Notifications

You have no notifications

GDPR Compliance

We respect your privacy and are committed to protecting your personal data. This page explains how Grad Incubator aligns with GDPR principles and how you can exercise your rights.

Last updated: Feb 10, 2026

GDPR Principles

Our approach to data protection

We process personal data in line with GDPR principles such as lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity, and confidentiality.

We aim to collect only what is necessary to operate the platform and support students and mentors.
Lawful Bases

Why we process data

  • Consent (e.g., optional newsletters).
  • Contract (e.g., delivering services you request).
  • Legitimate interests (e.g., improving the platform, security).
  • Legal obligations where applicable.
Data Retention

How long we keep data

We retain personal data only as long as needed for the purposes described, including providing the service, meeting legal requirements, resolving disputes, and enforcing our agreements. When data is no longer needed, we delete or anonymize it.

Your Rights

What you can request under GDPR

  • Access to your personal data.
  • Rectification of inaccurate data.
  • Erasure ("right to be forgotten") where applicable.
  • Restriction of processing in certain cases.
  • Data portability for data you provided to us.
  • Objection to processing based on legitimate interests.
  • Withdraw consent at any time (where processing is based on consent).
  • Lodge a complaint with a supervisory authority.
How to Submit a Request

Request steps

1
Send your request

Use our Contact Us page and choose a clear subject like "GDPR Request".

2
Verify identity

To protect your data, we may ask for additional information to verify you.

3
We respond

We aim to respond within a reasonable timeframe and provide updates if more time is needed.

Security & Transfers

How we protect data

We use reasonable technical and organizational measures to protect personal data from unauthorized access, alteration, disclosure, or destruction.

If data is transferred internationally, we take steps intended to ensure an adequate level of protection consistent with GDPR requirements.