Legal & Compliance

General Data Protection Regulation (GDPR) Policy

Last Updated: December 15, 2025

1. Scope & Applicability

This policy outlines how Aevum Encyclopedia ("we," "us," or "our") collects, uses, processes, and protects the personal data of users residing in the European Economic Area (EEA) and the United Kingdom, in full compliance with the General Data Protection Regulation (EU) 2016/679 and the UK GDPR.

Our commitment to data protection is integral to our mission of providing open, verified, and secure knowledge resources globally. We process personal data lawfully, transparently, and for specified purposes.

2. Data We Collect

We collect only the data necessary to provide, maintain, and improve our encyclopedia platform. Categories include:

  • Identity & Contact Data: Name, email address, username, and profile information provided during account registration or article contributions.
  • Usage & Technical Data: IP address, browser type, device information, pages viewed, search queries, and interaction timestamps collected via secure logs and analytics.
  • Contribution Data: Text, citations, media uploads, and editorial notes submitted by verified contributors for encyclopedia entries.
  • Communication Data: Records of support tickets, newsletter preferences, and correspondence with our editorial or customer success teams.

Note: We do not collect special category data (e.g., health, biometric, or political opinions) unless explicitly required for verified contributor credentials, and only with explicit consent.

3. How We Use Your Data

Personal data is processed for the following purposes:

  • Delivering and securing access to the Aevum Encyclopedia platform
  • Verifying contributor identities and maintaining editorial standards
  • Improving search algorithms, AI knowledge graphs, and content recommendations
  • Communicating service updates, security alerts, and policy changes
  • Complying with legal obligations, including tax, anti-fraud, and copyright enforcement
  • Anonymized statistical reporting for research and platform optimization

5. Data Sharing & Third Parties

We do not sell personal data. Data may be shared only with trusted service providers operating under strict data processing agreements (DPAs), including:

  • Cloud infrastructure and CDN providers
  • AI/ML training partners (using only anonymized or consented data)
  • Payment processors (for premium tiers, if applicable)
  • Legal authorities when required by law or to protect rights/safety

All third parties are contractually bound to confidentiality, security standards, and GDPR compliance.

6. International Data Transfers

Aevum Encyclopedia operates globally. When data is transferred outside the EEA/UK, we ensure adequate protection via:

  • European Commission Adequacy Decisions
  • Standard Contractual Clauses (SCCs)
  • Encryption and technical safeguards during transit and storage

7. Data Retention

We retain personal data only as long as necessary to fulfill the purposes outlined in this policy, or as required by law. Retention periods vary by data type:

  • Account Data: Active indefinitely; archived after 24 months of inactivity
  • Contribution Records: Retained permanently for attribution and version control
  • Usage/Logs: Anonymized after 12 months
  • Support/Communications: Retained for 3 years post-resolution

Upon deletion requests, data is securely erased or anonymized within 30 days, barring legal retention requirements.

8. Your Rights Under GDPR

EEA and UK residents have the following rights regarding their personal data:

  • Right of Access: Request a copy of data we hold about you
  • Right to Rectification: Correct inaccurate or incomplete information
  • Right to Erasure: Request deletion under qualifying conditions
  • Right to Restrict Processing: Limit how we use your data temporarily
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Opt out of processing based on legitimate interests or direct marketing
  • Right to Withdraw Consent: Revoke prior consent at any time without affecting lawful processing already completed

To exercise any right, submit a request via our contact details below. We will respond within 30 days and may request identity verification for security.

9. Data Security

We implement industry-leading technical and organizational measures to protect personal data, including:

  • End-to-end TLS encryption for data in transit
  • AES-256 encryption for data at rest
  • Role-based access controls and multi-factor authentication for staff
  • Regular security audits, penetration testing, and vulnerability assessments
  • Incident response protocols compliant with GDPR Article 33/34 notification requirements

10. Cookies & Tracking

Our platform uses essential cookies for authentication and security, and optional analytics cookies to improve user experience. You may manage preferences via your account settings or browser controls. For full details, please review our Cookie Policy.

11. Contact & Data Protection Officer

If you have questions about this policy, wish to exercise your data rights, or report a privacy concern, please contact our Data Protection Office:

📧 Data Protection Office

Email: dpo@aevumencyclopedia.com

Support Portal: Support Center

Postal Address:
Aevum Encyclopedia GmbH
Data Privacy Department
10115 Berlin, Germany

For urgent security incidents, please prefix your email subject with "URGENT: DATA SECURITY".

Supervisory Authority: You have the right to lodge a complaint with your local data protection authority. A list of EU regulators is available at edpb.europa.eu.

Policy Updates

We may update this policy to reflect changes in law, technology, or service offerings. Material changes will be communicated via email or platform notification at least 14 days before implementation. Continued use of our services constitutes acceptance of updated terms.