Skip to content

Privacy notice

Effective 31 August 2026. Version 2.0.

This page is about you, the person using EURVISTA. If you are looking for information about data EURVISTA holds about MEPs, officials or registered organisations, that is on the data sources and your rights page.

In short: the public pages set no cookies, run no analytics, and load nothing from any third party. Signing in to the platform sets one strictly necessary session cookie and nothing else. Your browser talks to our server and to nobody else.

1. Who is responsible

The data controller is University College Dublin, Belfield, Dublin 4, Ireland. Contact the Principal Investigator, Dr James Cross, at contact@eurvista.com, or the UCD Data Protection Officer at gdpr@ucd.ie (+353 1 716 8743).

2. What this site is

There are two parts, and they behave differently.

The public pages (this one, the home page, and everything reachable without signing in) are static files. They set no cookies, send nothing you do to a server, and make no requests to anyone but us. The one exception is the access-request form on the contact page, which sends what you type in it when you press the button, and only then.

The platform, behind the sign-in, holds an account for you. It stores the watchlists you create and can send you a daily digest of what changed on them. Signing in sets a session cookie. Most of what the platform does still runs inside your own browser: filters, searches and selections are computed locally from static data files.

3. What we record

WhatWhyKept for
Your account. The e-mail address we invited, the display name you were given, and whether the daily digest is switched on. To let you sign in, to hold your watchlists against something, and to be able to withdraw access. Until your access ends or you ask us to delete it
Sign-in tokens and sessions. Stored hashed, never in the clear, with their expiry times. To keep you signed in and to expire access safely. Sessions 90 days, invite links 30 days, single-use sign-in links 15 minutes. Expired rows are deleted automatically
Your watchlists. The files, members, organisations and topics you choose to track. To show them back to you and to build your digest. Until you delete them or your account
Digest records. Which digests were sent to you on which day, and the message that was sent. So the same digest is never sent twice, and so a delivery problem can be diagnosed. Until your account is deleted
Access requests. If you use the form on the contact page: your name, e-mail address, organisation, role, what you said you would use it for, and the IP address the request came from. To reply to you, to decide whether to issue an invitation, and to identify abuse of the form. 12 months, or until you ask us to delete it, whichever is sooner. If we invite you it becomes an account and the request row is deleted
Web server logs. Your IP address, the date and time, the page or file requested, the response code, and your browser's user-agent string. To keep the service running and secure, to diagnose faults, and to count visits to the public pages. We do this by reading these logs rather than by running an analytics script, which is why there is nothing to consent to. No more than 90 days
Correspondence. Anything you send us by e-mail. To reply to you. As long as needed for the project, then deleted under UCD's records policy

Our lawful basis is legitimate interests (Article 6(1)(f)) for running, securing and diagnosing a service you have asked to use, for deciding on access requests, and for counting visits from server logs. The interest is operating a research platform and deciding who may use it; the processing is limited to what that needs; and you can object at any time using the contact details above. The daily digest is sent only if you switch it on, and every digest carries a one-click unsubscribe link.

We do not use anything in this table for marketing, we do not sell or share it, and we do not profile you.

4. Cookies, and why there is still no banner

The public pages set no cookies at all. Nothing on this page, the home page or any other page you can reach without signing in writes a cookie.

Signing in sets one cookie, named __Host-ev_sess. It holds a random session identifier and nothing else: no name, no e-mail address, no tracking identifier. It is marked HttpOnly and Secure, is restricted to this site, and lasts 90 days from your last visit, or until you sign out. It exists purely so the platform knows you are signed in.

A cookie that is strictly necessary to provide a service the user has asked for does not require consent under Article 5(3) of the ePrivacy Directive, and we set no others. There is therefore nothing to consent to and no cookie banner. We take no measurement from this cookie.

Several pages also store a small preference in your browser's local storage, such as a committee filter, a dismissed notice or a draft report you have configured. These stay on your own device, are never transmitted to us, and are cleared when you clear your browser data.

5. No analytics and no third-party requests

We use no analytics service, no tag manager, no advertising or social media pixels, and no error-reporting service. Every font, script, stylesheet and image is served from our own server rather than a content delivery network, so loading a EURVISTA page causes your browser to contact no other company. You can verify this in your browser's network inspector.

Where we want to know how many people visited a page, we read the web server's own logs, which the server writes anyway in order to operate. Nothing is added to the page to do it, and nothing about you leaves our server.

The one exception is under your control: pages link out to source documents at the European Parliament, the Council, the Commission, the Transparency Register and EUR-Lex. If you follow one of those links you are on that institution's website, subject to its own privacy policy.

6. Who else is involved

ProviderRoleLocation
Hetzner Online GmbH Hosts the server this site runs on, and stores its backups Finland and Germany (EU)

That is the complete list. All data stays within the European Economic Area, and there is no international transfer. We will update this list before adding any provider, and we will tell people who have accounts before a change takes effect.

7. Security

The site is served over HTTPS. The platform is reachable only with an account we have issued, or with a preview password held by the team. Sign-in links are single use and short lived, and both they and your session are stored only as hashes, so a copy of our database does not let anyone sign in as you.

Backups are held in the EU and the most recent 14 daily copies are kept. If we suffer a personal data breach that presents a risk to people, we will notify the Data Protection Commission within 72 hours as required by Article 33, and tell affected individuals without undue delay where the risk to them is high.

8. Your rights

You have the right to access, rectification, erasure, restriction, portability and objection under Articles 15 to 21 of the GDPR. Because we hold very little about you, most requests are simple to answer. E-mail contact@eurvista.com and we will acknowledge within 5 working days and respond within one month, at no charge. Deleting an account erases it and everything it owns: the account, its sessions and tokens, its watchlists and its digest records.

You can complain to the UCD Data Protection Officer (gdpr@ucd.ie) or to the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, www.dataprotection.ie.

9. Children

EURVISTA is a professional research tool and is not intended for use by anyone under 18. We do not knowingly hold data about children.

10. Changes

We will revise this notice as the platform develops. The effective date at the top records the current version. Version 2.0 replaced version 1.0 of 3 August 2026, which described the site before accounts, watchlists and digests existed and before any part of it was public.

See also data sources and your rights and the terms of access.