Data Governance
How data enters the platform, who can reach it, and what happens to it — covering both public sources and microdata you upload.
Last reviewed 20 August 2026
Two classes of data, handled differently
AIC holds two kinds of data and does not mix them. Public statistical data — World Bank, WHO, FAO, DHS Program, HDX, IPUMS and national statistical offices — is aggregated, openly licensed and served to anyone. Microdata you upload is private, access-controlled, and never redistributed or added to any public dataset.
Uploaded microdata
Uploaded survey files are written to private object storage bound to the uploading account. They are not listed publicly, not indexed, and not shared with other users unless you explicitly grant access.
- Stored in access-controlled cloud storage, not on the public web
- Reachable only with a valid token belonging to the owning account
- Never redistributed, resold, or added to public catalogues
- Deletable on request, together with derived analysis artefacts
Licensing and attribution of public data
Public data carries the licence of its original provider. AIC does not relicense it. Each catalogued source records its licence category, access conditions, update frequency and whether redistribution or registration is required — visible in the data source catalogue rather than buried in terms.
Where a source requires registration or approval before use, AIC links you to the provider rather than proxying the restricted data.
Re-identification
Household survey microdata is de-identified by its producers, but de-identification is not absolute. Attempting to re-identify individuals or households in any dataset accessed through AIC is prohibited under the terms of service, and analysis outputs should be reported at a level of aggregation that does not expose individual records.
Lifecycle, retention and deletion
AIC keeps public-source records with their provenance so analytical results remain reproducible. Uploaded data and its derived artefacts are retained while the workspace is active or as agreed with an institutional customer. An owner may request deletion; operational backups expire through the cloud provider's normal rotation rather than being used to restore deleted customer content.
Before an institutional engagement, the parties should agree any statutory retention, legal-hold, archival or data-residency requirements in writing. AIC does not claim a universal retention period where the governing contract or source licence requires a different one.
Product analytics and data minimisation
AIC records first-party events needed to understand activation, retention and feature use: page views, calls to action, feature starts, completions, failures and enquiries. Events use pseudonymous browser and session identifiers and approved categorical context only.
- No uploaded dataset values, filenames, analytical questions or prompts are captured
- No email address, personal name, authentication token, IP address or user-agent string is stored in the product-event table
- Analytics summaries are restricted to administrators
Accountability and requests
AIC is accountable for platform controls; source publishers remain accountable for the data they publish, and workspace owners remain responsible for their authority to upload and analyse restricted data. Questions, access requests, correction requests and deletion requests can be sent to info.aic@hyrin.org and will be verified before action is taken.
Questions about this?
Email info.aic@hyrin.org. If you are assessing AIC for an institutional data partnership and need something addressed formally, say so and we will respond in writing.