1. Who we are
The African Heritage Documentation & Research Centre (AHDRC) is a non-profit organisation registered in Brussels, Belgium. References to "we", "us" and "our" in this policy refer to AHDRC. AHDRC acts as controller for personal data processed through this website.
2. Scope
This Privacy Policy explains how we collect, use, share, retain and safeguard personal data when you visit ahdrc.org, register for an account, use the archive, submit information, contact us or otherwise interact with our services. It applies to visitors, members, sponsors, fellows, helpers, administrators and research partners.
3. Information we collect
Account data: email address, username, name, professional category, institution or organisation where supplied, password hash, email-confirmation state, role, subscription state, account lockout information and two-factor-authentication state. Authentication secrets such as passwords and authenticator keys are not included in personal-data downloads.
Archive activity and contributions: saved lists, recently viewed objects, image-download history, comments, data suggestions, image or new-ID proposals, review status, reviewer notes and archive-edit audit entries associated with an account.
Usage and security data: limited server logs and security events needed to operate and protect the website.
Turnstile security signals: Login, Registration and Forgot Password use Cloudflare Turnstile for bot detection. Cloudflare states that Turnstile processes security signals such as IP address, TLS fingerprint, User-Agent header, sitekey and associated origin. AHDRC uses Turnstile for security and abuse prevention, not advertising or behavioural profiling. Turnstile does not receive the contents of the AHDRC form fields from AHDRC.
Communications: messages sent through the contact form, support enquiries and correspondence with AHDRC. Contact-form submissions are transmitted to AHDRC by email and are not stored as contact-form records in the website database.
Payment data: where payment services are used, payment-card processing is handled by the relevant payment provider and AHDRC does not store full card numbers in this website application.
4. How we use your data
We use personal data to authenticate users, provide authorised archive access, operate saved lists and archive features, process contributions, maintain review and edit workflows, respond to enquiries, administer subscriptions, send transactional account messages, prevent abuse, investigate security incidents and meet legal obligations.
Archive activity data may also be used to detect unusually high-volume use and protect the collection against misuse. AHDRC does not use the website to create advertising profiles.
5. Legal bases under the GDPR
Performance of a contract: providing account and archive services and administering subscriptions.
Legitimate interests: maintaining platform security, detecting abuse, preserving the integrity and provenance of archive changes, improving service quality and protecting AHDRC's collections and systems.
Consent: where a feature specifically requires consent, such as an optional marketing communication.
Legal obligation: retaining information that must be kept under applicable accounting, tax or other legal requirements and responding to lawful requests.
6. Processors, sharing and international transfers
AHDRC does not sell or rent personal data. Data is shared only where necessary with service providers used to operate the website, such as hosting, email delivery, payment or security providers, or where disclosure is required by law.
Cloudflare provides Turnstile as a website-security service. Cloudflare's Turnstile Privacy Addendum explains the security signals it processes and states that Turnstile uses them to distinguish legitimate users from automated traffic. See Cloudflare's Turnstile Privacy Addendum.
Where a processor or service involves a transfer outside the European Economic Area, AHDRC relies on the applicable transfer mechanism and contractual safeguards required by data-protection law.
7. Retention and account deletion
Account data and account-owned archive activity are retained while the account is active unless a longer period is required for a specific legal or security reason.
Users can request a machine-readable copy of the personal data held in the account area. The export includes profile and role information, subscription state, saved lists, viewing and download activity, data suggestions, comments, account-owned archive edit audits and contribution workflow records that remain available to the application.
Self-service account deletion removes the Identity account and its account-owned lists, subscription record, comments, suggestions, viewing/download history and other Identity tokens. Contribution workflow rows submitted by that account are removed and pending contribution files are deleted. If the account reviewed another member's contribution, the contribution may remain for archive-workflow integrity but the deleted reviewer's account reference is cleared. Accepted archive objects and images remain part of the archive, and reviewer-side audit entries that referred to a contribution from the deleted account are retained only with the contributor identity replaced by "Deleted account".
Server logs are retained only for the period needed for operations, security and incident investigation, up to 12 months unless a specific incident or legal obligation requires longer retention. Accounting and invoicing information is retained for the period required by applicable law. Email correspondence is retained under AHDRC's correspondence practices.
8. Your rights
Subject to the conditions and exceptions in applicable law, you may have rights to access, rectify, erase, restrict or object to processing, and to receive certain personal data in portable form. You also have the right to lodge a complaint with the Belgian Data Protection Authority.
The Personal data section of an authenticated AHDRC account provides a self-service data download and account-deletion control. For other privacy requests, or if you cannot access your account, contact legal@ahdrc.org.
9. Cookies, local storage and Turnstile
AHDRC uses first-party cookies and local storage for authentication, antiforgery protection, two-factor authentication, comparison state, language and theme preferences, onboarding state and the new-site transition notice. AHDRC does not currently use analytics, advertising or profiling cookies.
Cloudflare Turnstile is loaded only on protected authentication forms and may use browser-side security mechanisms needed to complete its challenge. See the Cookie and Local Storage Policy for the storage used by AHDRC and the Turnstile disclosure.
10. Security
AHDRC uses HTTPS, hashed passwords, role-based access control, antiforgery protection, two-factor authentication for elevated archive operations, protected media storage, server-side Turnstile verification, security logging and regular dependency maintenance. No internet service can provide an absolute guarantee of security.
11. Changes to this policy
We may update this policy when our services, processors or legal obligations change. The revision date is shown at the top of the page. Material changes will be communicated through an appropriate website or account notice where required.
12. Contact
AHDRC NPO, Brussels, Belgium. For privacy-related questions or requests, contact legal@ahdrc.org.