Data protection

Privacy Notice

Operator:
Science Communications Worldwide (Science Communications Worldwide - Verein zur weltweiten Verbreitung wissenschaftlicher Kommunikation)
Last updated:
5 September 2026
Version:
2.3 — supersedes the revision dated 4 September 2026

In short

World Wide is a research-information platform operated by a small Austrian non-profit association. We collect the data needed to run accounts, publish research content, and keep the service secure. Web analytics run only if you opt in. Some content processing uses AI (OpenAI) under provider API terms. We show no advertising, sell no personal data, and do not disclose it for targeted advertising. You can ask us about, correct, export, or delete your data at any time.

Controller and contact

The controller responsible for processing personal data on world-wide.org is:

Science Communications Worldwide
Science Communications Worldwide - Verein zur weltweiten Verbreitung wissenschaftlicher Kommunikation
ZVR 1255966019
c/o Tim Vogels, Fischergasse 6, 3400 Klosterneuburg, Austria

For all privacy matters, including exercising your rights under Section 10, contact info@world-wide.org. The association is not legally required to appoint, and has not appointed, a data protection officer; privacy requests are handled by the association’s board through the address above.

Scope of this notice

This notice covers the World Wide platform at world-wide.org, including its domain-branded areas (for example World Wide Neuro), its conference portals (for example the FENS 2026 ePoster portal), and its APIs. It covers both people who hold an account and people whose personal data appears in research content we host (see Section 3.3). Conference- or campaign-specific terms, such as the FENS 2026 ePoster posting terms, supplement this notice for those submissions.

Data we process and where it comes from

3.1 Account and profile data

World Wide has no passwords. You sign in with Google or with a passkey stored on your device; no other identity provider is offered at present, and this notice will be updated before any is added. When you first sign in with Google we receive your Google account identifier, your name, and your email address. We store your name and email address in your account record, and we keep the link to the Google account in the form of the provider’s identifier and a keyed hash of the provider-side email address, so that the same Google account is recognised on later sign-ins. Passkey sign-in stores a public-key credential, never a password. Optional security features (two-factor codes, additional passkeys, active-session management) store the data needed to operate them; two-factor secrets are stored encrypted, and each active session is described only by a device label, a keyed hash of a truncated network prefix, a keyed hash of the browser string, and a last-activity time.

Everything beyond that is up to you. Your profile can hold, if you choose to add it: display name, biography, position, affiliation, research interests and statements, ORCID iD, links to personal sites and social profiles, an avatar, CV documents, and — if you opt into the talent directory — availability and career fields. Profile visibility and search discoverability are controlled in your privacy settings.

3.2 Content you submit

Listings you post (seminars, conferences, workshops, courses, jobs, grants, podcasts, preprints, ePosters) are stored together with the submission record. Where a listing names other people — speakers, instructors, organisers, co-authors — you are providing personal data about third parties and must be entitled to do so. Uploaded files are isolated and checked for malware before they are published or delivered. Job applications submitted through the platform (name, email, cover letter, CV) are shared with the posting employer. Reports, feedback, and support messages you send us are stored with the request.

3.3 Data about people who do not use World Wide

World Wide is a directory of public research activity, so it also contains personal data that we did not obtain from the person concerned (Article 14 GDPR). This falls into four groups:

  • Imported listings. Seminar, conference, job, grant, and podcast announcements ingested from public sources (institutional websites, funder databases, event pages) can include the names and affiliations of speakers, organisers, and contacts as published there. We record the source of each imported item.
  • Conference programme data. Conference organisers provide us with programme and abstract data — author names, affiliations, and contact addresses — so that accepted work can be hosted and, where authors request it, made citable. We may contact listed authors about their own submission (for example, to let them claim or manage their poster).
  • Speaker pages. Public speaker pages describe researchers by name, affiliation, and public scholarly identifiers, drawn from event listings and public academic sources.
  • DOI metadata. Where a DOI is registered for hosted work, its identifier and bibliographic metadata are distributed through DataCite. The DOI is intended to remain resolvable, including through a tombstone if the work is withdrawn; that persistence does not make inaccurate or unlawfully retained personal metadata immune from correction, restriction, or erasure (see Sections 7, 9, and 10).

The data in these groups is limited to professional, publicly presented information. Public availability does not remove the Article 14 duty to inform you. Individual information is normally due no later than one month after collection, or at the first communication or disclosure if earlier. An Article 14(5)(b) exception requires a documented assessment that individual notice is impossible or involves disproportionate effort, considering the number of people, the source age, safeguards, and effects on each person. This public notice alone does not establish that exception. If you are named on World Wide and want your entry corrected, restricted, or removed, contact info@world-wide.org — Section 10 applies to you in full.

3.4 Technical, security, and operational data

Operating a public platform requires technical records. We keep them in two layers, which differ in what they contain:

  • Perimeter records. Every request first passes our content delivery network, web application firewall, and load balancer. Their logs contain the full IP address of the requesting device together with the requested address, timestamp, response status, and browser identification string. Firewall logs are kept for 7 days and load-balancer access logs for 90 days. They are used to detect and block abusive or automated traffic, investigate security and reliability incidents, and attribute errors. They are stored separately from product analytics and may be correlated with other records when an incident requires it.
  • Application records. Inside the platform itself, network identifiers are stored only as truncated, keyed hashes — an IPv4 address is cut to its first three groups and an IPv6 address to its first four before hashing — and raw IP addresses are used transiently for request delivery, rate limiting, and security checks without being written to our database. Country is supplied as a coarse request header by our content delivery network rather than inferred by an external geolocation service. Security-relevant events (sign-in attempts, security-setting changes, administrative actions) are written to an append-only audit trail, and calls to our APIs are recorded in operational logs kept for 7 days, both in the same pseudonymised form. Browser security reports (Content Security Policy violations) record the page and the blocked resource, not who you are.

3.5 Optional analytics (only with consent)

If — and only if — you accept analytics in the cookie banner or on the Cookie Policy page, we measure how the platform is used: pages viewed (the page path, never query strings), the referring page, search terms entered, product interactions such as sharing or saving, clicks on links to external sites (destination site and page only, never query parameters), performance timings, and the campaign or channel (UTM parameters) a visit arrived from. These records use a short-lived session identifier and pseudonymised technical fields; country-level location comes from our content delivery network, and no external IP-geolocation service is used. With the same consent, the consent-gated Google Analytics described in the Cookie Policy runs in parallel. After our first-party database accepts a selected, high-signal product event, our server also sends PostHog a pseudonymous copy containing the event name, generalised surface, coarse technical context, and hashed entity references. The copy excludes search text, form content, query strings, raw account, session, and content identifiers, email addresses, and IP addresses. No PostHog code runs in your browser, and PostHog autocapture, session replay, heat maps, and exception capture are disabled. Declining analytics stops both first-party measurement and these provider copies, and never limits the platform.

3.6 Advertising campaigns and attribution

World Wide displays no advertising and sets no advertising cookies. We may occasionally buy search advertising (Google Ads) to make the platform known to researchers. Such campaigns bring visitors to world-wide.org through links that carry campaign parameters in the address. If you have accepted analytics, those parameters are recorded as the source of your visit — that is how we judge whether a campaign was worthwhile. No advertising tag, conversion pixel, or remarketing code runs on the platform. Consented Google Analytics does receive coarse, server-confirmed actions such as a completed submission in addition to source and route data; whether an advertising account imports such an event is controlled outside this website. Google Analytics runs here with advertising storage, signals, and personalisation disabled. Without analytics consent, a visit from an advertisement leaves no trace beyond the perimeter records described in Section 3.4.

3.7 Cookies and device storage

The cookies and material browser-storage categories the platform uses, together with their purposes and lifetimes, are documented in the Cookie Policy, together with the control for changing your choice at any time.

3.8 Email and notifications

We send transactional email (for example sign-in and account notices, submission confirmations, moderation outcomes) and the notifications you enable yourself, such as keyword alerts, event reminders, and digests. Email is delivered through Amazon Simple Email Service from our EU hosting region. Notification preferences are managed in your account settings where the relevant control is available. We do not send advertising on behalf of third parties.

Purposes and legal bases

In short

Each purpose has its own legal basis under Article 6(1) GDPR — we do not rely on one blanket justification. Analytics rely on consent; running your account relies on our contract with you; security and hosting public research information rely on legitimate interests you can object to.
Processing purposes and their legal bases
PurposeData involvedLegal basis (Art. 6(1) GDPR)
Providing your account and the platform features you use (sign-in, profile, submissions, bookmarks, follows, alerts)Account, profile, and content data (3.1, 3.2)(b) — performance of a contract (the free user agreement in our Terms)
Hosting and publishing research content, including listings that name third parties, speaker pages, and conference programmesContent data; third-party person data (3.2, 3.3)(f) — legitimate interest in operating an open scholarly information resource; for your own submissions also (b)
Registering DOIs and maintaining the citable scholarly recordBibliographic metadata incl. author names (3.3)(f) — legitimate interest in persistent scholarly citation, alongside the submitter’s request (b)
Perimeter security: blocking abusive and automated traffic, incident investigationPerimeter records incl. full IP addresses (3.4)(f) — legitimate interest in protecting the service and its users
Application security, rate-limiting, audit trails, and operational loggingPseudonymised technical data (3.4)(f) — legitimate interest in secure, reliable operations
Usage analytics and campaign attribution (first-party, PostHog, and Google Analytics)Analytics data (3.5, 3.6)(a) — consent, withdrawable at any time
Recording your consent decision itselfConsent status, timestamp, policy version, pseudonymised technical context(c) — legal obligation to demonstrate consent (Art. 7(1) GDPR)
AI-assisted content processing (Section 5)Submitted content; profile text; search queries(b) for features you invoke; (f) for enrichment, classification, and moderation support
Transactional email and notifications you enableEmail address, notification settings(b); optional categories can be disabled at any time
Responding to requests, reports, and rights requestsCorrespondence data(b) or (f) depending on context; (c) for rights handling
Compliance with legal obligations and defence of legal claimsThe minimum records required(c); (f) for establishing or defending claims

Where we rely on legitimate interests (Article 6(1)(f)), we have balanced those interests against your rights, limited the data involved (professional context, pseudonymisation of technical identifiers inside the platform, short retention of perimeter records), and you may object at any time as described in Section 10.

AI-assisted processing

World Wide uses machine-learning services to make research content discoverable. In concrete terms: submitted announcements and abstracts are parsed to pre-fill forms and extract keywords; summaries, topic descriptions, and subject classifications are generated; submissions are screened for policy violations, with human review available for contested outcomes; and text — including search queries and, if you maintain one, your profile — is converted into numerical representations (embeddings) that power semantic search and recommendations. Decorative artwork for scientific domains is generated from text prompts that contain no personal data.

This processing is performed by OpenAI as our processor via its API platform. Under OpenAI’s API terms, content submitted through the API is not used to train OpenAI’s models unless the customer affirmatively opts in. Under the standard API controls, abuse-monitoring logs may be retained for up to 30 days. Every applicable World Wide Responses API request disables application-state storage with store: false. That setting does not remove standard abuse-monitoring logs, and World Wide does not claim Zero Data Retention or Modified Abuse Monitoring because the organisation account does not show either approved control. We send only the content needed for the task, which can include personal data contained in a submission, profile, CV, or search. We do not send credentials or analytics event records to OpenAI. Uploaded recordings are not automatically transcribed.

The Library offers optional AI chat and voice. Chat shares your messages and relevant public or saved-item details with OpenAI to answer. Explicit interests can influence retrieval when personalization is enabled; private notes and analytics observations are not used by this assistant. If you start voice, your browser streams microphone audio to OpenAI for the spoken conversation. Typed messages, search results, and the saved-item details needed for your request are also provided to the model. API credentials remain on our server. World Wide does not save the audio or conversation history. Requested searches and bookmark changes use the same records and retention rules as those actions elsewhere on the platform; we also record usage and cost metadata. OpenAI’s applicable API data controls still apply. You can mute the microphone or end the conversation at any time.

What AI is used for, its limits, and how to report problems with machine-generated content are described in the AI Transparency Statement.

Recommendations and personalisation

The Library’s recommendation views rank publicly available research content using your interactions on the platform — what you view, follow, save, and search. If you browse anonymously with analytics consent, this uses the short-lived session described in Section 3.5; when you sign in, that session’s interests are linked to your account so your recommendations carry over. Personalisation only orders content; it produces no legal or similarly significant effects, and no advertising. You can use every content surface without signing in.

Recipients and processors

In short

Your data lives on EU-region infrastructure (AWS Ireland). A small number of contracted providers process specific slices: OpenAI for AI features; Google for sign-in, optional user-activated form protection, location suggestions, and opt-in analytics; PostHog for consented pseudonymous product analytics; DataCite for DOIs. Map tiles, embedded recordings, and externally hosted images load in your browser from their providers when you use those features.
Processors and recipients of personal data
RecipientRole and purposeData reached
Amazon Web Services EMEA SARL (primary region eu-west-1, Ireland)Processor — hosting: compute, database, file storage, content delivery, web application firewall, email delivery (Amazon SES), caching, logging, and backups. A legacy archive of conference poster files from earlier World Wide Neuro events is stored in the London region (eu-west-2)All platform data, stored in the EU except the legacy poster archive in the United Kingdom
OpenAI (contracting entity for the EEA: OpenAI Ireland Ltd)Processor — AI content processing per Section 5Submitted content text, profile text, search queries
Google Ireland Ltd / Google LLCSign in with Google (independent controller for the sign-in itself); optional, user-activated reCAPTCHA on posting forms; Google Maps Platform — address suggestions in posting forms, loaded in your browser, and server-side geocoding of listing locations; Google Analytics 4 (processor, only with your analytics consent)Sign-in: your Google identity attributes. reCAPTCHA: browser signals only if you choose Google instead of World Wide’s first-party security check. Maps: the location text typed into a posting form plus your IP address and browser characteristics while the suggestion widget is loaded; server-side geocoding sends only the listing’s location text. Analytics: consent-gated usage data
PostHog, Inc. (US Cloud)Processor — selected consent-gated product analytics sent only by World Wide’s server after the authoritative first-party record is writtenPseudonymous event and provider-session identifiers, event name, generalised product surface, coarse technical and source context, and hashed entity references; no free text, raw account or content identifiers, email address, or IP address
DataCite e.V. (Hannover, Germany, VR 201182)DOI registration agency — publishes registered bibliographic metadata as part of the global, permanent scholarly recordTitles, author names and identifiers, publication metadata
CARTO (basemaps.cartocdn.com) and unpkg.com (CDN)Map basemap tiles and the map stylesheet, loaded directly by your browser when a map is shownYour IP address, browser characteristics, and requested map area
Media platforms (YouTube in privacy-enhanced “nocookie” mode, Vimeo, Loom, Crowdcast, Dailymotion, Spotify)Click-to-load players: World Wide renders a local placeholder and your browser contacts the named provider only after you choose to load itYour IP address and browser characteristics; the platform’s own terms apply on playback
External image hostsProfile images referenced from Gravatar, Google, GitHub, LinkedIn, or ui-avatars.com load from the named host. Listing images load only from World Wide and its configured object-storage origins; other external image hosts are blocked by the browser security policyYour IP address and browser characteristics
Posting employers and event organisersSeparate controllers — receive the applications or submissions addressed to themApplication or submission content you direct to them
Authorities and legal recipientsOnly where a legal obligation requires disclosure or where necessary to establish, exercise, or defend legal claimsThe minimum required records

Where a provider acts as our processor, the processing is governed by Article 28 GDPR terms. Some named recipients instead act as separate controllers for their own service, as the table states. We do not sell personal data or share it with advertising networks.

International data transfers

The platform is hosted in the European Union (AWS region eu-west-1, Ireland). Some data reaches other countries:

  • United Kingdom. The legacy poster archive named in Section 7 is stored in AWS’s London region. The United Kingdom benefits from an EU adequacy decision (Article 45 GDPR), renewed by the European Commission in December 2025.
  • United States. Google LLC, PostHog, Inc., and Amazon Web Services, Inc. process the limited data described in Section 7 in the United States. Where the relevant recipient is currently certified, the EU–U.S. Data Privacy Framework applies; otherwise the provider terms use the European Commission’s Standard Contractual Clauses or another lawful safeguard. A framework listing or group certification is not a blanket statement about every transfer.
  • OpenAI processing takes place in part in the United States. OpenAI’s data processing addendum uses an adequacy decision or the EU Standard Contractual Clauses (Article 46(2)(c) GDPR), as applicable, for onward transfers.
  • Browser-side requests to map-tile CDNs, embedded video platforms, Google Maps, and image hosts may reach servers outside the EEA; these load only when you use the respective feature.

Copies of the relevant safeguards can be requested via info@world-wide.org.

Retention

We keep personal data no longer than the purpose requires; the Data Retention & Deletion Policy lists the concrete periods. The key points:

  • Account data is kept while your account exists. Deleting your account starts a 30-day restoration window, after which identity data is erased or irreversibly de-linked.
  • Published research content forms a scholarly record and can outlive an account in de-identified or attributed form as appropriate; a DOI remains resolvable by design, while associated metadata can be corrected, restricted, or reduced where applicable rights require it. Withdrawn material resolves to a tombstone.
  • Automated backups of the production database are retained for 7 days. Manual recovery snapshots can remain longer while a migration, recovery, or documented legal hold requires them. Application, worker, and API logs are kept for 7 days; firewall logs for 7 days; load-balancer access logs for 90 days; build logs for up to 30 days.
  • Raw opt-in analytics records are pseudonymised at collection and deleted automatically after 26 months by a daily audited job. Aggregate content metrics and consent records are excluded from that purge; consent evidence is kept as long as needed to demonstrate compliance.

Your rights

In short

You can ask what we hold about you, have it corrected or deleted, restrict or object to processing, take your data with you, and withdraw any consent — free of charge. If you are unhappy with our answer, you can complain to the Austrian Data Protection Authority.

Under Articles 15–21 GDPR you have the right to:

  • Access (Art. 15) — obtain confirmation and a copy of your personal data;
  • Rectification (Art. 16) — have inaccurate data corrected; most profile data you can edit directly in your settings;
  • Erasure (Art. 17) — have data deleted; account deletion is available self-service under Settings → Security and follows the process in the retention policy;
  • Restriction (Art. 18) — have processing limited while a dispute is resolved;
  • Portability (Art. 20) — receive data you provided in a machine-readable format. A self-service JSON export is available in Settings → Privacy and covers account/profile data, settings, content and submissions, comments, alerts, applications, attendance, consent, and attributable analytics. You can also request an export by email;
  • Objection (Art. 21) — object, on grounds relating to your particular situation, to processing based on legitimate interests, including the third-party listings described in Section 3.3.

Where processing is based on consent, you may withdraw it at any time with effect for the future — for analytics, directly on the Cookie Policy page. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any right, email info@world-wide.org. We normally respond within one month (Art. 12(3) GDPR). For a complex request or several requests, the GDPR permits an extension of up to two further months; if that is necessary, we will tell you within the first month and explain why. We may need to verify that a request really comes from you. Exercising your rights is free of charge, except where the GDPR permits a reasonable fee for manifestly unfounded or excessive requests.

You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence or workplace. For Austria:

Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40–42, 1030 Vienna, Austria
Tel. +43 1 52 152-0 · dsb@dsb.gv.at · dsb.gv.at

If you are in the United Kingdom, the UK GDPR gives you equivalent rights, which you exercise through the same address; complaints can be lodged with the Information Commissioner's Office (ICO).

Automated decision-making

Automated systems assist with content screening and ranking, and rules can approve or reject a submission. These decisions affect publication on World Wide. You can contest an outcome and request human review using the report controls or by contacting us. If you believe a decision has legal or similarly significant effects on you, explain those effects so we can assess the applicable Article 22 GDPR rights and safeguards.

Children

World Wide addresses the research community and is not directed at children. As a product rule, accounts require a minimum age of 14. Separately, § 4(4) DSG sets 14 as Austria’s threshold for a child to consent independently to information-society services where consent is the applicable legal basis. We do not knowingly permit younger children to create accounts; contact us if you believe one has done so.

Security of processing

We apply technical and organisational measures appropriate to the risk (Article 32 GDPR), including HTTPS for public connections and certificate-verified TLS for database connections, passwordless authentication with passkeys and optional two-factor authentication, least-privilege access to production systems, malware scanning of uploads before publication or delivery, pseudonymisation of network identifiers inside the platform, append-only security audit trails, and regular backups. Details that would aid attackers are not published; the Security & Responsible Disclosure page describes our practices and how to report vulnerabilities. In the event of a personal-data breach we will notify the supervisory authority and affected people where Articles 33 and 34 GDPR require it.

Whether you must provide data

You can read everything on World Wide without an account. An account requires only a sign-in identity (which includes an email address) — without it we cannot operate the account. All profile fields beyond that are voluntary. Posting a listing requires the information needed to publish it. There is no statutory obligation to provide us with any data.

Changes to this notice

We update this notice when the platform or the law changes; the “Last updated” date and version above identify the current revision. For material changes affecting account holders we will provide notice through the platform or by email. Earlier versions are available on request.

Contact

For legal, privacy, and policy inquiries, email info@world-wide.org.

This notice is provided in English, the working language of the platform. It is written to satisfy Articles 12–14 of Regulation (EU) 2016/679 (GDPR) together with the Austrian Datenschutzgesetz (DSG). Where a plain-language summary and the formal text differ, the formal text governs.

We use essential cookies to run the site. Analytics cookies are optional and help us improve World Wide. Learn more.

Privacy Notice | World Wide - World Wide