Personal Data Collection Statement

This Statement concerns the collection of personal data in the Procurement and Inventory Information System (hereinafter referred to as “PIIS”) operated by the laboratory.

1. PIIS

PIIS is a record of laboratory procurement and inventory, operated as a controlled pilot, and may be withdrawn. PIIS also holds a register of laboratory method documents, with the successive versions of each document. It further holds a shared roster of routine laboratory duties — which member is to do what, by when — with the record of each duty's completion or cancellation. Registered documents and the duty roster are visible to every signed-in member.

User accounts are issued to laboratory members. Signing in is required for every page of PIIS other than the sign-in and lockout pages and this Statement.

The authoritative records of the laboratory are the University's official systems and the physical stock held; in the event of a discrepancy between PIIS and verified physical stock, the physical stock prevails and the record is corrected.

Sign-in is governed by the sign-in protection component. The count of failed attempts is kept against the account name and not against the computer used; repeated failed attempts against an account name, by any person, lock that account name for approximately 30 minutes. The administrator (section 6) can unlock the account.

2. Purposes of collection

PIIS processes personal data for the following purposes:

  • administering user accounts and controlling access to PIIS;
  • recording and administering laboratory procurement and inventory activity, including what is ordered, received, stored and consumed;
  • making stock already held visible to laboratory members, so that items are not purchased a second time, and identifying items that have expired or are approaching expiry;
  • attributing requests, receipts, stock movements and issues to the members who performed or received them;
  • tracing stock, batches and problem cases;
  • registering laboratory method documents and maintaining the record of their successive versions;
  • assigning routine upkeep duties to members and recording their assignment, reassignment, completion and cancellation;
  • protecting the security of user accounts and investigating unsuccessful or abnormal sign-in activity;
  • diagnosing system errors and maintaining, backing up and restoring the system; and
  • responding to requests concerning personal data held in PIIS.

Personal data will not be used for purposes incompatible with those stated above.

3. Personal data collected

The following personal data are collected:

  • the account name of each member, and, if provided, a name and an email address;
  • the account name of the member who raised each request;
  • the account name of the member who received goods, moved stock, opened a container, placed or released a hold, or worked on a problem case;
  • the account name of the member to whom an item was issued, and of the member who issued the item. Where one member collects an item for another, these two account names differ;
  • the text entered by members into free-text fields, including notes, reasons and descriptions of problems;
  • the account name of the member who registered a method document or a new version of one, and the description that member gave of what changed;
  • personal data contained in the text of a method document, where a member has written such data into it;
  • the account name of the member to whom a duty is assigned, of the member recorded as having done the work, and of the member who recorded, reassigned, completed or cancelled the duty entry;
  • sign-in records, comprising the time of the attempt, the account name, the network address, the browser and device information contained in the user-agent string, the page requested, and the fields submitted with the sign-in form. The password and the account name are masked within the record of the submitted fields. Sign-in records are maintained separately from the procurement and inventory records within PIIS;
  • a session cookie and a cross-site request forgery token, stored in the browser of the member. Both are required to sign in and to submit forms.

The following are not collected:

  • precise device location or satellite positioning data. The network address recorded during sign-in may indicate the approximate location of the connection;
  • third-party analytics, advertising identifiers and tracking pixels. No page of PIIS loads content from a third party.

4. Mandatory and optional data

An account name is required to use PIIS; a member for whom the required account information is not provided cannot be given access to the system. The recording of actions carried out through an account, against the account name, is a necessary part of the system. It is not possible to use PIIS while being omitted from the procurement and inventory records. A name and an email address are optional and may be left blank; leaving them blank does not restrict the use of PIIS.

5. Use of the data collected

The account names recorded against each transaction identify which member requested, received or took an item, so that stock held in common can be traced to the member holding it. The account names on the duty roster identify which member is responsible for each duty and who completed or cancelled it; the roster is visible to every signed-in member. Sign-in records are used for the purposes stated in section 2.

Communication with members concerning PIIS, including account set-up and notice of changes, is by the means otherwise used by the laboratory. PIIS does not send email.

6. Personnel with access to the data

Every laboratory member who can sign in can read the procurement and inventory records on screen, including the account names recorded against them. This follows from the purposes stated in section 2: stock held in common is visible to the members who share it. Role membership determines which operations a member may perform.

Several of the listings that a member can read on screen can also be exported by that member as a spreadsheet; such exports include the account names shown in them. Export of the complete list of stock units is available only to members in the inventory role and to the administrator.

One member of the laboratory administers PIIS (in this Statement, the administrator). The administrator holds the administrator account, the credentials for the services listed in section 7, and access to responses submitted through the suggestions form. The administrator works through an administrative console, which records every change made in it. The database may also be reached directly where necessary for maintenance, security investigation, correction or recovery; such access is governed by a documented operating procedure of the laboratory, which requires each occasion to be recorded.

7. Where the data are kept

PIIS runs on services operated by other companies. The following receive data automatically:

ServiceFunctionLocation as published by the service
Railwayruns the application and the databaseUS West (California), as configured for this project
GitHubruns the nightly backup jobnot published for an individual job
Cloudflare R2holds the nightly backupthe region Cloudflare designates “Eastern Europe” (EEUR)
Sentryerror reports raised when a page failsFrankfurt, Germany (Sentry's European region)
  • No service listed above holds data in Macao. Cloudflare publishes only a region name for storage of this kind and does not publish which countries that region covers.
  • The nightly backup is made by a job running on a machine operated by GitHub. The job copies the database in full, including free-text notes and sign-in records, and uploads the copy to Cloudflare R2. The machine is not retained after the job ends. GitHub does not publish its location.
  • Sentry receives the time, the address of the page, the point in the code at which the failure occurred, and a record of the database statements run beforehand, with the values used in them removed. Request contents, account identity and internal code values are not transmitted.
  • The suggestions link on the home page directs the member to a service operated independently by Google. Opening the form causes the device of the member to connect directly to Google, which may record that connection. PIIS transmits no information about the member, and none about the page from which the link was opened. Where the member submits the form, the response, including the PIIS account name entered by the member, is stored through Google Forms and can be read by the administrator. The form does not collect the Google account address of the member submitting it. Google does not publish where responses to a form are held.
  • Data exported in spreadsheet form and label files prepared for printing are stored on the device of the member who requested them, and are no longer subject to the retention arrangements described in section 8. Such files are to be stored, used and deleted in accordance with the requirements of the laboratory and of the University.

8. Data retention period

  • Procurement and inventory records are retained until a decision is taken to remove them. There is at present no routine deletion schedule for them.
  • Certain records are append-only. Once a stock movement, an event or a case action has been written, PIIS provides no function by which it may be edited or removed. A correction is made by writing a further record; the original entry remains visible.
  • Records of successful sign-in are retained for 365 days. Removal takes effect at the next monthly maintenance.
  • Records of failed sign-in attempts become due for removal once the lock-out window of approximately 30 minutes has passed. Removal occurs when a sign-in is next processed.
  • A signed-in session expires after 14 days. Records of expired sessions are removed at the next monthly maintenance.
  • Method documents and their registered versions are retained until a decision is taken to remove them. There is at present no routine deletion schedule for them. A registered version may be withdrawn; the version number and the date remain visible so that the sequence of versions stays intelligible, while the text of that version and the reason given for the withdrawal are no longer displayed.
  • Duty records, including the record of who was assigned, who did the work and who cancelled a duty, are retained until a decision is taken to remove them. There is at present no routine deletion schedule for them.
  • Error reports are deleted by Sentry 30 days after they are received.
  • A backup of the entire database is taken nightly and retained for 30 days. Removal of data from PIIS takes effect on the live database immediately; the data may remain in a backup for up to 30 days. Each night's backup is a separate file and is deleted on that schedule. Individual records are not removed from within a backup.
  • When a member leaves the laboratory, the account is disabled. Identifiers necessary to preserve the intelligibility and integrity of historical transaction records continue to be retained for the applicable retention period. See section 10.

Monthly maintenance is performed manually, on the first working day of each month, by a person designated by the laboratory, who records what was removed. Maintenance not performed in a given month is performed at the next monthly maintenance.

9. Prohibited content and incident reporting

The following must not be entered into any free-text field:

  • passwords or other access credentials;
  • confidential or unpublished research data;
  • personal information concerning other people;
  • any other content that would be unsuitable for retention in a shared record.

Free-text entries should describe the item and the problem, not the person. Matters concerning a person should be raised with the Principal Investigator.

PIIS provides no function by which text entered in the following places can be edited or removed:

  • the reason recorded on a problem case;
  • the note recorded on a stock issue;
  • the note recorded on a case action;
  • the note attached to an event, into which text entered when carrying out other actions is written.

The text of a method document is a free-text field for the purposes of this section. It is the largest such field in PIIS and is visible to every signed-in member.

A registered version of a method document differs from the entries listed above in one respect. It cannot be edited, but it can be withdrawn by the administrator under a documented procedure of the laboratory, after which its text is no longer displayed; the version number, the status and the date remain visible so that the sequence of versions stays intelligible. The reason recorded for a withdrawal is not displayed. A withdrawal cannot be reversed. The considerations set out in section 8 concerning backups apply.

A member who has entered prohibited content should inform the administrator without delay. PIIS itself provides no means of removing the entry, and a correction may be written alongside it. Removal from the live records, where warranted, is carried out under a documented procedure of the laboratory and requires the approval of the Principal Investigator. A copy taken beforehand may remain in a backup for up to 30 days. The matter is reported to the Principal Investigator, who determines what further action is taken.

10. Rights of members

The following are available to a member directly: My items, listing the items issued to that member, and My Orders, listing the requests that member has raised.

A member may request confirmation of whether PIIS processes personal data concerning that member, access to those data, information concerning the purposes, categories, sources and recipients of those data, and correction, deletion or restriction of the data where applicable under law. Such a request may be addressed to the administrator or to the Principal Investigator. Where the request cannot be met through the ordinary functions of PIIS, it is considered under the operating procedures of the laboratory, and the member is informed of the outcome and of the reason for it. Corrections made through PIIS are themselves recorded.

When a member leaves the laboratory, the account is disabled; the account name remains visible on the records in which it appears, as described in section 8. Questions about this Statement may be raised with the administrator or with the Principal Investigator.

Last reviewed: 5 August 2026.