Last updated: August 2025
1. Who we are
HERI Africa (“we”, “us”) operates a research funding platform that connects researchers, institutions, reviewers, and funders across the African continent. This policy explains how we handle personal data submitted through the platform.
2. What data we collect
- Account data: Your name, email address, and password (stored as a one-way hash). Multi-factor authentication secrets if you enable MFA.
- Institution data: Your role within an institution, institution name, and team membership for applications you participate in.
- Application data: All content you enter into research funding applications, including form responses, uploaded documents, and communication with your team.
- Review data: If you are a reviewer, your assessments, scores, conflict-of-interest declarations, and review assignments.
- Audit data: Records of actions you take on the platform, including login times, settings changes, and submissions. These records are permanent and tamper-evident.
- Communication data: Email and in-app notifications sent to you, delivery status, and your notification preferences.
3. Why we use your data
- To create and manage your account.
- To process research funding applications and reviews.
- To communicate with you about your applications and reviews.
- To maintain a permanent audit trail for accountability.
- To comply with legal obligations and funder requirements.
4. Who can see your data
Access to personal data is role-based and scoped. Your application data is visible to you, your institution team, assigned reviewers, and authorised administrators. Reviewer identities are not visible to applicants. Administrator access is logged and auditable.
5. How long we keep your data
We retain data according to published retention policies that vary by communication type and record category. Application records are retained for the duration of the opportunity plus a defined period for audit and appeal purposes. Legal holds override standard retention schedules.
6. Your rights
- Access: You can request a copy of your personal data.
- Correction: You can request correction of inaccurate data.
- Restriction: You can request that we restrict processing of your data.
- Portability: You can request your data in a machine-readable format.
- Deletion review: You can request deletion of your data, subject to legal and audit obligations.
To exercise any of these rights, contact us at info@heriafrica.org.
7. Security
We use encryption for data in transit and at rest. Passwords are stored as one-way hashes. Sensitive credentials (such as email service passwords) are encrypted with a separate key. Multi-factor authentication is available and required for staff accounts. All sensitive configuration changes require dual control approval.
8. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top of this page reflects the most recent revision. Significant changes will be communicated through the platform.
9. Contact
For questions about this privacy policy or to exercise your data rights, contact us at info@heriafrica.org.