Privacy Policy
Everedge Group (United Arab Emirates) operates DRI and is the controller of the personal data described here. This notice covers three kinds of people: the applicants and administrators of member organizations, the authors named in the metadata members register, and visitors who resolve an identifier. Contact: privacy@dri-id.everedgegroup.com (ops@dri-id.everedgegroup.com until that address is live).
What we collect, and why
| Data | About whom | Purpose · legal basis | Kept |
|---|---|---|---|
| Contact name, role, email; organization name, type, country, website, identifiers | applicants, administrators | reviewing the application and running the membership · performance of the contract | life of the membership, then as records of who accepted the terms |
| Password (as a hash only), session cookie, login timestamps | administrators | authenticating you · contract | sessions expire after 14 days; reset links after 1 hour; invitations after 7 days |
| IP address | anyone who submits a form or logs in | rate limiting against abuse · legitimate interest | counted in 15–60 minute windows and swept nightly; not stored with your account |
| Billing address, tax ID, purchase-order numbers, payment references | members | invoicing · contract and legal obligation | as long as tax law requires. Card numbers never reach DRI; they are held by the payment gateway you chose |
| Audit log: which administrator did what, when | administrators, operators | integrity of a permanent registry · legitimate interest | life of the registry; the actor field can be pseudonymised on request once you leave |
| Author names, ORCID iDs, affiliations, and other bibliographic metadata | authors of registered works | publishing a persistent scholarly record · legitimate interest of the scholarly community, the same basis every DOI and PID registry relies on | permanently — see below |
| Country and referring site of a resolution | visitors | aggregate usage statistics for members · legitimate interest | no IP address or identifier of the visitor is stored |
Metadata about authors
Members register works, and the metadata that describes them — including the names of authors — is read from the member's own public pages or supplied by the member, and then published openly through the resolver, the public API and OAI-PMH, and escrowed nightly so the registry can outlive us. This is the purpose of a persistent identifier and cannot be selectively undone; a work can be withdrawn or corrected by the publishing member, and we will correct an inaccurate record on request. Authors who object to how a member has described a work should contact that member first; we will help where the member does not respond.
Who else processes your data
| Provider | What for | Where |
|---|---|---|
| Cloudflare | hosting the resolver and API; DNS; edge caching | global edge; USA |
| Turso (libSQL) | the registry database | region chosen at provisioning |
| GitHub | running scheduled jobs; holding the nightly escrow copy | USA |
| Resend | sending email | USA |
| Google (Gemini API) | extracting bibliographic metadata from the public text of a publication page when the page does not declare it in machine-readable form, and checking extracted metadata against the page | USA |
| Stripe, PayPal, Ziina, Tabby | taking payments; holding card details if you enable auto-pay | per provider |
Where data leaves the country it was collected in, we rely on the provider's standard contractual safeguards. We do not sell personal data and we do not use it for advertising.
Cookies
The portal sets one strictly necessary cookie, dri_session, to keep an
administrator signed in. The resolver and the public API set none. There is no analytics or
advertising tracking.
Your rights
Depending on where you are, you may have the right to access, correct, export or erase your personal data, to object to or restrict its processing, and to complain to a supervisory authority. Administrators can see and edit their own details in the portal; for anything else write to privacy@dri-id.everedgegroup.com and we will answer within 30 days. Erasure has one limit we state up front: the audit trail of a permanent registry, and the published metadata that other people's citations already depend on, are retained; personal identifiers in them are pseudonymised where the law requires.
Security
Passwords are stored only as salted PBKDF2 hashes; session and reset tokens only as hashes;
tenant data is isolated per organization; the crawler reaches only hosts a member enrolled;
payment webhooks and publisher webhooks are signature-verified and fail closed. Report a
vulnerability to security@dri-id.everedgegroup.com
(/.well-known/security.txt).
Changes
We will post changes here and notify member administrators of material ones by email.