Privacy notice

What happens to the personal data of those who read the portal and of those who open an account on it.

Data controller

Determines the purposes and means of the processing carried out through this portal:

PCS di Ambrosio Espedito
Via Luigi Maradei 15, 87026 Mormanno (CS), Italia
P. IVA 03272650783 — C.F. MBRSDT76D23F735S
www.pcsai.it
redazione@anatomiavariabile.net

Scientific direction of the content is separate from technical operation of the portal: whoever builds the infrastructure does not answer for scientific merit, and vice versa.

Reading the portal

Reading the portal requires no account and involves no behavioural tracking. These are statements verifiable in the source code, not generic commitments:

  • no web analytics or audience measurement tool is installed;
  • the fonts are served by the application itself: reading a page involves no requests to external domains;
  • neither the browser’s local storage nor its session storage is used;
  • the only cookie set is the session cookie, and only after a login: cookie page.

Entries translated from other people’s works display figures that remain hosted on the source site: to show them the reader’s browser contacts that site directly, which therefore receives their IP address. The portal does not tell it which page was being read. The reason for this choice is explained on the Licences and attribution page.

Opening an account

The registration form asks for:

Identification
first name, last name, email address
Credentials
a password, which is not stored in clear text
Acceptances
terms of service and acknowledgement of this notice, each with its date and time

The email address is used to confirm the account and to send service messages, such as the password reset link. No promotional messages: the portal sends none and keeps no mailing lists.

The form also contains a hidden field that must stay empty: it serves to recognise automated submissions and collects nothing from someone filling the form by hand.

The professional profile

It is optional and concerns only those who wish to propose content: the editorial team must be able to verify that whoever signs an article is who they claim to be. The profile collects profession, institution, optional department, city and country, ORCID identifier, institutional profile URL, a biography and — if declared — the type, number and region of the professional register entry.

The register number is never public: it serves the verification and stays visible to the editorial team alone. The profile asks for no date of birth, no tax code and no health data.

The dates of the actions that make up the verification are stored as well: profile submission, email confirmation, outcome, any reason for refusal or suspension, and who decided.

The verification documents

Anyone requesting professional verification uploads a supporting document. The document is stored in a private space — never in the public media store — and can be downloaded only through an endpoint that checks the identity of the requester; the storage path is exposed by no API.

Alongside the document are recorded its declared type, the original filename, the content type, the size, the upload date, the review outcome with its note, who reviewed it and when, the date until which it must be retained and, if removed, the deletion date.

If the private space is not configured the feature stays closed: an identity document cannot be kept in a public store, and the portal would rather switch verification off than accept it.

IP address and service protection

The IP address of anyone submitting a sensitive request — registration, login, password recovery, a question to the assistant — is used as the key of the counter that limits request frequency. It serves to prevent repeated password guessing and resource exhaustion; it is kept for the duration of the counting window and is not associated with the account or with the editorial records.

The session of a logged-in user is held by a technical cookie that JavaScript cannot read, lasting seven days.

The assistant

When the installation enables it, the portal offers an assistant that answers questions about the published content. The question and the previous messages of the same conversation are sent to an external language-model provider, which processes them to produce the answer. The portal keeps no conversations: neither question nor answer reaches the database.

Anyone who does not want a question to leave the portal can simply not ask it: the assistant is an extra and reading the portal does not depend on it. The identity of the provider belongs in the list of processors, which is among the missing information at the top of this page.

Why this data, and on what basis

Account and credentials
allowing access to the reserved area and the recovery of credentials. Legal basis: performance of the portal’s contract of use (Art. 6(1)(b) GDPR).
Professional verification
verifying the credentials of those proposing scientific content, which underpins the reliability declared on every article. Legal basis: performance of the contract for those asking to contribute, and the legitimate interest of the controller and of readers in the reliability of what the portal publishes (Art. 6(1)(b) and (f)).
Public attribution
publicly attributing authorship of articles. This happens only if the author chooses to make their profile public, and the choice can be withdrawn at any time from the profile itself. Legal basis: consent (Art. 6(1)(a)).
Service protection
protecting the service from abusive access and from automated use that would make it unavailable. Legal basis: the controller’s legitimate interest (Art. 6(1)(f)). The balancing rests on three verifiable facts: only the IP address is used, only for the duration of the counting window, without linking it to the account and without any profiling.

Providing the data requested by the forms is necessary to obtain the corresponding features — no email, no account; no profile, no verification — but none of these features is needed to read the portal.

Who else sees the data

The portal does not sell, transfer or exchange personal data. To operate, however, it relies on technical providers that process data on behalf of the controller. These are they, with their location and what each actually processes:

Vercel Inc. Site hosting and content delivery

Data processed: IP address and technical connection data, in server logs

Location: United States, with servers in the European Union

Provider’s privacy notice

Neon Inc. Portal database

Data processed: Registered account data and editorial content

Location: European Union

Provider’s privacy notice

Resend Inc. Service email delivery (address confirmation, password reset, editorial notices)

Data processed: Email address and message content

Location: United States

Provider’s privacy notice

OpenRouter, Inc. The portal’s conversational assistant

Data processed: The text of the question put to the assistant. No account data is sent: the assistant does not know who is writing.

Location: United States

Provider’s privacy notice

Some of these providers are based in the United States, so part of the data is transferred outside the European Economic Area. The relationship with each provider is governed by its data-processing terms, accepted upon subscribing to the service, which incorporate the standard contractual clauses approved by the European Commission; where the provider adheres to the Data Privacy Framework, the transfer also rests on the corresponding adequacy decision. Each provider’s notice, linked above, states the applicable instrument.

For how long

Account and profile
for the life of the account. Upon closure, requested by email to the controller’s address, the data is erased within 30 days.
Editorial record
decisions concerning published content — who approved, who retracted, when and why — are kept for as long as the content remains available, even after the closure of the account of whoever took them. The scientific record is not rewritten: the same reason a retracted article stays readable with its notice.
Verification documents
until the date set case by case at review time, recorded with the document.
Protection counters
the IP address used for rate limiting lives only for the duration of the counting window, measured in minutes.

The rights of data subjects

Anyone holding an account on this portal may request access to their data, its correction or erasure, the restriction of or objection to its processing, and to receive it in a machine-readable format. They may also lodge a complaint with the competent supervisory authority: in Italy, the Garante per la protezione dei dati personali.

Requests should be addressed to redazione@anatomiavariabile.net, the contact of the controller named at the top of this page. No data protection officer has been appointed: if and when one is, their details will appear here.

How the data is protected

  • the session cookie cannot be read by JavaScript and, in production, travels only over an encrypted connection;
  • verification documents live in a private space and are served by an endpoint that checks who is requesting them;
  • repeatedly failed logins temporarily lock the account, and sensitive requests are rate-limited.

Updates

Substantial changes to this notice are flagged on this page, with the new version and effective date stated below; account holders are also notified at their registered email address. The rules for reusing content are instead on the Terms page.

Version

Version 2.0, effective 12 August 2026. Later versions replace the previous one from the stated date; substantial changes are flagged on this page.