R Rigora
  • What You Get
  • Sample
  • Pricing
  • Guides
  • FAQ
ENDEITES
Submit Your Manuscript

Privacy Policy

Understand SciBridge's commitment to data privacy. This page details SciBridge GmbH's compliance with the GDPR and the principles that shape its privacy policies and practices for Rigora Scientific Editing.

1. Controller

The controller within the meaning of the GDPR is:

SciBridge GmbH
Pestalozzistraße 25
22305 Hamburg, Germany

Phone: +49 40 41188460
Email: info@rigora.net
Web: https://rigora.net

Represented by the Managing Director: Priv.-Doz. Dr. med. Sied Kebir

Data protection contact

For data protection inquiries and requests concerning your rights, please contact us at info@rigora.net.

2. Processing of personal data when visiting the website

2.1 Server log files

When you access our website, the hosting provider automatically records the following data:

  • IP address
  • Date and time of the request
  • Time zone difference to GMT
  • Content of the request (specific page)
  • Access status / HTTP status code
  • Amount of data transferred
  • Website from which the request originates (referrer URL)
  • Browser type, version, and operating system
  • Response time
  • Approximate country derived from the IP address

Purpose: Ensuring technical operation, IT security, and error analysis.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable provision of the website).
Storage period: The access logs made available to us in hPanel cover a rolling period of up to seven days. We preserve individual records for longer only where this is necessary to investigate a security incident, establish or defend legal claims, or meet a legal obligation.

2.2 Hosting

Our website is hosted by Hostinger International Ltd. (61 Lordou Vironos Street, 6023 Larnaca, Cyprus). The website server is located in Germany. Provider backups are stored in France. Both locations are in the European Union. Hostinger processes personal data on our behalf as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable provision of our website).

3. Cookies and similar technologies

We distinguish between necessary technologies and the optional categories analytics, marketing, and external media. Optional technologies are blocked until you make the corresponding selection. Their legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Necessary technologies. We store your privacy selection in local storage under the key rigora_consent_v2. The free Table 1 and sample-size tools may store the non-personal flags rigora_t1_unlocked and rigora_ss_unlocked after successful email verification. These entries are required to remember and apply functions you requested. They remain on your device until you clear browser data or the relevant version changes. The legal basis is Art. 6(1)(f) GDPR and Section 25(2)(2) TDDDG.

Analytics. With your consent, we load Google Tag Manager and Google Analytics 4, measurement ID G-B06WFHL4C3. Google Analytics processes page URLs, page titles, approximate location and device information, and interaction events. It may set the first-party cookies _ga and _ga_* for up to two years. For users in the EU, Google states that IP addresses are discarded before they are logged. The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We also use a first-party analytics endpoint that stores only time, path, a coarse source, and the referrer host without an IP address in the application log. These first-party analytics records are deleted after 93 days. Details are available in Google's Analytics privacy information.

Marketing and advertising measurement. With your consent, Google Ads click identifiers such as GCLID, WBRAID, or GBRAID and campaign parameters may be stored in local storage, attached to an order, and kept in a protected conversion file for up to 93 days. For conversion measurement, we may import the click identifier together with the conversion time, Stripe session reference, value, currency, and package into Google Ads. We do not include your name, email address, or other contact details in this import. The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Details are available in the Google Privacy Policy and Google Ads information about conversion data. With the same consent, selected campaign pages may load the Meta Pixel and send matching events through the Meta Conversions API. Depending on the event, Meta receives page or conversion information, browser and device data, the IP address, Meta cookie or click identifiers, and hashed contact details supplied during a conversion. The recipient is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Details are available in the Meta Privacy Policy and the Meta Business Tools Terms.

External media and management of consent. The Cal.com appointment calendar is loaded only after you select external media or press the dedicated load button. Cal.com then receives technical connection data such as your IP address and browser data. If you book, it also processes your name, email address, selected appointment, and booking details. Cal.com, Inc. is based in the United States. Details are available in the Cal.com Privacy Policy. You can change or withdraw any optional selection at any time through the permanently available privacy settings. Revocation applies for the future and reloads the page so that optional services are removed.

4. Contacting us (email, WhatsApp, or contact form)

If you contact us by email, WhatsApp, or via a contact form, we process:

  • Name
  • Email address
  • Phone number (if provided)
  • Content of your message

Purpose: Handling your enquiry and any follow-up questions.
Legal basis: Art. 6(1)(b) GDPR (contract initiation or performance) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
Storage period: We delete your enquiries once they have been fully processed and no statutory retention obligations prevent deletion. If you choose WhatsApp, WhatsApp Ireland Limited also processes communications and technical data under its own terms. No WhatsApp connection is established merely by visiting our website.

5. Services, intake, booking, and payment

When you order an editing or statistics service, register for a course, or book an appointment, we process the data required for the selected service:

  • Name, title
  • Billing address
  • Email address
  • Institution / company (if applicable)
  • Selected package and order details
  • Manuscript content provided by you
  • Payment information (see below regarding payment service providers)

Purpose: Contract performance, invoicing, and provision of the editing service (including delivery of annotated manuscripts and reports).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

5.1 Payment service providers (Stripe)

For payment processing we use the external payment service provider Stripe. Payment data is transmitted directly to the provider; we do not receive complete credit card details.

Purpose: Secure processing of payments.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and, where applicable, Art. 6(1)(f) GDPR (legitimate interest in efficient payment processing).

The payment service provider processes data under its own responsibility (e.g. for fraud prevention and legal retention obligations). For details, please refer to the privacy policy of the provider.

Data transferred to Stripe: Name, email address, billing address, payment instrument type, transaction amount, and IP address.

Note on third countries: Stripe, Inc. is based in the United States. Data transfers to the USA are safeguarded by EU Standard Contractual Clauses (EU Commission Decision 2021/914). Stripe may use sub-processors for fraud prevention and payment processing. For details, see Stripe's Privacy Policy and Data Processing Agreement.

5.2 Course rosters and online meetings

For paid courses, we maintain a protected participant roster in Google Sheets. The roster contains the name, email address, course and payment status, Stripe session reference, and any registration details supplied for the course. It is used to organise participation, access details, and contractual communication under Art. 6(1)(b) GDPR. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Where Google processes the roster on our behalf, the applicable Google data processing terms govern the processing. Google may use subprocessors in third countries subject to appropriate transfer safeguards. Details are available in the Google Privacy Policy and, where applicable, the Google Workspace data processing terms.

Appointments, consultations, and live online courses may be held through Zoom or Microsoft Teams, as stated in the booking or course information. The selected provider processes the participant name, email address, meeting details, technical connection data, and content actively shared during the meeting. Processing is necessary to provide the booked appointment or course under Art. 6(1)(b) GDPR. The providers are Zoom Communications, Inc., United States, or Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Third-country transfers are governed by the providers' data processing terms and appropriate safeguards. Details are available in the Zoom Privacy Statement and the Microsoft Privacy Statement.

5.3 Fonts

This website uses locally hosted web fonts (Inter and Source Serif 4). The font files are served from our own domain. No requests are made to external font services such as Google Fonts. No personal data is transmitted to third parties for the purpose of loading fonts.

6. Requested emails and optional newsletter

If you request a sample report, checklist, sample edit, quote, free-tool verification code, booking confirmation, order confirmation, or other email, we process:

  • Email address
  • Name, if provided
  • Date, time, language, and content of your request

The requested message is transactional and is sent to perform a contract or take steps at your request under Art. 6(1)(b) GDPR. A newsletter subscription takes place only if you select the separate optional newsletter checkbox. Newsletter processing is based on Art. 6(1)(a) GDPR. You can unsubscribe at any time through the link in a newsletter or by contacting us.

Withdrawing newsletter consent does not affect the lawfulness of processing carried out before withdrawal and does not stop transactional messages that are required to handle your request or contract.

Email providers. Transactional messages are primarily delivered through Resend, operated by Plus Five Five, Inc. in the United States, and may fall back to MailerSend, Inc., 228 Park Ave S, PMB 54955, New York, NY 10003-1502, United States. Their data processing addenda include the EU Standard Contractual Clauses. Optional newsletters are managed through MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland, only after the separate newsletter selection. Details are available in the Resend Data Processing Addendum, the MailerSend Data Processing Addendum, and the MailerLite Privacy Policy.

7. Overview of legal bases

We process personal data on the basis of:

  • Art. 6(1)(a) GDPR, consent
  • Art. 6(1)(b) GDPR, contract / contract initiation
  • Art. 6(1)(c) GDPR, legal obligation (e.g. statutory retention under tax and commercial law)
  • Art. 6(1)(f) GDPR, legitimate interests (e.g. IT security, efficient communication, economic operation of our website)

8. Storage period

We store personal data only for as long as necessary for the purposes stated above or as required by statutory retention periods. Specific retention periods:

  • Order and invoice data: generally 8 years for accounting records (§ 147 AO, § 257 HGB); longer only where another statutory obligation or an unresolved legal matter requires it
  • Manuscript files: deleted within 30 days after project completion
  • Server access logs are available to us in hPanel for up to 7 days. Longer separate storage occurs only for a specific security incident or legal requirement.
  • Newsletter subscriber data: until withdrawal of consent (unsubscribe)
  • Privacy selection on your device: until you change it, clear browser data, or the consent version changes
  • Google Ads and campaign identifiers: no more than 93 days in our conversion file; browser entries are ignored and removed on the next visit after 93 days

After the purposes cease to apply or the retention periods expire, the data is deleted or anonymised.

9. Your rights as a data subject

Under the GDPR, you have in particular the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR)
  • Right to withdraw consent with effect for the future (Art. 7(3) GDPR)

To exercise these rights, a simple email to info@rigora.net is sufficient.

You also have the right to lodge a complaint with a data protection supervisory authority, for example with our competent authority:

The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22
20459 Hamburg, Germany
https://datenschutz-hamburg.de

10. Updates to this Privacy Policy

This Privacy Policy was last updated on 23 July 2026 and applies from that date onward. We reserve the right to adapt it in the event of changes to our processing activities or to the legal situation. The current version is always available on this page.

© 2026 Rigora Scientific Editing, a service of SciBridge GmbH. All rights reserved.

Privacy Policy Terms & Conditions Impressum Email us LinkedIn
Withdraw from contract