Information governance
Privacy Notice
Effective date: 31 July 2026
This notice explains how personal information is handled when you visit this website or use its verified contact channel.
Causal Architectonics applies the same structural discipline to information handling that it brings to research and governance design: collect deliberately, retain proportionately, and preserve clear lines of responsibility.
Who is responsible for processing
Who is responsible for processing
Causal Architectonics is an independent, unincorporated research initiative administered from Saudi Arabia. It determines how information submitted through this website and its verified contact channel is processed.
Bjorn Bjornsvik is publicly identified elsewhere on this website as Principal Investigator. This notice does not introduce any additional personal contact details. Privacy requests must use the verified pathway described below.
Scope of this notice
Scope of this notice
This notice applies to visits to causalarchitectonics.org and www.causalarchitectonics.org, the email-verification process, enquiries submitted through the contact form, and the minimal record maintained for privacy-rights requests. It does not govern independent third-party websites reached through external links.
Information collected
Information collected
The contact channel may collect a verified email address, name, contact purpose, subject, message, and limited category-specific details that materially help route and understand an enquiry. Depending on the selected pathway, these may include an institution, country, research area, programme, framework, organisational context, media outlet, deadline, affected webpage, device, or browser.
OTP verification and security screening
OTP verification and security screening
During verification and abuse prevention, the system processes the submitted email address, internet protocol address, Cloudflare Turnstile token and outcome, cryptographically generated challenge and verification values, attempt counts, timestamps, and rate-limit information. Plaintext OTPs and verification tokens are not stored; only cryptographic hashes are retained temporarily.
Purposes of processing
Purposes of processing
Information is processed to verify that a contact address can receive a reply, prevent automated abuse, route and respond to enquiries, assess potential research or institutional relationships, maintain correspondence where appropriate, diagnose website problems, meet legal or contractual responsibilities, and receive and administer verified privacy requests.
Legal bases
Legal bases
Depending on the circumstances and the law that applies, processing may be based on a person's consent, steps requested before entering a relationship or arrangement, the initiative's legitimate interests in operating a secure research website and responding to serious enquiries, or compliance with a legal obligation. These descriptions do not assert that one legal framework applies universally; the appropriate basis is assessed in context.
Required and optional information
Required and optional information
An email address, successful Turnstile and OTP verification, a contact category, name, subject, message, and category fields marked as required are necessary to use the channel. Fields identified as optional need not be completed. Visitors should not provide information that is unnecessary for the enquiry, including identity documents, sensitive personal information, or confidential third-party material unless specifically requested through an appropriate process.
Cloudflare Turnstile and abuse prevention
Cloudflare Turnstile and abuse prevention
Cloudflare Turnstile is used in Managed mode, without pre-clearance, to distinguish legitimate visitors from automated abuse. Cloudflare receives technical information necessary to perform this check. The Turnstile token is validated by the website server and accepted only for the approved Causal Architectonics hostnames.
Resend verification and message delivery
Resend verification and message delivery
Resend transmits the automated six-digit verification email and the completed contact message. Verification mail is sent from a dedicated no-reply subdomain. Delivery records may be maintained by Resend according to its configured service and legal obligations.
OpenAI Sites hosting
OpenAI Sites hosting
The website is hosted through OpenAI Sites. OpenAI and its infrastructure providers may process technical information needed to serve the website, execute its server-side functions, protect the service, and operate the website database.
Receiving mailbox provider
Receiving mailbox provider
Completed messages are delivered to a Causal Architectonics mailbox provided through Proton Mail. The website does not publish that mailbox address. The receiving mailbox may retain correspondence and related delivery information according to its configuration, security controls, and applicable obligations.
International processing
International processing
The initiative is administered from Saudi Arabia. The hosting, security, delivery, and mailbox providers may process information in other countries. Those countries may have different privacy laws. Appropriate provider terms, security measures, and transfer arrangements are relied upon where relevant and available.
Retention periods
Retention periods
OTP challenges and rate-limiting records are retained for approximately 24 hours. Irrelevant or abusive correspondence may be retained for up to 90 days. Ordinary correspondence may be retained for up to two years after the last substantive exchange. Collaboration, funding, institutional, contractual, or legal correspondence may be retained longer where reasonably necessary for the relationship, accountability, legal claims, or applicable obligations.
The minimal privacy-request log may be retained for up to three years after closure, unless longer retention is required to establish compliance or address a legal claim. Ordinary message content is not retained in the website database after delivery, although the receiving mailbox and email-delivery provider maintain records according to their configured services and legal obligations.
Privacy rights
Privacy rights
Depending on applicable law and the circumstances, a person may have rights to ask for access, correction, deletion, restriction or objection, withdrawal of consent, or information about processing. Rights can be subject to legal limits, exemptions, identity verification, and the need to preserve records required for legal, contractual, security, or evidentiary purposes.
Verified-email identity rule
Verified-email identity rule
Your verified email address is the identifier for a privacy request. Causal Architectonics can search for, disclose, correct or delete only information associated with that exact address. A separate verified request must be submitted for each additional email address.
If the requester cannot verify an address and no other independent identifier exists, Causal Architectonics will not disclose, alter or delete information associated with that address.
Privacy-request record
Privacy-request record
For a verified privacy request, the website database records only a unique request reference, a cryptographic hash of the verified email address, the request category and type, date received, status, completion date, and, where applicable, a reason for refusal or partial refusal. It does not store the full email address, name, organisation, message body, identity documents, or OTP code in that log. The initial status is received.
External links
External links
The website may link to research resources, publications, funders, institutions, or other external services. Their operators determine their own processing practices. Visitors should consult the privacy information provided by those services.
Children
Children
This website and its verified contact channel are intended for professional, institutional, research, and public-interest engagement and are not directed to children. Children should not submit personal information through the contact channel.
Changes to this notice
Changes to this notice
This notice may be revised as the initiative, website, providers, or applicable requirements develop. Material changes will be published on this page with an updated effective date. Earlier processing remains governed by the notice and circumstances applicable at the relevant time.
Make a verified privacy request
Make a verified privacy request
Privacy enquiries and personal-data requests must pass through the same protected contact journey as every other enquiry. Turnstile and email OTP verification remain mandatory, and the privacy category will be selected when the form becomes available.
Make a verified privacy request