Legal
Riff Systems Privacy Notice
Effective date: 08 September 2026
This Privacy Notice explains how Riff Systems Ltd
handles personal information in connection with
riffsystems.org, correspondence, publication enquiries and
related Riff Systems activities.
1. Who we are
The data controller is:
Riff Systems Ltd Company No. 17419314 Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ Email: contact@riffsystems.org
Riff Systems is a cross-domain research and scholarly publication programme operated by Riff Systems Ltd.
2. Information we may process
Riff Systems is designed to collect as little personal information from website visitors as reasonably practicable.
When you simply browse the website, Riff Systems does not intentionally ask you to create an account, provide a name, complete a user profile, or submit behavioural or demographic information.
Technical information may nevertheless be processed as part of delivering and securing the website. This can include an IP address, browser or device information, requested page, request time and related technical request information.
The website is intended to be hosted using GitHub Pages. GitHub states that when a GitHub Pages site is visited, the visitor’s IP address is logged and stored for security purposes. This occurs regardless of whether the visitor is signed into GitHub. (GitHub Docs)
If you contact Riff Systems by email, we may process your name, email address, the content of your message, attachments you choose to send, and information required to respond to or administer your enquiry.
3. Why we use personal information
Technical request information may be processed where necessary to deliver, maintain and protect the website, diagnose technical problems, prevent abuse and maintain security.
Correspondence information may be processed to respond to enquiries, administer publication corrections, deal with copyright or licensing requests, maintain appropriate records of permissions and communications, and conduct legitimate Riff Systems business.
We do not use website visitor information to construct behavioural profiles for advertising.
4. Lawful bases
Where Riff Systems Ltd determines the purpose and means of processing, the applicable lawful basis will depend on the particular activity.
For ordinary website operation, security and administration, we may rely on legitimate interests. Those interests are maintaining a secure and functional research-publication website, protecting the website and its content from misuse, and administering legitimate communications concerning Riff Systems.
For correspondence concerning a proposed licence, permission, agreement or other transaction, processing may also be necessary to take steps at your request before entering into a contract or to perform a contract.
Where processing is necessary to comply with a legal obligation, we may rely on that obligation.
Where consent is specifically requested for a future activity, consent will be the relevant basis for that activity and may be withdrawn as provided by applicable law.
The ICO advises that legitimate interests require a legitimate purpose, necessity and a balancing of that interest against the person’s rights and freedoms. (ICO)
5. Analytics, advertising and tracking
At quiet launch, Riff Systems does not intentionally deploy
website analytics, advertising trackers, behavioural profiling tools or
marketing pixels on
riffsystems.org.
We also do not intentionally deploy non-essential cookies for advertising or behavioural analytics.
This does not mean that no technical information is processed when the website is accessed. Infrastructure and hosting providers may process request information for purposes such as security, network operation and service delivery.
If Riff Systems later introduces analytics, non-essential cookies or comparable tracking technologies, this Privacy Notice and any required cookie information or consent mechanism will be updated before those technologies are intentionally deployed.
6. Who may receive information
Personal information may be processed by service providers where necessary to operate the website, communications or related business systems.
For the planned website hosting, this includes GitHub in connection with GitHub Pages.
Email and infrastructure providers may also process information
required to transmit, store, secure or deliver communications. We will
not describe an email provider as part of the permanent notice until the
actual service used for contact@riffsystems.org has been
verified.
We may also disclose information where reasonably necessary to professional advisers, regulators, courts, law-enforcement authorities or other parties where disclosure is required or permitted by law.
Riff Systems does not sell personal information to advertisers.
7. International transfers
Some technology providers may process information outside the United Kingdom.
GitHub states that it stores and processes personal data in multiple locations, including the United States and other countries, and describes safeguards for international transfers, including participation in the UK Extension to the EU-U.S. Data Privacy Framework and contractual transfer mechanisms where applicable. (GitHub Docs)
Where Riff Systems engages service providers that process personal information internationally, we will seek to use providers and arrangements offering safeguards appropriate under applicable UK data-protection law.
8. How long information is retained
Riff Systems will not retain personal information for longer than reasonably necessary for the purpose for which it is processed.
Routine correspondence may be retained for as long as necessary to resolve the enquiry and maintain an appropriate record. Communications relating to licences, permissions, contractual matters, disputes, publication corrections or legal obligations may be retained for longer where reasonably required to establish the relevant record or comply with legal requirements.
Technical logs controlled by infrastructure or hosting providers are retained according to those providers’ applicable operational and privacy policies. Riff Systems may not control the exact retention period of provider-generated security logs.
Information that is no longer reasonably required will be deleted, anonymised or allowed to expire according to the relevant system’s retention process, subject to legal or evidential requirements.
9. Your data-protection rights
Depending on the circumstances and the lawful basis involved, UK data-protection law may give you rights including:
- access to personal information held about you; correction of inaccurate information; erasure in applicable circumstances; restriction of processing; objection to processing, particularly where legitimate interests are relied upon; data portability where applicable; withdrawal of consent where processing depends on consent; and the right to complain to the Information Commissioner’s Office (ICO).
Not every right applies to every processing activity.
The ICO confirms that privacy information should explain the rights available to individuals and their right to complain to the supervisory authority. (ICO)
Requests concerning Riff Systems’ processing can be sent to contact@riffsystems.org.
10. Automated decision-making
Riff Systems does not currently use personal information collected
through riffsystems.org to make solely automated decisions
about website visitors that produce legal or similarly significant
effects.
The website does not currently operate visitor profiling for personalised advertising or marketing.
11. Children
The Riff Systems website is a scholarly research and publication website and is not designed as a service directed specifically at children.
Riff Systems does not intentionally ask children to create accounts or provide personal profiles through the website.
If future Riff Systems services materially change this position, the relevant privacy arrangements will be reviewed before those services are launched.
12. Security
Riff Systems takes reasonable measures appropriate to the nature of the information processed and relies on reputable infrastructure and communications providers for relevant technical services.
No internet transmission or electronic storage system can be guaranteed to be completely secure.
13. External websites
Riff Systems papers and webpages may link to journals, repositories, datasets, services and other third-party websites.
Those organisations determine their own processing of personal information. Their privacy practices are governed by their own notices and are not controlled by this Riff Systems Privacy Notice.
14. Changes to this Privacy Notice
This Privacy Notice may be updated where Riff Systems changes its website, service providers, data-processing activities or legal obligations.
The current version will identify its effective date.
A material change to how Riff Systems intentionally collects or uses personal information will be reflected in the Privacy Notice as appropriate before or when the relevant processing begins.
15. Contact and complaints
Questions, requests or concerns about privacy can be sent to:
Riff Systems Ltd Company No. 17419314 71-75 Shelton Street Covent Garden London United Kingdom WC2H 9JQ contact@riffsystems.org
You also have the right to raise concerns with the UK Information Commissioner’s Office if you believe your personal information has been handled in breach of applicable data-protection law.
