Privacy policy
Last updated: July 2026
This policy explains how the Lisbon AI Safety Hub (LAISH) processes personal data when you use our website, apply to our programmes, attend our events, subscribe to updates, or contact us. It is written to meet the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Portuguese Law no. 58/2019.
1. Data controller and contact
LAISH (Lisbon AI Safety Hub) is a student-led community hosted at ISCTE – Instituto Universitário de Lisboa (ISCTE-IUL), Av. das Forças Armadas, 1649-026 Lisboa, Portugal. For any question about this policy or to exercise your rights, contact us at: - Email: contact@lisbonaisafetyhub.org ISCTE-IUL has a designated Data Protection Officer (DPO) reachable through the university's official channels for matters relating to ISCTE-IUL as an institution.
2. Personal data we collect
Depending on how you interact with us, we may process: - Identity and contact data: name, email address, and any other details you enter in forms, applications, or messages. - Application content: your answers, background information, and materials you submit for a fellowship, programme, or event. - Contact submissions: the subject, message, and metadata (timestamp, IP address hash) of enquiries sent through our contact form. - Account data (admins only): email, hashed password, role, and audit information for people who manage the site. - Technical data: IP address, browser type, referrer, and pages visited, collected through standard server logs strictly for security and abuse prevention. We do not knowingly collect special categories of data (Article 9 GDPR). Do not send us sensitive data unless we specifically ask for it.
3. Purposes and legal bases
We process personal data only for the purposes below and on the following legal bases (Article 6 GDPR): - Running fellowships, events, and community programmes — performance of a contract or pre-contractual steps at your request (Art. 6(1)(b)), and our legitimate interest in operating the community (Art. 6(1)(f)). - Replying to contact-form messages and support requests — our legitimate interest in responding to enquiries (Art. 6(1)(f)). - Sending newsletters or programme updates — your explicit consent (Art. 6(1)(a)), which you can withdraw at any time. - Website security, abuse prevention, and log analysis — our legitimate interest in protecting the service (Art. 6(1)(f)). - Administering admin accounts and access control — performance of a contract / our legitimate interest in operating the site. - Compliance with legal obligations — where required by EU or Portuguese law (Art. 6(1)(c)). We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Recipients, processors and international transfers
We share personal data only with service providers acting as processors under written agreements meeting Article 28 GDPR. Our current processors include: - Lovable — website hosting and application platform. - Supabase — database, authentication, and file storage (EU region). - Cloudflare — content delivery, DNS, and DDoS protection. - Email delivery providers used to reply to enquiries. Some of these providers are established outside the European Economic Area or may transfer data internationally. Where that happens, transfers are protected by the European Commission's Standard Contractual Clauses (SCCs) and, where relevant, supplementary measures. A copy of the safeguards used is available on request. We never sell your personal data and do not use it for third-party advertising.
5. Retention periods
We keep personal data only as long as necessary for the purpose it was collected for: - Contact-form submissions: up to 24 months from the last exchange, then deleted or anonymised. - Fellowship / programme applications: for the duration of the selection process and up to 24 months afterwards, so we can answer follow-ups and evaluate cohorts. - Newsletter subscribers: until you unsubscribe, and then removed from active mailing lists. - Server and security logs: up to 30 days, unless retained longer to investigate an incident. - Admin accounts: until the admin role is revoked, plus a short window for security auditing. We may keep data longer where required by law or to establish, exercise, or defend legal claims.
6. Your rights under the GDPR
Subject to the conditions set out in the GDPR, you have the right to: - Access the personal data we hold about you (Art. 15). - Have inaccurate data corrected (Art. 16). - Have your data erased where the legal conditions are met (Art. 17). - Restrict our processing of your data (Art. 18). - Receive your data in a portable, machine-readable format (Art. 20). - Object to processing based on our legitimate interests (Art. 21). - Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)). To exercise any of these rights, email contact@lisbonaisafetyhub.org. We will respond within one month, as required by Article 12(3) GDPR. You also have the right to lodge a complaint with the Portuguese supervisory authority: Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134 – 1.º, 1200-651 Lisboa, Portugal Email: geral@cnpd.pt · Web: www.cnpd.pt
7. Cookies and similar technologies
This website uses only strictly necessary storage and cookies, which do not require prior consent under Article 5(3) of the ePrivacy Directive: - A session/authentication token, set only when an admin signs in, to keep them logged in securely. - Local browser storage for your language (EN / PT) and theme (light / dark) preference. We do not use advertising cookies, cross-site tracking, or third-party analytics that identify you. If we ever introduce optional analytics or marketing cookies, we will ask for your prior, freely given consent through a cookie banner before setting them, and you will be able to withdraw that consent at any time. You can also clear or block cookies at any time in your browser settings.
8. Children
Our programmes and this website are intended for adults (typically university students and professionals). We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9. Security and changes to this policy
We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit (HTTPS), role-based admin access, and audit logging. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the CNPD within 72 hours and, where required, inform affected individuals in accordance with Articles 33 and 34 GDPR. We may update this policy to reflect changes in our tools, practices, or legal obligations. The date at the top of this page always reflects the most recent version. Material changes will be highlighted on the website.