Privacy Policy
Version v2.0 · Effective Thursday, July 30, 2026
This Policy explains how ResearchCave collects, uses, discloses, and protects personal data.
Scope and controller
This Policy applies to ResearchCave websites, accounts, applications, support channels, and related services that link to it. The controller is , located at . A service-specific notice may provide additional or different details where another entity or customer determines processing purposes.
Data you provide
We collect account and profile details, age or eligibility information where required, content and files, messages and support communications, preferences, survey responses, payment and transaction references, and information submitted when exercising rights or reporting safety concerns.
Data collected automatically
We collect device and browser attributes, IP address and approximate country or region, identifiers, authentication and security events, pages and features used, referring URLs, timestamps, diagnostics, crash data, and cookie or similar-technology choices. Precise location, contacts, camera, or microphone data is collected only when the feature requests it and the required permission or legal basis exists.
Sources and inferences
Data may come from other users, organisations administering an account, identity and payment providers, security and fraud-prevention partners, public sources, and integrations you enable. We may derive approximate interests, language, reliability, or safety signals, but do not make a legally significant decision based solely on such inferences unless separately disclosed and permitted.
Purposes and legal bases
We process data to provide requested services and contracts; authenticate users; personalise selected features; process payments; communicate service information; provide support; maintain security and reliability; prevent fraud, spam, and abuse; moderate content; comply with law; establish or defend claims; and improve services. Depending on the activity and territory, the basis may be contract, legal obligation, vital interests, legitimate interests, public interest, or consent. Consent is used only for the specific optional purpose presented and can be withdrawn.
Cookies, advertising and communications
Necessary technologies support operation and security. Optional analytics, personalisation, third-party media, marketing, or targeted advertising are controlled through Privacy Choices where required. Marketing messages include an available opt-out; operational and security messages may still be sent.
Recipients
We disclose data only as needed to processors and vendors supporting hosting, communications, analytics, payments, support, safety, and professional advice; to account administrators and recipients chosen through a feature; to competent authorities where lawfully required; and in a merger, financing, reorganisation, or asset transfer subject to appropriate safeguards. We do not disclose message contents to advertisers for their own advertising.
International transfers
Data may be processed where we and our providers operate. Where restricted transfers require safeguards, we use an applicable adequacy decision, standard contractual clauses, approved standard contracts, or another lawful mechanism and supplementary measures where appropriate.
Retention and deletion
Retention depends on purpose, account status, sensitivity, legal obligations, safety needs, disputes, and technical backup cycles. Account and content data is deleted or de-identified when no longer needed, while limited security, transaction, moderation, consent, and legal records may be retained for documented periods. Deleted backup data is isolated from ordinary use and expires through protected rotation.
Security and incidents
We use risk-appropriate access controls, encryption in transit and where appropriate at rest, logging, monitoring, backups, secure development, vulnerability management, vendor review, and incident response. No system is perfectly secure; report suspected issues promptly to .
Your rights
Depending on applicable law, you may request information, access, correction, deletion, restriction, portability, or an appeal; object to certain processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; and complain to a competent authority. We verify requests proportionately and may apply lawful exceptions without charging except where permitted for manifestly unfounded or excessive requests.
Children
ResearchCave services are not directed to children below the minimum age stated for the relevant service. We use age-appropriate design and parental authorisation where required. Contact if you believe a child supplied data contrary to the applicable requirements.
Changes and contact
Material changes will be identified by a new version or effective date and notified when required. Privacy requests may be sent to . Data-protection-officer contact, where appointed: .