Privacy

Operational privacy for an institutional academic platform.

NODOVOX applies data minimization, aggregated metrics and institutional separation to operate academic discovery, metadata, holdings and interoperability services.

Scope

This policy describes general criteria for processing technical, operational, institutional and contact data related to the use of NODOVOX.

Contracts, technical addenda and institution-specific agreements may establish additional conditions.

Principles

NODOVOX seeks to operate according to:

  • data minimization;
  • clear operational purpose;
  • aggregated metrics;
  • institutional separation;
  • restricted access to portals;
  • protection of internal documentation.

Data NODOVOX may process

To operate and improve the platform, NODOVOX may record or process:

  • data voluntarily submitted through contact forms;
  • technical session data;
  • technical IP data for security, institutional attribution or abuse prevention;
  • searches and usage events;
  • bibliographic records opened;
  • access attempts;
  • traffic source;
  • associated institution when a reliable signal exists;
  • technical, error, rate-limit or security logs;
  • bibliographic integration data supplied by institutions or providers.

Data not required for basic discovery

For basic institutional discovery use, NODOVOX does not require the following from students, faculty or researchers:

  • national ID or student/employee number;
  • institutional password;
  • complete student database;
  • individual academic history;
  • campus or internal system credentials.

Purposes

Technical and operational data may be used to:

  • operate the platform;
  • provide support;
  • prevent abuse or misuse;
  • measure institutional usage in aggregated form;
  • improve search, metadata and user experience;
  • generate institutional or commercial reports;
  • audit operations, errors and security;
  • respond to commercial, technical or institutional inquiries.

Metrics and reporting

Institutional and provider portals should display aggregated indicators, not identifiable individual activity.

NODOVOX should not expose raw IP addresses, complete user agents, internal logs, data from other institutions or data from other providers without authorization.

Cookies and sessions

NODOVOX may use technical cookies or equivalent mechanisms to maintain sessions, protect forms, operate portals, remember temporary institutional context, prevent abuse and measure aggregated usage.

These technical cookies are necessary for the platform's basic operation.

Retention and security

Retention periods may vary according to operational purpose, technical requirements, support, security, contractual obligations or audit needs.

NODOVOX applies controls to reduce public exposure of internal documentation, logs, backups, dumps and sensitive technical files.

Content and third parties

NODOVOX may integrate metadata, links, identifiers, repositories, providers and external resources.

Final access to content may depend on third parties, institutional licenses, repositories, providers, proxies, institutional link resolvers or external technical availability.

Privacy inquiries

Questions about privacy, data, contracts or information processing may be handled through institutional contact channels.

Institutional note: this page describes general operational privacy criteria. It does not replace contracts, data-processing addenda, confidentiality agreements, specific legal documents or professional review applicable to each institution or jurisdiction.