Privacy
Privacy and data protection
How we handle personal data on our public website and the PCA Platform.
About this notice
Last updated: 19 August 2026. POSC Caesar Association (PCA, “we”, “us”) is responsible for the processing of personal data described in this notice.
This notice covers the public website at posccaesar.org, the documentation hub at docs.posccaesar.org, PCA’s openly available content, and the authenticated PCA Platform service available at https://posccaesar.org/libraries/pcardl.
The public PCA website
The public website is a statically generated website hosted using Microsoft Azure Static Web Apps. PCA does not use website analytics, advertising trackers, marketing pixels or visitor profiles on the public website.
When you visit, Microsoft Azure processes technical information needed to deliver and protect the service. This may include your IP address, the time of the request, the requested page or file, browser information and associated security information. PCA does not use this information to identify individual visitors or analyse their behaviour.
The legal basis is PCA’s legitimate interest under Article 6(1)(f) GDPR in providing, securing and protecting its public services.
The documentation hub
The documentation hub at docs.posccaesar.org is a statically generated website built from content maintained in PCA’s GitHub repositories and hosted using Cloudflare Workers. PCA does not use analytics, advertising trackers, marketing pixels or visitor profiles on the documentation hub. Search is performed locally in your browser and search terms are not sent to an external search provider.
Cloudflare processes limited technical request and security information, such as IP address, requested page, timestamp, browser information and response status, to deliver and protect the service. The hub currently loads font and icon resources from Google, which may receive limited technical request information. The legal basis is PCA’s legitimate interest under Article 6(1)(f) GDPR in providing secure and reliable technical documentation.
Links to GitHub and other external services take you to separately operated destinations with their own privacy practices.
Contact, membership enquiries and external destinations
If you submit a contact or membership enquiry form, PCA processes the information you provide, such as your name, contact details, organisation, subject and message. The information is sent by email to authorised PCA recipients and is used to respond, follow up and, where relevant, assess or administer a membership enquiry.
The legal basis for general enquiries is PCA’s legitimate interest under Article 6(1)(f) GDPR in communicating with interested persons and organisations. Where processing is necessary to take steps at your request before entering into an agreement, Article 6(1)(b) GDPR may apply.
Enquiries are retained only for as long as necessary to respond and complete relevant follow-up. Information may be retained for longer where an enquiry results in a membership or other ongoing relationship, or where retention is necessary to document the relationship or meet legal obligations. Do not submit sensitive, confidential or unrelated personal information through the forms.
Links to the PCA Platform, YouTube, LinkedIn and other external services take you to separately operated destinations. Those services process information under their own privacy notices. PCA does not load embedded content from them when you view the public website.
The PCA Platform
The PCA Platform supports the transparent development, review and governance of industrial standards, ontologies, reference data and related digital content. Public, attributable provenance is a core characteristic of the PCA Platform.
Sign-in is provided through Microsoft Entra ID. Depending on your organisation’s Entra configuration, PCA may receive your display name, username or email address, account and tenant identifiers, assigned PCA Platform roles, authentication information and sign-in security information.
The PCA Platform uses browser storage and authentication technologies required for Microsoft Entra ID sign-in, session management, access control and security.
Use of the PCA Platform is governed by PCA’s Terms of use. Before PCA grants Creator, Reviewer or Admin access, the user must expressly accept the current Terms of use.
Public attribution and provenance
Before PCA creates authenticated access, PCA provides written information about public attribution and requires the user to expressly accept the current Terms of use. Creator, Reviewer or Admin access is not created unless the user has confirmed that they understand that attributable provenance is public and normally permanent.
When you create, edit, review, approve, reject or otherwise govern content, the public provenance record may display:
- your PCA Platform username or email address;
- the action you performed;
- the resource or content concerned;
- the date and time of the action; and
- any comment or reason submitted with the action.
The purpose is to let anyone understand who performed an action, what was done, when it happened and, where a comment is provided, why it was done. The legal basis for publishing and retaining these personal data is PCA’s legitimate interest under Article 6(1)(f) GDPR in preserving the transparent, attributable and verifiable development and governance of standards, ontologies and reference data.
Public provenance can be viewed without signing in. It may be accessed from any country, indexed by search engines, copied or quoted by third parties, and retained by independent web archives. PCA cannot guarantee deletion from services or copies controlled by others.
Do not include sensitive, private, confidential or unrelated personal information in public comments. Do not include personal information about another person unless its publication is necessary and authorised.
Objections, erasure and contributor access
You may object to processing based on PCA’s legitimate interests and may request erasure where the conditions under data-protection law are met. PCA will assess each request in light of the individual’s circumstances and the need to preserve the integrity, traceability and accountability of the standards and reference-data lifecycle.
If you ask PCA to stop creating new public provenance associated with you, PCA will suspend or remove permissions that allow you to create, review, approve or otherwise govern content. This prevents new attributable actions from being created. Access to publicly available content is not affected.
Historical provenance will normally be retained where PCA determines that compelling legitimate grounds for preserving an accurate and verifiable record override the individual’s interests, rights and freedoms. PCA will explain its decision and the available right to complain.
PCA will respond without undue delay and normally within one month. Where a request is complex or PCA has received several requests, the period may be extended by up to two additional months. PCA will inform you of any extension within the first month.
Other PCA Platform information
The PCA Platform may also process:
- contributed content such as names, descriptions, symbols, classifications and ontologies;
- uploaded files, filenames, file sizes, storage identifiers and version information;
- administrative job identifiers, status and error messages; and
- technical request and security information, including IP address, requested URL, browser information, response status, response time and correlation identifiers.
This information is used to operate, secure, support and administer the PCA Platform. Account identifiers, tokens, IP addresses, administrator logs and technical errors are not published as part of the public provenance record.
Files are stored using Microsoft Azure Storage. The PCA Platform stores reference data and provenance. Where operational Slack notifications are enabled, limited error information may be sent to Slack.
Cookies and browser storage
The public website and documentation hub do not use cookies or similar technologies for analytics, advertising or profiling.
The PCA Platform uses browser storage and technologies required for Microsoft Entra ID authentication, access control and security. Microsoft’s sign-in service may set cookies on Microsoft domains as part of authentication. PCA does not use these technologies for advertising or cross-site behavioural profiling.
Who receives information and where it is processed
Personal data may be accessible to:
- authorised PCA personnel and PCA Platform administrators;
- authorised PCA Platform users according to their roles;
- your organisation where appropriate;
- Microsoft as provider of Azure and Microsoft Entra services;
- Cloudflare as hosting and content-delivery provider for the documentation hub;
- Google as provider of font and icon resources currently loaded by the documentation hub;
- PCA’s email and form-delivery providers;
- Slack where operational notifications are enabled;
- service providers acting under PCA’s instructions; and
- public visitors, search engines and archival services for public provenance information.
Core PCA Platform application data and personal data at rest are stored in Microsoft Azure regions Norway East in Norway and West Europe in the Netherlands, both within the European Economic Area. PCA also uses global Azure services for traffic delivery, monitoring and alerting. These services may process limited network, security and operational information in other locations.
Where Microsoft or another service provider transfers personal data outside the European Economic Area, the transfer is subject to applicable contractual and legal safeguards. Public provenance information is openly available and may be accessed, indexed or copied from any country.
How long information is retained
- Authentication and account information held in browser storage is retained for the relevant browser session or authentication lifecycle.
- Account and role information is used while you have authorised PCA Platform access.
- Public provenance is normally retained for the lifetime of the related standards, ontologies, reference data and governance records because it forms part of their integrity, traceability and accountability history. Requests for erasure or objections are assessed individually under applicable data-protection law.
- Uploaded files and metadata are retained according to the lifecycle of the relevant resource.
- Records showing the Terms of use version accepted, the date, time and account, and that privacy information was provided and acknowledged are retained as long as needed to demonstrate compliance.
- Enquiries are retained for as long as necessary to respond and complete relevant follow-up, and longer where the enquiry leads to an ongoing relationship or another retention requirement.
- Operational and security information is retained only for as long as needed to operate, secure and troubleshoot the relevant service.
Your rights
Subject to applicable data-protection law, you may request access, correction, deletion, restriction of processing or data portability where applicable. You may object to processing based on PCA’s legitimate interests and lodge a complaint with a supervisory authority.
PCA does not use the personal data described here to make decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise your rights or ask about this notice, contact [email protected]. You may also complain to the Norwegian Data Protection Authority.
Changes to this notice
PCA will update this notice when its services, purposes, providers or processing practices change. Material changes affecting PCA Platform contributors will be communicated before the changed processing begins. Renewed acceptance of the Terms of use, acknowledgement or consent will be requested where required.
