Scope and responsibility
This draft covers the Dynodoc homepage and the associated hosted research workspace. It explains the behavior of the current pilot. A separately operated installation may have a different operator, hosting arrangement and privacy notice.
“Dynodoc,” “we” and “our” refer to the operator of this hosted service, whose legal identity is still to be supplied below. We handle account and service-operation information to run the workspace. A research organization that uploads study materials generally determines why those materials are processed, who may access them and what participant information belongs in them.
The precise controller, processor or equivalent roles depend on applicable law and the study arrangement. This notice is not a data processing agreement, a participant information sheet or an ethics approval. Those arrangements must be agreed before the pilot is used for identifiable participant data.
Information we handle
| Category | Examples and source | Why it is needed |
|---|---|---|
| Account and identity | Your email address, supplied display name, account identifier and sign-in records. These come from you or your selected sign-in provider. | Identify you, authenticate your session and attribute contributions. |
| Research content | Uploaded documents and workbooks, original filenames and files, paragraphs, cells, formulas, questions, choices, notes, comments and suggestions. | Provide editing, import, export, review and collaboration. |
| Version and collaboration records | Content changes, author identifiers, timestamps, saved versions, drafts, document membership, roles and import provenance. | Show changes in context, manage access and preserve a working history. |
| Integration information | The server URL, project or form you select, the token supplied for a request, and the instrument or response data you import. | Retrieve the requested material from your research platform. |
| Technical and support information | Server request information, which may include IP address, request path, time, browser information and error details; information you give an administrator when requesting help. | Operate, troubleshoot and protect the service. |
An email address is required to use the authenticated workspace. Browsing the public homepage does not require an account. The interactive homepage examples use sample information and keep their edits in the page’s memory; they do not create research records or submit example responses.
How information is used
The pilot uses information to sign you in, save and retrieve work, display history and attribution, apply document permissions, process requested imports and exports, send sign-in emails, respond to support needs and investigate errors or misuse.
The current application does not include advertising trackers, marketing profiling, sale of research content, AI model training or automated decisions about people with legal or similarly significant effects. It does not send document contents to an AI service.
Legal basis
Where a law requires a legal basis, the operator must identify it for each purpose before this draft becomes effective. Account and workspace operation may be necessary to provide the requested service; proportionate security and support processing may rely on legitimate interests where permitted; legal obligations may require particular records. Consent, where used, must be specific and withdrawable. These examples do not establish a legal basis for sensitive research data or replace the research organization’s assessment.
Who can see your work
Document access is controlled by membership and assigned roles. Editors, reviewers and readers have different capabilities. People with permission to manage membership can give others access. A collaborator who is allowed to view or export content may retain a copy outside Dynodoc; removing access cannot recall copies they already obtained.
Personal drafts are kept separate from the shared team version until you share changes. Saved versions and attribution may reveal earlier wording and contributor identities to people authorized to view the relevant document history.
Authorized service administrators may access stored information when needed to operate or support the service. The pilot is not end-to-end encrypted. Access roles restrict application access; they do not prevent the infrastructure operator from administering the database.
We may need to disclose information to comply with a binding legal requirement or address a substantiated security issue. Any adopted policy must specify the responsible operator and its process for assessing such requests.
Service providers and integrations
Sign-in and hosting
- Google, when enabled: sign-in requests identity, email and profile information. It does not request Google Drive, Docs or Sheets access. Google processes sign-in activity under its own privacy policy.
- Resend, when configured: receives the recipient email address and sign-in message needed to deliver a magic link. Its handling is described in the Resend privacy policy.
- Hosting providers: the workspace runs on the operator’s server. A homepage deployed on Vercel also involves Vercel in serving page requests. The final provider list, hosting locations and contractual arrangements remain to be confirmed by the operator.
Research platforms
When you choose an ODK Central or KoboToolbox connection, the server contacts the platform address you provide using your supplied token. The token is used for the requested connection and is not intentionally saved in the application database or browser local storage. Imported files or responses, their source information and the resulting workspace content are retained as research material.
Imports are snapshots. The pilot does not schedule background synchronization or write changes back to the source platform. REDCap, SurveyCTO, SurveyMonkey and CSPro compatibility currently uses uploaded files rather than direct account connections.
External content
Homepage integration logos are served locally. If you insert an externally hosted image into a research document, a viewer’s browser may contact that image host and disclose ordinary request information to it. External links take you to services with their own policies.
History, retention and deletion
Removing text from the current version is not permanent erasure. Dynodoc preserves content history. Earlier wording, deleted cells or questions, attribution and original uploads can remain in historical records.
Archiving a document changes its visibility in the working area; it does not erase its content or history. The current pilot has no automatic expiry for research documents, original uploads or account records, and no self-service permanent-erasure feature.
The current hosted backup schedule keeps a rolling set of daily database backups for 14 days. That backup rotation does not delete records from the live database, and restored backups may contain earlier copies. The operator must establish and publish retention rules for research projects, accounts, access logs, support records and any additional backups before wider use.
A deletion or correction request must be assessed by the operator and, where appropriate, the responsible research organization. The assessment must account for the request, applicable rights, research obligations, restricted access, legal retention duties and the append-only history. The operator must not treat version history as a blanket exemption from deletion rights. This draft does not promise an automated or immediate erasure process that the pilot does not provide.
Security and storage
The hosted pilot uses HTTPS for public traffic, authenticated server requests, document permissions, protected session cookies and a database isolated from public access. Content history includes integrity checks. Integrity checks help detect changes to recorded history; they do not prove that research content is correct or prevent every form of unauthorized access.
No internet service can guarantee absolute security. This draft makes no claim of end-to-end encryption, a particular encryption-at-rest configuration, an external security certification or a regulated-data hosting standard. Local server backups are not a substitute for a confirmed offsite recovery arrangement.
The operator must identify the hosting provider, processing countries, relevant subprocessors and any required international-transfer safeguards before the final policy is published. If a personal-data incident occurs, the operator and responsible organization must assess and meet applicable notification duties.
Research and sensitive data
The workspace is intended for professional research collaboration. Study materials can contain information about participants who do not have Dynodoc accounts, including information supplied by research collaborators or imported from connected platforms.
Research teams are responsible for their participant notices, consent or other lawful authority, ethics approvals, access decisions and retention requirements. Use the minimum information necessary. Avoid uploading identifiable, sensitive or regulated participant data until the institution and operator have agreed suitable safeguards and processing arrangements.
The service is not directed at children. A study involving children requires its own lawful and ethical arrangements; the presence of research tools in this pilot does not authorize collecting children’s information.
Your choices and rights
You can review the content you are authorized to access, export supported files, update research content through the editor, manage access where your role permits, sign out and choose not to use optional connections.
Depending on the law that applies, you may have rights to obtain information or a copy, correct inaccurate personal information, request erasure, restrict processing, receive portable data, withdraw consent or complain to an appropriate supervisory authority. These rights may have conditions or exceptions.
You may also have a right to object to processing based on legitimate interests. If applicable, the operator must consider the objection and explain its response. Where consent is the basis, withdrawing it does not affect the lawfulness of processing before withdrawal.
To exercise a right, contact the operator using the details to be completed below. A research participant may also contact the organization responsible for the study. For the current limited pilot, use the administrator who invited you as the interim contact. Do not send sensitive study records through public repository issues. Identity checks should be proportionate, and requests must be handled within applicable legal deadlines.
Changes to this notice
The final notice must carry an effective date and identify its operator. Material changes to purposes, providers or data handling should be communicated before they take effect when required. A revised notice does not itself authorize incompatible uses of previously collected information.
For the proposed rules governing use of the service, see the terms and conditions.
Contact and operator details
- Legal operator
- Awaiting confirmation.
- Privacy contact email
- Awaiting confirmation.
- Mailing address
- Awaiting confirmation.
- Hosting jurisdictions
- Awaiting confirmation.
- Representative or DPO
- To be identified if required by applicable law.
These missing details are intentional markers in a draft. They are not a substitute for an identifiable operator and a functioning privacy-request channel.