Privacy Policy
Effective Date: August 7, 2025; Last Updated: August 7, 2025.
1. Introduction
This Privacy Policy describes how Uni Feedback ("we," "us," "our," or the "Platform") collects, uses, and shares information when you use our university course review platform. This policy applies to all users, including students who submit reviews and administrators who manage the platform.
Controller Information:
- Platform: Uni Feedback
- Operator: Afonso (Individual Proprietorship)
- Location: Portugal
- Contact: [email protected]
2. Information We Collect
2.1 Information You Provide Directly
Student Users:
- Email address (required for account verification and communication)
- Course reviews and related content
- University affiliation (derived from email domain)
- Any additional information you choose to provide in communications with us
Administrator Users:
- Email address for authentication and account management
- Any additional information provided during account setup or communications
2.2 Information Collected Automatically
When you use our Platform, we may automatically collect:
- Device information (browser type, operating system, device identifiers)
- Usage information (pages visited, time spent, interactions)
- Technical data (IP addresses, log files)
- Analytics data to understand Platform usage patterns
We use Cloudflare for hosting services, which may collect additional technical data according to their privacy policy.
2.3 Information from Third Parties
We may receive information from:
- University email verification systems
- Mailgun (our email service provider) for authentication flows
- Legal authorities when required by law
3. How We Use Your Information
3.1 Primary Uses
For All Users:
- Provide and maintain Platform services
- Verify account eligibility and authenticity
- Communicate important Platform updates and changes
- Respond to your requests and provide customer support
- Protect Platform security and prevent fraud
- Comply with Portuguese law and EU regulations
For Student Users Specifically:
- Verify university enrollment through email domain checking
- Contact you for clarification or additional information about review submissions (only when necessary for approval)
- Thank you for your contributions to the Platform
- Process and moderate your content submissions
For Administrator Users Specifically:
- Authentication and account management (signup, login, password reset)
- Provide Platform updates and administrative communications
- Manage Platform operations and security
3.2 Analytics and Business Intelligence
We use aggregated and anonymized data derived from reviews and Platform usage to:
- Generate insights and reports about course trends and student preferences in Portuguese universities
- Improve Platform functionality and user experience
- Create data products and services for potential partnerships with universities
- Conduct research and analysis for business development
- Support educational improvement initiatives
Important: Individual student identities are never included in these analytics or shared with third parties.
3.3 Communication Purposes
We may contact you via email for:
- Account verification and security purposes (admin only)
- Responses to your inquiries or support requests
- Platform updates and important announcements
- Follow-up questions about your review submissions (student users only)
- Appreciation messages for your contributions (student users only)
We do not send marketing emails or promotional communications.
4. How We Share Your Information
4.1 Public Information
- Approved course reviews are published on the Platform without any personally identifiable information
- Aggregated and anonymized data may be shared publicly or with university partners
- Student emails are only visible to Platform administrators for verification purposes
4.2 We Do Not Sell Personal Information
We do not sell, rent, or trade your personal information to third parties for monetary gain.
4.3 Limited Sharing Scenarios
We may share your information only in these specific circumstances:
Service Providers:
- Cloudflare: Hosting and content delivery services
- Mailgun: Email delivery for admin authentication flows
- These providers are bound by confidentiality agreements and may only use your information to provide services to us
Legal Requirements:
- When required by Portuguese law, EU regulation, or legal process
- To protect our rights, safety, or property
- To investigate potential violations of our Terms of Service
Business Transfers:
- In connection with a merger, acquisition, or sale of assets (with notice to users)
Data Exports:
- We may export review data in various formats (CSV, PDF, aggregated summaries) for business purposes
- Personal information including author emails are never included in exports
- Exports are used for university partnerships, educational insights, and platform improvement
5. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Access controls and authentication measures
- Secure hosting through Cloudflare infrastructure
- Regular security assessments and updates
- Limited administrator access to personal data
However, no system is completely secure, and we cannot guarantee absolute security of your information.
6. Data Retention
6.1 Account Data
- Student user emails: Retained as long as necessary for Platform operations and legal compliance under Portuguese law
- Administrator account data: Retained for the duration of the account plus 7 days after deletion request
6.2 Content Data
- Approved reviews: Retained indefinitely as part of our Platform content to serve educational purposes
- Rejected or pending reviews: Retained for moderation purposes and may be deleted after reasonable period
- Author identities remain permanently confidential
6.3 Analytics Data
- Aggregated and anonymized usage data may be retained indefinitely for business intelligence purposes
7. Your Rights and Choices
Under Portuguese law and the General Data Protection Regulation (GDPR), you have the following rights:
7.1 Access and Correction
You may request access to or correction of your personal information by contacting us.
7.2 Data Portability
Upon request, we can provide you with a copy of your personal information in a commonly used format.
7.3 Account Deletion
Administrator Users: You may request account deletion by emailing [email protected]. We will process deletion requests within 7 days.
Student Users: Contact us for information about data deletion options. Note that published reviews may remain on the Platform as they become part of our educational content database, but your identity will never be disclosed.
7.4 Objection and Restriction
You may object to certain processing activities or request restrictions under applicable circumstances.
7.5 Communication Preferences
You may opt out of non-essential communications, though some service-related messages are necessary for Platform operation.
7.6 Data Subject Complaints
You have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) if you believe your rights have been violated.
8. International Data Transfers
As we operate in Portugal, your data is primarily processed within the European Union. However, some of our service providers (Cloudflare, Mailgun) may process data internationally with appropriate safeguards in place as required by GDPR.
9. Children's Privacy
Our Platform is intended for university students and administrators. We do not knowingly collect personal information from children under 18. If we become aware of such collection, we will delete the information promptly.
10. European Privacy Rights (GDPR)
As a platform operating in Portugal, we comply with the General Data Protection Regulation (GDPR):
10.1 Legal Basis for Processing
- Legitimate interest: Providing educational platform services and improving Portuguese higher education
- Consent: Where explicitly provided for certain activities
- Legal compliance: Meeting Portuguese and EU legal requirements
10.2 Your GDPR Rights
- Right to access, rectify, erase, restrict, or object to processing
- Right to data portability
- Right to withdraw consent where applicable
- Right to lodge a complaint with supervisory authorities
10.3 Data Protection Officer
For privacy-related questions or to exercise your rights, contact us at [email protected] with "Privacy Request" in the subject line.
11. Specific Portuguese Compliance
We comply with Portuguese data protection laws and educational regulations:
- Data processing complies with Portuguese Law 58/2019 (GDPR implementation)
- We respect academic freedom and student rights under Portuguese educational law
- Our verification processes align with Portuguese university email systems
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will:
- Post the updated policy on our Platform
- Update the "Last Updated" date
- Provide notice of material changes via email or Platform notification
- Continue to honor the privacy practices described in the version that was in effect when your information was collected
13. Contact Information
For privacy-related questions, concerns, or requests:
- Email: [email protected]
- Subject Line: Privacy Request
- Address: Available upon request
Data Protection Contact:
- Data Controller: Afonso Gonçalves (Individual Proprietorship)
- Location: Portugal
- Response Time: We aim to respond to privacy inquiries within 30 days as required by GDPR
14. Supervisory Authority
Portuguese Data Protection Authority (CNPD):
- Website: www.cnpd.pt
- Email: [email protected]
- Address: Av. D. Carlos I, 134, 1º, 1200-651 Lisboa, Portugal