Legal information
Privacy policy
This policy describes how Erasmus International Student Community (“EISCo”) collects and processes the personal data of users and participants. It is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and French law no. 78-17 of 6 January 1978.
1Data controller
The data controller is Erasmus International Student Community, a non-profit association governed by the French law of 1 July 1901 — register no. W013005120, 76 allée Pierre Blanchet, 34090 Montpellier, France.
EISCo is not legally required to appoint a data protection officer. A single point of contact is available for any question about your data: contact@eisco.fr.
2Data we collect
We collect only the data necessary for the purposes described below:
- Identification and contact: surname, first name, email address, and where applicable telephone number and nationality.
- Orders: events booked, ticket type and quantity, purchase history, amounts.
- Account: your email address and, if you create one, your profile details. Sign-in uses a single-use link sent by email — no password is stored.
- Communication preferences: if you ask to receive our upcoming events by email, the date of that request and where you made it (registration, ticketing, account).
- Application file, if you apply for housing or a job: school, level of study, languages, right-to-work status, guarantees. This information is shared only with the establishments you actually apply to.
- Payment: card details are entered on our payment provider’s interface and are neither collected nor stored on our servers.
- Contact messages: if you write from the contact form, your name, address, phone number where given and the text of your message are kept — so that we can reply even if the forwarding email fails.
We do not collect sensitive data within the meaning of article 9 of the GDPR — health, opinions, origin. Please do not send us any.
3Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Managing orders, ticketing and access to events | Performance of a contract (art. 6.1.b) |
| Account management | Performance of a contract (art. 6.1.b) |
| Emailing you our upcoming events, if you asked for it | Consent (art. 6.1.a) — tick box, unticked by default |
| Forwarding an application for housing or a job | Consent (art. 6.1.a) |
| Answering enquiries, complaints and participant support | Legitimate interest / performance of a contract (art. 6.1.b and f) |
| Accounting, tax and invoicing obligations | Legal obligation (art. 6.1.c) |
| Photographs and videos taken during events | Consent (art. 6.1.a) |
| Website security and fraud prevention | Legitimate interest (art. 6.1.f) |
You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4Recipients and sub-processors
Your data is intended for authorised members of the association. It is never sold or transferred to third parties for commercial purposes.
We use the following technical providers, which act on our instructions:
| Provider | Role | Location |
|---|---|---|
| Vercel Inc. | Hosting the website pages | United States — Data Privacy Framework |
| Supabase | Database and image storage | Paris region (European Union) |
| Stripe | Online payment | Ireland and United States — Data Privacy Framework |
| Resend | Sending tickets, sign-in links and, if you asked for it, our upcoming events | United States — standard contractual clauses |
| Make | Workflow automation, and fallback for sending tickets | European Union |
| Telegram | Internal alerts to the team: a new registration is announced there with the participant’s name and email address | United Arab Emirates — standard contractual clauses |
| Anthropic | Internal assistant and translation of published content | United States — standard contractual clauses |
If you apply for housing or a job, your file is passed to the establishment concerned, which becomes a recipient of it. This is done only on your explicit application, establishment by establishment.
5Transfers outside the European Union
Some of the providers listed above are established outside the European Union. These transfers are framed as follows: where the provider is certified under the EU-US Data Privacy Framework — European Commission adequacy decision of 10 July 2023 — the transfer is deemed to offer an adequate level of protection. Otherwise, it relies on the standard contractual clauses adopted by the Commission.
A provider’s certification can be checked at dataprivacyframework.gov/list. The database, which holds most of the personal data, is hosted within the European Union.
6Retention periods
| Category | Period |
|---|---|
| Account and orders | For the duration of the relationship, then 3 years from the last contact |
| Accounting records and invoices | 10 years (legal obligation) |
| Application file | Until you delete it, or 3 years after the last contact |
| Contact messages | 3 years from the last exchange |
| Address signed up for our upcoming events | Until you unsubscribe, and at most 3 years after your last contact |
| Proof of consent | For the duration of the processing concerned |
| Event photographs and videos | For as long as they are used, subject to your right to object |
At the end of these periods, data is deleted or anonymised.
7Security
We implement appropriate technical and organisational measures: end-to-end encrypted connections, cryptographically signed sessions, access restricted to authorised people, data partitioned by organisation. No password is stored — sign-in relies on a single-use link sent to your address.
8Your rights
Under the GDPR, you have the following rights:
- Access: obtain confirmation that your data is being processed, and a copy of it.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data, within the limits allowed by law.
- Restriction of processing.
- Objection to processing, in particular to direct marketing.
- Portability of your data.
- Withdrawal of consent, at any time.
- Instructions as to what happens to your data after your death.
Proof of identity may be requested where there is reasonable doubt as to your identity. We reply within one month at the latest.
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French data protection authority, the CNIL: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.
10Minors
The events offered are strictly reserved for adults. We do not knowingly collect data concerning minors. If you believe a minor has sent us data, write to contact@eisco.fr so that it can be deleted.
11Changes to this policy
We may amend this policy to reflect legal changes or changes in our processing. The applicable version is the one published on the site on the date you consult it; its update date is shown at the top of the page.