Privacy Policy

Last updated: July 2026

1. Introduction

Metaseed Hub is a collaborative metadata management platform operated by the Faculty of Electrical Engineering, Mathematics and Computer Science (EWI) at Delft University of Technology. This policy describes how we collect, use, and protect your personal data.

2. Data Controller

Delft University of Technology
Faculty of EEMCS (EWI)
Van Mourik Broekmanweg 6
2628 XE Delft, The Netherlands

3. Data We Collect

3.1 Authentication Data

When you log in via SRAM/SURFconext, we receive and store:

  • Your name and email address
  • Your unique identifier (eduPersonPrincipalName or similar)
  • Your institutional affiliation

3.2 Application Data

We store data you create within the application:

  • Datasets and specifications you create
  • Scientific metadata you enter (MIAPPE, ISA, DiSSCo, Darwin Core records)
  • Notes and comments on metadata records

3.3 Technical Data

For security and operational purposes:

  • Standard web-server logs (IP address, timestamp, and the request made), kept briefly under normal server log rotation
  • Records of unhandled server errors — the request path, the error type and message, and the signed-in user — never request bodies or personal content
  • The date of your most recent sign-in

3.4 Usage Analytics

We collect anonymous usage statistics with a self-hosted Matomo instance running on the same server. It is configured for privacy:

  • No cookies are set and no cross-site tracking is performed, so no consent banner is required
  • Visitor IP addresses are anonymized
  • The data stays on our own server and is never sent to or shared with any third party

4. Purpose and Legal Basis

We process your data for:

  • Service provision (public task): To provide the metadata management service as part of TU Delft's research and education mission
  • Collaboration (legitimate interest): To enable team collaboration on shared projects
  • Security (legitimate interest): To protect the service and detect unauthorized access

5. Data Sharing

Your data is not sold or shared with third parties for commercial purposes. Data may be shared:

  • With collaborators you explicitly invite to your datasets
  • With TU Delft IT services for infrastructure and security purposes
  • When required by law or legal process

6. Data Retention

  • Account data: Retained while your account is active. You can permanently delete your account and personal data yourself from your profile page.
  • Project data: Retained until you delete it. When you delete your account, datasets you solely own must first be reassigned to a new owner or deleted; datasets shared with colleagues remain with their other owners.
  • Server logs: standard web-server access logs are kept briefly under normal log rotation; recorded application errors are removed automatically after 30 days
  • Analytics: anonymous, aggregated usage statistics, kept for reporting

7. Your Rights

Under GDPR, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data ("right to be forgotten") — you can do this yourself from your profile page, or contact us
  • Export your data in a portable format
  • Object to processing
  • Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)

To exercise these rights, contact: privacy-tud@tudelft.nl

8. Security

We implement appropriate technical and organizational measures:

  • Encrypted connections (HTTPS/TLS)
  • Authentication via trusted identity providers (SRAM/SURFconext)
  • Access controls and audit logging
  • Regular security updates

9. Contact

For questions about this privacy policy or your data:

Email: privacy-tud@tudelft.nl

TU Delft Data Protection Officer: fg@tudelft.nl