cumlaude

Privacy policy

Last updated: 2 August 2026

This page explains what personal data cumlaude processes, why, for how long, and what rights the people concerned have.

Who processes the data

The service is operated by Christophe Soares. For any question about personal data, including exercising your rights, write to soareschristophe@gmail.com. Where the service is used by an educational institution, that institution determines the purpose of the assessment and responsibilities are shared under a written agreement between the parties.

What data is processed

About the defence: candidate name, thesis title, institution, date and time. About the panel: each member's name, title and affiliation and, if the chair provides them, email addresses used to send access links and the result. About the assessment: criterion scores, written justifications, votes and the final text of the minutes. About the chair's account: the email address and name associated with the account used to sign in.

On what basis

Processing is necessary to provide the service requested by whoever creates the session and, in an institutional context, to carry out academic assessment duties. Panel members' addresses are supplied by the chair and used only to send them the access link and the result summary; every message includes an unsubscribe link.

Who it is shared with

Data is neither sold nor disclosed for advertising. It is processed by sub-processors strictly necessary to operate the service: Vercel (application hosting), Neon (database), Cloudflare (change-notification channel, which carries no session data), Resend (email delivery) and Google (chair account authentication).

Where it is processed

The application runs on servers located in the European Union. The database is hosted in the United Kingdom, a country recognised by the European Commission as ensuring an adequate level of protection. The notification channel is confined to the European Union jurisdiction.

For how long

Sessions are deleted automatically 30 days after creation, along with everything they contain: scores, justifications, votes, addresses and the text of the minutes. The application is not the archive of the defence — the minutes are emailed as an attachment when the chair seals them, and archiving them is the institution's responsibility. The chair may also delete a session at any time.

What rights you have

Access, rectification, erasure, restriction, portability and objection. The session chair can exercise most of these directly in the application: export the session in an open format, correct the data and delete everything. For anything else, write to soareschristophe@gmail.com. You also have the right to lodge a complaint with your national supervisory authority.

Cookies and local storage

There is no advertising, traffic analytics or user tracking, so there is no consent banner to show. Only the strictly necessary is used: a session cookie to keep the chair signed in, and browser local storage to hold the device's access links.

Changes

If this policy changes, the date at the top is updated. Substantial changes are announced within the application itself.