Privacy Policy
Last updated: 14 July 2026
This policy is provided to you before you create an account or submit any data. It explains what personal data ChemRepro collects, why, on what legal basis, and what rights you have over it. It applies to all users of chemrepro.io and any other domain operated by ChemRepro.
1. Data controller
ChemRepro is an independent project operated by:
[Registered correspondence address — to be confirmed before publication]
Basel, Switzerland
[email protected]
There is no appointed Data Protection Officer. For all data-related enquiries, contact the address above. We will respond within one calendar month.
2. EU representative (GDPR Art. 27)
ChemRepro is established in Switzerland and processes personal data of individuals in the EU on an occasional basis in connection with the use of the platform.
We have not yet appointed a formal EU representative under GDPR Art. 27. We rely on the "occasional processing" basis under Art. 27(2)(a) at this stage of the platform's development, on the basis that: (a) processing is not systematic or large-scale; (b) it does not involve special category data under Art. 9; and (c) it is unlikely to result in a risk to the rights and freedoms of data subjects in the EU given its limited scope and purpose.
Note: whether the "occasional processing" exemption applies at ChemRepro's current scale should be confirmed with legal counsel before this policy is published. An EU representative will be appointed if and when that exemption no longer applies.
3. What data we collect, why, and on what legal basis
Account data – ORCID login
When you log in with ORCID, we receive your ORCID iD (e.g. 0000-0002-1234-5678) and your public name as registered with ORCID. We do not receive your email address, publication list, or institutional affiliation — we do not request those scopes.
Legal basis: Art. 6(1)(a) GDPR (consent — you actively choose to authenticate via ORCID); nDSG Art. 31(2)(a).
Mandatory? Not mandatory. You may use guest login instead. Without any login you can browse the site but cannot submit reviews or comments.
Account data – guest login
If you use guest login, you choose a display name yourself. We generate a random internal identifier (UUID) that is stored in your session and database. No email address is collected.
Legal basis: Art. 6(1)(a) GDPR (consent — you actively choose this login method); nDSG Art. 31(2)(a).
Mandatory? Not mandatory — it is an alternative to ORCID login. Without any login you can browse but not submit content.
Career stage (optional)
After your first login we ask you to optionally select a career stage (e.g. PhD student, postdoc, industry chemist). This is shown alongside your reviews as context for other readers. It is not linked to your name or email on any public page. You may skip this step or select "Prefer not to say." Career stage is recorded at the time each review is submitted and is not retroactively updated if you change your career stage later (see also section 3a on career stage immutability).
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in providing contextual credibility signals that help other researchers assess the relevance of a review, balanced against the minimal privacy impact of an optional, non-identifying category; nDSG Art. 31(2)(c). A Legitimate Interest Assessment (LIA) supporting this basis is maintained internally and is available to supervisory authorities on request.
Mandatory? Entirely optional. Skipping has no effect on your ability to use any feature of the site.
Review content
When you submit a reproducibility rating we store: the paper DOI, your star rating (1–5), failure context (for star 1: whether you tested the original procedure or only an extension), your written observation, and the submission timestamp. Reviews are linked internally to your account to enforce the one-rating-per-paper rule and to allow you to edit or delete your own content.
Where a review is subject to a formal dispute under sections 4b or 4c of our Terms of Service, we may also process substantiation documentation provided by the reviewer for the limited purpose of resolving that dispute. Such documentation is treated as confidential and deleted once the dispute is closed. See also section 7 (retention) for how long dispute-related data is kept.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in maintaining an accurate, non-duplicated scientific reproducibility record for the benefit of the chemistry community; nDSG Art. 31(2)(c). An LIA for this processing is maintained internally and available to supervisory authorities on request.
Mandatory? Not mandatory — submitting a review is always voluntary. You may delete your reviews at any time directly on the site.
Author right-of-reply responses
If you are an author of a reviewed paper and choose to post a right-of-reply response using the mechanism provided in the platform, your response is stored and displayed alongside the relevant review. The reply is linked to your ORCID iD as author verification evidence.
Legal basis: Art. 6(1)(a) GDPR (consent — posting a reply is voluntary and requires an affirmative action); nDSG Art. 31(2)(a).
Mandatory? Entirely optional. You may request removal of your reply by contacting us.
Comments and likes
Comments you post on reviews and likes you register are stored and linked to your internal account identifier.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in enabling community discussion and engagement around reproducibility reports; nDSG Art. 31(2)(c). An LIA is maintained internally.
Mandatory? Entirely optional. You may delete your comments by contacting us; likes can be removed directly on the site.
Feedback form responses
If you submit the optional feedback form, we store any written comment you provide. If you are logged in, the response is associated with your internal account identifier but not displayed publicly.
Legal basis: Art. 6(1)(a) GDPR (consent — you choose to submit this form); nDSG Art. 31(2)(a).
Mandatory? Entirely optional.
Session cookie
We set one first-party session cookie:
chemrepro_session —
a signed, encrypted token that keeps you logged in for up to 7 days (or until you
sign out). No third-party cookies are set. No advertising or tracking cookies are
used. Under ePrivacy rules, strictly necessary cookies do not require a consent
banner, but we disclose this fully for transparency.
Mandatory? Yes — the session cookie is required for login to function. You can block it but you will not be able to sign in.
Server logs
Our hosting provider (Railway) automatically records IP addresses, request paths, and timestamps in infrastructure logs. These are retained according to Railway's own policy and are not stored in our application database.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in maintaining service security and diagnosing technical failures.
3a. Career stage shown on reviews
Your career stage as selected at the time a review is submitted is recorded with that review and is not retrospectively updated if you later change your career stage in your profile settings. This ensures that the contextual information visible alongside a review accurately reflects who you were when you performed the work, not who you are now. You may update your current career stage in profile settings at any time; this affects only future submissions.
4. Paper author metadata
When a DOI is looked up, we fetch and store the paper's title, author list, journal, year, and abstract from CrossRef and Europe PMC. Author names appear in paper listings as part of the bibliographic record of published works. We treat this data as publicly available bibliographic metadata — the same information visible in any literature database — rather than personal data requiring consent. If you are an author and wish for your name to be removed from a paper listing, contact us at the address in section 1.
5. Third-party services and processors
No other third parties receive personal data. We do not use any analytics, advertising, error-tracking, or monitoring services that receive user data.
6. International data transfers
Our database is hosted by Railway in the United States. For EU users, we rely on Railway's participation in the EU–US Data Privacy Framework (adequacy decision of 10 July 2023, Commission Implementing Decision (EU) 2023/1795). For Swiss users, we rely on the Swiss–US Data Privacy Framework as recognised by the Swiss Federal Council (September 2023), provided Railway maintains certification under that framework — which we verify periodically. If Railway's certification lapses, we will rely on Standard Contractual Clauses as a fallback transfer mechanism and update this policy accordingly.
7. Retention periods
8. Security measures
We implement appropriate technical and organisational measures in accordance with GDPR Art. 32 and Swiss nDSG Art. 27, including:
- ✓ All connections are encrypted in transit via HTTPS (TLS).
- ✓ The database is hosted on Railway's managed PostgreSQL, which provides encryption at rest.
- ✓ Database credentials are stored as environment variables and never committed to source code.
- ✓ Access to the database and server logs is limited to the data controller.
- ✓ Privacy-by-design and privacy-by-default principles govern the system: we collect only the minimum data necessary, reviews are pseudonymised (not linked to your public name in the display), and optional fields default to not collected.
Data breach notification: In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority within 72 hours (GDPR Art. 33; nDSG Art. 24). Where the risk is high, we will notify affected users without undue delay.
9. Your rights
Under the GDPR and the Swiss Federal Act on Data Protection (nDSG) you have the following rights:
To exercise any of these rights, email [email protected]. We will respond within one calendar month (extendable by a further two months for complex or multiple requests, with notification of the extension). No fee is charged for reasonable requests.
You also have the right to lodge a complaint with a supervisory authority (see section 10).
10. EU Digital Services Act — notice and action
Where the EU Digital Services Act (Regulation (EU) 2022/2065) applies to ChemRepro, the following applies to the handling of notices about potentially illegal content:
How to submit a notice: Send an email to [email protected] with the subject line "DSA Notice". Your notice should include: (a) the URL of the content; (b) an explanation of why you consider it illegal or contrary to these terms; (c) your contact information; and (d) a statement that you believe in good faith the information in the notice is accurate.
Statement of reasons: When content is removed or restricted in response to a notice, or on ChemRepro's own initiative, we will provide a statement of reasons to the content submitter explaining the decision, the legal or policy basis, and the available redress options (DSA Art. 17).
Redress: You may challenge a content moderation decision by contacting us at the address above. We will review the challenge and communicate an outcome within 14 days.
Note: whether ChemRepro falls within the scope of the DSA (as a hosting service provider with users established in the EU) should be confirmed with legal counsel before this section is published.
11. Right to lodge a complaint
If you believe we have processed your data unlawfully, you have the right to lodge a complaint with a supervisory authority — without prejudice to any other remedy.
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — www.edoeb.admin.ch
- EU residents: the supervisory authority of your country of residence, habitual place of work, or the place where the alleged infringement occurred.
We would always prefer to resolve any concern directly — please contact us first.
12. Changes to this policy
We may update this policy as the platform evolves. The "last updated" date at the top of this page reflects the most recent version. If changes are material and affect how we process your data, we will notify registered users and, where required by law, re-obtain consent before the changes take effect.
Questions? [email protected]