MOBILABPartner workspace

PRIVACY NOTICE · VERSION OF 1 SEPTEMBER 2026

Your data in MOBILAB

This notice explains how data is used to assess requests, secure access, coordinate work and document decisions.

Data controller

The data controller is Äerdschëff asbl, 1, rue du Lycée, L-8508 Redange-sur-Attert, Luxembourg. Requests concerning personal data may be sent to tarik@aerdscheff.lu or by calling +352 671 161 663.

Data concerned

The portal processes email addresses, display names, job roles, optional work telephone numbers, organisations, contribution areas, roles, territories, account status, last-visit dates, field contributions, internal messages, voluntarily attached documents, alert preferences and technical records needed for security and audit. The public participation questionnaire collects name, email address, profile, selected groups, proposed contribution and availability, with organisation and territory optional.

Purposes and legal bases

This data is used to control access, coordinate partners, attribute contributions, monitor activities and document decisions. Questionnaire responses are used only to assess a proposal, prepare a discussion and decide whether an invitation is appropriate. Processing is based on pre-contractual steps requested by the person, performance of the partnership cooperation and the legitimate interest in securing and managing the programme. Separate consent is requested where the research protocol requires it.

Access and recipients

Profiles, contributions and messages are accessible to authorised members according to their role. Public expressions of interest are accessible to coordination and authorised administrators. A structured notification may be emailed to coordination. An account created directly with Supabase does not grant access without an active portal invitation.

Technical processors

Supabase provides authentication, the database, the document index and private file storage in the European eu-north-1 region in Sweden. Application hosting and technical delivery of the portal are provided by Sites and Cloudflare infrastructure. Resend sends alerts, forwarded emails and notifications related to the public questionnaire when that service is configured. Each provider must process data only to deliver, secure and maintain the service under its applicable contractual terms.

MOBILAB assistant

The assistant operates in read-only mode. Supabase search first filters contributions and document excerpts according to the role and authorised scopes. Documentary mode responds without a generative model. After acceptance of the service rules, WebLLM is prepared automatically on compatible devices: the model is downloaded and runs in the browser, then remains in its local cache. The question and authorised excerpts are not sent to any model API provider. Text added only to a question stays on the device and is not saved as a contribution.

Attachments and alerts

Uploaded documents remain in private storage and are accessible only to authorised members. Drafts not linked to a question or contribution are deleted after forty-eight hours during portal maintenance. Emails do not reproduce message content: they report the event and link to the secure workspace. Forwarding and alerts are disabled by default.

Data concerning young people

The public questionnaire must not be completed directly by a minor: a class or group of young people is represented by an adult contact person. The LTC strand remains closed until the impact assessment, pseudonymisation, rules for images, voices, transcripts and outputs, withdrawal procedure and rights of teachers or supervisors are formalised. LTC and MOBILAB-ZFT workspaces are separated by permissions. The assistant does not access individual LTC contributions.

Transfers outside the European Economic Area

Identity data managed by the Supabase project is located in the European Union. Some international providers may nevertheless involve technical access or processing outside the European Economic Area. Any such transfer must be governed by a mechanism recognised by the GDPR, including an adequacy decision or standard contractual clauses, and recorded in the processing register.

Invitations and administration log

The account-creation link is personal, works with the invited address and expires after seven days. Generating a new link invalidates the previous one. Role changes, suspensions, invitations, contributions and validations are logged to establish who performed an administrative action and when.

Retention periods

Account data is retained during participation in the programme, then deleted or archived no later than twelve months after access closes, unless a clearly identified legal obligation applies. An expression of interest that does not lead to participation is deleted no later than twelve months after the last exchange. Research materials follow the retention periods, minimisation rules and anonymisation arrangements set out in the protocol.

Your rights

You may request access, rectification, erasure, restriction, portability or object to processing where those rights apply. A response is provided within the GDPR deadlines. If exercising your rights receives no response or proves difficult, you may lodge a complaint with the National Commission for Data Protection.

Security and use

Use a unique password of at least twelve characters. Do not share sensitive data through internal messaging. Coordination may suspend access in the event of a risk, the end of participation or use contrary to the programme.

Supervisory authority

National Commission for Data Protection · Complaints department · 15, boulevard du Jazz · L-4370 Belvaux.

Go directly to the CNPD complaint form