Privacy Policy

This Privacy Policy explains how ArchaeoLocus.org processes personal data when you use the website or contact ArchaeoLocus.

Controller and contact

The controller for personal data processed directly through ArchaeoLocus.org is Eric C.B. Cauchi | ArchaeoLocus | Greece. For privacy or data-protection enquiries, contact contact@archaeolocus.org.

What the public website currently does

ArchaeoLocus.org is an independent research and publication website. The public site does not currently provide public user registration, public comments, e-commerce, behavioural advertising or a newsletter subscription form. The ArchaeoLocus theme and ArchaeoLocus Core plugin do not intentionally add behavioural-profiling or advertising code.

Personal data you provide

If you use the Contact form, ArchaeoLocus processes the name, email address, enquiry type, subject and message that you choose to provide. The form sends the submitted information by email and does not intentionally save a separate copy of the message in the WordPress database.

Please do not submit passwords, payment-card data, unnecessary confidential personal information, special-category personal data or sensitive unpublished archaeological-location data through the Contact form.

Technical and security data

Hosting, email, backup, security and server infrastructure may process technical information such as IP address, browser or user-agent information, requested URLs, timestamps, delivery records and security events. This information may be generated automatically when the website or its infrastructure is used.

Purposes and legal bases

  • Contact and correspondence. Contact-form information is processed to receive, assess, manage and reply to research, publication, correction, media, presentation, technical and other relevant enquiries. The principal legal basis is Article 6(1)(f) GDPR: the legitimate interests of ArchaeoLocus in conducting and administering the research project, communicating with people who contact it and maintaining appropriate correspondence, provided those interests are not overridden by the rights and freedoms of the individual.
  • Steps requested before an arrangement. Where an enquiry asks ArchaeoLocus to take steps before entering into an arrangement or providing a requested service, processing may instead be necessary under Article 6(1)(b) GDPR.
  • Website and information security. Technical and security data may be processed under Article 6(1)(f) GDPR for the legitimate interests of operating, securing, troubleshooting and protecting the website, email and related infrastructure.
  • Legal obligations and claims. Information may be processed where necessary to comply with an applicable legal obligation under Article 6(1)(c) GDPR or where necessary to establish, exercise or defend legal claims.

ArchaeoLocus does not rely on consent merely to receive an ordinary Contact-form enquiry. If a future service requires consent, that consent will be requested separately and may be withdrawn as described at the point of collection.

Cookies and similar technologies

For ordinary public visitors, ArchaeoLocus does not intentionally use analytics, advertising or social-media tracking cookies through the ArchaeoLocus theme or Core plugin. WordPress, hosting or security infrastructure may use cookies or similar storage where technically necessary for administration, authentication, security or a service specifically requested by the user.

If optional analytics, advertising, newsletter tracking, social-media widgets or third-party media players are added, their privacy and cookie effects will be reviewed before activation. Where consent is required for non-essential storage or access, the relevant technology will not be loaded before the required consent is obtained.

Recipients and service providers

Personal data may be processed by service providers supporting website hosting, email delivery, backup, security and technical administration, but only to the extent necessary for those services. ArchaeoLocus does not sell personal data and does not use Contact-form information for behavioural advertising.

International transfers

Some service providers or their subprocessors may process personal data outside the European Economic Area. Where this occurs, the transfer must use a mechanism permitted by Chapter V of the GDPR, such as an applicable European Commission adequacy decision or appropriate safeguards. You may request further information about a material international transfer affecting your data by contacting ArchaeoLocus.

How long data is kept

Routine Contact-form correspondence is normally kept for no longer than 24 months after the last substantive correspondence, unless it can be deleted earlier or there is a justified reason to keep it longer. Correspondence that forms part of an active research, publication, correction, permission or administrative record may be retained for as long as that record remains relevant. Information may also be kept for longer where required by law or where necessary to establish, exercise or defend legal claims.

Technical logs, email systems and backups may follow separate operational retention cycles. Where those cycles are controlled by a service provider, retention is governed by the relevant service and security requirements; ArchaeoLocus seeks to avoid retaining personal data for longer than reasonably necessary.

Your rights

Subject to the conditions in applicable data-protection law, you may have rights of access, rectification, erasure, restriction of processing, data portability and objection. In particular, where processing is based on legitimate interests, you have the right to object on grounds relating to your particular situation. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise a right concerning personal data processed directly through ArchaeoLocus.org, contact contact@archaeolocus.org. Requests will be handled without undue delay and normally within one month, subject to the conditions and extensions permitted by the GDPR.

You also have the right to lodge a complaint with a competent supervisory authority. In Greece, the supervisory authority is the Hellenic Data Protection Authority; information about submitting a complaint is available on its website.

Automated decision-making and profiling

ArchaeoLocus does not use Contact-form information for solely automated decision-making or profiling that produces legal effects or similarly significant effects.

Security

ArchaeoLocus uses reasonable technical and organisational measures intended to protect personal data against accidental loss, unauthorised access, misuse or disclosure. No internet or email system can be guaranteed to be completely secure.

External links

ArchaeoLocus.org may link to journals, repositories, archaeological authorities, ORCID, podcast or media platforms and other external websites. When you follow an external link, the external service’s own privacy practices apply.

Changes to this policy

This Privacy Policy is reviewed when ArchaeoLocus materially changes the way the website processes personal data, including the addition of forms, analytics, newsletters, third-party media embeds, accounts or advertising. The current version and date are shown below.

Privacy Policy | website version v003 | 18 August 2026