{% extends 'base.html' %}

{% block title %}Privacy Policy - IMProofBench{% endblock %}

{% block extra_css %}
<style>
    .privacy-content {
        max-width: 800px;
        margin: 0 auto;
        line-height: 1.6;
    }
    .privacy-content h2 {
        color: #0d6efd;
        margin-top: 2rem;
        margin-bottom: 1rem;
        border-bottom: 2px solid #e9ecef;
        padding-bottom: 0.5rem;
    }
    .privacy-content h3 {
        color: #495057;
        margin-top: 1.5rem;
        margin-bottom: 0.75rem;
    }
    .contact-box {
        background-color: #f8f9fa;
        border-left: 4px solid #0d6efd;
        padding: 1rem;
        margin: 1rem 0;
    }
</style>
{% endblock %}

{% block page_header %}
<div class="text-center mb-4">
    <div class="bg-info bg-gradient rounded-circle d-inline-flex align-items-center justify-content-center mb-3" 
         style="width: 60px; height: 60px;">
        <i class="bi bi-shield-check text-white fs-3"></i>
    </div>
    <h1 class="display-6 fw-bold text-primary mb-2">Privacy Policy</h1>
    <p class="lead text-muted">How we protect and handle your personal data</p>
    <p class="text-muted"><small>Last updated: June 13, 2025</small></p>
</div>
{% endblock %}

{% block content %}
<div class="privacy-content">
    <h2>1. Introduction</h2>
	<p>IMProofBench ("we", "our", or "the platform") is an academic benchmarking platform for evaluating AI systems on research-level mathematics, operated as a research project at <redacted>. We are committed to protecting your privacy and handling your personal data transparently and securely.</p>
    <p>This privacy policy explains what personal data we collect, why we collect it, and your rights regarding this data.</p>

    <h2>2. Data Controller</h2>
    <div class="contact-box">
        <strong>The data controller for IMProofBench is:</strong><br><br>
    </div>
	<p><strong>For general data protection inquiries at <redacted>:</strong><br>
    Data Protection Officer: Tomislav Mitar<br>
	Email: <a href="mailto:<redacted>"><redacted></a></p>

    <h2>3. What Personal Data We Collect</h2>
    <p>We collect and process the following personal data:</p>
    <ul>
        <li><strong>Name</strong>: Used for attribution of your contributions and display on the platform</li>
        <li><strong>Email address</strong>: Used for authentication and account management</li>
        <li><strong>Account metadata</strong>: Registration date, last login time</li>
        <li><strong>Your contributions</strong>: Mathematical questions, solutions, and grading schemes you create</li>
    </ul>
    
    <div class="alert alert-info">
        <strong>We do NOT collect:</strong>
        <ul class="mb-0">
            <li>Passwords (only secure hashes are stored)</li>
            <li>IP addresses or location data</li>
            <li>Cookies for tracking or analytics</li>
            <li>Any sensitive personal data</li>
        </ul>
    </div>

    <h2>4. How We Use Your Data</h2>
    <p>We process your personal data for the following purposes:</p>
    <ul>
        <li><strong>Account management</strong>: Creating and maintaining your user account</li>
        <li><strong>Authentication</strong>: Verifying your identity when you log in</li>
        <li><strong>Attribution</strong>: Crediting you for your mathematical contributions</li>
        <li><strong>Communication</strong>: Sending essential platform-related emails (password resets, account verification)</li>
        <li><strong>Platform operation</strong>: Enabling collaboration features and maintaining platform integrity</li>
    </ul>

    <h2>5. Legal Basis for Processing</h2>
    <p>We process your personal data based on <strong>legitimate interest</strong> (Article 6(1)(f) of the GDPR):</p>
    <ul>
        <li>We have a legitimate interest in facilitating academic collaboration and mathematical research</li>
        <li>The processing is necessary for operating an academic benchmarking platform</li>
        <li>Your interests and fundamental rights do not override these legitimate interests, given the minimal data collected and academic context</li>
    </ul>

    <h2>6. Data Storage and Security</h2>
    <p>Your data is:</p>
    <ul>
		<li>Stored on secure <redacted></li>
		<li>Protected by <redacted> institutional security measures</li>
        <li>Encrypted in transit using HTTPS</li>
        <li>Password-protected with industry-standard hashing (PBKDF2+SHA256)</li>
        <li>Accessible only to authorized platform administrators</li>
    </ul>

    <h2>7. Data Retention</h2>
    <p>We retain your personal data:</p>
    <ul>
        <li><strong>Active accounts</strong>: As long as your account remains active</li>
        <li><strong>Inactive accounts</strong>: May be deleted after 3 years of inactivity</li>
        <li><strong>After deletion request</strong>: Removed within 30 days of your request</li>
    </ul>
    <p>Your mathematical contributions may be retained for academic integrity but will be anonymized upon account deletion.</p>

    <h2>8. Data Sharing</h2>
    <div class="alert alert-warning">
        <strong>We do NOT:</strong>
        <ul class="mb-0">
            <li>Sell your personal data</li>
            <li>Share your data with third parties for marketing</li>
			<li>Transfer your data outside of <redacted> systems</li>
        </ul>
    </div>
    
    <p><strong>We MAY share data only:</strong></p>
    <ul>
        <li>With other registered platform users (your name on contributed questions)</li>
		<li>If required by Swiss law or <redacted> policies</li>
        <li>With your explicit consent</li>
    </ul>

    <h2>9. Your Rights</h2>
    <p>Under Swiss data protection law and the GDPR, you have the right to:</p>
    <ul>
        <li><strong>Access</strong>: Request a copy of your personal data</li>
        <li><strong>Rectification</strong>: Correct inaccurate personal data (via your profile settings)</li>
        <li><strong>Erasure</strong>: Request deletion of your account and personal data</li>
        <li><strong>Portability</strong>: Receive your data in a machine-readable format</li>
        <li><strong>Object</strong>: Object to processing based on legitimate interest</li>
        <li><strong>Complaint</strong>: Lodge a complaint with supervisory authorities</li>
    </ul>

    <h2>10. AI Model Testing</h2>
    <p>We test AI systems on mathematical questions submitted to the platform. This testing:</p>
    <ul>
        <li>Evaluates mathematical reasoning capabilities only</li>
        <li>Does NOT involve processing of personal data</li>
        <li>Does NOT profile or make automated decisions about users</li>
        <li>Results are used solely for academic research purposes</li>
    </ul>

    <h2>11. International Users</h2>
    <p>While we welcome international collaboration:</p>
    <ul>
        <li>Data is processed and stored in Switzerland</li>
        <li>Switzerland is recognized by the EU as providing adequate data protection</li>
        <li>We comply with GDPR for EU/EEA users</li>
        <li>Users from other jurisdictions participate under Swiss law</li>
    </ul>

    <h2>12. Children's Privacy</h2>
    <p>IMProofBench is intended for academic researchers and is not directed at children under 16. We do not knowingly collect personal data from children.</p>

    <h2>13. Changes to This Policy</h2>
    <p>We may update this privacy policy to reflect changes in our practices or legal requirements. We will notify registered users of significant changes via email.</p>

    <h2>14. Contact Us</h2>
    <p>For privacy-related questions or to exercise your rights:</p>
    
    <div class="row">
        <div class="col-md-6">
            <div class="contact-box">
                <strong>Project-specific inquiries:</strong><br>
            </div>
        </div>
        <div class="col-md-6">
            <div class="contact-box">
				<strong><redacted> data protection inquiries:</strong><br>
                Data Protection Officer: Tomislav Mitar<br>
				Email: <redacted><br>
				Address: <redacted>
            </div>
        </div>
    </div>

    <div class="contact-box mt-3">
        <strong>Swiss Federal Data Protection Authority:</strong><br>
        Federal Data Protection and Information Commissioner (FDPIC)<br>
        Feldeggweg 1, 3003 Bern<br>
        Website: <a href="https://www.edoeb.admin.ch" target="_blank">www.edoeb.admin.ch</a>
    </div>

    <hr class="my-4">
    <p class="text-center"><em>By creating an account on IMProofBench, you acknowledge that you have read and understood this privacy policy.</em></p>
</div>
{% endblock %}
