Herizon Partner Portal — Privacy Policy

Last updated: 29 May 2026

This page explains how the Herizon Partner Portal processes the personal data of the school staff and partner-organisation representatives who use it. The portal is one of three Herizon surfaces with its own policy — see also the Herizon Matcher policy at match.herizon.io/privacy-policy and the Herizon community sign-up policy at join.herizon.io/privacy-policy.

We may update this policy as the service evolves or legislation changes. Please check back from time to time.

1. Contact information

For questions about this statement, contact the service provider:

Herizon Oy
Email: [email protected]

2. What data is processed?

The Partner Portal processes the following personal information about its users (school staff, supervisors, and partner-company contacts who have been granted access):

  • Name
  • Work email address
  • The school or organisation the user represents, including the specific cohort tag (e.g. HIP_HH_2026_05)
  • Session and authentication data (one-time login codes, browser session tokens)
  • Action history within the portal — for example, which student applications a user approved or sent back, and when

In addition, the service processes standard network identification data generated by the use of the portal (e.g. IP address, browser user agent).

About people other than the portal user: when a school staff member reviews student applications, they see the student's name, email address, school, and the application content the student submitted via join.herizon.io. That student data is governed by the join.herizon.io privacy policy linked above; the Partner Portal only displays it.

3. Where does the information come from?

Most information about portal users comes directly from those users — they enter their name and verify their work email when first invited.

Access rights (which school cohorts a user can review) are added by Herizon staff in our internal CRM at the request of the partner school or organisation.

Student application content reviewed in the portal originates from join.herizon.io — Herizon does not edit applicant content on behalf of the school.

4. For what purpose is the information processed?

Personal information is processed in order to:

  • Authenticate the portal user and protect the account
  • Show the right student applications + reports to the right school
  • Send transactional notifications about pending approvals (e.g. the bi-monthly “Pending applications” email)
  • Keep an audit trail of approval decisions for the school's own records
  • Produce anonymised reports about programme outcomes (no personal data of portal users appears in these)

The portal does not run automated decisioning that materially affects the user or the students. Approval decisions are taken by the school staff member.

5. Is information disclosed or transferred to third parties?

User information is not sold or shared with marketing partners.

The service relies on third-party infrastructure providers to operate. Data in transit and at rest passes through these providers under data-processing agreements that uphold the rights described in this policy.

List of third-party services:

ServiceLocation
Hetzner CloudEU
PostmarkUSA
SlackUSA
CloudflareUSA

Information can be forwarded to public authorities where there is a legal basis. Outside of that, no transfer happens without the user's consent.

6. Where is the data stored?

Data is stored in the EU/EEA area on infrastructure operated by Hetzner Cloud (Helsinki, Finland).

7. Is data transferred outside the EU/EEA area?

Limited operational data (e.g. transactional email delivery, edge caching) may be processed by service providers based in the USA. These providers are bound by standard contractual clauses and process data under data-processing agreements.

8. How long is the data kept?

Portal user accounts are kept while the user's access tag is active. When a school ends a cohort or terminates the partnership, the user's access is revoked promptly. The user's name and email are retained for audit purposes unless the user requests deletion.

Login session tokens expire automatically. Network identification data is stored for a maximum of 1 year.

9. How is data protected?

All data is stored on servers in the EU. Network traffic between the user's browser and the portal is TLS encrypted. Access to production data is limited to a small number of Herizon staff, on a least-privilege basis.

10. The user's rights

Portal users have the following rights:

  • Reviewing information. You can request a copy of the information we hold about you by emailing [email protected].
  • Right to correction. You can request that we correct any inaccurate information.
  • Right to erasure. You can request that we delete your account and associated personal data, subject to any legal retention obligation.