Privacy and consent
Privacy Policy
How L&FIT Network collects, uses, shares and protects personal information when people visit the website, apply for membership or contribute content.
About this notice
Last updated: 1 August 2026. This notice applies to visitors, applicants, members and people who submit guest comments. L&FIT Network manages this website. Before public launch, this section will be updated with the formally approved data-controller identity and direct privacy contact. Until then, privacy questions can be sent through our Contact us page.
Information we collect
When you apply for membership, we collect your chosen username, name, private login email address, password hash, email-verification state and the outcome of human membership review. We also keep a limited audit record of approval or rejection decisions.
If you complete a member profile, we may collect your affiliation, role, country, biography, research interests, website, social-media link and an optional display email. You decide whether to join the directory and how the applicable profile fields are shared.
When you contribute content, we keep post drafts and submissions, uploaded images and alternative text, categories, tags, comments, review decisions, dates and workflow messages. A guest commenter supplies a public name, a private email address and their comment.
How and why we use information
We use personal information to verify accounts, assess membership applications, provide secure sign-in and password recovery, operate the member directory, publish approved contributions, moderate the community and protect the service from abuse. We do not use automated decision-making or profiling.
The intended lawful bases are our legitimate interests in operating a secure, well-moderated research network; consent for optional directory publication and newsletter preferences; and legal obligations where they apply. The final controller must confirm and record these bases before production launch.
Directory and profile visibility
Joining the members directory is optional. If you opt in, your name, username and any supplied role and affiliation are shown in the directory. Other applicable fields can be Public, Members only or Private. Public information is visible without signing in and may be indexed or copied by search engines and other services. Members-only information is available to approved signed-in members. Private information is limited to you and authorised staff who need it to operate the service.
Separately, when a registered user has a published post or approved member comment, their name links to the same public profile page used for directory members. If they have not joined the directory, that page shows only their name, username and any supplied role and affiliation. This attribution does not add them to the members directory, and no other profile fields are shown on that basis.
Your login email is never directory or public-profile content. An optional display email is separate: if you choose to make it Public, it cannot be made reliably inaccessible to automated collection. You can change your directory and field-visibility choices from My Profile.
Posts, comments and moderation
Approved posts show the author's name linked to their profile. Post authors and authorised reviewers can see the associated submission and moderation conversation. Those workflow records are retained as an append-only history so that decisions are accountable.
Comments from approved, signed-in members are published immediately with the member's name and username linked to their profile, but may later be moderated or archived. For each guest comment, we send a private email verification link that expires after 48 hours. The comment enters staff moderation only after verification. Unverified comments are deleted after the link expires. If approved, the guest's name and comment become public without a member-profile link; the guest email remains private and is erased when a moderation or archive decision is made. Guest comments also use a one-way network fingerprint and duplicate signature to limit spam without storing the submitted network address in the comment record.
Newsletter preferences and email
Newsletter consent is optional and separate from essential account email. Opt out is the default. Members can choose Daily, Weekly or Monthly. Visitors can request the same preference with their name and email address, plus an optional role and affiliation. We store the pending request, consent time, notice version and a one-way network fingerprint used to limit abuse, then send a time-limited verification link. Opening the link does not confirm the request: the visitor must explicitly submit the confirmation form.
Only verified visitors appear with opted-in members in the protected Newsletter subscribers list for Administrators and Editors. The website does not currently deliver newsletters or send these preferences to a mailing provider. Transactional messages such as email verification, password reset and review outcomes are sent through Infomaniak Mail.
Cookies and technical information
The website uses first-party cookies that are necessary for security, forms, sign-in and session continuity. These include a session cookie for signed-in use and a CSRF cookie that helps prevent forged form submissions. We also use local browser storage only to remember that you dismissed the cookie notice. We do not currently use analytics, advertising or social-tracking cookies. A separate consent control will be added before any non-essential cookies or similar technologies are introduced.
The production web server and hosting platform may keep short-lived request and security logs, such as timestamps, requested pages, browser information and network addresses. The provider and final log-retention period will be documented before launch.
Sharing, service providers and transfers
We do not sell personal information. Authorised Editors, Moderators and administrators can access only the information needed for their duties. Infrastructure providers may process data on our instructions to host the application, database, encrypted backups, media and transactional email.
Infomaniak provides the initial hosting and transactional mail services, and encrypted recovery archives are stored in Google Drive. Newsletter preferences remain inside the website until the mailing service is approved and connected. The controller must document each provider's role, location, security, retention and any safeguards required for transfers outside the UK before public launch.
How long we keep information
Account and profile information is kept while an account remains active and afterwards only as needed to close the account, resolve disputes, protect the service or meet legal obligations. Published posts and comments may be retained as part of the network's scholarly and community record, while moderation tools favour reversible archiving over routine deletion.
A guest email is erased when its comment is approved, rejected or archived. Before production launch, the controller must approve specific periods for rejected applications, inactive accounts, pending guest comments, workflow audit records, server logs and backups. The published notice will be updated with those periods.
Security
Access is role-based, ordinary members use the frontend rather than the content-management administration, passwords are not stored in readable form, uploads are validated and member content is treated as untrusted. Rate limits and duplicate checks protect comment forms. No internet service can guarantee absolute security; suspected incidents will be assessed and handled under the network's response process.
Your data-protection rights
Depending on the information and lawful basis, you may have rights to access, correct, erase, restrict or object to our use of your information, and to receive portable information. You can withdraw directory or newsletter consent at any time without affecting earlier lawful use. Use the Contact us page to make a request or raise a concern. We may need to verify your identity.
If a concern is not resolved, you can complain to the UK Information Commissioner's Office through its complaints service. The rights available in a particular case depend on data-protection law and the reason the information is used.
Children
The network is intended for postgraduate researchers, early-career researchers and other adult participants. It is not designed for children, and applications from people under 18 should not be approved without a separate safeguarding and privacy review.
Changes to this notice
We will update this page when website functions, providers or governance arrangements change, and will revise the date above. Material changes affecting members will also be communicated through an appropriate account or email notice.
Contact enquiries
When you use the Contact us form, we store your selected category, name, email address, subject, message, submission time, privacy acknowledgement and a reference number as a delivery-safety copy. We also store one-way network and duplicate fingerprints to limit spam; the submitted network address is not stored in the enquiry record.
The website sends an acknowledgement to the address you provide and sends the complete enquiry to the monitored L&FIT contact mailbox so authorised staff can reply directly. The safety copy is not exposed as a routine CMS work queue. It is retained while delivery and the enquiry are handled; the precise retention and deletion schedule still requires governance approval before public launch.