DEVELOPMENT VERSION: This is an experimental DALICC environment. Features, data and APIs may change or be reset without notice. A stable version of this service, with a potentially different feature set, will be made available soon at dalicc.net.

Privacy notice


This page says what happens to personal data on dalicc.net: what is processed in each part of the site, why, how long it is kept and who else sees it. The version of this wording and the date it was last changed are printed at the end of the page.

Who is responsible

DALICC, Verein zur Förderung der Rechtssicherheit in der Datenbewirtschaftung (ZVR 1249185710), Campus-Platz 1, 3100 St. Pölten, Austria.

Write to tassilo.pellegrini@ustp.at or giray.havur@ustp.at about anything on this page. The board answers these questions itself; there is no separate data protection officer.

The machine this service sits on is provided by Hochschule für Angewandte Wissenschaften St. Pölten GmbH (FN 146616m, Campus-Platz 1, 3100 St. Pölten), the school that trades as USTP. An agreement on processing under Art. 28 GDPR is being concluded between the association and the school. Running the machine means its administration can reach the server logs and the stored data.

You do not have to give us anything to read this site, search the library, compare licenses or compose one for yourself: those pages ask for no name and refuse you nothing for not giving one. An account needs an address and a name, because that is what an account is; without them there is no account, and that is the whole of what follows.

What is processed, and why

Visiting a page

The server in front of the service writes one line for every request: your address, the time, the address requested including anything after the question mark, the status, the size of the answer, the page you came from and what your browser calls itself. A second file holds the same kind of line for a request that went wrong. Both are there to keep the service running and to find out what happened after something breaks, which is our legitimate interest in a service that works and is not abused (Art. 6(1)(f) GDPR). The lines are kept for about two weeks and then deleted. They go to no third party; on the machine, the association's administrators and the host's administration can read them.

The service behind it writes one line of its own per request: the method, the path without anything after the question mark, the status, how long it took and an identifier that lets one line be matched with the line in front of it. That line holds no address. It lives in the container's log, which is kept to a fixed size and drops its oldest part when it is full.

Counting what is used

One row per day per thing counted: the day, what was counted, which one of it, and a number. Nothing about an anonymous visitor is written there, and there is no column an address, a browser name or a visitor identifier could go in. For two days a row also says which accounts and which tokens were active that day, and how many readings of a license text each account started, so that a day can be counted without counting anybody twice and so that the daily allowance holds; after two days those rows become a single number. It is how the project sees which pages and endpoints are worth keeping, which is our legitimate interest in running the service. The rows are kept for three years. Administrators see them on the statistics page.

Writing to us

The contact form takes your name, your address, a subject and your message, and sends one mail to the two addresses above so that we can answer you. Nothing is stored on this site. The form also carries one hidden field that a person never fills in, which is how an automatic submission is recognised; whatever is in it is thrown away. The mail travels through the mail server this service is configured to send through, and both addresses are at ustp.at, the host's domain, so the mailbox it lands in is the host's. Your message lives in those mailboxes for as long as the correspondence needs it. We rely on our legitimate interest in answering you, and on Art. 6(1)(b) GDPR when you write about using the service itself.

Being invited

An account is created by invitation, or, where the administrators have opened it, by signing up yourself or by signing in with an identity provider. With an invitation, somebody who already has an account gives us your address so that we can send you a link; that is where your address comes from, and the invitation page tells you who it was. We keep the invitation with the address, the role, a one-way hash of the link, who sent it and when it expires, so that the link can be checked once and not again. It is deleted with your account, and so are the invitations you send.

When you accept, you confirm that you have read this page and that the name you choose is shown on every license you publish. We record the date and which version of this page was on the screen, so that we can tell you later what you agreed to. Where the administrators have opened sign-up, you can also create an account yourself on the sign-up page, which asks for the same things and records the same confirmation; the table at the end of this page says what that keeps and for how long, and the same automatic submission check as on the composer can be on that form, which then says so.

Having an account

Your address, the name you publish under, a one-way hash of your password, your role, when the account was made, when you last signed in, whether you have to choose a new password, and which version of this page you have read. It is what an account is made of, and we need it to give you one. The name you choose is shown on every license you publish. Your address is never shown on a public page. Administrators see it.

The account is kept until you delete it. Deleting replaces the name and the address with placeholders and keeps the row, because other records point at it; see "Deleting your account" below. If you change your name, it is the new one that appears from then on, everywhere the site draws it. A license you have already published keeps the name it was published with, the way a signature does; write to us if one is wrong.

Once you have published something, the name you published under stays reserved so that nobody else can publish a license in your name. That reservation holds after the account is closed, and no record of it says whose name it was.

The audit log

Who did what, when, and to which thing: signing in, changing a password, creating a token, publishing, accepting an invitation, an administrator changing somebody's account. It is how an intrusion becomes visible afterwards, and how you can see that an administrator touched something of yours. No password, no token and no message body goes in; the released form of a publisher name and the file name of an uploaded image do. It is our legitimate interest in a service whose history can be checked. It is kept for two years and then deleted, and administrators see it.

Notification mail

When something in your inbox needs you, the subject line and one sentence about what happened go to your address. That sentence can name the person who acted, by the display name their account carries at the moment the line is read. The mail never quotes a message and never carries somebody else's address. Switch the copies off at /account/notifications and keep the inbox. The note in your inbox stays whether the mail was sent or not, until you delete your account, which deletes every note written for it.

Publishing a license

The license model and the creator name you type become public and permanent under CC BY 4.0, signed in or not. Signed in, the document also carries the identifier of your account, https://dalicc.net/users/<id>, which resolves to a public profile page with your published name and your published work on it and never to your address. That page is also served as RDF, in Turtle, JSON-LD or RDF/XML, to anything that asks for it that way. You tick a box before anything is written, and that tick is what we rely on; we record it with the license and with the version of this page that was current.

You can withdraw that consent at any time by writing to the addresses above. A withdrawal works from then on: it does not make a publication that already happened undone, and what it changes is that we publish nothing further for you. A license has to say who granted it, so the name stays on the document even after the account that published it is closed. What you can do is mark a license withdrawn: its address keeps working, its terms stay readable for the people who already rely on them, and its page says from which date you no longer stand behind it. If you want the name taken off a withdrawn license as well, write to us and say which one. The association decides such a request, because taking a name off a public legal instrument is a balancing exercise and not a side effect of a button; we keep the version as published, unpublished, in case somebody has to establish what was granted.

A license you published without an account carries no account and no identifier, so there is nothing here to connect it to you with. If you want the creator name on one changed, write to us with its identifier.

Submissions, correction requests and messages

What you write, kept with your account, because it is the record of a review that other people took part in and that has to stay explicable. Administrators and the other people in the conversation see it. It stays after you delete your account, under the placeholder name: every page that shows a name reads it from your account, so it becomes the placeholder there too. A line written before September 2026 may still spell a name out, because those lines were stored with the name in them; write to us and we will redact one.

Dependency graphs

A dependency graph you make belongs to your account like a license does, and a published one shows the name of the account that owns it. That name is read from your account when the page is drawn, so it changes when your name changes and becomes the placeholder when your account is closed. Unpublished ones are deleted with your account.

API tokens and the request log

A token is stored as a name, a one-way hash, its first characters and its dates. Every request made with a token is counted against your account and written to a request log with the account, which token it was, the path without anything after the question mark, the method, the status and the time, so that the limits can be enforced and a runaway script can be found. We need it to run the service. The log is trimmed to the last seven days. The daily counts that outlive it have no personal reference. Administrators see it, and so do you, on your tokens page.

Text-to-License

The license text you submit is sent to a provider outside DALICC, which reads it and proposes a model. The providers are listed at the end of this page; where the first one has nothing left the text goes to the next. They are outside the European Union, so you tick a box on every submission, and that tick is both your consent to the processing and your consent to sending the text out of the Union. The box names the provider the text goes to first and the ones that may take over, and your tick covers all of them; a submission is refused when no provider can be named. The list at the end of this page gives each provider's legal name, its country and its own privacy notice. Do not submit a text that is not yours to send.

DALICC does not store the text. It stores a count of the run: your account, how long the text was, how many parts it was read in, what it cost, how long it took and what came of it. The proposal, which quotes short passages of the text, is kept only as long as the page that shows it needs it. Both are removed about two hours after the run. What is left is the day's number, which has no text and no name in it, and the draft you saved if you saved one, which is yours and lives in your own workspace.

License-to-Text

A license model you submit is sent to the same providers, outside the European Union, so that it can be written out as a text. There is no consent box on that form, because the model that leaves DALICC carries no personal data: the box that replaces every name in it with "the licensor" is ticked to begin with, and the text reads the same either way. Sending the model is what you asked us to do, which is the ground we rely on. Untick the box and the names in the model travel with it. Nothing is stored except the same count as above.

The GitHub License Compatibility Checker

The repository owner and name you type are sent to libraries.io, which resolves the repository's declared dependencies, because that is what you asked for. Our server makes that request, not your browser, so your address and nothing else about you goes with it, and nothing is stored here. The service is outside the European Union; what leaves is the repository you named, which is yours to name or not.

Images in blog posts

Only administrators upload images. Every upload is decoded and written out again, which drops what a camera records about where and when a picture was taken and everything else in the file that is not the picture. The file on disk gets a random name; the name it was uploaded under survives in the post and in its address.

What your browser loads

Every page, stylesheet, script, image and font comes from this service, so no other company learns that you were here, which page you read or what your address is.

Two exceptions are possible: on the license composer when you publish without an account, and on the sign-up page where the administrators have switched the check on there. Both forms can be protected against automatic submissions. You can see for yourself whether one is: when the check is on, the form shows a box to tick with a note above it saying what happens, and when it is off there is no box and nothing is loaded.

The check is Google reCAPTCHA. Google's privacy policy names Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as the company responsible for its users in the European Economic Area. While the box is on the page, your browser loads a script from Google and reaches Google while you fill the form in, which means Google receives your address as any website you open does. When you send the form, we send Google the answer you gave, and not your address. Google keeps servers around the world, and its policy says that what it collects may be processed outside the country where you live, which includes countries outside the European Union; what it does with it is a matter for its own notice. No other page loads it.

Cookies and what your browser keeps

This site sets no advertising cookie and runs no analytics or tracking service, so there is nothing to click away.

Two cookies are set for everybody who needs them. dalicc_session says which account you are signed in as; it is signed so it cannot be edited, it runs out after fourteen days, and a browser that never signs in never gets it. dalicc_csrf is one random value that each form has to carry back, so that another website cannot make your browser act in your name; it runs out after the same fourteen days.

Signing in with an identity provider, where it is offered, sets two more for the length of the sign-in: dalicc_sso, which lives ten minutes and carries the values the provider has to send back, and dalicc_sso_signup, which lives fifteen minutes and carries the provider's answer to the last step of a new account. An administrator who previews another look of the site gets dalicc_appearance, which holds that choice until the preview ends.

None of them can be read by JavaScript and none goes anywhere but to this site. None asks for your consent, because a cookie that is strictly necessary for a service you asked for does not need one (§ 165(3) TKG 2021).

Three things your browser keeps for itself and never sends: your shortlist on the Bookmarks page, the bundle you are working on in the License Compatibility Checker, and the mode you last used in the License Composer. They stay in your browser, they follow you to no other device, and nobody here can see them.

Sending data outside the European Union

Text-to-License and License-to-Text send what you submit to providers outside the Union, listed at the end of this page. For Text-to-License we rely on your explicit consent, which you give on the form for each submission, both to the processing and to the transfer (Art. 6(1)(a) and Art. 49(1)(a) GDPR). For License-to-Text the model that leaves the country carries no personal data unless you untick the box that takes the names out; untick it, and the same ground and the same words below apply to the names in it.

There is no adequacy decision of the European Commission for these transfers and no safeguard of the kind Art. 46 GDPR lists. What that means for you: the country the data goes to has no protection equivalent to the Regulation, public authorities there may be able to reach what was sent, and you may have no enforceable rights and no effective remedy there. You give the consent knowing that, you can withdraw it at any time with effect from then on, and a withdrawal leaves what was already sent as it is. Do not submit a text you are not free to send.

Where the automatic submission check is on, on the composer or on the sign-up page, your browser reaches Google, which may process what it collects outside the Union. The service that resolves a repository's dependencies is outside the Union too, but our server calls it and carries nothing about you into the call. Nothing else on this site sends anything abroad.

What we rely on, and how long we keep it

One row per thing that is kept, with the ground it rests on and how long it lives. The sections above say the same in sentences; this is for looking one thing up.

What Ground How long
The proxy access and error logs legitimate interest, Art. 6(1)(f) about two weeks, one rotation a day
The application log line, which holds no address legitimate interest, Art. 6(1)(f) until the container log runs over its fixed size
The daily counts legitimate interest, Art. 6(1)(f) three years; the per-account rows inside them, two days
A contact message legitimate interest in answering you, Art. 6(1)(f); Art. 6(1)(b) before a contract as long as the correspondence needs it, in our mailboxes; nothing is stored on this site
An invitation the use relationship, Art. 6(1)(b) a pending one until it is used or withdrawn; a used one until the account it created is deleted
A password reset link: a one-way hash of the link, the account it is for and when it runs out the use relationship, Art. 6(1)(b) 24 hours or until it is used; then it is deleted within the hour
The account the use relationship, Art. 6(1)(b) until you delete it, which replaces the name and the address with placeholders
Signing up yourself, where it is open: the account as above, the version of this page you confirmed, a one-way hash of the link that confirms your address, and whether an administrator has approved the account yet the use relationship, Art. 6(1)(b) the link, 24 hours or until it is used, and deleted with the account; an account whose address is never confirmed, a week after its last link runs out; a rejected account is deleted the way you would delete it yourself
Signing in with an identity provider, where it is offered: the provider learns that you signed in to this site and when; we receive its identifier for you, your address, whether it has confirmed the address, and your name if it sends one, and keep the identifier and the dates with the account the use relationship, Art. 6(1)(b) the identifier, until you delete the account; the name and the address as the account
The audit log legitimate interest, Art. 6(1)(f) two years
Notifications and their mail copy the use relationship, Art. 6(1)(b) until you delete the account, which deletes every note written for it
A published license, with the name on it your consent, Art. 6(1)(a), given on the form published for good; you can mark it withdrawn
A published dependency graph, which shows the name of the account that owns it the use relationship, Art. 6(1)(b) it stays when the account is closed, under the placeholder name; an unpublished one is deleted with the account
Submissions, correction requests and messages the use relationship, Art. 6(1)(b), and the record of a review other people took part in kept after the account is deleted, under the placeholder name
API tokens and the request log the use relationship, Art. 6(1)(b) the log, seven days; a token, until you revoke it or the account goes
A run of one of the two assistants Text-to-License: your consent, Art. 6(1)(a), and Art. 49(1)(a) for the transfer. License-to-Text: carrying out what you asked for, Art. 6(1)(b), with the names taken out before the model goes about two hours for the run and its proposal; after that the day's number, which holds no text and no name

Your rights

Under the General Data Protection Regulation you can ask for access to the data we hold about you, for a copy of it in a machine-readable form, for a correction, for erasure, for processing to be restricted, and you can object to processing we base on our legitimate interest, which here means the logs, the statistics, the audit log and the request log. We will look at every objection; we will usually keep a security log, and we will tell you why. Where you gave consent, you can withdraw it at any time by writing to the addresses above, which works from then on and does not affect what was done before you withdrew it.

We answer within one month. If a request is complicated we will say so and take up to two months more.

Nothing here decides anything about you automatically. The assistant proposes a reading of a text and a person decides what to do with it; the reasoner works on licenses, not on people. This site is not meant for children.

If something goes wrong with data we hold and it is likely to put you at risk, we will tell you and the supervisory authority, as the Regulation requires.

You can complain to the supervisory authority:

Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, Austria, dsb@dsb.gv.at.

How to use them

With an account, two pages do most of it without asking anybody.

  • /account/export downloads what your account holds as one JSON file: your profile, your licenses and dependency graphs with the RDF of each and every saved version of them, your submissions and correction requests, the conversations you are part of with the messages everybody wrote in them, the notes written for you, the invitations you received and sent, your runs of the two assistants, your recent API requests and the limits set on your account, the publisher name reserved for you, the password resets and address confirmations requested for your account, the identity provider linked to it, your API tokens by name and dates, and the audit entries about your account and the things it owns. It never contains a password, a token value or a one-time link, because those are keys rather than facts about you.
  • /account/delete deletes your account. Your name and your address are replaced by placeholders, your password is cleared, your tokens are revoked, every session ends and your notification settings and notes go. Your unpublished licenses and dependency graphs are deleted with every saved version of them. The invitations that brought you here and the ones you sent are deleted. The runs of the two assistants lose their link to you. What stays is what other people took part in or rely on: the licenses and dependency graphs you published, with the names on them, your submissions, correction requests and messages, and the audit entries about the account. The page lists all of it before you confirm, asks for your password, and offers to mark each of your published licenses withdrawn first. It cannot be undone, and the placeholder address can neither sign in nor be invited back.

If you cannot sign in any more, write to us and an administrator does the same thing from your account page. For anything the two pages do not cover, write to tassilo.pellegrini@ustp.at or giray.havur@ustp.at, and say what you are asking for and which address or license it is about, so that we can find it.

When this page changes

This page is written in English. The imprint carries a short German version of it; where the two say different things, this page is the one that governs, and a full German version is to follow. Until it is here, we answer questions about this page in German at the addresses above.

Every version of this page has a date, printed below, and the version you accepted is recorded with your account. When something changes that a member would want to know about, we raise the date and tell you the next time you are signed in, with a note saying what changed and a button that records that you have read it. Nothing is blocked while you have not: reading the page again is enough, and where something does need your agreement we ask for it on the form where you give it.

The providers behind Text-to-License and License-to-Text

A text or a model you submit to one of those two features is sent to one of the providers below, and may be sent to any of the others when the first one is out of its allowance. They are outside the European Union. On Text-to-License the box you tick covers every one of them, for the processing and for the transfer; on License-to-Text there is no box, because a model with the names left out carries nothing about a person, and the form offers to take the names out before it goes.

  • groq API (The administrators have not yet recorded the legal name, the country, the privacy notice of this provider.)

This is version 2026-09-24.3 of this page, last changed on 24 September 2026. When you created your account, whether by invitation, on the sign-up page or through an identity provider, the version that was on the screen was recorded with it, so we can tell you what you agreed to.