Privacy Policy
MIE Network (“the Service”, “we”) is a private directory and messaging tool for students and alumni of the MSc in Innovation & Entrepreneurship at Esade Business School. It is an independent initiative and is not operated by Esade. This policy explains what personal data we process, why, and what your rights are under the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The data controller is [TODO controller full name], an alumnus of the programme acting on behalf of the MIE alumni community, reachable at privacy@mie-network.org. [TODO: postal address, or the association’s details once it is incorporated]
2. What data we process, and why
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Name, email address, profile photo, LinkedIn user ID | LinkedIn, when you sign in | Create and secure your account; identify you to other members | Contract (Art. 6(1)(b)); legitimate interest in account security (Art. 6(1)(f)) |
| Graduation cohort, role, company, city, country, sectors, functions, bio, LinkedIn URL, phone (optional) | You, in your profile | Show you in the member directory according to your visibility settings | Consent (Art. 6(1)(a)), given at onboarding and withdrawable at any time |
| Status signals (looking for a co-founder, hiring, open to work) and their notes | You | Signal board; audience for broadcasts | Consent (Art. 6(1)(a)) |
| Visibility and email preferences | You | Apply your choices | Contract (Art. 6(1)(b)) |
| Messages and broadcasts you send; delivery status of messages sent to you (delivered, bounced, unsubscribed) | You; our email provider | Deliver messages, enforce sending limits, respect opt-outs, protect deliverability | Contract; legitimate interest in preventing abuse (Art. 6(1)(f)) |
| Membership review data: claimed cohort, the classmate who can vouch for you, approval decision and reviewer | You; cohort captains | Verify that members belong to the programme | Legitimate interest in keeping the community restricted (Art. 6(1)(f)) |
| Technical logs (IP address, browser, timestamps, errors) | Automatically | Security, debugging, abuse prevention | Legitimate interest (Art. 6(1)(f)); kept up to 30 days |
We do not process special categories of data, do not profile you, and make no automated decisions with legal effect.
3. Who can see your profile
Only approved members can access the directory. For every profile field you choose one of three levels: visible to the whole community, visible to your cohort only, or hidden. Your name, photo and cohort are always visible to approved members, because a directory cannot function without them. A hidden field can still be used to match broadcast filters (for example, “members open to work”), but it is never displayed. Nothing is visible to the public internet.
4. Emails we send
Account emails (sign-in, approval) are necessary to provide the Service. Broadcasts from other members and the weekly digest are optional: you can switch each category off in Settings, and every broadcast contains a one-click unsubscribe link. When a member contacts you directly, the email is sent by us with the sender’s address in Reply-To; your address is not disclosed unless you reply.
5. Processors and where data is stored
We use the following providers under data-processing agreements. Data is hosted in the European Union unless stated.
- Supabase (database, authentication, file storage) — Frankfurt, Germany.
- Vercel (application hosting) — primary region Frankfurt; edge network worldwide for request routing.
- Resend (email delivery) — EU region.
- Cloudflare (DNS, email forwarding for our contact addresses).
- LinkedIn / Microsoft (sign-in only). We receive your name, email and photo; we do not post on your behalf and do not access your connections. LinkedIn’s own privacy policy governs your LinkedIn account.
- Sentry (error monitoring) — technical error reports without profile content. [TODO: confirm EU data residency or remove]
Where a provider transfers data outside the EEA (for example, edge routing), it does so under the EU Standard Contractual Clauses or an adequacy decision.
6. How long we keep data
- Your profile: for as long as your account exists.
- Inactive accounts: after 24 months without signing in we email you; without a reply within 30 days the account is deleted.
- Messages you sent: metadata (subject, audience size, delivery counts) for 12 months; the recipient list is deleted 90 days after sending.
- Bounce and unsubscribe records: kept while your account exists, so we never email an address that asked us not to.
- Technical logs: up to 30 days.
7. Your rights
You can, at any time and free of charge:
- Access and export your data — Settings → “Export my data” gives you a JSON file.
- Correct it — edit your profile.
- Withdraw consent — set fields to hidden, switch signals off, or delete the account.
- Erase it — Settings → “Delete my account” removes your profile, photo, signals and message history immediately. Emails already delivered to other members’ inboxes cannot be recalled.
- Object to processing based on legitimate interest, and restrict processing, by writing to privacy@mie-network.org.
- Complain to a supervisory authority. In Spain: Agencia Española de Protección de Datos (aepd.es). You may also contact the authority of your own EU country.
We answer requests within one month.
8. Cookies
We use only the strictly necessary cookies that keep you signed in. There are no advertising or third-party analytics cookies, so no cookie banner is shown.
9. Age
The Service is for people who study or studied in a postgraduate programme and is not intended for anyone under 18.
10. Changes
If we change this policy in a way that affects you, we will email you before the change takes effect. Previous versions are available on request.