No edit summary
 
(No difference)

Latest revision as of 09:37, 1 September 2026

Last updated: 31 August 2026

This Privacy Policy describes how the OpenVerse Wiki (https://wiki.open-verse.eu), operated by Martel GmbH ("we", "us", or "our"), processes personal data. We are committed to protecting your privacy and handling your data in accordance with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

As a public MediaWiki platform designed for collaborative open science and repository sharing, **we process your personal data only for essential technical operations and, if you give your explicit consent, for self-hosted website statistics.**


1. Data Controller and Representatives

Data Controller (Switzerland)

The entity responsible for processing your personal data on this platform is:

  • Martel GmbH
    Überlandstrasse 111, 8600 Dübendorf, Switzerland
    Email: info@martel-innovate.com

Designated EU Representative (EEA)

Because Martel GmbH is established outside the European Economic Area (EEA), we have designated the following entity as our representative in the European Union under Article 27 of the GDPR:

  • Martel Innovate B.V.
    Keizersgracht 482, 1017 EG Amsterdam, Netherlands

2. Categories of Data Processed

A. Strictly Necessary Session Cookies

This website uses strictly necessary session cookies native to the MediaWiki platform.

  • Purpose: These cookies are technically indispensable to manage your current page request, coordinate standard MediaWiki platform features (such as user log-ins, language preferences, or maintaining secure edit state), and guarantee stable navigation.
  • No Consent Required: Under Swiss FADP and EU ePrivacy rules, functional cookies that are technically essential to deliver a requested service do not require user consent. They do not track or profile you across other websites.

B. Web Analytics (Matomo – Opt-In Only)

To understand how visitors use our wiki and to improve our repository, this website uses Matomo, an open-source web analytics platform.

  • Explicit Opt-In: Analytics are enabled only if you give your explicit, active consent via our cookie banner. If you ignore or decline the banner, no analytics scripts are loaded, and no analytics cookies are set.
  • Our Safe Matomo Setup:
    • Self-Hosted: It runs on cloud infrastructure operated directly by Martel GmbH. No data is sent to external Matomo servers.
    • Anonymised at Source: We configure Matomo to automatically mask visitors' IP addresses (by truncating the last bytes), ensuring that your raw IP address is never stored or associated with your wiki usage.
    • No Third-Party Sharing: Your statistics are first-party only and are never transmitted to, shared with, or sold to any third party.
  • Cookies Set: If you consent, Matomo sets performance cookies (such as _pk_id and _pk_ses) in your browser.

C. Essential Cybersecurity & Technical Logs

When you access this wiki, our secure hosting infrastructure automatically logs standard technical connection data. This is done solely to guarantee the stability, functionality, and cyber-resilience of the platform.

  • Data Logged: IP address, date and time of request, requested URL, HTTP status code, volume of data transferred, referrer URL, and browser User-Agent string.
  • Purpose & Legal Basis: Under Swiss revFADP (Art. 31(1)-(2)) and GDPR (Art. 6(1)(f)), processing this technical connection data is justified by our overriding legitimate interests to block cyber-threats (such as DDoS attacks or malicious bots) and maintain system security.

3. Cloud Providers and Data Processors

We partner with reliable cloud and security providers to deliver this website securely. These entities process data strictly on our behalf under formal Data Processing Agreements (DPAs):

  1. Hosting Infrastructure – AWS Sovereign Cloud (Germany / European Union): The wiki database, files, and server security logs are hosted on physical AWS servers located within the European Union (EU), ensuring robust data sovereignty and isolation.
  2. Web Security & Delivery – Cloudflare (United States / Global): Website traffic is routed through Cloudflare to inspect technical connection metadata (including IP addresses) to detect and block malicious requests. Cloudflare acts under strict DPAs and EU/Swiss Standard Contractual Clauses (SCCs) to safeguard global web-routing metadata.

4. Cross-Border Data Transfers

  • Primary Storage: All wiki content, database records, and server logs remain stored on secure AWS servers in the European Union (EU).
  • Global Security Processing: Security metadata processed by Cloudflare may be routed through global data centers to optimize delivery. Any transfer of connection metadata to third countries (such as the United States) is covered under standard safeguards:
    • EU/Swiss Standard Contractual Clauses (SCCs) integrated into our agreements.
    • The Swiss-U.S. Data Privacy Framework and the EU-U.S. Data Privacy Framework where certified.
  • Adequacy Status: Switzerland is formally recognized by the European Commission as providing an adequate level of data protection (Article 45 GDPR). Similarly, Switzerland recognizes the EU/EEA countries as guaranteeing adequate protection (Annex 1 of the Swiss Data Protection Ordinance - DPO).

5. Data Retention and Consent Withdrawal

  • Withdrawing Consent: You can withdraw your consent for Matomo analytics at any time by clearing this website’s cookies and site data in your web browser settings. Upon your next page load, the cookie banner will reappear, allowing you to re-adjust your choice.
  • Retention of Security Logs: Standard technical connection and security logs are automatically deleted and purged within 14 to 30 days, unless an active cyber-incident is detected and requires longer-term investigation.
  • Session Cookies: Strictly necessary cookies are purged from your device as soon as you close your browser session.

6. Your Statutory Rights

Under the Swiss revFADP and, where applicable, the GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 25 FADP / Art. 15 GDPR): Request confirmation of data processing and receive a free copy of your personal data.
  • Right to Rectification (Art. 32 FADP / Art. 16 GDPR): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 32 FADP / Art. 17 GDPR): Obtain the deletion of your personal data, subject to legal or contractual retention obligations.
  • Right to Restriction of Processing (Art. 41 FADP / Art. 18 GDPR): Request that data processing be restricted.
  • Right to Object (Art. 32 FADP / Art. 21 GDPR): Object to processing activities based on our legitimate interests (such as cybersecurity logging).
  • Right to Data Portability (Art. 28 FADP / Art. 20 GDPR): Request your data in a structured, electronic format.
  • Right to Mark Data as Disputed (Art. 32(3) FADP - Switzerland): Request that contested data be formally marked as disputed in our systems.

To exercise these rights, please contact us directly at info@martel-innovate.com.

Right to Lodge a Complaint

If you believe our processing violates data protection laws, you may lodge a complaint with:

  • In Switzerland: The Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern, Switzerland (www.edoeb.admin.ch).
  • In the EU/EEA: Your local national Data Protection Authority (DPA) in the country of your residence or work.

Note: this privacy policy has been prepared with the assistance of a generative AI tool, with human instructions, drafting and review.