1. Data Controller Identification
This Privacy Policy applies to the data processing activities of Sortsycompss Historical Archive Ltd (herein "Sortsycompss", "we", "our", or "the Archive"), a legal entity registered under Company Number HRB-883920-B at the District Court of Charlottenburg, Berlin, with corporate offices established at Friedrichstraße 185, 10117 Berlin, Germany.
Our appointed Data Protection Officer (DPO) can be contacted directly at: [email protected] or via physical courier addressed to: Data Governance Directorate, Sortsycompss, Friedrichstraße 185, 10117 Berlin, Germany.
2. Principles of Data Collection & Processing
Sortsycompss processes personal data strictly in adherence with the European Union General Data Protection Regulation (Regulation EU 2016/679, "GDPR"), the German Federal Data Protection Act (BDSG 2018), the California Consumer Privacy Act (CCPA as amended by CPRA), and applicable international data governance statutes.
We adhere to the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality (Article 5 GDPR).
3. Categories of Personal Data We Process
A. Voluntarily Submitted Information
When you subscribe to our Curatorial Dispatches, submit academic research inquiries through our Curatorial Desk, or register for field seminars, we collect:
- Full legal name, title, and academic affiliation (where provided).
- Electronic mail address (email) and telephone coordinates.
- Specific archival inquiries, geographic focus areas, and textual communications.
B. Automatically Harvested Technical Telemetry
When you navigate our portal, our European server clusters log anonymized server requests:
- Truncated Internet Protocol (IP) address with the final octet masked (e.g., 192.168.1.xxx).
- Browser type, engine version, operating system, and viewport resolution.
- Referring URLs, visited monograph pages, time spent per archival dossier, and timestamp data.
4. Legal Grounds for Processing (GDPR Art. 6)
We rely on the following explicit legal bases:
- Consent (Art. 6(1)(a) GDPR): For optional academic newsletters, subscriber communications, and non-essential telemetry.
- Contractual Performance (Art. 6(1)(b) GDPR): For processing institutional archive access agreements and seminar registrations.
- Legitimate Interests (Art. 6(1)(f) GDPR): For ensuring cybersecurity, safeguarding archive infrastructure against denial-of-service intrusions, and debugging system errors.
- Legal Compliance (Art. 6(1)(c) GDPR): For compliance with corporate statutory retention, accounting standards, and regulatory disclosure mandates.
5. Third-Party Data Processors & International Transfers
We do NOT sell, rent, or commercialize personal user data under any circumstances. In strict execution of our educational mission, technical data may be processed by contractually bound Data Processors (Art. 28 GDPR) located within the European Economic Area (EEA), including sovereign hosting partners and CDN infrastructure.
Where international data transfers occur, we implement European Commission Standard Contractual Clauses (SCCs) and supplementary technical encryption safeguards.
6. User Data Rights Under GDPR & CCPA
As a data subject, you possess the following enforceable rights:
- Right of Access (Art. 15 GDPR): Obtain confirmation of whether your data is processed and receive a full structural copy.
- Right to Rectification (Art. 16 GDPR): Correct inaccurate or incomplete records.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Request complete deletion where data is no longer necessary.
- Right to Restriction of Processing (Art. 18 GDPR): Limit processing during verification disputes.
- Right to Data Portability (Art. 20 GDPR): Receive your submitted data in a structured, machine-readable format (JSON/CSV).
- Right to Object (Art. 21 GDPR): Object at any moment to processing based on legitimate interests.
- Right to Withdraw Consent: Revoke consent at any time without affecting past processing legality.
To exercise any right, submit an authenticated request to [email protected]. We respond within 30 statutory days. You also maintain the right to lodge a complaint with the supervisory authority: Berliner Beauftragte für Datenschutz und Informationsfreiheit.
7. Data Retention & Erasure Schedules
Inquiry records submitted via the Curatorial Desk are retained for 24 months after ticket closure for academic continuity, following which they are permanently wiped. Server access logs are held for 14 calendar days strictly for intrusion analysis before automatic purging.