Privacy Policy
Effective date: 2026-08-17.
NEMAR (Neuroelectromagnetic Data Archive and Tools Resource) is a research data archive. This policy covers the personal information NEMAR holds about its registered users. The datasets NEMAR hosts are covered separately by the Data Contributor Terms and the GDPR Position Statement.
Contact for anything in this policy: [email protected].
What we collect
Section titled “What we collect”When you create a NEMAR account, we collect:
- name and email address;
- username and, where provided, ORCID iD, GitHub username, affiliation, city, and country;
- a password hash for command-line accounts (we never store plaintext passwords).
While you use the service, we also process:
- credentials we issue to you (an API token, storage credentials, and a GitHub access token), which exist so you can upload and manage datasets;
- short-lived email verification and login codes;
- operational logs of requests to our services, used for reliability and abuse prevention;
- your email notification preferences.
We do not sell personal information, use it for advertising, or share it with third parties except the service providers listed below.
Why we collect it
Section titled “Why we collect it”- To operate your account: authentication, dataset ownership, and collaborator access control.
- To contact you about your account and datasets: verification, approval, publication review, and service notices. Non-essential notifications respect your email preferences.
- To attribute published datasets: if you publish a dataset, your name and, where provided, ORCID iD appear in the public dataset metadata and Digital Object Identifier (DOI) record. This is standard scholarly attribution and is part of what you agree to when publishing.
Where it is processed
Section titled “Where it is processed”NEMAR runs on infrastructure in the United States. Our service providers process data on our behalf: Cloudflare (application hosting and database), Amazon Web Services (dataset storage), GitHub (dataset version control), and an email delivery provider (transactional email). Each provides contractual data protection commitments, including Standard Contractual Clauses or certification under the EU-US Data Privacy Framework where European data is involved. See the GDPR Position Statement for details on international transfers.
Cookies
Section titled “Cookies”The website uses one strictly necessary cookie to keep you signed in. Optional analytics cookies, if enabled, are used only after you accept them in the cookie notice.
Retention
Section titled “Retention”Account records are kept while your account is active. Verification and login codes expire shortly after issue. Operational logs are retained for a limited period for security and debugging. If your account is deleted, we remove your account record and revoke all issued credentials; your name may remain in the public metadata of datasets you published, because published scholarly records are permanent.
Your rights
Section titled “Your rights”You can ask us at any time to:
- access or export the information we hold about your account;
- correct it (much of it is self-service in your account settings);
- delete your account, which revokes all issued credentials;
- object to non-essential email, or adjust your notification preferences directly.
If you are in the European Union or another jurisdiction with statutory data subject rights, these requests are honored under those laws. Write to [email protected] and we will respond within 30 days. You also have the right to complain to your local data protection authority.