Site policies, privacy and consent
By checking the required box when creating an account or signing in, you accept Terms of Use, Contribution Terms and Content Rights, Community and Moderation Rules and Adolescent Participation and Child Safety, acknowledge this Privacy Notice, and authorize CORESIS SAS to process the data necessary to provide and protect your account and handle your participation as described here. This is not consent to advertising, optional tracking or unrelated processing. You confirm that you are at least 18, or are signing in to an adolescent account with parental authorization previously approved by our team. Direct registration without prior parental review is for adults; ages 13–17 use the guardian procedure in Adolescent Participation and Child Safety. A login checkbox does not grant or renew parental approval. We record the policy version and acceptance time. The linked policies open only when you choose to read them; no Contact page is required during sign-up or sign-in.
Controller and contact
CORESIS SAS operates FutureSciences and is responsible for the processing described here. Current identification and contact: Contact and Operator Identification. Send access, correction, erasure, withdrawal, objection, portability or restriction requests through Private requests or the contact email. No account is required. Do not send identity documents unless a reviewer has arranged a necessary, proportionate verification.
Data and purposes
- Reading: IP address, requested URL, time and technical connection information reach our hosting and security services to deliver pages, prevent abuse and diagnose failures. GA4 counts anonymous public visits with first-party _ga cookies by default outside the EEA, United Kingdom and Switzerland. In those regions, or when the region cannot be verified, analytics cookies require your explicit choice. A saved rejection is respected everywhere. You can disable analytics cookies at any time in Cookies and Tracking; explicit choices are saved in browser local storage. Advertising consent remains separate. Its cookieless requests to Google may include the IP address and browser/device signals, the page URL without query parameters or fragments, and only the referring site's origin. No account identifiers or form contents are deliberately sent; account, search and private-request pages are excluded. Google Tag Manager and Visitors audience collection remain disabled.
- Advertising: on selected editorial pages viewed without signing in, Google AdSense and its advertising partners may receive the IP address, page and referrer URLs, approximate location derived from IP, browser, device and connection information, advertising or consent identifiers, and ad impressions or interactions. They use this information to deliver and protect ads, limit repetition, measure and report performance, and personalize ads where the visitor’s region and choices permit. Signed-in accounts receive no ad units.
- Accounts: email, password hash or external authentication link, alias, language, verification and login state, and optional preferences. We use these to provide and protect the account and send essential account messages. Passwords are not published.
- Participation: private eligibility declaration, country of residence where supplied during a participation or guardian review, policy version, time and method of acceptance; for adolescents, the reviewed representative request. These support eligibility, authorization and accountability. Public contributions carry an alias. An adult may separately choose a public profile. An adolescent profile, country and portrait are not published by our profile interface.
- Content: submitted text, references, comments, proposal revisions, editorial decisions, permitted credits and necessary rights evidence. Public contributions may be indexed and copied by third parties. Drafts and rights evidence are restricted to authorized personnel.
- Requests: the name and contact details supplied, relevant URLs, explanation, representative declarations and review history. We use them to examine and answer a request, verify authority where necessary, meet duties and defend actual claims.
- Optional reply or proposal notifications: we use your preference for service-related updates. They are not permission for promotional email. You may change these preferences in your account.
Legal grounds and choices
We request prior, informed authorization where required for account participation and record its scope. Mandatory exceptions and duties apply independently. Where the GDPR applies, necessary account functions rely on contract or pre-contractual steps; proportionate security and claims handling may rely on legitimate interests after balancing affected rights; statutory obligations rely on the relevant legal duty; optional functions requiring consent use a separate choice. We do not treat acceptance of this notice as blanket GDPR consent. Information needed for the requested account service is identified in the forms; without the required eligibility and authorization we cannot enable participation. Reading and rights requests remain available.
We do not request sensitive data for registration. Do not submit health records, biometrics, intimate material or unnecessary data about others. Such data have additional legal conditions; a free-text field is not a request or authorization to collect them. CORESIS SAS does not independently sell account, contribution or legal-request data. Depending on applicable law, advertising identifiers used for personalized ads may be treated as targeted advertising, sale or sharing; the choices described in Cookies and Tracking apply. There is no significant solely automated decision-making in the participation process described here.
Children and authentication providers
Accounts are available from age 13 with the safeguards in Adolescent Participation and Child Safety. A guardian checkbox or payment alone does not complete our review. Google sign-in is optional: after you choose it, Google processes authentication under its own notice and we receive identity and verified-email information. We generate an alias rather than importing the provider’s name as a public profile, and do not import its photograph. You may use email registration instead.
Recipients and international processing
Authorized editors and administrators receive access according to their task. Hosting, static resource delivery networks (currently jsDelivr), Cloudflare security and delivery, email delivery and an authentication provider chosen by you may process data needed for their services. On eligible anonymous editorial visits, Google AdSense and the ad technology providers disclosed by its consent interface may process the advertising data described above. We do not send account, contribution or legal-request contents to advertising systems. A legally necessary disclosure to an affected contributor, rights holder or competent authority may occur, with attention to safety and data minimization.
Using international providers, including Google advertising services, can involve processing outside your country, including the United States. Applicable controller/processor contracts, transmission or transfer requirements and, where relevant, GDPR Chapter V safeguards must support the actual flow; server location or a privacy notice alone is not a transfer mechanism. Request current recipient and safeguard information through the privacy channel. Google publishes information about its processing and safeguards in its Privacy Policy.
Retention
Account and authorization records are kept while needed for the account and proof of authorized participation. Following account deletion, our participation evidence has a scheduled one-year retention period unless a documented legal preservation duty applies. Ordinary closed request records are deleted after one year; uncompleted guardian requests expire after 30 days without further activity. An approved guardian authorization remains necessary while it supports an active adolescent account. Public contribution revisions may remain where a lawful editorial, attribution or legal basis exists; erasure requests receive an individual assessment. Historic audience logs are subject to the previously configured 90-day purge; collection has stopped. Security and infrastructure records are limited according to incident investigation, service operation and applicable preservation duties; ask for the applicable provider-specific period. Backups and mail-service copies follow their service retention and restricted recovery cycles and need separate erasure handling.
Your rights and deadlines
You may learn what data we process, obtain access or proof of authorization, correct inaccuracies, ask about uses, and request withdrawal or erasure where legally available. Where applicable you may also object, restrict processing or request portability. Withdrawing consent does not invalidate prior lawful processing. Response periods depend on the law applicable to the request. Where these periods apply, consultations ordinarily have 10 working days, with a justified extension of up to 5; claims ordinarily have 15 working days, with a justified extension of up to 8. We must follow the applicable receipt, completion and extension rules. GDPR requests ordinarily receive action or an explanation within one month, with a notified extension of up to two additional months where permitted. We verify identity proportionately and do not disclose account data merely because an email asks for it.
You may complain to the competent data protection authority after the applicable prior complaint process. Contacting us does not remove your remedies. In the EEA, UK and Switzerland, Google’s consent interface provides Consent, Do not consent and Manage options; its privacy-settings link allows a later change. Elsewhere, use any regional privacy control shown on the site and Google Ads Settings to opt out of personalized advertising. Changes to this notice are dated; materially changed participation policies require a fresh recorded acceptance.
Security on account and private request forms
Sign-in, registration, password recovery and private request forms use Google reCAPTCHA v3 to assess automated abuse without a visible puzzle. It processes technical device and connection signals, including IP address, and may set the _GRECAPTCHA security cookie. The form checks the token, hostname, action and risk score on the server. This service loads on those forms, not during ordinary reading. A rejected security check does not decide the merits of a request: you can use the email on Contact and Operator Identification instead. Google provides its Privacy Policy and Terms of Service. See Cookies and Tracking.
Effective date: 2026-10-01.