Privacy notice
What happens to the personal data of those who read the portal and of those who open an account on it.
Data controller
Determines the purposes and means of the processing carried out through this portal:
PCS di Ambrosio Espedito
Via Luigi Maradei 15, 87026 Mormanno (CS), Italia
P. IVA 03272650783 — C.F. MBRSDT76D23F735S
www.pcsai.it
redazione@anatomiavariabile.net
Scientific direction of the content is separate from technical operation of the portal: whoever builds the infrastructure does not answer for scientific merit, and vice versa.
Reading the portal
Reading the portal requires no account and involves no behavioural tracking. These are statements verifiable in the source code, not generic commitments:
- no web analytics or audience measurement tool is installed;
- the fonts are served by the application itself: reading a page involves no requests to external domains;
- neither the browser’s local storage nor its session storage is used;
- the only cookie set is the session cookie, and only after a login: cookie page.
Entries translated from other people’s works display figures that remain hosted on the source site: to show them the reader’s browser contacts that site directly, which therefore receives their IP address. The portal does not tell it which page was being read. The reason for this choice is explained on the Licences and attribution page.
Opening an account
The registration form asks for:
- Identification
- first name, last name, email address
- Credentials
- a password, which is not stored in clear text
- Acceptances
- terms of service and acknowledgement of this notice, each with its date and time
The email address is used to confirm the account and to send service messages, such as the password reset link. No promotional messages: the portal sends none and keeps no mailing lists.
The form also contains a hidden field that must stay empty: it serves to recognise automated submissions and collects nothing from someone filling the form by hand.
The professional profile
It is optional and concerns only those who wish to propose content: the editorial team must be able to verify that whoever signs an article is who they claim to be. The profile collects profession, institution, optional department, city and country, ORCID identifier, institutional profile URL, a biography and — if declared — the type, number and region of the professional register entry.
The register number is never public: it serves the verification and stays visible to the editorial team alone. The profile asks for no date of birth, no tax code and no health data.
The dates of the actions that make up the verification are stored as well: profile submission, email confirmation, outcome, any reason for refusal or suspension, and who decided.
The verification documents
Anyone requesting professional verification uploads a supporting document. The document is stored in a private space — never in the public media store — and can be downloaded only through an endpoint that checks the identity of the requester; the storage path is exposed by no API.
Alongside the document are recorded its declared type, the original filename, the content type, the size, the upload date, the review outcome with its note, who reviewed it and when, the date until which it must be retained and, if removed, the deletion date.
If the private space is not configured the feature stays closed: an identity document cannot be kept in a public store, and the portal would rather switch verification off than accept it.
IP address and service protection
The IP address of anyone submitting a sensitive request — registration, login, password recovery, a question to the assistant — is used as the key of the counter that limits request frequency. It serves to prevent repeated password guessing and resource exhaustion; it is kept for the duration of the counting window and is not associated with the account or with the editorial records.
The session of a logged-in user is held by a technical cookie that JavaScript cannot read, lasting seven days.
The assistant
When the installation enables it, the portal offers an assistant that answers questions about the published content. The question and the previous messages of the same conversation are sent to an external language-model provider, which processes them to produce the answer. The portal keeps no conversations: neither question nor answer reaches the database.
Anyone who does not want a question to leave the portal can simply not ask it: the assistant is an extra and reading the portal does not depend on it. The identity of the provider belongs in the list of processors, which is among the missing information at the top of this page.
Why this data, and on what basis
- Account and credentials
- allowing access to the reserved area and the recovery of credentials. Legal basis: performance of the portal’s contract of use (Art. 6(1)(b) GDPR).
- Professional verification
- verifying the credentials of those proposing scientific content, which underpins the reliability declared on every article. Legal basis: performance of the contract for those asking to contribute, and the legitimate interest of the controller and of readers in the reliability of what the portal publishes (Art. 6(1)(b) and (f)).
- Public attribution
- publicly attributing authorship of articles. This happens only if the author chooses to make their profile public, and the choice can be withdrawn at any time from the profile itself. Legal basis: consent (Art. 6(1)(a)).
- Service protection
- protecting the service from abusive access and from automated use that would make it unavailable. Legal basis: the controller’s legitimate interest (Art. 6(1)(f)). The balancing rests on three verifiable facts: only the IP address is used, only for the duration of the counting window, without linking it to the account and without any profiling.
Providing the data requested by the forms is necessary to obtain the corresponding features — no email, no account; no profile, no verification — but none of these features is needed to read the portal.
Who else sees the data
The portal does not sell, transfer or exchange personal data. To operate, however, it relies on technical providers that process data on behalf of the controller. These are they, with their location and what each actually processes:
- Vercel Inc. — Site hosting and content delivery
Data processed: IP address and technical connection data, in server logs
Location: United States, with servers in the European Union
- Neon Inc. — Portal database
Data processed: Registered account data and editorial content
Location: European Union
- Resend Inc. — Service email delivery (address confirmation, password reset, editorial notices)
Data processed: Email address and message content
Location: United States
- OpenRouter, Inc. — The portal’s conversational assistant
Data processed: The text of the question put to the assistant. No account data is sent: the assistant does not know who is writing.
Location: United States
Some of these providers are based in the United States, so part of the data is transferred outside the European Economic Area. The relationship with each provider is governed by its data-processing terms, accepted upon subscribing to the service, which incorporate the standard contractual clauses approved by the European Commission; where the provider adheres to the Data Privacy Framework, the transfer also rests on the corresponding adequacy decision. Each provider’s notice, linked above, states the applicable instrument.
For how long
- Account and profile
- for the life of the account. Upon closure, requested by email to the controller’s address, the data is erased within 30 days.
- Editorial record
- decisions concerning published content — who approved, who retracted, when and why — are kept for as long as the content remains available, even after the closure of the account of whoever took them. The scientific record is not rewritten: the same reason a retracted article stays readable with its notice.
- Verification documents
- until the date set case by case at review time, recorded with the document.
- Protection counters
- the IP address used for rate limiting lives only for the duration of the counting window, measured in minutes.
The rights of data subjects
Anyone holding an account on this portal may request access to their data, its correction or erasure, the restriction of or objection to its processing, and to receive it in a machine-readable format. They may also lodge a complaint with the competent supervisory authority: in Italy, the Garante per la protezione dei dati personali.
Requests should be addressed to redazione@anatomiavariabile.net, the contact of the controller named at the top of this page. No data protection officer has been appointed: if and when one is, their details will appear here.
How the data is protected
- the session cookie cannot be read by JavaScript and, in production, travels only over an encrypted connection;
- verification documents live in a private space and are served by an endpoint that checks who is requesting them;
- repeatedly failed logins temporarily lock the account, and sensitive requests are rate-limited.
Updates
Substantial changes to this notice are flagged on this page, with the new version and effective date stated below; account holders are also notified at their registered email address. The rules for reusing content are instead on the Terms page.
Version
Version 2.0, effective 12 August 2026. Later versions replace the previous one from the stated date; substantial changes are flagged on this page.