Privacy policy

Information under Art. 13 and 14 GDPR

Review before launch.This describes what the portal technically does today, but it is not legal advice. Fill in the controller details and have it reviewed by the university's data protection officer before going live.

1. Controller

[Exact legal name as used in the university's own Impressum], a public-law corporation (Körperschaft des öffentlichen Rechts), [address], Bamberg, Germany. Contact: [contact email].

Data protection officer: [name and contact of the university's DPO]. German public universities are legally required to have one, so this cannot be left empty — use the university's existing officer rather than appointing a new one for this portal.

2. What we process

We process only what you provide or what is technically required to operate the portal:

  • Account data: your email address and password. The password is stored and verified solely by Google Firebase Authentication — we never see it.
  • Profile data: name, role (student or alumnus), biography, skills and self-assessed skill ratings, profile photo, and — depending on your role — degree, faculty, semester, student ID, expected graduation, or job title, company, industry, location and graduation year.
  • Links you add: LinkedIn, portfolio, GitHub, X/Twitter and a CV link.
  • Activity data: posts and job listings you publish, and connection requests.
  • Direct messages: encrypted end-to-end in your browser before they are sent. We store ciphertext only and cannot read them.
  • Access key: the enrolment code used to register, so that eligibility can be verified.
  • Safety data: reports you submit and users you block.

We do not use advertising, third-party analytics, tracking pixels or profiling, and we set no marketing cookies. Your session is kept in your browser's local storage so that you stay signed in.

3. Legal basis

  • Art. 6(1)(b) GDPR — performance of a contract: operating your account and the portal's core functions.
  • Art. 6(1)(f) GDPR — legitimate interests: keeping the platform secure, preventing abuse and moderating reported content.
  • Art. 6(1)(a) GDPR — consent: any optional profile information you choose to add, which you may remove at any time.

4. Who can see your data

Your profile is visible to other signed-in members of the portal. It is not public and is not indexed by search engines. Students can see an alumnus's profile only once that alumnus has offered to mentor them.

Direct messages are end-to-end encrypted. They are encrypted in your browser with a key that only you hold, and can be read solely by you and the person you are messaging. Administrators cannot read them — neither through the portal nor through the underlying database. Administrators can see that a conversation exists and may delete a reported one, but never its contents.

Because the key exists only on your device, we cannot recover your messages for you. Account settings lets you back the key up and restore it on another device.

We do not sell your data and do not share it with advertisers.

5. Processors and hosting

  • Google Ireland Ltd. — Firebase Authentication and Cloud Firestore. Data is stored in the European Union (multi-region 'eur3'). Message contents reach this processor only as ciphertext. A data processing agreement under Art. 28 GDPR is in place via the Google Cloud Data Processing Addendum.
  • Vercel Inc. — application hosting and delivery. Server logs may briefly contain your IP address for security and operational purposes.
  • ui-avatars.com — used only to generate a placeholder image when you have not uploaded a photo. Your name is transmitted in order to render the initials.

6. Retention

We retain your data for as long as your account exists. When your account is deleted, your profile, posts and connections are removed. Messages you have sent may remain visible in the recipient's conversation, as they are also that person's correspondence. Safety reports are retained for as long as they are needed to handle the case.

7. Your rights

Under the GDPR you have the right to:

  • Access (Art. 15) — download everything we hold about you at any time from Profile → Account. Messages are exported as stored, which means encrypted.
  • Rectification (Art. 16) — edit your profile directly in the portal.
  • Erasure (Art. 17) — request deletion of your account from Profile → Account.
  • Restriction (Art. 18) and objection (Art. 21) to processing.
  • Data portability (Art. 20) — your export is machine-readable JSON.
  • Withdrawal of consent at any time, without affecting processing already carried out.

You also have the right to lodge a complaint with a supervisory authority. For Bavaria this is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) in Ansbach.

8. Security

All traffic is encrypted in transit (TLS). Access to data is enforced server-side by Firestore security rules: only signed-in members can view profiles, only participants can read a conversation, and administrative access is restricted to a single verified administrator account. Direct messages are additionally encrypted end-to-end, so their contents are not readable even with database access.

9. Changes

We may update this policy as the portal develops. Material changes will be communicated within the portal.

See also our Impressum.