Who is responsible
The Material Record determines why and how personal data is used for this independent archive and website. The public repository does not currently identify a separate registered company, legal person acting as controller, or postal address, so this notice does not invent one.
Privacy questions, requests, objections and corrections can be sent to archive@thematerialrecord.org.
Public catalogue and imagery
The public catalogue describes cultural objects and their relationships to people, organisations, publications, events, themes and collections. That information may include names, roles, biographical or organisational context, credited creative work and other information already connected with the public cultural record.
Public catalogue pages, sitemaps, search indexes and imagery are intended to be found, indexed, quoted and linked by search engines, researchers and other visitors. Public images are delivered from images.thematerialrecord.org using Cloudflare R2; the website itself is delivered through Cloudflare Pages.
Publication is based on the archive’s legitimate interests in accurate cultural documentation, research, preservation and public access, balanced against the rights of the people concerned. Uncertainty and disputed information should be recorded rather than silently resolved.
Ordinary website and security data
When a visitor requests a page or image, Cloudflare may process the IP address, date and time, requested URL, request and response metadata, browser or device information, network identifiers, security signals and diagnostic logs needed to deliver, cache, protect and troubleshoot the service. This is used for reliable delivery, abuse prevention and security.
The Material Record does not include advertising, marketing trackers or public visitor analytics in the audited site code. If that changes, this notice and the need for consent will be reviewed before deployment.
Private archive and owner controls
Private archive pages are restricted to the owner through Cloudflare Access. Access processes authentication and session information and can make the authenticated email address available to the private application. Private Cloudflare D1 records may contain acquisition information, working valuations, seller or source information, private provenance, conservation notes, internal research notes and owner-only audit revisions.
Accession and editorial controls also process immutable requests, lifecycle state, publication results, revision locks, workflow references, audit history and other control information needed to keep permanent identifiers, publication and private changes accountable. Preservation images and receipts use Cloudflare R2. These private systems are not exposed through the public catalogue.
GitHub, Microsoft, OpenAI and ChatGPT
The private GitHub repository and GitHub Actions process website source, structured catalogue material, private operational source files, validation output, commits, reviews and workflow logs. GitHub is a Microsoft company, so GitHub and Microsoft may process this material as part of providing those services.
OpenAI processes TMR information when the owner or another authorised user deliberately uses ChatGPT, Codex or the authenticated TMR connector. This can include the owner’s instructions, selected public or private archive information, connector requests and responses, and the authentication or control data needed for that session. Ordinary public website visits do not send catalogue browsing activity to OpenAI through TMR site code.
Cookies and browser storage
The public site does not set advertising or analytics cookies. The optional research selection uses browser storage when you save objects.
- Research selection: when you save objects,
tmr-research-selection-v1stores their public TMR identifiers in this browser. The selection is not uploaded to an account or tracking service. You can remove individual objects or clear the selection on the selection page; clearing site data also removes it. It has no automatic expiry. Share links contain public object identifiers in the URL fragment and can be read by anyone you give the link to. If browser storage is unavailable, changes last only on the current page. - Cloudflare Access: strictly necessary authentication and session cookies or equivalent storage may be used when the owner signs in to private routes. Cloudflare security services may also use strictly necessary storage when needed to distinguish legitimate requests from abuse.
tmr_private: after the owner deliberately enters the private archive, the site stores the valuetmr_private=1in local storage. It only tells the browser to request owner-only details on relevant pages. It contains no token, email, catalogue record or private value, and it is removed on sign-out or if authentication fails.
The research selection and private-mode preference are the browser storage used by the public application.
Retention
Public catalogue records and their documented history are kept for the long-term archival purpose, subject to correction, legal obligations and applicable rights. Permanent identifiers, accession history, editorial history, private audit history, provenance and preservation evidence are not treated as temporary authentication data.
Private operational and provider records are retained according to their archival or security purpose, the need to preserve an accountable history, repository and service configuration, legal requirements, and the relevant Cloudflare, GitHub/Microsoft or OpenAI service terms. No unsupported fixed period is stated where the repository does not establish one.
Temporary TMR OAuth consent grants and authorisation codes expire after 5 minutes; access tokens after 12 hours; and refresh tokens after 30 days. Expired grants, tokens, consent results and their one-time-use markers become eligible for bounded deletion only after an additional 1-day safety period. The latest temporary OAuth diagnostics become eligible after 30 days plus the same safety period. Cleanup never includes permanent, accession, publication, provenance, audit, editorial or preservation records.
International processing
Cloudflare, GitHub/Microsoft and OpenAI operate internationally and may process information outside the United Kingdom. Where UK data-protection law applies, international processing is handled under the relevant provider arrangements and lawful transfer safeguards. The exact location can depend on the service, account configuration and request.
Your rights and corrections
Depending on the circumstances, UK data-protection rights can include access, correction, erasure, restriction, objection and data portability, and the right to withdraw consent where consent is the basis used. Archival accuracy, freedom of expression, legal obligations and other lawful grounds may affect how a request is resolved.
To correct a public person, organisation or object record, object to processing, or make a privacy request, email archive@thematerialrecord.org with enough detail to identify the relevant page or record. Identity may need to be checked before private information is disclosed.
You also have the right to complain to the UK Information Commissioner’s Office. See Make a data protection complaint to the ICO.
Changes
This notice will be reviewed when the archive changes its public tracking, authentication, hosting, connected applications or handling of personal data. Material changes will be dated on this page.
Known publication gap: the exact legal controller identity and a controller postal address have not yet been confirmed in the repository. The verified public contact route above is available in the meantime.