This Privacy Policy explains how macrocosma processes personal data when you create an account, build a professional profile, publish or respond to an open call, submit a scientific event, or otherwise use the platform.
The controller is the non-governmental organisation Crnogorski naučno tehnološki Hub ZNANJE-EPISTEME (epiSTEMe Hub), registration number UPI 01-056/24-613/4, Luke Ivaniševića 28, 81250 Cetinje, Montenegro. You can contact us at epistemecetinje@gmail.com.
We process personal data under the Law on Personal Data Protection of Montenegro (Official Gazette of Montenegro Nos. 79/08, 70/09, 44/12, 22/17 and 77/24) and other applicable law. If another mandatory data-protection regime applies to you, we will also respect the rights it gives you.
1. Who this policy covers
This policy covers visitors to the public macrocosma website, people who sign in or apply for membership, verified members, administrators, and people whose professional information is entered by an authorised administrator.
macrocosma is a professional community for scientists, young scientists and industry experts connected with Montenegro. It is not intended for children. A person under 18 may use the platform only with the prior permission and involvement of a parent or legal guardian, and we may ask for proof of that permission.
2. Personal data we collect
We collect data directly from you, from an administrator who creates a profile at your request or under an existing relationship with you, and automatically when you use the service.
Account and identity data
- Your name, primary email address, account identifier, user type, verification status and the time and source of verification.
- Authentication records needed for passwordless email-code login, such as login time, security events, IP address and browser or device information. Authentication is provided through our Keycloak service.
- Where an administrator creates or reviews an account, we record the administrator responsible for the action.
Profile and eligibility data
- Optional contact and profile details: additional email, work and mobile telephone numbers, LinkedIn handle, website, skills, biography, profile photo and cover photo.
- For scientists: title, ORCID identifier, university and research field.
- For young scientists: university, field of study, ISIC identifier and a student-card image used to verify eligibility.
- For industry experts: title, employer or institution, professional base, field of specialisation, biography and an optional external link.
Content and activity
- Open calls you publish, including their description, type, deadline, location, working mode, compensation, duration, tags and status.
- Scientific events you submit, including their title, description, location, dates, format and tags.
- A count of applications or expressions of interest submitted through the platform. The current application action records the count and does not send an application file or full application profile to the publisher.
- Technical upload metadata, including filename, file type, file size, checksum, storage identifier and upload or attachment time.
3. Why we use personal data
We use only the data reasonably needed for the following purposes and legal grounds:
- To create and administer your account, authenticate you, provide platform functions and respond to your requests. This processing is necessary to provide the service you ask us to provide and to take steps at your request before you join.
- To verify that a member belongs to the selected professional category, prevent false profiles and protect the integrity of the community. We rely on your request to join and our legitimate interest in operating a trusted professional network.
- To display your member profile, contact details and content to other verified members. We do this to provide the networking service you request. Optional fields can be removed from your profile at any time.
- To publish institution-level locations and aggregate statistics on the public website without intentionally identifying individual members. We rely on our legitimate interest in showing the reach and composition of the scientific community.
- To operate, secure, troubleshoot and improve the platform, prevent abuse, enforce this User Agreement and keep necessary audit records. We rely on our legitimate interests in a reliable and secure service.
- To send login codes, verification updates, service messages and responses to support requests. These communications are necessary to provide and protect the service; we do not use them for unrelated advertising without a separate lawful basis.
- To comply with legal obligations, lawful requests from authorities, and the establishment, exercise or defence of legal claims.
4. Who can see your information
Verified members can browse member cards and profiles. Depending on what you enter, a profile may show your name, category, title, institution, field, biography, skills, photos, ORCID identifier, location or professional base, links and contact details. Open calls and scientific events also identify the member who published them.
Visitors who are not signed in can access public institution-level map information and aggregate analytics. We do not intentionally include names, contact details, profile photos, student-card images or individual activity in those public results.
Platform administrators can access account, verification and moderation information needed for their role. Student-card images and ISIC identifiers are used for verification and are not shown on member profiles or public analytics.
A signed profile-image URL contains a short-lived access token. Anyone who receives the complete URL while it remains valid may load that image, so do not forward it outside the platform.
5. Service providers and other recipients
We share personal data only where necessary for the purposes in this policy. Recipients may include authorised epiSTEMe Hub administrators; the platform developer and technical maintenance providers acting under our instructions; hosting, database, file-storage, backup and email-delivery providers; professional advisers; and public authorities where disclosure is required by law.
We use Cloudflare Turnstile during authentication to detect automated abuse. Cloudflare receives the technical information required to perform that check, which may include your IP address and browser or device signals. Institution names may be sent from our server to OpenStreetMap Nominatim to obtain institution-level coordinates. External links that you choose to open, including ORCID, LinkedIn and member websites, are governed by the privacy practices of those services.
We do not sell personal data and do not disclose it for third-party behavioural advertising.
6. International processing
Some service providers or their infrastructure may process data outside Montenegro. Before such processing, we assess the recipient, limit the data disclosed and use the safeguards required by applicable law, such as contractual data-protection obligations. You may contact us for information about the safeguards relevant to your data.
7. How long we keep data
We keep personal data only for as long as it is needed for the purpose for which it was collected, for the operation of an active account, or for a legal obligation or claim. We periodically review whether retained data is still necessary.
- Account and profile data are normally kept while the account is active. After an accepted deletion request, we delete or anonymise the data unless a legal obligation, active dispute or necessary security record requires limited retention.
- An uploaded file that is not attached to a profile is automatically scheduled for deletion after 24 hours.
- A profile or cover photo is deleted from active storage when you use the removal control, subject to short-lived technical copies and backups.
- A student-card image is retained with the verification record while the account is active, unless an earlier erasure request is accepted. Access is restricted to authorised administrators. We delete it when it is no longer needed to document or resolve the eligibility review.
- Cancelled open calls remain recorded as cancelled so that existing links show the correct status and aggregate statistics remain accurate. We minimise or anonymise the associated personal data when it is no longer needed.
- Security and operational logs are kept for a limited period based on their purpose, risk and applicable legal requirements. Backup copies are removed through the normal backup rotation.
8. Security
We use organisational and technical measures appropriate to the nature of the data and the risks of processing. These include role-based access, authenticated API access, separate administrator permissions, passwordless email-code authentication, limits on login attempts, restricted media access, short-lived signed image URLs, file validation and protected storage. No internet service can guarantee absolute security.
If a personal-data incident creates a legal duty to notify affected people or the competent authority, we will provide the notice required by applicable law.
9. Your rights
Subject to the conditions and exceptions in applicable law, you may ask whether we process your data and request access to it, information about its source and use, correction or completion of inaccurate data, deletion of unlawfully processed or unnecessary data, restriction or cessation of particular processing, and withdrawal of consent where consent is the legal ground. Withdrawal does not affect processing that was lawful before withdrawal.
You may also object to processing based on our legitimate interests and request a human review if we ever introduce a decision based solely on automated processing that significantly affects you. We currently do not make such solely automated decisions.
Send a request to epistemecetinje@gmail.com. Describe the request and the account concerned. We may ask for information needed to confirm your identity and protect the account. We will act within the period required by law and explain any lawful reason for refusing or limiting a request.
You may seek protection from the Agency for Personal Data Protection and Free Access to Information, Bulevar Revolucije 11, 81000 Podgorica, Montenegro, azlp@azlp.me, www.azlp.me, or before a competent court. Contacting us first may allow us to resolve the matter more quickly, but it is not a condition of approaching the Agency.
10. Your choices and responsibilities
You can edit many profile fields and remove profile or cover images from your profile. You may leave optional contact fields blank. Because member profiles support professional discovery and trust, you must keep required identity, affiliation and eligibility information accurate.
If you provide personal data about another person in an event, open call, biography or other content, you must have a lawful reason to do so and give that person any notice required by law.
11. Changes to this policy
We may update this policy when the platform, our providers or applicable law changes. We will publish the revised version with a new date and, where a change materially affects your rights or how we use data, provide an additional notice through the platform or by email before the change takes effect where required.
12. Contact
For privacy questions, rights requests or complaints, contact Crnogorski naučno tehnološki Hub ZNANJE-EPISTEME (epiSTEMe Hub) at epistemecetinje@gmail.com or Luke Ivaniševića 28, 81250 Cetinje, Montenegro.