Data & Compliance

Transparency, security, and regulatory adherence form the foundation of Aevum Encyclopedia. This document outlines how we collect, process, protect, and govern your data in accordance with global standards.

Last Updated: October 24, 2025

Data Privacy & Collection

We collect and process data strictly for service delivery, platform improvement, and compliance purposes. All data handling follows a privacy-by-design methodology.

๐Ÿ”น Account Data

Email, username, profile preferences, and authentication tokens required for account creation and session management.

๐Ÿ”น Usage Analytics

Aggregated, anonymized telemetry including page views, search queries, and feature interactions to optimize content delivery.

๐Ÿ”น Contribution Metadata

Editorial history, revision timestamps, IP anonymization hashes, and contribution verification signatures for academic integrity.

๐Ÿ”น Communication Logs

Support tickets, feedback submissions, and opt-in newsletter preferences retained for service continuity.

Legal Basis: Data collection is grounded in explicit consent, contractual necessity, legitimate interest, and legal obligation, documented in our Data Processing Register.

Security Infrastructure

Aevum Encyclopedia employs defense-in-depth security architecture, regularly audited by independent third parties.

Control Domain Implementation Status
Data Encryption AES-256 at rest, TLS 1.3 in transit, zero-knowledge where applicable Active
Access Management RBAC + MFA, principle of least privilege, automated session revocation Active
Infrastructure Monitoring 24/7 SOC, SIEM integration, anomaly detection, automated incident response Active
Vulnerability Management Quarterly penetration testing, continuous CVE scanning, patch SLA <72hrs Scheduled

Regulatory Compliance

We maintain continuous alignment with global data protection frameworks. Compliance is validated through annual audits and automated policy checks.

  • GDPR (EU/UK) โ€” Full compliance with Articles 6โ€“9, DPO appointment, cross-border transfer safeguards (SCCs)
  • CCPA/CPRA (California) โ€” Consumer privacy notices, opt-out mechanisms, sale/sharing disclosures
  • COPPA / GDPR-K โ€” Age-gating, parental consent workflows, child-safe content filtering
  • ISO 27001:2022 โ€” Certified Information Security Management System (ISMS)
  • SOC 2 Type II โ€” Annual audit covering Security, Availability, Processing Integrity, Confidentiality, and Privacy

User Rights & Controls

Users retain full sovereignty over their data. All requests are processed within statutory timeframes, typically 14โ€“30 business days.

Right Description Execution Method
Access Retrieve a complete export of all personal data we hold Dashboard export or email request
Rectification Correct inaccurate or incomplete profile information Self-serve settings or support ticket
Erasure Request permanent deletion of account and associated data One-click account closure flow
Portability Download structured, machine-readable data (JSON/CSV) API endpoint or dashboard export
Opt-Out / Consent Withdrawal Revoke marketing, analytics, or research participation consent Privacy center toggle or unsubscribe link

Data Retention & Erasure

Data is retained only as long as necessary to fulfill its purpose, comply with legal obligations, or resolve disputes. Automated lifecycle policies enforce expiration and anonymization.

  • Active Accounts: Data retained indefinitely until voluntary deletion or inactivity triggers
  • Inactive Accounts: Suspended after 24 months; data anonymized or deleted after 36 months
  • Analytics/Logs: Aggregated and anonymized after 12 months; raw logs purged at 6 months
  • Legal Holds: Data preserved per regulatory or litigation requirements regardless of default retention

Third-Party Processors

We engage vetted service providers under strict Data Processing Agreements (DPAs). All processors undergo security reviews and compliance certification checks before onboarding.

Service Provider Data Processed Location
Cloud HostingAWS / GCPAll platform dataEU / US / APAC
AuthenticationAuth0 / CloudflareEmail, MFA tokensEU / US
AnalyticsPlausible / Self-HostedAggregated usage metricsEU
SupportIntercomTicket content, contact infoUS

Full vendor register and DPA templates are available upon request to verified users and legal representatives.

Data Protection Officer & Contact

For privacy inquiries, data subject requests, or compliance documentation, our dedicated DPO team is available to assist.

Reach the Compliance Team

All requests are reviewed within 48 hours. Legal and academic institutional requests receive priority handling.

โœ‰๏ธ dpo@aevumencyclopedia.org

Postal: Aevum Compliance Division, 42 Knowledge Way, London EC2A 4BX, United Kingdom