Privacy policy
Last updated: 18 July 2026
This policy describes what our system genuinely does with your data — not a generic template. Where we say a file is stored outside the public web, or that your mentor cannot see your identity, that is a statement about how the software is actually built.
1. Who we are
[[Authiq Research Agency — full registered name]] (“Authiq”, “we”, “us”) operates authiq.info and the Authiq research portal. We are the data controller for the personal data described in this policy.
Registered details: [[registration number and country of registration]].
Address: [[registered postal address]].
Email: doctor@authiq.info
2. What we collect
2.1 If you create a researcher (client) account
| Data | Required? | Where it comes from |
|---|---|---|
| Email address | Yes | You, at registration |
| Password | Yes | You. Stored only as a bcrypt hash — we cannot read it |
| Full name | Yes | You, at registration |
| Country | Yes | You, at registration |
| Institution, position, time zone, preferred language | No | You, in your profile |
| Phone, WeChat ID, WhatsApp number, preferred contact method | No | You, in your profile |
| ORCID iD, research fields | No | You, in your profile |
2.2 If you are an invited research specialist (mentor)
| Data | Required? | Where it comes from |
|---|---|---|
| Email address | Yes | Your invitation |
| Password | Yes | You. Stored only as a bcrypt hash |
| Display name and legal name | Yes | You / your invitation |
| Country, time zone, academic fields, methods, software and language skills, biography | No | You, in your profile |
| Availability, workload capacity | No | You |
| Preferred payment method and payment details | No | You, for paying you |
| Our internal quality rating and administrative notes about you | — | Created by us. Never shown to clients |
2.3 The research content you give us
Your requests, briefs, problem statements, manuscripts, data files, messages, and anything else you upload or write in the portal. This is often unpublished research, and we treat it as the most sensitive material we hold.
2.4 What we record automatically
| Data | Why |
|---|---|
| IP address | Recorded against every significant action, for security and abuse investigation |
| Browser and device string | Recorded with the same actions, for the same reason |
| Action history (what changed, when, by whom) | An audit trail — so that if anything ever goes wrong, we can show exactly what happened |
| Last login time, failed login attempts, lockout time | Protecting your account from password guessing |
| A session cookie | Keeping you logged in. See cookies |
We do not use advertising trackers, third-party analytics profiling, or social media pixels.
2.5 If you use our contact form
Your name, email, and message, plus optionally your institution and country. We also record your IP address and browser string to prevent abuse of the form.
3. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account | Performance of a contract with you |
| Matching you with a suitable mentor, and running your project | Performance of a contract |
| Mediating communication between you and your mentor | Performance of a contract |
| Reviewing quality and academic integrity | Performance of a contract; our legitimate interest in maintaining standards |
| Sending you notifications that something needs your attention | Performance of a contract. You can switch these emails off at any time |
| Security, audit logging, fraud and abuse prevention | Our legitimate interest in keeping the service and your research safe |
| Recording payments and keeping financial records | Performance of a contract; legal obligation |
| Responding to your enquiries | Our legitimate interest in answering you; steps prior to a contract |
| Complying with law, or responding to a lawful request | Legal obligation |
We do not sell your personal data. We do not use your research to train machine-learning models. We do not use your data for advertising.
4. Who can see your data
4.1 Your mentor cannot see who you are
Client and mentor identities are separated in the software itself. A mentor working on your project sees your research topic, brief and drafts. They do not see your name, email, institution, country or contact details — there is no screen in the system that would show them.
The reverse is also true: you see a mentor's expertise, approach and plan, but not their name or contact details.
4.2 Authiq administrators can see your data
Our administrators can see your identity and your research, because they review quality and mediate the relationship. They are bound by confidentiality obligations.
4.3 Service providers
| Who | What they process |
|---|---|
| Hostinger (our hosting provider) | Stores the database and files that run this service |
| Our email provider | Delivers notification emails. These contain no research content — only that something is waiting |
4.4 Legal disclosure
We may disclose personal data where we are lawfully required to — for example under a court order or a valid regulatory request. Where we are legally permitted to tell you, we will.
4.5 What we never do
- Sell, rent or trade your personal data.
- Share your unpublished research with anyone outside the people described above.
- Give your contact details to a mentor, or a mentor's contact details to you.
- Put your research content, message text, or manuscript details into an email.
5. How we protect it
These are specific measures, not aspirations:
- Passwords are stored as bcrypt hashes. Nobody at Authiq can read your password.
- Your files are stored outside the public web root. There is no web address that serves them directly.
- Files are stored under randomised identifiers, not their real filenames — the storage reveals nothing about you or your topic.
- Every download is permission-checked against your identity and that specific document. The default answer is refusal.
- Documents always download rather than open in the browser, which closes off a category of attack.
- Uploads are restricted to a fixed list of document types and a size limit. Executable files are rejected.
- Every access — allowed or refused — is logged with the actor, IP address and time.
- Repeated failed logins lock the account temporarily.
- The site is served over HTTPS.
- All database access is parameterised, and every form is protected against cross-site request forgery.
No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your rights, we will notify you and the relevant authority as required by law.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account is open, then up to 12 months after closure unless you ask us to erase it sooner |
| Research files and project records | While your project is active, and for a period afterwards so you can retrieve your own work. Erased on request, subject to legal limits |
| Messages | With the project they belong to |
| Financial records | As long as tax and accounting law requires |
| Security and audit logs | Typically 24 months |
| Contact form enquiries | Up to 24 months |
7. International transfers
Authiq works with researchers and specialists across the world, so your data may be processed in a country other than your own — including where our hosting provider operates. Where the law requires it, we use appropriate safeguards for those transfers.
If you are in a jurisdiction with specific data-export rules — for example the EU/UK under the GDPR, or China under the PIPL — and you would like details of the safeguards that apply to you, please ask.
8. Your rights
Depending on where you live, you may have some or all of the following rights. We will honour them wherever we reasonably can, regardless of jurisdiction:
- Access — a copy of the personal data we hold about you.
- Correction — fix anything inaccurate. Most of it you can edit yourself in your profile.
- Erasure — ask us to delete your data, subject to records we must keep by law.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where we rely on consent, withdraw it at any time.
- Complain — to your local data protection authority.
Your research always belongs to you. Your data, your ideas and your manuscript remain yours. We claim no ownership over your work, and closing your account does not change that.
To exercise any right, email doctor@authiq.info. We will respond within 30 days. We may need to verify your identity first — which is itself a protection for you.
You can switch off notification emails yourself at any time: Profile → Notification settings. You will still see notifications inside the portal, because some of them concern decisions only you can make.
9. Cookies
We use one cookie: a session cookie that keeps you logged in. It is essential — the portal cannot work
without it — so it is not something we ask consent for. It is marked HttpOnly (JavaScript
cannot read it) and SameSite (it is not sent from other sites). It expires when your
session ends.
We do not use advertising cookies, analytics cookies, or third-party trackers.
10. Children
Authiq is for academic researchers and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, please contact us and we will remove it.
11. Changes to this policy
If we change this policy we will update the date at the top. Where a change materially affects your rights, we will tell you directly rather than rely on you noticing.
12. Contact us
Questions, concerns, or a request about your data:
[[Authiq Research Agency — full registered name]]
[[registered postal address]]
doctor@authiq.info
If you are not satisfied with our response, you have the right to complain to the data protection authority in your country.
