Skip to main content
Ctrl K

IMPERIAL RESEARCH SOFTWARE DIRECTORY PRIVACY NOTICE

What is the purpose of this document?

The College is a "data controller". This means that we are responsible
for deciding how we hold and use personal information about you. We are
required under data protection legislation to notify you of the
information contained in this privacy notice.

This notice applies to all users of Imperial's Research Software
Directory website. This notice does not form part of any contract of
employment or other contract to provide services. We may update this
notice at any time.

It is important that you read this notice, together with any other
privacy notice we may provide on specific occasions when we are
collecting or processing personal information about you, so that you are
aware of how and why we are using such information.

Data protection principles

We will comply with data protection law. This says that the personal
information we hold about you must be:

  1. Used lawfully, fairly and in a transparent way.
  2. Collected only for valid purposes that we have clearly explained
    to you and not used in any way that is incompatible with those
    purposes.
  3. Relevant to the purposes we have told you about and limited only
    to those purposes.
  4. Accurate and kept up to date.
  5. Kept only as long as necessary for the purposes we have told you
    about.
  6. Kept securely.

The kind of information we hold about you

Personal data, or personal information, means any information about an
individual from which that person can be identified. It does not
include data where the identity has been removed (anonymous data).

The RSD stores personal data of:

  • Persons who have contributed to the development of the Research
    Software as project team members or as software contributors
    (developers) (each a Contributor);
  • Persons who have published materials about the Research Software
    itself or about results produced using the Research Software, e.g.
    in papers, books, journals, blogs, video's etc. (each also a
    Contributor);
  • Users of the RSD, including users who are appointed as maintainers
    of an Organization's account ("Maintainers").

Visitors to the RSD website can view the personal data of Contributors
that is shared publicly as part of the academic context of Research
Software and projects. Visitors and Users cannot view the personal data
of other Users, unless this personal data has intentionally been
published to indicate this User is also a Contributor.

Within the Research Software Directory service, for registered users
(i.e. anyone who has signed in to the system) we may collect, store, and
use the following categories of personal information about you:

  • Personal contact details such as your name, title, and personal
    email addresses.

  • Your Imperial department and job title

    For all users of the Research Software Directory website, whether
    you are registered or not, we may collect, store, and use the
    following categories of personal information about you:

  • IP addresses of devices you use to access the website

  • Information about your use of our information and communications
    systems

How is your personal information collected?

We collect the personal information about you through your Imperial user
account (if you are signed in to the website as an Imperial user) or, if
you are an external user or member of the public using this service and
are not signed in, through storage of data that is automatically sent by
the device that you are using to interact with the website.

Furthermore, we can obtain / users can provide additional personal
data where the individual is a Contributor from the following sources:

  • ORCID is a non-profit organization that
    seeks to support open access to information for the research
    community. If you have created an ORCID account and if you are a
    Contributor with respect to specific Research Software included in
    the RSD, we import personal data from your ORCID profile (name,
    ORDIC ID, organization you work for) which you have qualified in
    ORCID as public data. Users can add that data to the Research
    Software's entry in the RSD to list someone as a Contributor. Your
    ORCID ID is included in the RSD so that Visitors can easily find
    your ORCID profile. Please find ORCID's privacy policy
    here.

  • Crossref is a not-for-profit
    membership organization that exists to make scholarly
    communications better and makes research objects easy to find,
    cite, link, assess, and reuse. Crossref members can add metadata
    with respect to their publications to the Crossref database. To
    add Mentions to Research Software and Projects, Users can import
    metadata from Crossref, specifically the publication title, date,
    venue, and the names and affiliations of Contributors. Please find
    Crossref's privacy policy
    here.

  • DataCite is a global non-profit
    organization that provides persistent digital object identifiers
    (DOIs) for research data and other research outputs. DataCite
    members can add DOIs and metadata with respect to their
    publications to the DataCite database. The database is made
    publicly available. To add Mentions to Research Software and
    Projects, Users can import metadata from Datacite, specifically
    the publication title, date, venue, and the names and affiliations
    of Contributors. Please find DataCite's privacy policy
    here.

  • Zenodo is a repository that helps
    researchers receive credit by making the research results citable
    via a DOI. The Zenodo database is made publicly available. Through
    OpenAIRE, these results are integrated into existing reporting
    lines of funding agencies like the European Commission. When
    adding Research Software, Users may add the DOI of the Software
    Releases the have archived in Zenodo. Using this DOI, Users can
    then import metadata about the software from Zenodo, such as the
    list of Contributors (including their name and, -if available-,
    ORCID), Software License, and Keywords. In addition, the RSD will
    automatically create an up-to-date list of software releases, and
    present those to Visitors, including proper citation information.
    Please find the Zenodo privacy policy
    here.

  • Github is an online software development
    platform which provides version control, continuous integration,
    issues, etc. When adding Research Software, Users may add the
    GitHub repository URL to the Research Software Entry. Besides
    showing this URL to visitors, the RSD will also use it to retrieve
    public information about the software development from GitHub,
    including the programming languages used, the licence, and the
    development activity (such as commits.) Although publicly
    displayed user names of developers will be imported through this
    GitHub feed, only aggregated data on development activity will be
    shown to Visitors. Please find the Github privacy policy
    here.

  • GitLab in an online software development
    platform which provides version control, continuous integration,
    issues, etc. When adding Research Software, Users may add the
    GitLab repository URL to the Research Software Entry. Besides
    showing this URL to visitors, the RSD will also use it to retrieve
    public information about the software development from GitLab,
    including the programming languages used, the licence, and the
    development activity (such as commits). Although publicly
    displayed user names of developers will be imported through this
    GitLab feed, only aggregated data on development activity will be
    shown to Visitors. Please find the GitLab privacy policy
    here.

How we will use information about you and the legal basis for processing your data under the GDPR

We will only use your personal information when the law allows us to.
Most commonly, we will use your personal information in the following
circumstances:

  • Where it forms part of the contract / agreement with you to
    provide services relating to the RSD*.

  • Where we need to comply with a legal obligation**.

  • Where it is necessary for our legitimate interests (or those of a
    third party) and your interests and fundamental rights do not
    override those interests***.

  • Where you have consented to the processing****.

Situations in which we will use your personal information

We need all the categories of information in the list above (see The
kind of information we hold about you) primarily to access and use the
RSD. In some cases we may use your personal information to pursue
legitimate interests of our own or those of third parties[**],
provided your interests and fundamental rights do not override those
interests. We have indicated by [asterisks] the purpose or purposes
for which we are processing or will process your personal information,
as well as indicating which categories of data are involved.

  • To ensure network and information security, including preventing
    unauthorised access to our computer and electronic communications
    systems and preventing malicious software distribution**.

  • To enable you to use view the Research Software Directory and make
    use of the functionality that it provides*.

  • To conduct data analytics studies to review and better understand
    how research software is developed and used***.

The following describe how we will process your personal information
which is depend on whether you are a Contributor to or User of the RSD:

Contributors:

  1. Show Visitors which Contributors contributed to the relevant
    Research Software and Projects;*

  2. Show Visitors relevant publications about the Research Software and
    to show the Contributor's of such publications;*

  3. Direct Visitors to more information about a Contributor, i.e.,
    through an ORCID-ID;*

  4. Allow Users to add Contributors to the relevant Research Software
    and/or Project entry;****

  5. To contact you in relation to software that you or your
    collaborators have added to the directory.*

  6. To administer and fulfil requirements as agreed in the Terms of
    Use;*

  7. Where we need to comply with a legal obligation;**

Users:

  1. Allow Users to create, use and manage their Account;*

  2. Verify their authorization to create and use an Account;*

  3. Verify their access to the Account and, where required, to take
    appropriate actions, e.g. block the Account in case of
    unauthorized access;*/**/***

  4. Allow us to create and manage Accounts of Organization
    Maintainers;**

  5. Keep an administration with respect to the Users;*

  6. Enforce the Terms of Service;*

  7. Where we need to comply with a legal obligation;**

Some of the above grounds for processing will overlap and there may be
several grounds which justify our use of your personal information.

If you fail to provide personal information

If you fail to provide certain information when requested, we may not be
able to provide you with access to the directory and allow you to list
your software on the platform.

Change of purpose

We will only use your personal information for the purposes for which we
collected it, unless we reasonably consider that we need to use it for
another reason and that reason is compatible with the original purpose.
If we need to use your personal information for an unrelated purpose, we
will notify you and we will explain the legal basis which allows us to
do so.

Please note that we may process your personal information without your
knowledge or consent, in compliance with the above rules, where this is
required or permitted by law.

Automated decision-making

We do not envisage that any decisions will be taken about you using
automated means, however we will notify you in writing if this position
changes.

Data sharing

Why might you share my personal information with third parties?

We may share your personal information with third parties where required
by law, where it is necessary to administer the relationship with you or
where we have another legitimate interest in doing so.

Which third-party service providers process my personal information?

"Third parties" includes third-party service providers (including
contractors and designated agents) and other entities within the College
group.

The content stored in the Research Software Directory may be held at
premises and/or on computer systems owned and administered by third
parties, e.g. for cloud-based deployment of the website.

How secure is my information with third-party service providers and
other entities in our group?

All our third-party service providers and other entities in the College
group are required to take appropriate security measures to protect your
personal information in line with our policies. We do not allow our
third-party service providers to use your personal data for their own
purposes. We only permit them to process your personal data for
specified purposes and in accordance with our instructions.

What about other third parties?

We may share your personal information with other third parties, for
example in the context of the possible sale or restructuring of the
business and operations of the College. We may also need to share your
personal information with a regulator or to otherwise comply with the
law.

Transferring information outside the UK

In some cases, it is possible that third-party hosting providers
involved in cloud-based storage and deployment of the Research Software
Directory and its data may transfer and/or store this data outside of
the UK. This applies to the publicly accessible data within the
directory as well names and email addresses of users. Other personal
user data remains within the College's authentication infrastructure and
is not stored by the Research Software Directory.

However, to ensure that your personal information does receive an
adequate level of protection we always put in place the following
appropriate measure[s] to ensure that your personal information is
treated by those third parties in a way that is consistent with and
which respects UK legislation relating to data protection;

  • Implementation and completion of Standard Contract Clauses /
    International Data Transfer Agreement.

  • Completion of a Transfer Impact Assessment.

  • Utilisation of available frameworks that support the implementation
    of secure practices. Would include the UK / US Data Bridge

Data security

We have put in place appropriate security measures to prevent your
personal information from being accidentally lost, used or accessed in
an unauthorised way, altered or disclosed. In addition, we limit access
to your personal information to those employees, agents, contractors and
other third parties who have a business need to know. They will only
process your personal information on our instructions and they are
subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security
breach and will notify you and any applicable regulator of a suspected
breach where we are legally required to do so.

Data retention

How long will you use my information for?

We will only retain your personal information for as long as necessary
to fulfil the purposes we collected it for, including for the purposes
of satisfying any legal, accounting, or reporting requirements. Details
of retention periods for different records the College holds are
available in our retention policy which is available on this website:
http://www.imperial.ac.uk/media/imperial-college/administration-and-support-services/records-and-archives/public/RetentionSchedule.pdf.

To determine the appropriate retention period for personal data, we
consider the amount, nature, and sensitivity of the personal data, the
potential risk of harm from unauthorised use or disclosure of your
personal data, the purposes for which we process your personal data and
whether we can achieve those purposes through other means, and the
applicable legal requirements.

In some circumstances we may anonymise your personal information so that
it can no longer be associated with you, in which case we may use such
information without further notice to you.

Rights of access, correction, erasure, and restriction

Your duty to inform us of changes

It is important that the personal information we hold about you is
accurate and current. Please keep us informed if your personal
information changes during your relationship with us.

Your rights in connection with personal information

Under certain circumstances, by law you have the right to:

  • Request access to your personal information (commonly known as a
    "data subject access request"). This enables you to receive a copy
    of the personal information we hold about you and to check that we
    are lawfully processing it.

  • Request correction of the personal information that we hold
    about you. This enables you to have any incomplete or inaccurate
    information we hold about you corrected.

  • Request erasure of your personal information. This enables you
    to ask us to delete or remove personal information where there is no
    good reason for us continuing to process it. You also have the right
    to ask us to delete or remove your personal information where you
    have exercised your right to object to processing (see below).

  • Object to processing of your personal information where we are
    relying on a legitimate interest (or those of a third party) and
    there is something about your particular situation which makes you
    want to object to processing on this ground. You also have the right
    to object where we are processing your personal information for
    direct marketing purposes.

  • Request the restriction of processing of your personal
    information. This enables you to ask us to suspend the processing of
    personal information about you, for example if you want us to
    establish its accuracy or the reason for processing it.

  • Request the transfer of your personal information to another
    party.

If you want to review, verify, correct or request erasure of your
personal information, object to the processing of your personal data, or
request that we transfer a copy of your personal information to another
party, please contact the College's Data Protection Officer in writing.

No fee usually required

You will not have to pay a fee to access your personal information (or
to exercise any of the other rights). However, we may charge a
reasonable fee if your request for access is clearly unfounded or
excessive. Alternatively, we may refuse to comply with the request in
such circumstances.

What we may need from you

We may need to request specific information from you to help us confirm
your identity and ensure your right to access the information (or to
exercise any of your other rights). This is another appropriate security
measure to ensure that personal information is not disclosed to any
person who has no right to receive it.

Right to withdraw consent

In the limited circumstances where you may have provided your consent to
the collection, processing and transfer of your personal information for
a specific purpose, you have the right to withdraw your consent for that
specific processing at any time. To withdraw your consent, please
contact the College's Data Protection Officer. Once we have received
notification that you have withdrawn your consent, we will no longer
process your information for the purpose or purposes you originally
agreed to, unless we have another legitimate basis for doing so in law.

Data Protection Officer

We have appointed a Data Protection Officer to oversee compliance with
this privacy notice. If you have any questions about this privacy notice
or how we handle your personal information, please contact the Data
Protection Officer at:

Imperial College London
Data Protection Officer
Exhibition Road
Faculty Building Level 4
London SW7 2AZ

e-mail: dpo@imperial.ac.uk

You have the right to make a complaint at any time to the Information
Commissioner's Office (ICO), the UK supervisory authority for data
protection issues.

Changes to this privacy notice

We reserve the right to update this privacy notice at any time, and we
will provide you with a new privacy notice when we make any substantial
updates. We may also notify you in other ways from time to time about
the processing of your personal information.