Legal

How we handle data
with R64N.

R64N operates a research programme for organisations, corporates, and research institutions. This policy sets out how personal data is processed, how participant contributions are de-identified, and how GDPR rights are exercised.

Last updated · 6 August 2026

Contents

1. Scope and roles

This policy explains how R64N handles personal data in connection with the R64N website, the Resonant Network research infrastructure, and the organisational services we provide to corporates, research institutions, public bodies, and AI developers.

For the personal data of participants who contribute decision data through the Resonant participation environment, R64N acts as data controller and determines the purposes and means of processing under the Resonant Network research protocol. For personal data supplied by an organisation about its own personnel — for example named contacts within a partner institution — R64N acts as controller of that limited business-contact data. Where R64N delivers analysis on data an organisation supplies to us, R64N acts as processor on that organisation's documented instructions under a separate data processing agreement.

This policy does not apply to third-party websites, partner platforms, or organisational systems that link to or from R64N.

2. Data we process

Participant decision data. Each completed scenario produces a decision event recorded as the presented scenario, the selected response, the observation time, and minimal contextual metadata limited to country-level location. We do not collect age, gender, ethnicity, political affiliation, health information, precise location, or other special category data as part of decision events.

Account and participation data. Where a participant holds an account in the participation environment, we process the identifiers required to operate that account and to maintain the continuity of a longitudinal decision profile.

Organisational contact data. For prospective and active partners we process business contact details, the organisation represented, the stated use case, and correspondence relating to access requests, evaluations, and agreements.

Technical data. We process server logs, IP address, device and browser characteristics, and referral data for the purposes of security, abuse prevention, and service integrity.

3. Purposes and lawful bases

Scientific research. We process de-identified decision data to construct population-level descriptions of collective human decision-making. Where consent is the basis for participation, it is obtained separately, is specific to research use, and may be withdrawn at any time without affecting the lawfulness of prior processing. Article 89 GDPR safeguards apply to processing for scientific research purposes.

Provision of organisational services. We process organisational contact and account data to evaluate access requests, negotiate and perform agreements, deliver research outputs, and support partner institutions. The lawful basis is performance of a contract or steps taken at the organisation's request, and our legitimate interest in operating a research programme.

Security, integrity, and legal compliance. We process technical and account data on the basis of legitimate interest in protecting the network and its participants, and to comply with legal obligations to which R64N is subject.

We do not sell personal data, and we do not use participant decision data for advertising, credit scoring, employment screening, insurance underwriting, or any individual-level assessment of a participant.

4. De-identification and outputs

All scientific and commercial outputs are de-identified population-level aggregates. Identifiable participant trajectories are never published, licensed, or presented as results, and outputs are constructed so that individual participants cannot be singled out.

Contextual metadata is deliberately minimal by design. Country-level location and observation time are the only contextual attributes attached to a decision event, which materially limits the re-identification surface of the underlying record.

Organisations receiving R64N outputs are contractually prohibited from attempting re-identification, from combining outputs with other datasets for that purpose, and from using outputs to make decisions about identified individuals.

5. Disclosure and international transfers

We disclose personal data only to service providers acting on our documented instructions under written contracts covering confidentiality, security, and sub-processing; to professional advisers where necessary; and to competent authorities where required by law.

Where personal data is transferred outside the European Economic Area or the United Kingdom, transfers are made under an adequacy decision or the European Commission's Standard Contractual Clauses together with a transfer risk assessment and, where required, supplementary technical and organisational measures.

A current list of sub-processors is available to partner organisations on request as part of the applicable data processing agreement.

6. Retention

De-identified decision data is retained for the duration of the research programme, as continuity over time is essential to observing how decision patterns evolve. Account identifiers are retained while the account remains active and for a limited period afterwards to honour withdrawal and deletion requests.

Organisational contact and contract data is retained for the term of the relationship and for the period required to meet statutory record-keeping and limitation obligations. Technical logs are retained for a short period proportionate to the security purpose for which they were collected.

7. Your GDPR rights

Where R64N acts as controller, individuals in the EEA and the UK have the right to access their personal data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing carried out on the basis of legitimate interest. Where processing rests on consent, that consent may be withdrawn at any time.

Requests can be made to privacy@r64n.com and are answered within one month, extendable by two further months for complex requests. We may ask for information sufficient to verify the request. Rights may be limited where data has been irreversibly de-identified and can no longer be attributed to an individual, or where an Article 89 research exemption applies under the relevant national implementing law.

Individuals also have the right to lodge a complaint with their supervisory authority.

8. Security

R64N applies technical and organisational measures appropriate to the risk, including encryption in transit, access control on a least-privilege basis, environment separation, logging, and periodic review of access rights. Personnel with access to personal data are bound by confidentiality obligations.

In the event of a personal data breach presenting a risk to individuals, we notify the competent supervisory authority within 72 hours of becoming aware, and notify affected individuals and partner organisations where the applicable threshold is met.

9. Cookies

The R64N site uses strictly necessary cookies required to deliver the site and maintain security. Any analytics or non-essential cookies are set only with prior consent, and consent can be withdrawn at any time.

10. Contact and changes

Privacy enquiries, data subject requests, and data protection agreement requests can be directed to privacy@r64n.com. General enquiries can be directed to hello@r64n.com.

We may update this policy to reflect changes in the research programme, our services, or applicable law. Material changes will be reflected in the effective date above and, where appropriate, communicated to partner organisations directly.

Read the companion Terms of Use for the conditions governing access to R64N outputs.