Last updated: 6 October 2026
This privacy policy explains what personal data is processed when you use peaceresearch.institute (“the website”), why, and what rights you have. We collect as little as possible: you can browse the whole website without an account and without giving us any personal information.
1. Who is responsible
The controller of your personal data under the EU General Data Protection Regulation (GDPR) is:
European Peace Research Association (EuPRA)
Tampere University
Kalevantie 5, Linna 6072
33100 Tampere
Finland
Email: [email protected]
Please use this address for all privacy questions and requests.
2. What we process and why
2.1 Visiting the website
When you open a page, your browser automatically sends technical information to our servers: your IP address, the date and time, the page requested, the referring page, and your browser and operating system. This is needed to deliver the website, keep it secure and investigate errors or abuse. Server logs are kept for a limited period by our hosting providers, and our own system log keeps only the most recent 1,000 entries, which are overwritten continuously.
Legal basis: our legitimate interest in operating a secure, working website (Art. 6(1)(f) GDPR).
2.2 Visitor statistics (Matomo)
We use Matomo, an open-source analytics tool, to understand how the website is used — for example which pages are visited and how visitors find them. Matomo runs on a self-hosted server rather than a commercial analytics service, and the data is not sold or shared with advertisers. Matomo records pages viewed, time of visit, referring website, downloads and outbound links, searches made on this website, approximate location derived from the IP address, and browser, device and screen information. Matomo uses cookies to recognise returning visitors (see our Cookie policy).
If your browser sends a “Do Not Track” signal, Matomo will not track you at all.
Legal basis: our legitimate interest in improving the website (Art. 6(1)(f) GDPR) and, where cookies are concerned, your consent or browser settings as described in the Cookie policy.
2.3 Contact form and email
If you use the contact form or email us, we process your name, email address, subject and message, in order to reply to you. You receive a confirmation copy by email.
Our forms do not record your IP address.
Legal basis: our legitimate interest in answering your enquiry (Art. 6(1)(f) GDPR), or steps prior to an agreement where relevant (Art. 6(1)(b)).
2.4 Suggesting a resource
If you suggest an institute, journal or study programme, we process the details of the resource and your email address (so that we can ask follow-up questions). Your email address is never published.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
2.5 Submitting a thesis
If you submit a thesis, we process your name, email address, the thesis title, abstract, link, university and degree programme. If your submission is accepted, your name, thesis title, abstract, programme, university and links are published on the website. Your email address is never published.
Legal basis: your consent, given by submitting the thesis for publication (Art. 6(1)(a) GDPR). You can withdraw consent at any time and we will remove the listing.
2.6 Spam protection (Cloudflare Turnstile)
Our forms and the login page are protected by Cloudflare Turnstile, which checks that a human is filling in the form. To do this Cloudflare processes your IP address and technical information about your browser and device. Turnstile does not show puzzles in most cases and is not used for advertising. See Cloudflare’s Turnstile privacy addendum.
Legal basis: legitimate interest in protecting the website against spam and abuse (Art. 6(1)(f) GDPR).
2.7 Fonts
The website’s typefaces (Inter and Lora, both open-source) are served from our own server. No font or icon files are loaded from third-party services.
2.8 Editor accounts
Accounts exist only for the small team that maintains the website; the public cannot register. For editors we process username, email address, password (stored only as a secure hash), two-factor authentication data and login activity.
3. Who receives your data
We do not sell personal data or use it for advertising. We use the following service providers (processors), which handle data only on our instructions:
- Hostinger — web hosting, servers located in the EU (Lithuania).
- Cloudflare, Inc. — content delivery network, security and spam protection (Turnstile).
- Proton AG (Switzerland) — sending email from the website’s forms.
Personal data may also be disclosed where required by law.
4. Transfers outside the EU/EEA
Some of the providers above are based in, or may process data in, the United States or Switzerland. Switzerland is recognised by the European Commission as providing an adequate level of data protection. For US providers, transfers rely on the EU–US Data Privacy Framework where the provider is certified, or otherwise on the European Commission’s Standard Contractual Clauses.
5. How long we keep data
- Server and system logs: short-term, overwritten on a rolling basis.
- Visitor statistics: kept in Matomo for statistical purposes; Matomo cookies expire as listed in the Cookie policy.
- Contact messages and resource suggestions: automatically deleted from the website 12 months after they are sent.
- Thesis submissions: the submission itself, including your email address, is automatically deleted 12 months after it is sent. If your thesis is accepted, the published listing stays online until you ask us to remove it.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict processing;
- receive your data in a portable format (where processing is based on consent or contract);
- object at any time to processing based on our legitimate interests, including visitor statistics;
- withdraw consent at any time, without affecting processing that took place before withdrawal.
To exercise your rights, email [email protected]. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi. You may also contact the authority in your own EU country.
7. Security
The website is served only over encrypted HTTPS connections. Editor accounts are protected by strong password hashing and two-factor authentication, and access to personal data is limited to the people who need it.
8. Children
The website is intended for researchers, students and the general public and is not directed at children. We do not knowingly collect personal data from children under 13.
9. Changes to this policy
We may update this policy when the website or the law changes. The date at the top shows when it was last revised.
See also: Cookie policy · Terms of use