Privacy
How Virtual Franciscans OÜ handles personal data for the SPACE CODE journal.
Effective 16 July 20261. Controller
The data controller is Virtual Franciscans OÜ, registry code 16190480, EU VAT EE102428687, registered at Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia. Privacy enquiries may be sent to [email protected].
2. Scope and data collected
This policy applies to spacecode.franciscans.dev and the complete magazine issues published there. The public website has no registration, comments, contact form, or advertising.
- Technical request data: IP address, request time, requested URL, referrer, browser or user-agent information, and security events generated when a browser connects to the site.
- Analytics data after consent: Google Analytics may process cookie identifiers, approximate location, device and browser characteristics, page views, referrers, and interactions with the site.
- Correspondence: if you email us, we receive your email address, message, attachments, and the information you choose to provide.
- Editorial account data: authorised editors use private WordPress accounts. This does not apply to ordinary readers.
3. Purposes and legal bases
- Delivering pages and PDF issues, maintaining availability, preventing abuse, diagnosing errors, and protecting the service rely on our legitimate interests under GDPR Article 6(1)(f).
- Google Analytics is used to understand readership and improve the journal only after consent under GDPR Article 6(1)(a). Advertising storage, ad personalisation, and Google signals remain disabled.
- Answering editorial and general enquiries relies on our legitimate interests or steps taken at your request under Article 6(1)(f) or 6(1)(b), as applicable.
- Records required by law are processed under Article 6(1)(c).
We do not use personal data for automated decision-making, behavioural advertising, or sale.
4. Cookies and consent
Google Analytics does not load until you choose “Allow analytics” in the consent panel. If you choose “Essential only,” analytics remains disabled. Your consent preference is stored for 180 days in a first-party cookie named sc_analytics_consent_v1. When analytics is allowed, Google Analytics may set first-party cookies beginning with _ga. You can reopen Cookie settings in the footer at any time; withdrawing consent disables analytics and removes accessible Google Analytics cookies from this site. Strictly necessary security and authenticated-editor cookies may operate without analytics consent.
5. Recipients and processors
Data is available only to authorised personnel and service providers where needed to operate the journal. Infrastructure providers process limited technical data for hosting, delivery, and security. When you consent to analytics, Google Ireland Limited processes analytics data on our behalf. We disclose data to public authorities only where legally required.
6. International transfers
The publisher is established in Estonia and the journal infrastructure is operated within the European Union. Some service providers, including Google and network-protection providers, may process limited data outside the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission Standard Contractual Clauses, or another lawful safeguard.
7. Retention
- Routine technical and security logs use bounded rotation and are retained only for the shortest period needed to operate, secure, and diagnose the service. A specific security-event extract may be kept longer where necessary to investigate abuse or establish legal claims.
- Google Analytics data is retained according to the retention settings in the SPACE CODE Analytics property; Google Analytics cookies can persist for up to two years unless they are deleted earlier or consent is withdrawn.
- Editorial correspondence is normally kept for up to 24 months after the last substantive exchange, or longer where needed to resolve a dispute or meet a legal duty.
- Editorial account records are kept while access is authorised and removed or anonymised when no longer needed.
8. Your rights
Subject to the conditions in the GDPR, you may request access, correction, erasure, restriction, objection, and data portability, and may withdraw consent where consent is the legal basis. Send a request to [email protected]. We may ask for information necessary to verify identity. You will not be charged unless a request is manifestly unfounded or excessive.
9. Complaints
You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee, or to the supervisory authority in the EU or EEA country where you live or work.
10. Security
We use access controls, encrypted transport, software updates, backups, and network protections proportionate to this publication. No internet service can guarantee absolute security.
11. Changes
Material changes will be published on this page with a revised effective date. This version is effective 16 July 2026.