Privacy Policy
Version: 2026-07-30
This Privacy Policy explains how HiWi Finder processes personal data during the beta service. It should be reviewed and completed with the real operator details before paid public launch.
1. Controller
Controller: HiWi Finder Operator
Address: Address to be added before paid public launch
Contact: mohamad.ahmadzadeh@fau.de
Jurisdiction: Germany
2. Data we process
- Account data: username, email, display name, password hash, verification status, login timestamps.
- Sender settings: SMTP host, username, stored SMTP password, from email, sender profile fields.
- CV data: uploaded CV file and/or CV link if the user provides one.
- Outreach data: chair/contact records, email subjects, message bodies, status, sent timestamps, reply markers.
- Security and abuse data: activity logs, IP address in logs, trial cookie, hashed signup fingerprint.
3. Purposes
Data is used to provide the account, generate and send user-controlled emails, maintain contact queues, prevent duplicate trials and abuse, troubleshoot delivery issues, and keep basic service records.
4. Legal basis
Processing may be based on contract performance for account and paid-plan features, legitimate interests for security and abuse prevention, consent where explicitly requested, and legal obligations where record keeping is required.
5. University contact data
Contact data may include names, roles, public profile URLs, university email addresses, chair names, faculties, and departments. Users must use this data only for relevant academic outreach and must respect objections or removal requests.
6. Retention
Account and outreach data is kept while the account is active or while needed for service, security, billing, or legal reasons. Users can request deletion or correction of their own account data.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection to processing. Contact mohamad.ahmadzadeh@fau.de to make a request.
8. Processors and infrastructure
The service may run on cloud infrastructure and use email servers configured by the user. Users should only enter SMTP credentials they are authorized to use.