
Privacy Notice (Datenschutzerklärung)
Last updated: 24 August 2026
Controller
Constantin Seibold, contact: cms@heiconnect.com (see the legal notice). HeiConnect is a non-commercial research prototype (closed beta) that helps researchers at Universität Heidelberg and affiliated institutes find collaborators and open funding calls.
1. Researcher profiles from public sources (Art. 14 GDPR)
HeiConnect aggregates publicly available scholarly information about researchers: names and name variants, ORCID iD, current and past affiliations, publications and other scholarly works, career stage, collaboration links, and research-topic keywords derived from publication metadata. E-mail addresses are stored only where the researcher has published them in these public sources.
Sources: OpenAlex, ORCID, Crossref, GEPRIS (DFG), CORDIS (EU), DataCite/Zenodo, and heiDOK/DNB. Every record shows its provenance. No login-protected pages are scraped, and web harvesting respects robots.txt.
Legal basis: legitimate interest, Art. 6(1)(f) GDPR — supporting research collaboration and funding discovery on the basis of deliberately published professional scholarly records. Access to the profiles is restricted to verified, logged-in members of the closed beta; profiles are not publicly indexed.
Opt-out: researchers can object at any time and be removed from the platform entirely (Art. 21 GDPR). The opt-out persists across data refreshes, so a removed profile is not re-created by later harvesting runs. Verified researchers can also correct or curate their own profile directly. To object, e-mail cms@heiconnect.com.
Because individually notifying every researcher whose public record appears here would involve disproportionate effort, this notice serves as the public information required by Art. 14(5)(b) GDPR.
2. Account data (Art. 13 GDPR)
If you register, we process your e-mail address and/or ORCID iD, display name, and a password hash (argon2id — we never store the password itself). Signing in with ORCID transmits your ORCID iD and public name from ORCID to us. This data is used solely to provide your account (Art. 6(1)(b) GDPR) and is stored separately from the aggregated research data.
You can export all data linked to your account and delete your account yourself at any time from your profile page. The platform currently sends no e-mails (the weekly digest option is inactive).
3. Proposal workspace and documents you upload
Notes, drafts, and saved items you create in the proposal workspace are visible only to you (and collaborators you explicitly add, where that feature is available). Legal basis: Art. 6(1)(b) GDPR. They are deleted with your account.
Documents you deposit. You can deposit a CV, a publication list, your own earlier grant proposals, and the documents funding calls ask applicants for — degree certificates, confirmations of employment or affiliation, a photo, or anything else, under a name you choose. Each one is either a file you upload or a link to a file of your own.
Files behind a link. If you give a link, our server downloads the file behind it and keeps that copy: when you save the link, when you press “refresh”, and when you build a submission bundle. That is what lets a submission carry the current version of a CV you maintain on your own page. We only ever fetch the address you gave us, only over an encrypted connection, and only when you do one of those three things — there is no background crawling of your links.
What we read, and what we only store. For a CV and a publication list we also keep the plain text extracted from the file, so that the AI assistant you connect yourself (section 4) can read it and so that the CV analysis in section 5 can run if you ask for it. Extraction happens in memory on our own server; the file is never written to disk outside the database and object storage. Your other documents are stored as files and are never read: no text is extracted from them, they are never handed to an AI assistant, and they can never be shown on a public page. An assistant is told only the name and type you gave them, so that it can tell you which of your documents a call is asking for — never their contents.
Who can see them. A CV and publication list stay private unless you tick “show on my public researcher profile”, which additionally requires an ORCID-verified researcher link. Earlier proposals and the documents above have no such option at all. Everything here is deleted with your account, including the stored files. Legal basis: Art. 6(1)(b) GDPR.
Content versus activity. What you write stays private as described above. Metadata about your activity — how many sections a proposal has, when one was last saved, whether you have connected an assistant, whether you generated a submission bundle — is visible to the operator, who uses it to see where people get stuck during the closed beta and to offer help. That view never includes proposal or section titles, or any of your draft text. Legal basis: Art. 6(1)(f) GDPR; see section 6.
4. Optional AI assistant integration (MCP)
You can optionally connect an AI assistant to HeiConnect via the Model Context Protocol (MCP). HeiConnect itself holds no credentials for any AI provider and performs no calls to one: the assistant, and the language model behind it, always run on your side of the connection. Which assistant you use is your choice, and it determines entirely whether any third party sees the content of your session.
Assistants that run on your own device (for example LM Studio, Open WebUI or another MCP client executing a model locally): the content you work on is processed only on your device. No processor is involved, no data is transferred to a third party, and nothing leaves the EU.
Hosted assistants — currently Claude (Anthropic) and ChatGPT (OpenAI), among others you may configure: content you work on in that session — e.g. proposal notes, draft text, search queries, and profile data you retrieve — is processed by the provider of that assistant under your own account with them and under their privacy terms: Anthropic PBC (USA) for Claude, and OpenAI Ireland Ltd / OpenAI, L.L.C. (USA) for ChatGPT. Any transfer to a third country happens only at your initiative (Art. 6(1)(b), Art. 49(1)(a) GDPR) and is additionally covered by the respective provider's safeguards (EU-U.S. Data Privacy Framework participation and/or standard contractual clauses).
If you never connect an assistant, or connect only a locally-run one, no data leaves the EU. When a connector is active, your profile page shows which client last used it, and you can rotate or disable the token there at any time.
5. Reading your CV, if you ask us to
You can separately switch on an analysis of your uploaded CV. It is off by default, it is a per-document setting, and you can switch it off again at any time. Ticking it is what permits this processing: uploading a CV so that an assistant you connected can read it is not the same as agreeing that we run a language model over it and derive attributes from it, so we ask twice. Legal basis: your consent, Art. 6(1)(a) GDPR; withdrawing it has no effect on what was lawful before, and takes effect for everything not already computed.
Where it runs. On the operator's own hardware in Germany, with a language model that also runs there. No third party is involved, no processor, no transfer to a third country, and no AI provider — the platform holds no credentials for one. The analysis is a nightly batch: the text of your CV is transferred between our own servers via our own EU object storage and is replaced there by the next night's run.
What it produces, and what it changes: nothing, until you say so. The result is a short list of proposed research topics and, if your CV states one, your current career stage — each with the line of your CV it came from, so you can see why it was proposed. They are suggestions and stay suggestions. Nothing enters your profile, your matching, or your public researcher page unless you confirm it, and you can withdraw a confirmation later. If you confirm a career stage, that one becomes part of your public researcher profile, which the page tells you before you do it. Results usually take about a day and a half to appear.
The proposals — including ones you declined, which are kept so we stop proposing them — are part of the data export on your profile page, and are deleted with your account.
6. Cookies, local storage, logs
HeiConnect sets a single technically necessary session cookie (signed, valid 14 days) to keep you logged in — § 25(2) TDDDG. Your light/dark theme preference is kept in your browser's local storage. There are no third-party analytics, no tracking cookies, no cross-site tracking and no advertising, which is why there is no cookie banner.
First-party usage measurement. HeiConnect does record, on its own servers, which pages and result lists were shown to your account and which product steps you have reached — for example that a call-finder question was skipped, that an assistant session was started, or that a submission bundle was generated. This is used only to operate and improve the closed beta; it is never shared, sold, or sent to any third party, it sets no additional cookie, and it is deleted with your account. It records counts and timestamps, never the text you write and never the words you type into a search box. Legal basis: Art. 6(1)(f) GDPR. You can object at any time (section 9).
The web server keeps standard access logs (IP address, requested URL, timestamp) for security and abuse prevention (Art. 6(1)(f) GDPR); they are deleted on a short rotation and not used for any other purpose.
7. Hosting and recipients
The platform is hosted on servers of Hetzner Online GmbH (Gunzenhausen, Germany) in EU data centers, under a data processing agreement (Art. 28 GDPR). Apart from the optional AI assistant integration you initiate yourself (section 4), data is not shared with any other recipients and is never sold.
8. Retention
Account data and workspace content, including uploaded documents and the text extracted from them (section 3): until you delete your account. Aggregated researcher profiles: as long as the platform operates, unless you object (see section 1). CV analysis results (section 5): until you delete your account; the intermediate copy of your CV text used to run it is replaced by the next night's batch, i.e. within about 24 hours. Usage measurement (section 6): 365 days, then automatically deleted — and immediately, rather than after that period, if you delete your account. Backups of the account database are kept on a 14-day rotation. Server logs: short rotation. Session cookie: 14 days.
9. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and — in particular, for the profile aggregation described in section 1 — the right to object at any time to processing based on legitimate interest (Art. 21 GDPR). Contact: cms@heiconnect.com.
You also have the right to lodge a complaint with a supervisory authority, e.g. the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (baden-wuerttemberg.datenschutz.de).
10. Changes
This notice is updated when the platform's processing changes; the date above reflects the last revision.