Last updated: 29 May 2026
This page explains how the Herizon Partner Portal processes the personal data of the school staff and partner-organisation representatives who use it. The portal is one of three Herizon surfaces with its own policy — see also the Herizon Matcher policy at match.herizon.io/privacy-policy and the Herizon community sign-up policy at join.herizon.io/privacy-policy.
We may update this policy as the service evolves or legislation changes. Please check back from time to time.
For questions about this statement, contact the service provider:
Herizon Oy
Email: [email protected]
The Partner Portal processes the following personal information about its users (school staff, supervisors, and partner-company contacts who have been granted access):
HIP_HH_2026_05)In addition, the service processes standard network identification data generated by the use of the portal (e.g. IP address, browser user agent).
About people other than the portal user: when a school staff member reviews student applications, they see the student's name, email address, school, and the application content the student submitted via join.herizon.io. That student data is governed by the join.herizon.io privacy policy linked above; the Partner Portal only displays it.
Most information about portal users comes directly from those users — they enter their name and verify their work email when first invited.
Access rights (which school cohorts a user can review) are added by Herizon staff in our internal CRM at the request of the partner school or organisation.
Student application content reviewed in the portal originates from join.herizon.io — Herizon does not edit applicant content on behalf of the school.
Personal information is processed in order to:
The portal does not run automated decisioning that materially affects the user or the students. Approval decisions are taken by the school staff member.
User information is not sold or shared with marketing partners.
The service relies on third-party infrastructure providers to operate. Data in transit and at rest passes through these providers under data-processing agreements that uphold the rights described in this policy.
List of third-party services:
| Service | Location |
|---|---|
| Hetzner Cloud | EU |
| Postmark | USA |
| Slack | USA |
| Cloudflare | USA |
Information can be forwarded to public authorities where there is a legal basis. Outside of that, no transfer happens without the user's consent.
Data is stored in the EU/EEA area on infrastructure operated by Hetzner Cloud (Helsinki, Finland).
Limited operational data (e.g. transactional email delivery, edge caching) may be processed by service providers based in the USA. These providers are bound by standard contractual clauses and process data under data-processing agreements.
Portal user accounts are kept while the user's access tag is active. When a school ends a cohort or terminates the partnership, the user's access is revoked promptly. The user's name and email are retained for audit purposes unless the user requests deletion.
Login session tokens expire automatically. Network identification data is stored for a maximum of 1 year.
All data is stored on servers in the EU. Network traffic between the user's browser and the portal is TLS encrypted. Access to production data is limited to a small number of Herizon staff, on a least-privilege basis.
Portal users have the following rights: