Authored by humans. Machine-verifiable. Ed25519-signed. This notice covers csoai.org and the
CSOAI public services. It is short on purpose.
What we collect
Server logs — IP, user-agent, request path, status code. Standard Cloudflare Pages logs. Retained 30 days.
Article 50 passport submissions — the fields you fill in (system name, contact email, description) plus the generated signed receipt. Stored in CSOAI's signed-event log for verifier lookup.
Newsletter signups — email address, only if you submit.
We do not collect special-category data, biometric data, or anything we cannot
describe in one sentence. We do not run third-party analytics on csoai.org.
What we do with it
Server logs: aggregate stats, incident response. Never sold.
Passport submissions: produce a signed record. The record is publicly verifiable via the standard you can recompute against.
Newsletter: one email at a time, when there is a measurement patch worth telling you about. Unsubscribe is in every email.
Who we share with
Cloudflare — host of csoai.org only; processes request logs. Data processing addendum in place.
Hugging Face / Kaggle / Zenodo — public benchmark artefacts. No personal data. Anyone can recompute.
Law enforcement — only on a binding legal instrument. We will tell you if we can.
Your rights (UK GDPR / EU GDPR)
Access — request a copy of the data we hold on you.
Erasure — request we delete data we hold on you (passport submissions are part of the signed record; we mark them withdrawn rather than delete).
Object — to any processing.
Complain — to the ICO if you think we have done something wrong.
This is not legal advice. It is a notice. If you need a DPIA for a deployment that touches
protected characteristics, get a lawyer. We make the evidence layer verifiable and inexpensive;
the legal layer is its own layer.