Skip to content

Legal information

Privacy policy

This policy describes how Erasmus International Student Community (“EISCo”) collects and processes the personal data of users and participants. It is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and French law no. 78-17 of 6 January 1978.

1Data controller

The data controller is Erasmus International Student Community, a non-profit association governed by the French law of 1 July 1901 — register no. W013005120, 76 allée Pierre Blanchet, 34090 Montpellier, France.

EISCo is not legally required to appoint a data protection officer. A single point of contact is available for any question about your data: contact@eisco.fr.

2Data we collect

We collect only the data necessary for the purposes described below:

  • Identification and contact: surname, first name, email address, and where applicable telephone number and nationality.
  • Orders: events booked, ticket type and quantity, purchase history, amounts.
  • Account: your email address and, if you create one, your profile details. Sign-in uses a single-use link sent by email — no password is stored.
  • Communication preferences: if you ask to receive our upcoming events by email, the date of that request and where you made it (registration, ticketing, account).
  • Application file, if you apply for housing or a job: school, level of study, languages, right-to-work status, guarantees. This information is shared only with the establishments you actually apply to.
  • Payment: card details are entered on our payment provider’s interface and are neither collected nor stored on our servers.
  • Contact messages: if you write from the contact form, your name, address, phone number where given and the text of your message are kept — so that we can reply even if the forwarding email fails.

We do not collect sensitive data within the meaning of article 9 of the GDPR — health, opinions, origin. Please do not send us any.

3Purposes and legal bases

PurposeLegal basis (GDPR)
Managing orders, ticketing and access to eventsPerformance of a contract (art. 6.1.b)
Account managementPerformance of a contract (art. 6.1.b)
Emailing you our upcoming events, if you asked for itConsent (art. 6.1.a) — tick box, unticked by default
Forwarding an application for housing or a jobConsent (art. 6.1.a)
Answering enquiries, complaints and participant supportLegitimate interest / performance of a contract (art. 6.1.b and f)
Accounting, tax and invoicing obligationsLegal obligation (art. 6.1.c)
Photographs and videos taken during eventsConsent (art. 6.1.a)
Website security and fraud preventionLegitimate interest (art. 6.1.f)

You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

4Recipients and sub-processors

Your data is intended for authorised members of the association. It is never sold or transferred to third parties for commercial purposes.

We use the following technical providers, which act on our instructions:

ProviderRoleLocation
Vercel Inc.Hosting the website pagesUnited States — Data Privacy Framework
SupabaseDatabase and image storageParis region (European Union)
StripeOnline paymentIreland and United States — Data Privacy Framework
ResendSending tickets, sign-in links and, if you asked for it, our upcoming eventsUnited States — standard contractual clauses
MakeWorkflow automation, and fallback for sending ticketsEuropean Union
TelegramInternal alerts to the team: a new registration is announced there with the participant’s name and email addressUnited Arab Emirates — standard contractual clauses
AnthropicInternal assistant and translation of published contentUnited States — standard contractual clauses

If you apply for housing or a job, your file is passed to the establishment concerned, which becomes a recipient of it. This is done only on your explicit application, establishment by establishment.

5Transfers outside the European Union

Some of the providers listed above are established outside the European Union. These transfers are framed as follows: where the provider is certified under the EU-US Data Privacy Framework — European Commission adequacy decision of 10 July 2023 — the transfer is deemed to offer an adequate level of protection. Otherwise, it relies on the standard contractual clauses adopted by the Commission.

A provider’s certification can be checked at dataprivacyframework.gov/list. The database, which holds most of the personal data, is hosted within the European Union.

6Retention periods

CategoryPeriod
Account and ordersFor the duration of the relationship, then 3 years from the last contact
Accounting records and invoices10 years (legal obligation)
Application fileUntil you delete it, or 3 years after the last contact
Contact messages3 years from the last exchange
Address signed up for our upcoming eventsUntil you unsubscribe, and at most 3 years after your last contact
Proof of consentFor the duration of the processing concerned
Event photographs and videosFor as long as they are used, subject to your right to object

At the end of these periods, data is deleted or anonymised.

7Security

We implement appropriate technical and organisational measures: end-to-end encrypted connections, cryptographically signed sessions, access restricted to authorised people, data partitioned by organisation. No password is stored — sign-in relies on a single-use link sent to your address.

8Your rights

Under the GDPR, you have the following rights:

  • Access: obtain confirmation that your data is being processed, and a copy of it.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your data, within the limits allowed by law.
  • Restriction of processing.
  • Objection to processing, in particular to direct marketing.
  • Portability of your data.
  • Withdrawal of consent, at any time.
  • Instructions as to what happens to your data after your death.

Proof of identity may be requested where there is reasonable doubt as to your identity. We reply within one month at the latest.

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French data protection authority, the CNIL: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.

9Cookies

This site sets a single, strictly necessary cookie, and only if you sign in. Details are set out in the cookie policy.

10Minors

The events offered are strictly reserved for adults. We do not knowingly collect data concerning minors. If you believe a minor has sent us data, write to contact@eisco.fr so that it can be deleted.

11Changes to this policy

We may amend this policy to reflect legal changes or changes in our processing. The applicable version is the one published on the site on the date you consult it; its update date is shown at the top of the page.