What we hold about you
This page lists every kind of personal information Roles, Profiles and Flows keeps, why we keep it, and for how long.
Why we are allowed to hold it
Legitimate interest in operating a closed standards service, deciding who may use it, and protecting it from bulk copying.
What we hold
- What it is
- The name, affiliation and email address someone gives when asking for access.
- Why we keep it
- To decide whether to grant access, and to reply to the person who asked.
- How long
- 24 months from the request.
- What it is
- A reference to an existing account row, the reason sign-in was refused, and the date. No name, address or email of its own.
- Why we keep it
- To count how many people are turned away at a closed door, so the decision to open registration is made on evidence.
- How long
- 12 months from the event.
- What it is
- The IP address of an anonymous reader, and how much they read that day.
- Why we keep it
- To keep the public catalogue from being copied wholesale, and to keep costs bounded.
- How long
- 12 months from the reading day.
- What it is
- The contact email and affiliation of an approved API consumer.
- Why we keep it
- To identify who holds a credential, and to reach them about it. Also the record of the terms they agreed to.
- How long
- For as long as the key exists, and for 24 months after it is revoked.
- What it is
- The email address of anyone who has attempted to sign in, INCLUDING people who were refused, because the account row is created before access is checked.
- Why we keep it
- To hold an account. For a refused sign-in the row is a by-product rather than a purpose, which is why it has the shortest period here.
- How long
- 12 months, for rows that hold no roles and no organisation membership. An account in use is kept for as long as it is in use.
Your choices
You can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted. Write to us and we will reply.
Write to privacy@bimexcellence.org