LEGAL
Privacy
This notice explains what personal data OpenDeco processes, why it is processed, where it is stored, how long it is retained and the rights available to you.
On this page
Launch gate: this draft is not a production privacy notice. Account, contact, import, sync and research-contribution features must remain disabled until the controller, providers, locations, lawful bases and retention periods are verified and published.
Who controls the data
The legal name, address and privacy contact for the data controller have not been approved. They must be present here before any account or personal-data feature is enabled.
Account and authentication data
Before sign-in launches, this notice must identify every account identifier, identity provider, passkey record, session record and security event processed, together with its purpose, lawful basis and retention period.
Dive and device data
Before import or sync launches, this notice must identify the source files, device metadata, normalized exposure data and derived fields processed. The account copy is restricted to its owner. OpenDeco may also process an eligible, separated research record in its non-public research environment as described in this notice. Public release or richer voluntary contribution is a separate process.
Research processing
The private OpenDeco Research Corpus must not be activated until its lawful basis, special-category assessment, access controls, isolation, retention and data-protection impact assessment are complete and described here.
Research contributions
Voluntary contribution is separate from ordinary import. Before it launches, the contribution terms, consent or other lawful basis, withdrawal rules, review process and possible public-release pathway must be stated at the point of contribution and in this notice.
Outcome and health data
Health and outcome data require a documented legal basis, stricter access control, data minimisation, retention rules and appropriate research or ethics review before collection begins.
Logs, security and abuse prevention
A visit necessarily discloses network and request metadata to the systems serving the site. The production inventory must name the recipients, purposes and retention periods; this draft does not guess them.
Communications
Before contact intake or transactional email is enabled, this notice must identify the messages and delivery metadata retained, the provider used, the purpose of processing and the deletion schedule.
Service providers and international transfers
The final notice must list the actual hosting, identity, email, storage, monitoring and support providers, their processing locations and the transfer safeguards that apply. Verified provider and storage-region details will replace this draft before launch.
Retention
A retention schedule must cover account records, sessions, imported files, normalized records, research records, contributions, logs, correspondence, backups and deletion exceptions before those data are collected.
Anonymisation and pseudonymisation
Pseudonymised data remains personal data. Any public research release requires a recorded disclosure-risk review, small-count controls and a clear statement of what was removed or transformed.
Your rights
The final notice must state the rights available under the law that applies to the controller, including any limits that apply to research processing. This section will be completed after the controller jurisdiction is approved.
How to make a data-rights request
A verified privacy contact and request process, including identity checks, response timing, export and deletion handling, must be published before accounts launch.
Contact
A controller address and dedicated privacy contact must be added here after ownership and jurisdiction are confirmed. Security reports use the separate vulnerability-disclosure route.
Changes to this notice
Each issued notice will carry an effective date and remain available after replacement so material changes can be traced.