Data processing

Institutional basis for data-processing agreements.

This page summarizes NODOVOX general criteria on technical data, aggregated institutional usage, bibliographic integration, operational security and responsibilities to be defined contractually with each institution.

Purpose

Where applicable, a data-processing agreement should define how NODOVOX and the institution manage technical, institutional, analytical, contact and bibliographic-integration data.

Final conditions are established through a contract, technical addendum, commercial addendum or specific document signed by the parties.

Roles of the parties

The legal roles of each party should be defined according to contracted scope, applicable jurisdiction and the type of data involved.

  • contracting institution;
  • NODOVOX as technology provider;
  • integrated providers or repositories;
  • authorized technical third parties, if any.

Possible data

Depending on the case, NODOVOX may process:

  • institutional contact data;
  • technical session data;
  • technical IP data for security, institutional attribution or abuse prevention;
  • search and usage events;
  • aggregated metrics;
  • institution, provider or collection identifiers;
  • security, error or rate-limit logs;
  • bibliographic metadata supplied by institutions, repositories or providers.

Data not required for basic discovery

To operate basic institutional discovery, NODOVOX does not require:

  • complete student databases;
  • national ID or end-user record number;
  • institutional passwords;
  • campus credentials;
  • individual academic history;
  • internal administrative data not required for the service.

Purposes

Processing may serve operational, technical, support, security, interoperability and aggregated institutional-measurement purposes.

  • operate the platform;
  • integrate metadata, holdings, catalogs, collections or repositories;
  • provide technical or institutional support;
  • prevent abuse, spam or unauthorized access;
  • generate aggregated reports;
  • audit technical operation;
  • improve discovery, metadata and user experience.

Segregation and access

Institutional portals should filter information by institution and prevent unauthorized exposure of data from other clients, providers or sources.

Administrative access should be limited to authorized persons and specific operational needs.

Operational security

NODOVOX applies controls to reduce public exposure of internal documentation, backups, logs, dumps, test files and sensitive technical resources.

Specific measures may be expanded through technical addenda, SLAs, confidentiality agreements or institutional requirements.

Retention and deletion

Retention periods should be defined according to purpose, support, security, audit, contract and technical needs.

At the end of a contractual relationship, the parties may agree on return, limited retention, anonymization or deletion of data as appropriate.

Incidents and inquiries

Incident reports, information requests or data-processing inquiries should be handled through agreed institutional channels.

Relationship with other documents

This document is complemented by the privacy policy, terms of use, cookies and sessions, security and trust, SLA, SaaS agreement and technical addenda.

Institutional note: this page is a general informational basis. It is not itself a signed data-processing agreement, does not replace professional legal review and must be adapted to each institution, country, contract, data type, integrated provider and applicable jurisdiction.