Privacy Notice
Meta-Student Platform — Sports Science Replication Centre
Last updated: July 2026
This notice explains how the Meta-Student platform collects, uses, stores, and protects personal data, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
1. Who We Are (Data Controller)
The Meta-Student platform is operated by the Sports Science Replication Centre. The project coordinator and contact for all data protection matters is:
Joe Warne — Sports Science Replication Centre
Contact: ssreplicationcentre.com/contact
Data protection queries, including requests to exercise any of the rights set out below, should be directed to the project coordinator using the contact route above.
2. What Personal Data We Collect
- Account data — your name, university email address, institution, role (student / supervisor), and a securely hashed password.
- Registration data— the studies you register for, your supervisor's name and email address, and any co-contributors' names, emails, and institutions that you provide.
- Submission data — the dataset files, ethics approval letters, methods reports, and signed Data Sharing Agreements you upload.
- Research participant data — anonymous participant-level data contained in submitted datasets (no names or direct identifiers are accepted; see section 7).
- Communications preferences — whether you have opted in to project update emails, and your acceptance of the Terms and this notice.
We do not collect special-category data about platform users, and we do not use cookies for advertising or tracking — only the session cookie required to keep you signed in.
3. Why We Process It (Legal Bases)
- Running your account and the submission workflow — necessary for the performance of our agreement with you (GDPR Art. 6(1)(b)).
- Scientific research — pooling submitted datasets into collaborative meta-analyses is carried out in the public interest / our legitimate interest in conducting scientific research (Art. 6(1)(e)/(f)), with the safeguards of Art. 89.
- Project update emails — your consent (Art. 6(1)(a)), which you can withdraw at any time using the toggle on your dashboard.
- Supervisor and co-contributor details — our legitimate interest in verifying supervision and correctly attributing contributions (Art. 6(1)(f)). Co-contributors receive a notification email when their details are added.
- Security and audit records — our legitimate interest in keeping the platform and its data secure (Art. 6(1)(f)).
4. Who Receives Your Data
- Platform administrators and the project coordination team — for quality review, supervision checks, and analysis.
- Your supervisor — receives your name and submission materials as part of the approval workflow you initiate.
- Service providers (processors) — three providers process data on our behalf:
- Supabase — database and file storage, hosted in the EU (Ireland, eu-west-1).
- Netlify — website and application hosting. Server-side processing is configured to run in the EU (Ireland).
- Render — hosts the statistical analysis engine, which receives anonymous participant-level data to compute results. It does not retain that data after an analysis completes.
- Open repositories — anonymous research data included in a published meta-analysis may be deposited in open repositories such as Zenodo, as described in the Terms and covered by participant informed consent.
We never sell personal data, and we do not use it for advertising.
5. How Long We Keep It
Retention follows our research records retention schedule. In summary: research data not included in any analysis is retained for 7 years from the end of the project or destroyed on valid withdrawal request, whichever is sooner; ethics approvals for 7 years; protocols, methods documentation, and signed Data Sharing Agreements for 10 years; and data included in published, openly deposited meta-analyses in accordance with the repository's terms, which may be indefinite. Account data is kept while your account is active and removed when you delete your account (see section 6). Full details are on our FAQ page.
6. Your Rights
Under GDPR you have the right to:
- Access the personal data we hold about you (Art. 15);
- Rectify inaccurate or incomplete data (Art. 16);
- Erasure(“right to be forgotten”, Art. 17) — you can delete your account directly from your dashboard; withdrawal of already-submitted research data is subject to the practical limits described in the Terms (§8) and FAQ;
- Restrict or object to processing (Arts. 18, 21);
- Data portability (Art. 20);
- Withdraw consent at any time where processing is based on consent (e.g. the project-updates email toggle), without affecting prior processing;
- Lodge a complaint with the Irish supervisory authority — the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2 — or with your local EU supervisory authority.
To exercise any of these rights, use the tools on your dashboard or contact the project coordinator (section 1). We respond within one month.
7. Research Participant Data
Datasets submitted to the platform must be anonymous. They must contain no names, contact details or other direct identifiers, participants must be represented only by a meaningless sequential number, and the contributing student must have destroyed the key linking those numbers to real people before submitting. Students confirm this at the point of upload and their supervisor confirms it independently at approval.
Because no key survives, no party — not the student, not their institution, and not this platform — can identify a participant from a submitted dataset. Anonymous data is not personal data under GDPR, and the rights that attach to personal data cannot be exercised over it: an individual participant’s record cannot be located, corrected, or withdrawn once submitted, because nobody can tell which record is theirs. Participants must be informed of this before they consent. Any request concerning data collected for a contributing project should be directed to the student researcher, who may still hold identifiable records of their own under their institution’s ethics approval.
8. How We Protect Your Data
- All traffic is encrypted in transit (HTTPS/HSTS).
- Passwords are stored only as salted, peppered bcrypt hashes — we cannot read them.
- Uploaded files are not publicly accessible and are served only to authorised reviewers through short-lived signed URLs.
- Access to personal data is role-restricted, and administrative actions are recorded in an audit log.
- Data is hosted in the EU (Ireland).
9. Changes to This Notice
We will update this notice when our processing changes and revise the “last updated” date above. Significant changes will be announced to account holders by email or on the platform.