The operators of this website take the security of your private collector profiles, institution archives, and agricultural records very seriously. We treat all personal data with the highest level of confidentiality in strict accordance with statutory European General Data Protection Regulation (GDPR) frameworks and the California Consumer Privacy Act (CCPA) standards. Technical metadata, such as encrypted IP strings, request logging timestamps, and unit preferences, are handled solely to maintain database server integrity and seamless navigation.
When you register specimens or submit inquiries via our secure registry portal, we collect and store the following classifications of information:
Pursuant to Article 6 of the GDPR, we process personal data under several conditions:
To secure our users from security intrusions, the exact storage address and owner identity of elite registered flora (e.g. specimens valued at over $15,000 USD) are handled under a double-blind cryptographic tokenization routine. Front-end users of the index only view the generic municipal region and verified country of origin. Full owner directories are preserved offline and can only be accessed with dual authorization from the executive board of registrars.
All database registers are housed on European Union-based ISO/IEC 27001 certified physical servers. Data transmissions are shielded using 256-bit TLS encryption protocols. Active firewalls, periodic penetration tests, and strict role-based access protocols ensure that unauthorized agricultural competitors or illegal nursery brokers cannot harvest registry locations or metadata logs.
For trans-continental transfers, we may share registered genomic IDs and phytosanitary certificate copies with national customs, environmental authorities (such as IBAMA in Brazil or USDA in the USA), and EPPO monitoring networks. This processing is strictly restricted to executing necessary legal clearance and preventing asset seizure at border borders.
We preserve registration records for as long as the specimen maintains active entry status in the Collection Maximums Index. Should you decide to remove a specimen from the ledger or terminate your advisory board account, all structural records, geospatial locations, and contact identities are permanently expunged from our database archives within 14 business days, unless legal holding mandates apply.
Under the GDPR, you have comprehensive rights regarding your stored data. You may exercise these at any point by emailing our legal secretariat:
To trigger any actions, please contact our data safety division: [email protected].