Section 1 · Data Controller
Data Controller
Hexona Systems operates BipHub as an independent project. The data controller for personal data processed through this site is Hexona Systems. For privacy questions or to exercise your rights under GDPR Articles 15–18 and 21, contact us at contact@biphub.org.
Section 2 · What we collect
What we collect
Supabase Auth session cookies (essential). When you sign in as a university coordinator, our authentication provider (Supabase) sets HTTP-only cookies that keep you signed in across page loads. These cookies are strictly necessary for the sign-in feature to function and are exempt from consent under EU ePrivacy rules.
Saved BIPs. When a signed-in student saves a BIP, we store a saved_bips table row containing your user ID, the BIP's internal ID, and the timestamp of the save (saved_at). This data is stored in Supabase (EU region) and is used solely to sync your saved BIPs across devices. It is retained until you remove the BIP from your saved list or delete your account. All saved_bips rows are permanently deleted when you delete your account (cascading deletion via foreign key). No saved-BIP data is shared with third parties.
Legacy bookmark sweep. On first sign-in, the app reads any biphub:bookmarks value previously stored in your browser's localStorage (from an earlier version of BipHub), migrates valid BIP IDs into your server-side saved list, then immediately clears the localStorage key. After this one-time sweep the key is not written again.
Local browser storage. The bip-draft key holds an in-progress BIP submission so you do not lose your work if your session expires mid-form. This data is essential to the feature it supports and remains on your device only.
Coordinator profile and submission content. When a university coordinator registers, we store their full name, contact email, university affiliation, and Erasmus institutional code. When they submit a BIP, we store the submission content (programme title, description, dates, contact details they wish to publish, and so on). Approved submissions are published as part of the public Erasmus+ directory.
Student profile. When a student registers, we store their full name, country of residence, and (optionally) home university, plus the account email. This lets coordinators and admins recognise who saved a BIP or set an alert. Students who registered before these fields existed are asked to complete them on their next sign-in.
Alert preferences. When a signed-in student saves alert preferences, we store a single bip_alert_preferences row with your user ID, your chosen fields of study and/or countries (any number), frequency (weekly or daily), the explicit consent text you agreed to, and update time. This is used solely to send you the digest emails you requested.
Alert deliveries. Each time we send you a digest, we store a bip_alert_deliveries row (BIP ID + your user ID + delivery time) so the same BIP is never emailed twice. Both surfaces are retained until you clear your preferences or delete your account. All bip_alert_preferences and bip_alert_deliveries rows are permanently deleted when you delete your account (cascading deletion via foreign key). You can unsubscribe at any time via the link in the email (no sign-in required) or from your dashboard.
No analytics. We run no analytics scripts, no third-party trackers, no marketing pixels, no advertising cookies. We do not measure your behaviour. This is by design — the cheapest GDPR-compliant path is to collect nothing.
Processors and hosting. Your data is processed on our behalf by: Supabase (database and authentication hosting, EU region); Resend (transactional email — recipient email addresses and email content — for coordinator notifications and student digest alerts); and Vercel (application hosting — request metadata including IP addresses). Each processes personal data only to provide its service to us.
Section 3 · Legal basis
Legal basis
For coordinator accounts, the legal basis is contract performance (Art 6(1)(b) GDPR) — we cannot operate the directory without storing the account. For published BIP submissions, the legal basis is legitimate interest (Art 6(1)(f) GDPR) in maintaining a public Erasmus+ directory benefiting students across Europe.
Alert emails are consent-based. Digest emails are sent only to students who opt in by saving alert preferences, on the basis of consent (Art 6(1)(a) GDPR). The exact consent text you agreed to is stored alongside your preferences as a record. You may withdraw your consent at any time — via the unsubscribe link in any digest email (no sign-in required), by clearing your alert preferences, or by deleting your account — and withdrawal does not affect the lawfulness of processing before it.
Section 4 · Retention
Retention
Account data is retained until you delete your account from /dashboard/settings. When you delete your account, drafts and pending/rejected submissions are deleted; approved BIPs are anonymized (contact name and email are removed) and remain in the public directory as institutional information. Session cookies expire when you sign out or when their issuer's policy expires them.
Section 5 · Your rights
Your rights
Under GDPR you have the right of access (Art 15) to a copy of your personal data, the right of rectification (Art 16) to correct inaccurate data, and the right of erasure (Art 17) to have your data deleted. You also have the right to restriction of processing (Art 18) — to ask us to limit how we use your data while, for example, the accuracy of the data or the basis for processing is being checked. The right of erasure is exercised in-product via the Delete account button at /dashboard/settings. For access, rectification, or restriction requests, email contact@biphub.org — we respond within 30 days.
Right to object (Art 21). Where we process your data on legitimate-interest grounds — in particular published BIP submission data — you may object to that processing at any time on grounds relating to your particular situation. If you do, we will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing is needed for the establishment, exercise or defence of legal claims. To object, email contact@biphub.org.
Where processing is based on your consent — such as alert digest emails — you have the right to withdraw that consent at any time (Art 7(3)), as described under Legal basis above.
Right to complain. You have the right to lodge a complaint with a supervisory authority (Art 77) — normally your national data protection authority in the EU/EEA country where you live, work, or where the alleged infringement took place. You can find your authority on the European Data Protection Board's list of members (national data protection authorities).
Section 6 · How to exercise your rights
How to exercise your rights
In-product: open /dashboard/settings while signed in and use the Danger zone — Delete account. By email: write to contact@biphub.org from the email address on your account. We may ask for additional information to verify your identity before acting on a request affecting personal data.
Section 7 · Children
Children
BipHub is designed for higher-education students enrolled in Erasmus+-participating institutions. We do not knowingly process the personal data of children under 16 and we do not target children in any of our content.
Section 8 · Updates
Updates
We may update this policy as the product evolves. Material changes will be reflected on this page with an updated date stamp at the top. We do not currently maintain a public change log; if you need to see past versions, write to contact@biphub.org.