Short notice. When you register for FT-ITC interpretation access, we collect your name, email address and optional organisation. We first create a pending registration and send an activation link. After you verify the address, we create Registered-tier access and send the access code in a second email.
Registration uses Cloudflare Turnstile to reduce automated abuse. Transactional emails are sent through Resend. When you use AI interpretation, your submitted scientific package will be sent to the configured model provider for processing.
Questions, correction, deletion and access-code recovery requests may be sent to support@ft-itc.org.
1. Data controller
Frederik Friis Theisen
avenue des Martyrs 71
38044 Grenoble, France
frederik.theisen@ft-itc.org
Privacy contact: support@ft-itc.org
2. Information collected
Registration may collect:
- Name.
- Email address.
- Optional organisation.
- Registration date and pending, activation and account status.
- Activation expiry, consumption and transactional-email delivery timestamps.
- Access tier and quota information.
- Accepted Terms and Privacy Notice versions.
- Information needed for support, recovery, correction or deletion requests.
Limited technical information may also be processed for security and abuse prevention, including Turnstile results, rate-limit information, registration-cap information and safe delivery-failure categories.
FT-ITC does not intentionally put activation tokens, bearer access codes or email bodies in application logs, scientific reports, usage logs, browser storage or project files.
3. Purposes of processing
Information is processed to create and manage pending and active AI interpretation access; verify the submitted email address; send the activation and access-code emails; prevent duplicate, automated, fraudulent or abusive registrations; apply access tiers, quotas, rate limits, suspension and revocation; maintain security, accounting, audit and operational records; respond to support, correction, access, recovery and deletion requests; and operate and improve service reliability.
Registration information is not used for marketing and is not sold.
4. Legal basis
FT-ITC intends to rely on the following legal bases under Article 6 of the GDPR:
- Providing registered access and transactional emails — Article 6(1)(b). We need your name and email address to create the pending registration, verify the address, administer Registered-tier access and deliver the access code.
- Processing requested interpretations — Article 6(1)(b). When you request an interpretation, we process the submitted package and related account information to provide that requested service.
- Security and abuse prevention — Article 6(1)(f). This includes Turnstile, single-use activation tokens, rate limits, duplicate-registration checks, quota administration and access revocation.
- Operational, accounting, audit and support records — Articles 6(1)(f) and 6(1)(c) where a specific legal retention or disclosure requirement applies.
We do not rely on consent as the legal basis for providing registered access. Accepting the Terms is part of requesting and using the service, and acknowledging this Privacy Notice confirms that the information has been provided. Optional processing, such as marketing communications, would require separate consent.
5. Registration, activation and access codes
A registration submission creates a pending record. If eligible, the address receives a single-use activation link that expires after 24 hours. The token is placed in the link fragment so it is not included in the page request or referrer. The server stores a SHA-256 hash for validation; any raw token retained temporarily for email delivery is protected with application data protection. Registered-tier access and its bearer code are created only after successful activation, and the code is sent separately.
Anyone who obtains an available activation link or bearer code may be able to activate or use the associated access. Keep both confidential and contact support@ft-itc.org if either may have been exposed. FT-ITC may suspend, revoke or replace access for security, abuse prevention, quota administration or operational reasons.
6. Turnstile
Cloudflare Turnstile helps distinguish legitimate registration attempts from automated abuse. Cloudflare may process browser, device, network and challenge-related information. FT-ITC receives the verification result and limited metadata needed to evaluate the registration attempt. Turnstile processing is also subject to Cloudflare’s privacy documentation.
7. Email delivery
The activation email and the separate access-code email are sent through Resend. Resend may process the recipient address, message content, delivery, bounce, complaint and technical delivery information. The sender is no-reply@ft-itc.org; replies are directed to support@ft-itc.org. These messages are transactional, not marketing communications.
8. Automatic interpretation processing
When automatic interpretation is used, the scientific package may be sent to the configured AI provider. Depending on the task and server configuration, this may include the supplied evidence package, presentation instructions, scientific guidance, retrieved knowledge-base material and model or preset configuration.
FT-ITC records limited operational metadata such as request identifiers, access tier, model or preset, timing, token counts, estimated cost and outcome. Usage logs are intended not to contain prompts, scientific package contents, generated interpretation text, credentials, raw network addresses or raw provider errors.
AI-generated output may be incomplete or incorrect and must be reviewed by a qualified person before scientific, clinical, regulatory, commercial or publication use.
OpenAI API processing
FT-ITC currently uses OpenAI’s API to generate interpretation text. The FT-ITC server sends the selected scientific evidence package together with the applicable instructions and configuration to OpenAI. OpenAI processes that content to provide the requested response.
OpenAI states that data sent to its API is not used to train or improve its models. OpenAI may nevertheless retain abuse-monitoring logs, which can include prompts, responses and related metadata, for up to 30 days by default unless a longer legal retention period applies. FT-ITC requests the Responses API with response storage disabled (store: false).
For interpretation requests that use the FT-ITC knowledge base, OpenAI’s hosted vector-store service may process and retain indexed reference material according to the applicable OpenAI storage and deletion controls. Do not submit personal, confidential, regulated or third-party information unless you are authorised to do so and the processing is lawful. Further information is available in OpenAI’s API data-controls documentation.
9. Recipients and service providers
Information may be processed by providers used to operate FT-ITC, including Cloudflare for Turnstile, Resend for transactional email, the configured interpretation provider for interpretation, and hosting or infrastructure providers.
10. International transfers
Some providers may process information outside the European Economic Area.
11. Retention
- Pending registrations, activation state and delivery records are retained according to the configured registration retention and recovery period. Scrubbing a pending registration invalidates its activation token and cancels its queued emails.
- Active registration and account records are retained while access is active and afterward only as needed for security, accounting, audit, legal or support purposes.
- Failed-delivery and rate-limit metadata is intended to be removed after the configured operational period, currently 30 days.
- Usage metadata is retained according to the FT-ITC accounting and operational policy.
- Support correspondence is retained only as long as needed to handle and document the request.
You may request removal of personal information associated with your FT-ITC account by contacting support@ft-itc.org. We will verify the request and remove or anonymise personal information where legally and operationally possible.
12. Rights
Subject to applicable law, you may have rights to access, correct, delete, restrict, object to or receive portable copies of your personal data, and to withdraw consent where consent is the legal basis. Requests may be sent to support@ft-itc.org. Identity verification may be required.
13. Automated decision-making
FT-ITC does not intend to make decisions producing legal or similarly significant effects solely through automated processing. Turnstile and anti-abuse controls may automatically reject or delay suspicious registration attempts. Contact support@ft-itc.org if this appears to affect you incorrectly.
14. Security
FT-ITC uses measures intended to protect registration and access information, including restricted server permissions, protected configuration files, hashed activation-token and access-code storage, encrypted temporary delivery data, rate limiting and metadata-only operational logging where applicable. No transmission or storage method can be guaranteed completely secure.
15. Changes
This notice may be updated when the service, providers, processing purposes or legal requirements change. The version acknowledged during registration is recorded with the pending and active registration. The current version is ft-itc-privacy-1.0.
16. Contact and complaints
For privacy questions, correction, deletion or access-code recovery, contact support@ft-itc.org. You may also complain to the competent data-protection supervisory authority.