Privacy Policy
How the RUN-EU Academia Link Platform collects, uses and protects your personal data.
1. About this policy
This Privacy Policy explains how the RUN-EU Academia Link Platform ("RUN-EU ALP", "the Platform") collects, uses, stores and protects personal data when you register for an account, sign in, and use the collaboration features of the Platform. It applies to all users of RUN-EU ALP, including researchers, institutional managers, committee members and company/organization representatives.
2. Who is responsible for your data
The data controller for the RUN-EU Academia Link Platform is Universidade de Leiria e Oeste (ULO). The data controller is responsible for deciding why and how your personal data is processed on the Platform.
3. Personal data we process
We process the following categories of personal data:
Account information
- Email address
- Password (stored hashed)
- Account role
- Account status
Profile information
- Name
- Short biography
- Personal/professional link
- Avatar image (optional)
- ORCID identifier (researchers, optional)
Institutional / organization data
- Associated higher education institution (HEI)
- Organization name, sector, country, city
- Organization contact email and website
Collaboration data
- Collaboration proposals and their content
- Invitations sent and received
- Team membership and roles within a proposal
- Agreement documents uploaded to a proposal
Authentication data
- Session token (JSON Web Token), held in your browser
- Password reset tokens (short-lived, single use)
Analytics data (only with consent)
- Pages viewed and features used
- An analytics identifier linked to your account
We do not knowingly request special categories of data (such as health, religious or political information) through the Platform.
4. How we use your data
Personal data is used to:
- create and manage your user account;
- authenticate you when you sign in;
- let organizations create and manage collaboration proposals with HEIs and researchers;
- manage invitations, team formation and agreement documents related to proposals;
- display relevant profile and institutional information to other users you collaborate with;
- support matching between proposals, researchers and organizations (see "AI-assisted functionality" below);
- keep the Platform secure and functioning correctly;
- understand feature usage and improve the Platform, only where you have given analytics consent.
5. Legal basis for processing
RUN-EU ALP processes personal data on different legal bases under Article 6 of the GDPR, depending on the purpose of the processing.
- Public interest — Article 6(1)(e): account and profile management, collaboration proposals, invitations, team formation, agreement management, operational notifications and AI-assisted matching are processed as part of the ULO/RUN-EU mission to support academic, institutional and industry collaboration.
- Consent — Article 6(1)(a): analytics data collected through PostHog is processed only after you explicitly opt in, and this consent may be withdrawn at any time.
- Consent — Article 6(1)(a): linking an ORCID identifier is optional and is initiated by the researcher, to enrich their profile and improve collaboration recommendations.
6. Authentication and third-party services
You can sign in with an email and password, or by using Microsoft Entra ID (Microsoft sign-in, based on OpenID Connect). When you sign in with Microsoft, RUN-EU ALP receives the minimum profile information needed to identify your account — namely your email address — from Microsoft. RUN-EU ALP does not access your Microsoft mailbox, files or other Microsoft Graph data.
If you add an ORCID identifier to your researcher profile, the Platform may use it to retrieve publicly available information about your published works from the public ORCID API, in order to enrich your profile and support proposal matching.
Session authentication uses a signed token (JSON Web Token) stored in your browser's local storage. This token identifies your session and expires automatically after a limited period, after which you will need to sign in again.
7. Analytics and platform improvement
RUN-EU ALP uses PostHog to understand how the Platform is used (e.g. pages visited, features used) so that it can be improved over time.
Analytics is opt-in: it is only activated if you give consent through the cookie preferences banner/dialog available on the Platform. You can review or change your analytics consent at any time from that same control. If you do not consent, or if you later withdraw consent, no analytics data is collected about your usage.
Further information about cookies and similar technologies used by the Platform is available in our Cookies Policy.
8. AI-assisted functionality
RUN-EU ALP uses Google Gemini (a third-party AI service) to support the collaboration-proposal matching feature. This may involve:
- generating numerical representations ("embeddings") of researcher profiles, organization profiles and proposal content;
- ranking and reranking candidate matches, including generating a short explanation for each suggested match;
- summarizing uploaded proposal documents into short bullet points to support matching and review;
- where an ORCID identifier is provided, incorporating a summary of your public ORCID works into this matching process.
For researchers, this may involve processing data such as name, HEI, country, ORCID-derived topics and short bio, where available. For organizations, this may involve organization name, sector, type, description, country, city, webpage, and information about past proposals and proposal responses. For proposals, this may involve the title, description, areas, and extracted/summarized document content.
This means that profile, proposal and, where applicable, ORCID content may be sent to Google's Gemini API for processing. RUN-EU ALP does not use this data to train third-party AI models beyond the processing described here, to the best of our knowledge of the service configuration in use.
The AI-assisted matching feature provides recommendations only. It does not automatically select, invite, accept or reject researchers or organizations. Users remain responsible for all collaboration decisions.
9. Data sharing and service providers
We share personal data with the following categories of service providers, strictly to operate the Platform:
- Cloudinary — stores and serves profile avatar images you choose to upload;
- Google (Gemini API) — processes profile and proposal content to support AI-assisted matching, as described above;
- ORCID — supplies publicly available works data for researchers who link an ORCID identifier;
- PostHog — processes analytics data, only when you have given analytics consent;
- Email delivery service — used to send transactional emails (account invitations, password resets, proposal and agreement notifications). In production this is sent via the responsible institution's own mail infrastructure; in local development and staging environments a sandboxed testing service (Mailtrap) is used instead, and no real recipients are contacted from those environments.
We do not sell personal data, and we do not share personal data with third parties for their own marketing purposes.
10. International data transfers
Some third-party services used by RUN-EU ALP may process personal data outside the European Economic Area (EEA).
PostHog analytics is configured to use its European hosting region. However, other service providers used by the Platform may process data internationally. In particular, the Cloudinary account used by RUN-EU ALP uses Cloudinary's default US-based infrastructure, and ORCID operates infrastructure in the United States.
Other providers, including Microsoft and Google services, may also process data internationally depending on their applicable service configuration and data-processing terms.
Where personal data is transferred outside the EEA, such transfers are subject to appropriate safeguards under applicable data protection law. These may include adequacy decisions, Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework, or other legally recognized transfer mechanisms.
RUN-EU ALP limits the personal data shared with third-party services to what is necessary for the purposes described in this Privacy Policy.
11. Data retention
Some retention periods are defined at a technical level today:
- authentication session tokens expire automatically after 12 hours;
- password reset links expire automatically after 60 minutes, or immediately once used;
Account, profile, proposal, agreement, document and analytics data are currently retained without an automatic deletion period. Formal institutional retention periods may be defined or reviewed by the data controller as part of the Platform's data governance.
12. Security
RUN-EU ALP applies technical and organizational measures appropriate to the nature of the data processed. This includes encrypted connections (HTTPS) between your browser and the Platform, hashed password storage, signed and time-limited authentication tokens, and role-based access control restricting which data each type of user can view or manage. We continue to improve these measures over time. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Your rights
Subject to applicable data protection law, you may have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure of your data, where applicable;
- request restriction of processing, where applicable;
- object to certain processing, where applicable;
- request portability of your data, where applicable;
- withdraw consent at any time, where processing is based on consent (e.g. analytics), without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with the competent supervisory authority.
To exercise these rights, please contact the data controller using the details in the "Contact" section below. Some requests may currently require manual handling by the responsible team, rather than an automated in-platform process.
14. Contact and data protection enquiries
For privacy and data protection enquiries, including requests relating to your personal data, please contact alp@run-eu.eu.
15. Changes to this Privacy Policy
We may update this Privacy Policy as the Platform evolves, for example when new features or third-party services are introduced. Material changes will be reflected on this page. We encourage you to review this page periodically.