This Privacy Policy explains how Joporas ("we", "us", "our") collects, uses, shares and protects personal data when you visit our website, create a developer account, or use the Joporas API (together, the "Service").
Summary in plain language. We collect the account details you give us, technical information about how you use the Service, and payment records when you subscribe. We use this to run the Service, keep it secure, bill you and improve it. We do not sell your personal data. You can ask to see, correct, export or delete your data at any time by emailing privacy@joporas.com.
1. Introduction and Scope
1.1. This Policy applies to personal data we process as a controller, that is, data about visitors to our website and about registered developers who use our API.
1.2. This Policy does not apply to:
- the scholarship, job, grant, conference and internship listings we publish. This is organisational information sourced from public announcements, not personal data about you;
- applications and websites built by third-party developers using our API. Those developers are responsible for their own privacy practices (see clause 18);
- third-party websites we link to, including the official sources of listed opportunities.
1.3. Please read this Policy together with our Terms of Service.
2. Who We Are
2.1. Joporas operates a developer platform providing structured access to scholarship, job, grant, conference and internship data.
2.2. For any question about this Policy or about how we handle your data, contact privacy@joporas.com.
Action required before publishing: insert the registered legal name, postal address and country of the entity that operates Joporas here, and, if you are required to appoint one, the name of your Data Protection Officer or EU/UK representative. Data protection law requires a controller to be clearly identifiable.
3. Data We Collect
3.1. Account and identity data
Collected when you register and maintain a developer account:
| Data | Why we need it |
|---|---|
| Full name | Identify the account holder; address you in communications |
| Email address | Authentication, verification, service notices, billing receipts |
| Password (stored only as a salted cryptographic hash) | Secure your account. We never store or can retrieve your plaintext password |
| Company or organisation name (optional) | Distinguish business from individual accounts; invoicing |
| Phone number (optional) | Account recovery and support contact |
| Account type (individual or organisation) | Apply the correct plan rules and pricing |
| Email verification status and verification code | Confirm you control the address; prevent fraudulent sign-ups |
| Account creation date and active status | Account administration and audit |
3.2. API credentials and usage data
- API key issued to your account, and its active/permission status.
- Request logs for each API call: the endpoint requested, HTTP method, response status code and timestamp, linked to your API client.
- Plan and quota data: your current plan, daily allowance and consumption.
We use these records for billing accuracy, rate-limit enforcement, abuse detection, debugging and capacity planning.
3.3. Technical and analytics data
Collected automatically when you browse our website. We maintain a visit record containing:
- IP address, and the country and city derived from it;
- browser and device type, and the full user-agent string;
- session identifier, session start time, last-seen time and number of pages viewed;
- for each page view: the path requested, HTTP method, response status code and referring URL;
- your account identifier, where you are signed in.
Be aware: this is a page-level audit trail, not merely aggregate statistics. Because it includes IP address and can be linked to a signed-in account, it constitutes personal data under the GDPR and comparable laws. We use it for security, fraud prevention, abuse investigation and understanding which parts of the Service are used.
3.4. Subscription and payment data
- plan selected, billing cycle, amount and currency;
- subscription status, start and expiry dates;
- our internal transaction reference and the reference returned by our payment provider;
- payment status records and the transaction payload returned to us by the payment provider.
We never receive or store your full card number, expiry date, CVV or bank credentials. Card data is captured and processed entirely by our third-party payment provider on its own systems.
3.5. Communications data
Messages you send us through the contact form, by email or via support channels, together with our replies, plan-upgrade requests and any notes you attach to them.
3.6. Data we do not collect
We do not intentionally collect special category data (such as health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation), and you should not submit such data to us. We do not collect precise GPS location.
4. How We Collect Your Data
4.1. Directly from you. When you register, verify your email, subscribe to a plan, request an upgrade or contact support.
4.2. Automatically. Through server logs, session cookies and the visit-tracking described in clause 3.3, as you navigate the Service.
4.3. From Google, if you choose to sign in with Google. We receive the basic profile information you authorise (typically your name, email address and profile picture) to create or match your account. We do not receive your Google password. Your use of that sign-in method is also governed by Google's own privacy policy.
4.4. From our payment provider. Transaction outcome, reference and status, so we can activate or renew your subscription.
5. Legal Bases for Processing
Where the GDPR, UK GDPR or an equivalent law applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Creating and administering your account; providing API access; billing | Performance of a contract (Art. 6(1)(b)) |
| Security monitoring, abuse and fraud prevention, rate limiting, service improvement, analytics | Legitimate interests (Art. 6(1)(f)), balanced against your rights |
| Retaining financial and transaction records | Legal obligation (Art. 6(1)(c)) |
| Optional marketing or product-update emails | Consent (Art. 6(1)(a)), withdrawable at any time |
| Establishing, exercising or defending legal claims | Legitimate interests / legal obligation |
You may object to processing based on legitimate interests, see clause 13.
6. How We Use Your Data
We use personal data to:
- create, authenticate and administer your account, and verify your email address;
- issue, rotate and validate your API key, and authorise your API requests;
- meter usage, enforce plan allowances and rate limits, and prevent quota circumvention;
- process subscriptions, take payment, issue receipts and manage renewals and failures;
- provide support, respond to enquiries and handle plan-upgrade requests;
- send essential service communications such as security alerts, deprecation notices, billing and policy changes;
- detect, investigate and prevent fraud, credential abuse, scraping, denial-of-service and other security incidents;
- diagnose faults, monitor performance and plan infrastructure capacity;
- understand aggregate usage patterns in order to improve the Service;
- comply with legal obligations and enforce our Terms of Service.
We do not sell your personal data, and we do not share it with third parties for their own advertising or cross-context behavioural advertising purposes.
7. Cookies and Similar Technologies
7.1. We use a session cookie to keep you signed in and to associate your page views with a visit session, and a CSRF token cookie to protect forms against cross-site request forgery. These are strictly necessary for the Service to function securely.
7.2. We use the session identifier for the internal analytics described in clause 3.3.
7.3. We do not use third-party advertising or cross-site tracking cookies.
7.4. You can block or delete cookies in your browser settings, but if you block strictly necessary cookies you will not be able to sign in.
7.5. Do Not Track and Global Privacy Control. Because we do not engage in cross-context behavioural advertising, there is no advertising activity for these signals to disable. We honour applicable opt-out preference signals where the law requires it.
8. Sharing and Service Providers
8.1. We share personal data only as described below. Every provider is bound by contract to process data only on our instructions and to apply appropriate safeguards.
| Recipient category | Purpose | Data involved |
|---|---|---|
| Hosting and database infrastructure | Operate the Service | All categories, at rest |
| Payment provider | Process subscription payments | Name, email, amount, transaction references |
| Google (authentication) | "Sign in with Google", where you choose it | Profile data you authorise |
| Artificial intelligence providers | Structure opportunity data, see clause 9 | Listing content; not your account data |
| Email delivery | Verification codes, receipts, service notices | Email address, message content |
| Professional advisers | Legal, accounting and audit | Only as necessary |
| Authorities | Where legally compelled, see 8.2 | Only as required |
| Successor entity | Merger, acquisition or asset sale | Subject to this Policy; we will notify you |
8.2. Legal disclosure. We may disclose personal data where we are required to do so by law, court order or a validly issued request from a competent authority, or where disclosure is necessary to protect our rights, your safety or the safety of others. Where we are legally permitted to do so, we will notify you before disclosing.
8.3. Aggregate data. We may publish or share statistics that are aggregated and anonymised so that no individual or organisation can be identified, for example, total API calls served.
9. Artificial Intelligence Processing
9.1. We use third-party artificial intelligence services (currently Google Gemini, with OpenAI as a fallback) to read publicly published opportunity announcements (including text and uploaded screenshots of announcements) and convert them into structured records such as title, provider, country, deadline and award value.
9.2. Your account data, API keys, passwords and payment details are never sent to these AI providers. Only the announcement content being processed is transmitted.
9.3. This processing is subject to the AI provider's own terms and data handling commitments. Content sent through their paid API tiers is not used to train their public models under those terms.
9.4. No automated decisions about you. We do not use automated processing or profiling to make any decision that produces legal effects for you or otherwise significantly affects you. Decisions about account suspension are reviewed by a human.
10. International Data Transfers
10.1. Joporas serves users worldwide. Your personal data may therefore be transferred to, stored in and processed in countries other than your own, including countries whose data protection laws differ from those of your jurisdiction.
10.2. Where we transfer personal data out of the European Economic Area, the United Kingdom or another jurisdiction with transfer restrictions, we rely on an appropriate safeguard, such as:
- an adequacy decision covering the destination country; or
- the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Agreement or Addendum; together with
- a transfer risk assessment and, where appropriate, supplementary technical measures such as encryption in transit and at rest.
10.3. You may request a copy of the relevant safeguard by writing to privacy@joporas.com.
11. Data Retention
11.1. We keep personal data only as long as necessary for the purposes described in this Policy, then delete or anonymise it.
| Data | Retention period |
|---|---|
| Account and profile data | For the life of your account, then up to 90 days after deletion to allow for recovery and dispute handling |
| Email verification codes | Until verified or expired |
| API request logs | Up to 12 months, then deleted or aggregated |
| Visit and page-view records | Up to 12 months |
| Subscription, invoice and payment records | As required by applicable tax and accounting law, commonly 5 to 7 years |
| Support correspondence | Up to 24 months after the matter is closed |
| Security incident and abuse records | As long as necessary to investigate and prevent recurrence |
11.2. We may retain data for longer where necessary to comply with a legal obligation, or to establish, exercise or defend legal claims. In that case we restrict processing to that purpose only.
12. How We Protect Your Data
We apply technical and organisational measures appropriate to the risk, including:
- encryption of traffic in transit over HTTPS/TLS;
- storing passwords only as salted cryptographic hashes, never in plaintext or reversible form;
- API key authentication on every request, with the ability to revoke a compromised key immediately;
- role-based access control for internal staff, so personnel see only what their role requires;
- two-factor authentication on internal administrative accounts;
- protection against cross-site request forgery, clickjacking and common injection attacks;
- audit logging of administrative actions and of access to the Service;
- keeping card data entirely outside our systems by delegating payment capture to our provider.
12.1. Your responsibility. No system is perfectly secure. Please use a strong, unique password, keep your API key confidential, and tell us promptly at privacy@joporas.com if you suspect unauthorised access to your account.
13. Your Rights
Subject to applicable law, you have the following rights in relation to your personal data:
- Access. Obtain confirmation of whether we process your data, and a copy of it.
- Rectification. Have inaccurate data corrected and incomplete data completed.
- Erasure. Have your data deleted where there is no overriding lawful reason to keep it.
- Restriction. Have processing limited while a dispute about accuracy or lawfulness is resolved.
- Portability. Receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection. Object to processing based on our legitimate interests, and object at any time to direct marketing.
- Withdraw consent. Where processing relies on consent, withdraw it at any time. This does not affect the lawfulness of processing already carried out.
- Non-discrimination. We will not degrade your service or charge you differently because you exercised a privacy right.
- Complain. Lodge a complaint with your data protection authority (see clause 20).
13.1. How to exercise your rights
Email privacy@joporas.com from the address registered to your account, stating clearly which right you wish to exercise. We will:
- acknowledge your request and, where necessary, ask for information to verify your identity. We ask only for what is needed to confirm you are the account holder;
- respond within 30 days, or within one month where the GDPR applies. If your request is complex we may extend this and will tell you why;
- handle your request free of charge, unless it is manifestly unfounded or excessive.
13.2. You may also delete or correct most account information yourself from your dashboard.
14. Additional Information for Users in the EEA, UK and Switzerland
14.1. If you are located in the European Economic Area, the United Kingdom or Switzerland, the GDPR, UK GDPR or Swiss FADP applies to our processing of your personal data, and the rights in clause 13 apply in full.
14.2. Right to lodge a complaint. You may complain to the supervisory authority in your country of residence, place of work or where the alleged infringement occurred. In the UK this is the Information Commissioner's Office (ico.org.uk).
14.3. Legitimate interests balancing. Where we rely on legitimate interests, we have assessed that our interest in operating a secure, functioning and financially viable API service does not override your rights and freedoms. You may request a summary of that assessment.
14.4. No statutory obligation to provide data. If you do not provide the account data marked as required, we cannot create your account or provide API access.
15. Additional Information for California Residents
15.1. Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know what personal information we collect and why, to request deletion or correction, to obtain a portable copy, and to be free from retaliation for exercising these rights.
15.2. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.
15.3. We do not use or disclose sensitive personal information beyond the purposes permitted under the CPRA.
15.4. The categories we collect, our purposes, and the categories of recipients are set out in clauses 3, 6 and 8. Submit a request to privacy@joporas.com; an authorised agent may act on your behalf with proof of authorisation.
16. Children's Privacy
16.1. The developer platform is intended for users aged 18 and over and is not directed at children.
16.2. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@joporas.com and we will delete it promptly.
17. Data Breach Notification
17.1. We maintain procedures to detect, investigate and respond to personal data breaches.
17.2. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it.
17.3. Where a breach is likely to result in a high risk to you, we will notify you directly without undue delay, describing what happened, the likely consequences and the steps we are taking.
18. Data About Your End Users
18.1. If you build an application using the Joporas API, you are the controller of any personal data you collect from your own End Users. We do not receive it, and we are not responsible for it.
18.2. You are responsible for providing your End Users with your own privacy notice, obtaining any consent required in their jurisdiction, and honouring their data protection rights.
18.3. You must not transmit your End Users' personal data to our API. Our endpoints are for retrieving opportunity data, not for storing information about individuals.
19. Changes to This Policy
19.1. We may update this Policy to reflect changes in the Service, our providers, or legal requirements.
19.2. We will revise the "Last updated" date above. Where a change materially affects how we use your personal data, we will give you at least 30 days' notice by email or by prominent notice in the dashboard, and where the law requires it we will seek your consent.
19.3. We encourage you to review this Policy periodically.
20. Contact and Complaints
| Purpose | Contact |
|---|---|
| Privacy questions, data subject requests, account deletion | privacy@joporas.com |
| Legal notices and terms | legal@joporas.com |
| General support | info@joporas.com |
20.1. We aim to resolve every privacy concern directly. Please contact us first so we have the opportunity to put things right.
20.2. If you are not satisfied with our response, you have the right to complain to your national data protection authority. Exercising that right does not affect any other legal remedy available to you.
This Privacy Policy is published in English. Any translation is provided for convenience only, and the English version prevails in the event of conflict.