Skip to main content
Emperix

How Emperix works

Four steps, and you keep control at every one: deposit with terms, publish the description rather than the data, decide who gets it, and withdraw access when circumstances change.

  1. 01

    Deposit

    Terms recorded, file screened

  2. 02

    Describe

    Description public, data withheld

  3. 03

    Decide

    Each request judged by you

  4. 04

    Retain control

    Terms expire, access withdrawn

  1. Step 1. Deposit, and say what the terms are

    Describe the data and record how it may be used: the lawful basis for holding it, whether it concerns people, how it has been de-identified, what uses are permitted, and any ethics approval reference. Before anything is stored, Emperix screens the file for identifying columns and tells you what it found.

    GOVERNANCE

    CONCERNS PEOPLE
    Yes
    LAWFUL BASIS
    Informed consent obtained
    DE-IDENTIFICATION
    Pseudonymised (key held separately)
    PERMITTED USE
    Academic research only
    ACCESS TERM
    1 year

    PRIVACY SCREEN

    Column "phone" · Phone number

    Remove the column. A masked phone number is still traceable.

    Illustration · example data
  2. Step 2. Publish the description, not the data

    Your dataset becomes discoverable. The description, the terms and the column names are public so people can tell whether it is what they need. The data itself stays where nobody can reach it without your say-so.

    Household fever survey, 2023

    Visible to anyone: the description, the terms and the column names.

    COLUMNS

    age_banddistrictonset_weekfever_daystest_result

    TERMS

    Academic research only · Use agreement required · 1-year access

    Data withheld until the depositor approves a request
    Illustration · example data
  3. Step 3. Decide who gets it

    Requests arrive with a stated purpose and a named institution. You read what they intend to do and approve or decline, with a note if you want to explain. Nothing is granted automatically.

    REQUEST

    PENDING
    INSTITUTION OR ORGANISATION
    Public university
    WHAT WILL YOU USE IT FOR
    Re-analysis of fever duration by age band, for a thesis chapter.
    DATA USE AGREEMENT
    Accepted
    A note on your decision (optional, shared with the applicant)
    Illustration · example data
  4. Step 4. Keep control after you have granted it

    Access runs for a term you set and expires on its own. If circumstances change — consent withdrawn, an approval lapsed, a dataset that turned out to hold more than anyone realised — you can withdraw access, and the file stops being reachable.

    GRANT

    APPROVED 14 Mar 2026 · 1 year

    expires 14 Mar 2027

    WITHDRAWN 9 Sep 2026 · by the depositor

    AT THE NEXT DOWNLOAD ATTEMPT

    "Your access to this dataset was withdrawn."

    Illustration · example data

Built for data that comes with conditions

Everything below is working today.

Access by application, not by download

Datasets marked as controlled cannot simply be taken. Someone who wants your data submits an application stating what they intend to do with it and which institution they are accountable to. You decide. This is the same shape that established controlled-access archives use, because it is the only shape that works when data carries obligations.

Access that expires on its own

You choose how long a grant lasts — ninety days, a year, or indefinitely. When the term ends, access ends, without you having to remember. A licence that quietly runs forever is not a licence.

Withdrawal that actually withdraws

When you revoke someone's access, the file stops being reachable. Controlled data is never given a permanent link; every download is a short-lived one, issued only after Emperix has re-checked that the grant still stands. A withdrawn grant fails at the moment of download, not merely in a listing somewhere. The record of the original access remains — what changes is what they can still read.

Terms recorded with the data, not alongside it

Every dataset carries its lawful basis, whether it concerns people, its de-identification level, the uses permitted, its jurisdiction, any ethics or IRB reference, and any embargo date. These are not free-text notes. They are structured, they are shown to anyone considering the data, and a dataset cannot be published without them.

Agreements that are read and recorded

If your data requires a use agreement, the full text is shown before anyone can apply, and it must be accepted. The exact wording accepted is recorded against that person's access. If you revise your terms later, the record still shows what each earlier applicant actually agreed to — so a question about obligations has an answer rather than an argument.

A privacy check before anything is stored

When you upload, Emperix reads a sample and looks for identifying information: names, email addresses, phone numbers, national identity numbers, addresses, dates of birth, device identifiers. It also looks for the subtler risk — how distinctive your rows are on things like age, postcode and gender together, because that combination re-identifies people even when no single column does.

Each finding comes with something to do about it: band the ages, truncate the postcode, remove the column. And if what the file contains contradicts what you have declared — a column of phone numbers in a dataset marked as holding no personal data — it says so before you publish. Not to accuse anyone of anything. Depositors know their own subjects, and a column stops looking identifying when you know who is in it.

Derived data that remembers where it came from

Combine datasets and the result records its sources and how they were joined. It also inherits the strictest terms of its parents: join research-only data to open data and the result is research-only. Combining data cannot be a way to launder it into something less restricted than it was.

Versions that do not overwrite each other

Revising a dataset adds a version; it never replaces one. Every earlier version stays retrievable, and every grant records which version it was for. An analysis can therefore point at the exact data it used, months after the data has moved on.

Findable without being readable

Emperix publishes structured metadata for every public dataset, so they can be found through search engines and dataset indexes. Descriptions, terms and column names are included. Download locations and data are not. Being findable and being readable are different things, and controlled data needs the first without the second.

Credit that follows the person

Record your ORCID iD on your profile and it is published with your datasets, so credit attaches to you rather than to a name that thousands of people share. Institutions change, surnames change, email addresses change. An ORCID iD does not.

Data that comes with conditions deserves better than an inbox.