Skip to content
VetCaseAudit
  • Method
  • Checklists
  • Security
  • Project
  • FAQ
Sign inDeutsch

Privacy

This English page is a reading aid, not a second legal document. The full statement under Art. 13/14 GDPR is the German Datenschutzerklärung. Where the two differ, the German text governs.

1. Controller

PD Dr. Steven R. Talbot, Dr. Talbot Consulting, Lehrter Str. 51, 30559 Hannover, e-mail kontakt@vetcaseaudit.de.

2. Two surfaces

This site (www.) is a static export: no account, no cookies, no analytics. The application (app.) is the research tool, by invitation only.

3. This website

These pages set no cookies, use no local storage, embed no analytics or tracking, and load no fonts, scripts, maps or images from third-party servers. Everything your browser fetches here comes from this site. There is no consent banner because there is nothing to consent to.

An optional contact form at /request-access (not linked from the public navigation) submits name, e-mail address, institution and message to the application as a same-origin request. No third party is involved. The data are processed to answer the message. The legal basis is Art. 6(1)(b) GDPR where the message aims at working together, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering). Submissions are rate-limited per IP address.

The web server (Caddy) is configured without access logging in this installation, so visitor IP addresses are not written to persistent access logs. The public site is a static export. The application runs on a VPS under the operator named in the Impressum. Infrastructure providers necessarily process IP addresses in transit. TLS certificates are obtained automatically from Let's Encrypt, which receives the domain name and the operator's contact address. No visitor data. Hosting subprocessors will be named here when they are contracted.

4. The application

Access requires an account and is by invitation only. The service stores:

  • Account data: name, e-mail address, a hash of the password (never the password itself), organisation membership in the application, role, active status and timestamps. Invitations store the invitee's e-mail address, the intended role, who invited them, a hash of the single-use token, and expiry.
  • Sessions: short-lived access tokens and a refresh token stored only as a hash. The browser holds the refresh token in a strictly necessary HTTP-only cookie. Rate-limit counters are held briefly in Redis and expire after 60 to 300 seconds.
  • Uploaded manuscripts: the file, filename, size, a SHA-256 digest, the extracted full text, a page map, page and character counts, a title, the version chain, and who uploaded it. The organisation is a shared workspace, so documents are visible to its members. Manuscripts may themselves contain personal data (author names, and in case reports possibly animal-owner details). Whoever uploads decides what goes in.
  • Analysis records: provider, model, checklist version, generation parameters, status, token counts, who started the run, and timestamps. Per checklist item: the verdict, the rationale, the improvement suggestion and the evidence quotes, which are verbatim extracts of the manuscript. If an analysis fails, the raw model response may be kept for diagnosis and is deleted with the analysis.
  • Stored provider keys: encrypted at rest, held in clear only in memory for the duration of a provider call, never logged, never redisplayed. Analyses on a stored key are not billed by VetCaseAudit.
  • E-mails and the administration log: invitations and password resets may be sent once a mail transport is configured. A copy of each message is stored with secret links redacted. The mail provider will be named here when it is contracted. Administrative changes are logged with actor, time and object.

5. Where manuscript text is sent

Running an analysis splits the extracted text into overlapping chunks and sends each chunk, with the checklist items, to the language-model provider whose key is configured. At that point the manuscript text leaves the service's own server. When a key is configured, the expected provider is GWDG SAIA, Gesellschaft für wissenschaftliche Datenverarbeitung mbH Göttingen, processing in Germany. SAIA keys are personal, so VetCaseAudit holds no platform key for GWDG. If a stored OpenAI key is used, manuscript chunks go to OpenAI. There is no silent failover: if the chosen provider is unavailable, the analysis fails visibly.

The public site is a static export. The application runs on a VPS under the operator named in the Impressum. Subprocessors for email and hosting will be named here when they are contracted. They are not used on the static pages. TLS certificates come from Let's Encrypt (Internet Security Research Group). The data transmitted are the domain name and the operator's contact address.

6. Retention

Documents, analyses and evidence quotes stay until they are deleted. Deleting a document removes the database row and the files, and its analyses go with it. There is currently no automatic deletion schedule. Refresh tokens last 30 days (a continuously renewed session chain ends after 90 days at the latest), password-reset tokens 60 minutes, invitations 14 days, signed download links 120 seconds. Rate-limit counters expire after 60 to 300 seconds. Contact-form messages and stored e-mail copies have no automatic purge in the application yet. See the application's current configuration. Backups of the database and the document store are taken daily and kept for 14 days on the server, so deleted data can persist in backups for up to that long. They are not currently copied elsewhere.

7. Your rights

You have the rights of access, rectification, erasure, restriction, data portability and objection (Art. 15 to 21 GDPR) and may complain to a supervisory authority (Art. 77 GDPR). Requests: kontakt@vetcaseaudit.de. The competent authority for the controller is the Landesbeauftragte für den Datenschutz Niedersachsen, Hannover.

Analysing a manuscript is an automated assessment of a text, not of a person. No automated decision within the meaning of Art. 22 GDPR is made about anyone.

Read the authoritative German version →

  • Legal notice
  • Privacy
  • Deutsch

kontakt@vetcaseaudit.de

VetCaseAudit is a reporting-completeness screening tool. It replaces neither peer review nor any scientific or veterinary judgement.