Privacy / Datenschutz

Repository-grounded privacy information.

This page is drafted against the actual tracked VetAI Trust site implementation as inspected on August 17, 2026. Where the repository does not reveal an operational fact, the page marks that item for operator completion instead of inventing it.

Version0.1
Effective date2026-08-17
Last updated2026-08-17

Operational details that are not fully visible in this repository, such as the final hosting provider, mail provider, processor list and retention schedules, remain explicit TODO items for the project owner.

Controller / Verantwortlicher

Current contact point.

The operator identity fields are shared with the imprint. They should be completed once the final legal operator structure is confirmed.

Operator[TODO: legal operator name]
Address[TODO: street and house number]
[TODO: postal code and city]
Germany
Contact email[email protected]
Editorial responsibility[TODO: editorially responsible person]
Data protection contact

Implementation inventory

What the repository currently shows.

This is the internal inventory translated into public language. It reflects tracked website files plus the Research Radar tooling present in the repository.

Public site

Static public pages

  • The tracked website is a static HTML/CSS/JavaScript site under public/.
  • No public user accounts, portal logins or browser-side API calls were identified in the tracked site pages.
  • No embedded third-party videos, widgets or remote web-font calls were identified in the tracked public pages.
Contact and submissions

Email-first communication

  • The public submission route currently uses a mailto: link to [email protected].
  • No repository-backed public contact form database or CRM integration was identified.
  • Email content and metadata are therefore also processed by the sender's own email provider and whichever mail service the operator uses behind this inbox.
Cookies / storage

No non-essential browser storage identified

  • The tracked public script toggles mobile navigation and fills year placeholders only.
  • No cookies, localStorage or sessionStorage calls were identified in the tracked public website files.
  • No consent banner is added in this baseline because no non-essential storage or tracking was identified in the repository-backed public pages.
Research Radar tooling

Research scripts are not visitor analytics

  • Repository tooling under research-radar/ and scripts/research-radar/ fetches public literature and vendor web sources when run by the operator.
  • Those scripts can also call the OpenAI API if the operator supplies credentials, but that is a server-side or local research workflow, not a browser-side tracker on the public site.
  • The current data model is mainly vendor, product, claim, evidence and bibliographic metadata, with paper author names retained as scientific citation metadata.

Categories of personal data

What may be processed and why.

Some processing follows directly from the repository. Other items are an operational inference from serving any website over HTTP and are labeled as such.

Repository-backed facts

Directly visible from the codebase

  • Email address, name, role and message content if you choose to contact VetAI Trust by email.
  • Any evidence files, study links or factual corrections you voluntarily submit by email.
  • Scientific metadata such as author names, publication identifiers and source URLs in Research Radar paper records.
Operational inference

Website delivery metadata

  • Any live web service necessarily receives technical connection data such as IP address, request time, requested resource and user-agent information to deliver pages.
  • The exact deployed logging configuration, processor list and retention period are not fully visible in this repository and must be completed by the operator.
  • Because no analytics scripts were identified in the tracked public pages, this page does not claim audience profiling or advertising measurement.
Purposes

Processing purposes

  • Publishing and maintaining the VetAI Trust website.
  • Receiving, reviewing and responding to submissions, corrections, vendor responses and general enquiries.
  • Documenting editorial reasoning, evidence provenance and update history.
  • Running Research Radar literature or vendor-claim monitoring when the operator chooses to use that tooling.
Legal bases

Provisional legal-basis map

  • Website delivery and security: usually legitimate interests under Art. 6(1)(f) GDPR.
  • Responding to direct enquiries and submissions: usually Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on the nature of the request.
  • Editorial record-keeping for corrections, evidence provenance and publication accountability: usually Art. 6(1)(f) GDPR.
  • The operator should complete the final controller-specific legal-basis review with counsel before calling this page final.

Recipients / processors

What is known and what still needs owner input.

Public pagesNo third-party analytics, ad tech or embedded-media recipients were identified in the tracked public site pages.
Email handlingThe current public inbox route is email-based. The exact mail host and any associated processors are not documented in the repository and must be added by the operator.
Hosting / reverse proxyThe repository indicates a deployed public website, but it does not publish a complete processor list or retention schedule for web infrastructure logs. This remains a TODO.
OpenAI / external APIsOpenAI and literature-source calls exist in optional Research Radar tooling. They are not loaded in the browser for ordinary page visits. If the operator uses that tooling with personal data, a separate processor and transfer review is required.
Retention

Retention and deletion

  • No browser-side storage by cookies, localStorage or sessionStorage was identified in the tracked public pages.
  • No repository-backed public submission database was identified.
  • Specific retention periods for server logs, emails and any future processors are not documented in this repository and must be completed by the operator.
International transfers

Transfers need configuration review

  • No browser-side third-party tracking transfers were identified in the tracked public pages.
  • Email providers, hosting providers and optional Research Radar API vendors may involve cross-border processing depending on the operator's chosen configuration.
  • Those provider-specific transfer details cannot be inferred here and should be listed once the operator finalizes the stack.
Your rights

Data-subject rights

  • You may request information about whether personal data concerning you is processed and seek access, rectification, erasure, restriction or objection as applicable.
  • Use the contact details on the contact page or the imprint to make a request.
  • You also have the right to lodge a complaint with the competent supervisory authority, in particular in the EU member state of your habitual residence, workplace or the operator's seat.
Updates

Policy changes

  • This page should be updated whenever the public site adds analytics, embedded third-party content, a contact form, accounts or materially different data flows.
  • The visible version metadata at the top of the page is part of the policy baseline.
  • Legal review is still recommended before this text is treated as final counsel-approved language.

Related trust pages

Connected policies.

Privacy covers personal data. Data Policy covers benchmark and evidence materials. Contact and Corrections explain how people can raise concerns and send information.