Purpose
Where applicable, a data-processing agreement should define how NODOVOX and the institution manage technical, institutional, analytical, contact and bibliographic-integration data.
Final conditions are established through a contract, technical addendum, commercial addendum or specific document signed by the parties.
Roles of the parties
The legal roles of each party should be defined according to contracted scope, applicable jurisdiction and the type of data involved.
- contracting institution;
- NODOVOX as technology provider;
- integrated providers or repositories;
- authorized technical third parties, if any.
Possible data
Depending on the case, NODOVOX may process:
- institutional contact data;
- technical session data;
- technical IP data for security, institutional attribution or abuse prevention;
- search and usage events;
- aggregated metrics;
- institution, provider or collection identifiers;
- security, error or rate-limit logs;
- bibliographic metadata supplied by institutions, repositories or providers.
Data not required for basic discovery
To operate basic institutional discovery, NODOVOX does not require:
- complete student databases;
- national ID or end-user record number;
- institutional passwords;
- campus credentials;
- individual academic history;
- internal administrative data not required for the service.
Purposes
Processing may serve operational, technical, support, security, interoperability and aggregated institutional-measurement purposes.
- operate the platform;
- integrate metadata, holdings, catalogs, collections or repositories;
- provide technical or institutional support;
- prevent abuse, spam or unauthorized access;
- generate aggregated reports;
- audit technical operation;
- improve discovery, metadata and user experience.
Segregation and access
Institutional portals should filter information by institution and prevent unauthorized exposure of data from other clients, providers or sources.
Administrative access should be limited to authorized persons and specific operational needs.
Operational security
NODOVOX applies controls to reduce public exposure of internal documentation, backups, logs, dumps, test files and sensitive technical resources.
Specific measures may be expanded through technical addenda, SLAs, confidentiality agreements or institutional requirements.
Retention and deletion
Retention periods should be defined according to purpose, support, security, audit, contract and technical needs.
At the end of a contractual relationship, the parties may agree on return, limited retention, anonymization or deletion of data as appropriate.
Incidents and inquiries
Incident reports, information requests or data-processing inquiries should be handled through agreed institutional channels.
Relationship with other documents
This document is complemented by the privacy policy, terms of use, cookies and sessions, security and trust, SLA, SaaS agreement and technical addenda.