignment with global data protection frameworks. Compliance is validated through annual audits and automated policy checks.
- GDPR (EU/UK) โ Full compliance with Articles 6โ9, DPO appointment, cross-border transfer safeguards (SCCs)
- CCPA/CPRA (California) โ Consumer privacy notices, opt-out mechanisms, sale/sharing disclosures
- COPPA / GDPR-K โ Age-gating, parental consent workflows, child-safe content filtering
- ISO 27001:2022 โ Certified Information Security Management System (ISMS)
- SOC 2 Type II โ Annual audit covering Security, Availability, Processing Integrity, Confidentiality, and Privacy
User Rights & Controls
Users retain full sovereignty over their data. All requests are processed within statutory timeframes, typically 14โ30 business days.
| Right | Description | Execution Method |
|---|---|---|
| Access | Retrieve a complete export of all personal data we hold | Dashboard export or email request |
| Rectification | Correct inaccurate or incomplete profile information | Self-serve settings or support ticket |
| Erasure | Request permanent deletion of account and associated data | One-click account closure flow |
| Portability | Download structured, machine-readable data (JSON/CSV) | API endpoint or dashboard export |
| Opt-Out / Consent Withdrawal | Revoke marketing, analytics, or research participation consent | Privacy center toggle or unsubscribe link |
Data Retention & Erasure
Data is retained only as long as necessary to fulfill its purpose, comply with legal obligations, or resolve disputes. Automated lifecycle policies enforce expiration and anonymization.
- Active Accounts: Data retained indefinitely until voluntary deletion or inactivity triggers
- Inactive Accounts: Suspended after 24 months; data anonymized or deleted after 36 months
- Analytics/Logs: Aggregated and anonymized after 12 months; raw logs purged at 6 months
- Legal Holds: Data preserved per regulatory or litigation requirements regardless of default retention
Third-Party Processors
We engage vetted service providers under strict Data Processing Agreements (DPAs). All processors undergo security reviews and compliance certification checks before onboarding.
| Service | Provider | Data Processed | Location |
|---|---|---|---|
| Cloud Hosting | AWS / GCP | All platform data | EU / US / APAC |
| Authentication | Auth0 / Cloudflare | Email, MFA tokens | EU / US |
| Analytics | Plausible / Self-Hosted | Aggregated usage metrics | EU |
| Support | Intercom | Ticket content, contact info | US |
Full vendor register and DPA templates are available upon request to verified users and legal representatives.
Data Protection Officer & Contact
For privacy inquiries, data subject requests, or compliance documentation, our dedicated DPO team is available to assist.
Reach the Compliance Team
All requests are reviewed within 48 hours. Legal and academic institutional requests receive priority handling.
โ๏ธ dpo@aevumencyclopedia.orgPostal: Aevum Compliance Division, 42 Knowledge Way, London EC2A 4BX, United Kingdom