Summary: ScopusDB is an academic publication index tool. We collect minimal personal data, use it solely to operate and improve the service, never sell it to third parties, and comply with applicable data protection regulations.
1. Overview
ScopusDB ("we", "our", "us") is an academic bibliometric platform that indexes and presents publication data sourced from Elsevier's Scopus database. This Privacy Policy describes how we handle personal information when you access or use ScopusDB and its associated services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you disagree with any part of this policy, please discontinue use of the Service.
2. Data We Collect
2.1 Information You Provide
- Account registration: name, institutional email address, institution name, and role (researcher, librarian, administrator).
- Profile preferences: saved searches, followed authors or journals, notification settings.
- Contact & support: messages sent via our help form or email.
2.2 Information Collected Automatically
- Usage data: pages visited, search queries entered, filters applied, results clicked, session duration, and feature interactions.
- Device & browser data: IP address, browser type and version, operating system, screen resolution, and referring URL.
- Log data: server-side request logs including timestamps, response codes, and error information retained for up to 90 days.
2.3 Bibliographic Data
The publication records, author profiles, and affiliated institution data displayed in ScopusDB are sourced from Elsevier Scopus and are governed by Elsevier's own data licensing terms. We do not collect or store personal data about authors beyond what is already publicly available in Scopus.
3. How We Use Your Data
We use collected information for the following purposes:
- Service operation: to authenticate your account, display search results, and enable saved preferences.
- Service improvement: to analyze usage patterns, diagnose technical issues, and inform feature development.
- Communication: to send transactional emails (password reset, import notifications), and—with your consent—product updates or newsletters.
- Security: to detect and prevent fraudulent access, abuse, or unauthorized activity.
- Legal compliance: to fulfill obligations under applicable law or respond to lawful governmental requests.
We do not use your data for automated decision-making or profiling in ways that produce legal or similarly significant effects.
4. Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share data only in the following limited circumstances:
- Service providers: trusted third-party vendors who assist us in operating the Service (hosting, analytics, email delivery) under confidentiality agreements that prohibit them from using data for their own purposes.
- Institutional administrators: if your account is registered under an institutional license, your administrator may have access to aggregate usage statistics but not to your individual search queries.
- Legal requirements: when disclosure is required by applicable law, court order, or to protect the rights, property, or safety of ScopusDB, our users, or the public.
- Business transfers: in the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to equivalent privacy protections.
5. Cookies & Tracking Technologies
We use the following types of cookies and similar technologies:
- Strictly necessary cookies: required for authentication, session management, and security. Cannot be disabled.
- Preference cookies: remember your settings such as selected language, theme, and default sort order.
- Analytics cookies: help us understand how the Service is used. We use privacy-respecting analytics (no cross-site tracking, data stored on our own servers). You may opt out via your account settings.
We do not use advertising cookies or share any cookie data with advertising networks.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Account data is retained for the duration of your account and deleted within 30 days of account closure.
- Usage logs are retained for up to 90 days for security and debugging purposes.
- Support correspondence is retained for up to 2 years.
- Import logs created by administrators are retained for 1 year unless manually deleted.
7. Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. These include:
- TLS/HTTPS encryption for all data in transit.
- AES-256 encryption for sensitive data at rest.
- Role-based access controls for our internal team.
- Regular security audits and vulnerability assessments.
No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to certain processing activities, including analytics.
- Withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, contact us at info@invorda.org. We will respond within 30 days.
9. Children's Privacy
The Service is intended for use by researchers, students, librarians, and academic professionals. It is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have inadvertently collected such data, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify registered users via email and display a prominent notice in the application at least 14 days before the changes take effect. The "Effective" date at the top of this page will always indicate when the policy was last revised.
Continued use of the Service after the effective date constitutes acceptance of the updated policy.
If you have questions, concerns, or requests related to this Privacy Policy, please reach out to us:
- Email: info@invorda.org
- Postal: ScopusDB Data Privacy Team, Faculty of Engineering, Universitas Riau, Pekanbaru 28293, Indonesia
- Response time: We aim to respond to all privacy inquiries within 5 business days.
Last updated: 1 March 2026.