Core principle
Use data only for the purpose of the scholarship programme
Applicant forms, documents and contact information may be used to review applications, assess programme conditions, communicate where necessary and follow up with recipients. They must not be used for purposes outside the programme.
- Review whether an application meets programme conditions.
- Assess applicant declarations and uploaded documents.
- Communicate about additional documents, clarification, interviews or the process.
- Manage programme-related continuation, achievement and follow-up after support is awarded.
- Carry out authorised assessment, accounting and reporting related to the programme.
Submitting a scholarship application does not permit an organisation to use the applicant’s personal data without limits in its other activities.
Access authority
Only institution users authorised for the relevant programme should have access
Access must be limited to users responsible for the scholarship programme and to records necessary for their duties. Each user should use their own account; usernames and passwords must not be shared.
- View only applicant records necessary for your role.
- Do not use shared accounts or passwords.
- Remove access promptly when a person changes role or leaves the institution.
- Sign out after using a shared device.
- Report suspicious sign-in or unauthorised access to the responsible person in your institution.
Assessment and communication
Use data only to the extent necessary for decisions and communication
The institution defines its scholarship conditions, assesses applications under its own criteria and makes the final selection through its authorised processes. bursverenler.org provides infrastructure for applications, documents, assessment, reporting and secure transactions.
May I request additional information or documents?
Yes, where needed for programme assessment. The request should be made through the appropriate application process and remain relevant and proportionate to the scholarship conditions.
May I communicate with an applicant?
Yes. Communication must be limited to programme-related matters such as applications, documents, interviews, results and recipient follow-up. Applicant information must not be used for promotional or marketing messages.
Can the institution see every applicant’s data?
No. Institution users should access only records related to their own institution’s scholarships and programmes for which they are authorised. Access does not include the entire applicant pool on the platform.
Sharing limits
Do not share applicant data with unauthorised people or for unrelated purposes
Applicant personal information, documents and application details are not generally open to donors, other applicants or people outside the institution. Sharing must be necessary, limited and authorised for the relevant process.
- Do not send applicant lists, forms or documents through unauthorised people or channels.
- Do not use applicant data for promotion, marketing, announcements or unrelated communication.
- In scholarship models that allow candidates to be presented to a donor, share only the limited information necessary for selection.
- Do not unnecessarily duplicate identity, contact, income, education or other personal information.
- If sharing with another organisation or service provider is necessary, follow your institution’s authority, purpose and security procedures.
Export and storage
Files downloaded from the panel still contain personal data
Excel, PDF, document and other files exported for reporting or assessment do not cease to be personal data. The institution that downloads and stores a copy in its own systems must manage its security, access, use and eventual deletion or destruction.
- Export only necessary applicants and fields.
- Store files in a secure institution environment with restricted access.
- Do not archive them on personal devices, personal email or unauthorised cloud accounts.
- Do not retain files longer than the period defined by the institution.
- When the purpose ends, delete or destroy them under the institution’s retention-destruction policy and legal obligations.
bursverenler.org cannot see or automatically delete copies downloaded to the institution’s computers, email accounts or storage. Updating a panel record, closing access or deleting a membership does not itself remove copies held by the institution.
Secure working
Manage documents, messages and screenshots securely
Applicant-data security also depends on the daily practices of institution users. Assess access, storage and sharing risks whenever information is used outside the panel.
- Do not share files or screenshots through unauthorised email, messaging applications or public links.
- Do not send unnecessary applicant or recipient data in technical-support requests.
- Immediately inform the authorised person in your institution about a wrong recipient, lost device or suspicious access.
- Preserve incident records and follow the institution’s data-protection and information-security procedures.
Being able to view or export data does not grant a right to use, publish or transfer it without limits.