Who we are
This site and the services described below are operated by AEGEE Contact in Toulouse, a French non-profit association (association loi 1901 déclarée), registered office at 17 rue Sainte Catherine, 31400 Toulouse, France.
SIREN 944 174 051 · SIRET 944 174 051 00010 · RNA n° W313040502.
The data controller is the association itself, represented by its sitting President — not any named individual.
Your rights and how to reach us
You have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability, under Articles 15 to 22 of the GDPR.
To exercise any of these rights, contact us at dpo@aegeetoulouse.com.
The contact form
When you use the contact form on this site, we collect your name, email address, the subject you pick from the list, and your message.
We use this only to reply to your request — nothing more.
- Legal basis
- Our legitimate interest in responding to your request.
- Retention
- Up to 3 years from your last contact with us if no ongoing relationship develops. If you become a member, your data is then covered by the membership retention period below.
Announcements to members
As a member, you can receive announcements from us by email: a new events calendar, a new activity, a change to how registrations work. They are separate from the emails that follow something you did yourself, such as a registration confirmation, a payment receipt or a cancellation link. Those confirm what you asked for and carry no measurement of any kind.
Every announcement carries an unsubscribe link. Using it stops these announcements straight away, and only these: the emails that follow your own actions keep coming.
An announcement contains a tracking pixel: an image of a single pixel, invisible in the email, which your email program downloads when it displays the message. The address of that image is unique to you, so it tells us whether you opened the announcement. We record your membership record, the date and time of the first and of the latest download, and how many there were. We do not record your IP address, your email program, your device or your location. The image is served by our own platform, not by an advertising or analytics provider, and nobody else learns that you opened the message.
We use this to check that our announcements reach the members they are meant for and to decide what is worth sending. We do not use it to build a profile of you or to decide anything about you.
It is an imperfect measure, and you can avoid it. If your email program blocks remote images, nothing is recorded. Some programs also download images by themselves, so an opening on record is not proof that you read the message.
Separately, and without any tracker, we can see how many of the people who received an announcement registered for an event afterwards, from the registrations we hold anyway.
- Legal basis
- Our legitimate interest in knowing whether our announcements reach the people they are addressed to, balanced against how little is recorded and how easily you can avoid it: block remote images, unsubscribe, or write to dpo@aegeetoulouse.com and we stop recording openings for you and delete what we already hold.
- Retention
- 6 months after the announcement was sent, then deleted automatically. If your membership record is deleted, so is everything recorded about your openings.
Event registration and membership
You can become a member and book events directly on this site. The membership form asks for your first and last name, your email address, your phone number, your date of birth and your nationality.
It then asks what brings you to Toulouse: studies, an internship, work, or something else. If you are studying, it asks which university or higher education institution, at what level, and in which field. If you are working or interning, it asks in which sector. It asks everyone how long they are staying, roughly when they arrive, whether they have found accommodation, how they heard about us, what interests them about AEGEE, whether they want to hear from us about Erasmus Jobs, which now has its own application form described in the next section, and about Study Buddies, our WhatsApp group for studying together, and whether they would like to join the Event Facilitators list. Every question the form shows you has to be answered before it will submit, apart from the free-text box that appears when you pick Other, and the optional link to a social profile on the request form.
If you tell us you have found accommodation, temporary accommodation included, we also ask for the postal code where you live and how you are housed: alone, in a shared flat, in a university residence, or with family or a host. We ask for a postal code and never for a street address, because the only use we have for it is counting, in aggregate: how many members live in the commune of Toulouse and how many in the towns around it, which is a figure grant applications ask us for every year. The same goes for what brings you here and what you study or work in. We send no postal mail to anyone, and we hold nothing that would let us.
If you apply through the public request form, we also ask for a short motivation, an optional link to a social profile, and a photo of you. Only our volunteer board sees these, to review your request by hand before confirming membership and to help keep our community safe. We delete the photo as soon as that decision is made, whichever way it goes.
When you book an event or get on a waiting list we collect your email address and the record of which events you have booked.
Applying for membership asks you to agree to three things: our Statutes, our Membership Rules, and the use of your personal data for the association's activities. The first two are published in full on this site and linked from the form itself, so nothing asks you to confirm you have read something you cannot read. We record each agreement with the date and time you gave it, because otherwise we could not demonstrate later what you actually agreed to. Each of these documents carries its own version and date, and a revised one is published under a new name instead of replacing the file you accepted, so the text you were shown stays identifiable. That record stays in our own database and is never sent anywhere.
This runs on our own membership and events platform, stored in our database hosted by Cloudflare in the EU. The confirmation email for each registration carries a personal link you can use to cancel it.
For paid events, payment goes through Stripe Checkout: you enter your card details on a page hosted by Stripe and we never see or hold them. We keep the payment reference, amount and status in our accounting records.
BilletWeb, the ticketing platform we used before, still holds the records made through it. The membership records have been copied across to this platform so that your membership carries over and you do not have to join again: the name, email address, phone number, date of birth and nationality you gave BilletWeb, and the answers you gave to the same membership questions listed above. Your payment history and your event participation history were not copied and stay on BilletWeb.
Some events ask you a question or two of their own, and only what that event needs: a dietary requirement for a dinner, which language and level for a workshop, or a document proving you have bought your travel ticket for a day trip. Each answer is attached to that registration alone, used to run that event, and never reused for anything else.
A document you upload as proof carries more than we need to keep: a travel ticket shows your full name and a booking reference, a certificate of enrolment shows your identity and your school. We delete these files seven days after the event. The record that proof was provided stays, the document itself does not. Everything else you answer follows the retention period below.
- Legal basis
- Performance of the membership or event registration contract with you. A dietary requirement is health-adjacent data, so we only ever record what you choose to tell us, and only where you tell it to us. The same basis covers the motivation, social link and photo asked on the request form: they exist only to let us decide, by hand, whether to enter into that contract with you.
- Retention
- Membership and participation data for the duration of your membership plus 5 years afterwards (the standard civil limitation period). Answers to an event's own questions follow the same period; documents uploaded as proof are deleted 7 days after the event. Payment and accounting records are kept for 10 years, as required by French commercial law. If you apply through the request form, the photo is never kept past our decision on your request, whichever way it goes; the rest of the request (including your motivation and social link) is deleted entirely 30 days after that decision, whether it was accepted or declined — if accepted, your membership record itself lives on under the period above, independently of the request.
Erasmus Jobs applications
You can apply to Erasmus Jobs on this site to be put in touch with student jobs, internships and full-time roles in Toulouse. The application asks for your first and last name, your email address, your phone number and how you would like to be contacted, your date of birth, your gender and your nationality. It asks whether you are a citizen of the European Union and, if you are not, whether you have a residence permit. It asks whether you have a French bank account and which of these you already have: a social security number, workplace accident insurance, employer health insurance. We ask only whether you have them. We never ask for the numbers, and we never ask for your social security number itself.
It also asks where and what you study, when you arrived in Toulouse and when you plan to leave, what kind of work you are looking for and the conditions that matter to you, when you are available, which languages you speak and at what level, your work experience and any certifications, and, if you wish, a link to your LinkedIn profile or a portfolio. You upload your CV, which is required. You can also tick a separate box to receive job offers by email.
Only our volunteer board sees an application. We use it to decide whom to get in touch with when an opportunity fits. We do not send your CV or your profile to an employer without talking to you first. Your gender is stored for the board's internal use only: it is never included in an export and never passed on to anyone outside the board.
You give your consent by ticking a box on the last step of the form. We record the exact text you were shown, its version and the date and time, because otherwise we could not show later what you agreed to. If you apply again with the same email address, the new application replaces the previous one, and the earlier CV is deleted.
Your CV is kept in private file storage at Cloudflare and is never served from a public address: only the board can download it. Two emails are sent through Resend when you apply: a confirmation to you, which carries a personal link to withdraw your application, and a notification to the board. The link opens a page where one confirmation removes your application and your CV, with nothing further to send us.
- Legal basis
- Your consent, given by ticking a box on the last step of the form and recorded with the text you saw. You can withdraw it at any time.
- Retention
- 12 months after our last contact with you. Applying again with the same email address restarts that period. Withdrawing deletes the application and your CV at once. When the 12 months are over, both are deleted automatically.
Security and record-keeping
Separately from the analytics above, our hosting provider Cloudflare keeps short-lived technical logs of requests to our servers (Workers Logs), used only to debug problems when something breaks.
Cloudflare also applies its own protections to traffic arriving at the site, including always-on DDoS mitigation, a browser integrity check that refuses requests carrying known-abusive signatures, and a reputation-based security level that can challenge a visitor before any page is served. These see the IP address, the request headers and the request pattern of incoming traffic, in order to tell legitimate visitors from malicious or automated ones.
We do not filter automated visitors by the name they give themselves. Every public page of this site is served identically to everyone who asks for it: to a person's browser, to a search engine, to an assistant fetching a page because someone has just asked a question, and to the crawlers that copy pages in order to train AI models. This is a deliberate decision of the association, not an oversight. Our robots.txt allows everything, and we send no machine-readable signal reserving our rights against text and data mining, so the pages published here should be treated as freely collectable, training included. It follows that anything you see on our public pages may be read, copied and reused by an automated system — which is one more reason we never publish your membership record, your registration or anything you send us through a form.
The contact form, the newsletter sign-up, the membership application (including the eligibility check before you apply), the Erasmus Jobs application, and event registration are all protected by Cloudflare Turnstile, a human-verification challenge, to stop automated abuse. It doesn't publish or share anything beyond your IP address and whether you passed the check.
Your browser can also send us an automatic report when our content security policy blocks something on a page. This is a browser feature rather than a script of ours, and the report is sent to this site and nowhere else. We record the rule that fired, the file, line and column involved, and the address of the page you were on, cleaned first of anything that could carry a secret or a personal detail: the query string and the fragment are dropped, any secret carried in the path of a link is masked out, and the excerpt of blocked code that browsers offer to include is never stored.
The traffic counters Cloudflare produces for our domain are copied to Datadog, the monitoring service our volunteer board uses to see whether the site is up and how much traffic it is taking: numbers of requests, unique visitors, page views, bandwidth, and requests blocked as threats, broken down by country, response status and content type. Only those counts leave Cloudflare. No IP address, no page address, no form content and no membership record is sent to Datadog, and the access token used for this export is deliberately limited to traffic analytics so that it cannot read anything else. Datadog also runs uptime checks against our public pages from its own machines, which measure our servers and not our visitors.
None of this is used to build a profile of you, to track you across visits, or to personalise anything you see. It exists purely to keep the site working and secure.
- Legal basis
- Our legitimate interest in keeping the site secure and diagnosable when it breaks (GDPR Article 6.1.f), and our obligation under Article 32 to secure the data we process.
- Retention
- Workers request logs, including the content security policy reports described above: 3 days. The other protections (DDoS mitigation, browser integrity check, security level, Turnstile) run on Cloudflare's own operational retention for these features. The only thing we copy out of them is the aggregate traffic counters sent to Datadog, which carry no personal data.
How long we keep your data
In summary:
- Contact form, no ongoing relationship: up to 3 years from last contact
- Newsletter: 3 years from your subscription date
- Membership and event participation: duration of membership plus 5 years
- Erasmus Jobs application and CV: 12 months after our last contact, or immediately if you withdraw
- Openings of an announcement to members (tracking pixel): 6 months after it was sent
- Payment and accounting records: 10 years (legal requirement)
Who else sees your data
We share your data only with the service providers who help us run the association, each bound by a data processing agreement:
- Cloudflare — hosting and database (EU data residency)
- PostHog — analytics (page views, traffic sources, and, with your cookie consent, session replay), Cloud EU region
- Datadog, the monitoring and uptime service used by our board, receives Cloudflare's aggregate traffic counters for our domain (requests, unique visitors, page views, bandwidth, threats blocked, broken down by country, response status and content type) and nothing else, so no personal data reaches it. It is listed here for transparency rather than because it holds anything about you. Processing takes place in the United States, in Datadog's US5 region
- Resend — sends the association's transactional emails, most of them to you rather than to us: membership confirmation, event registration confirmations (carrying the personal link you use to cancel), payment confirmations, cancellation notices, and waitlist updates (invited, expired, or offered a place), plus the contact form notification to our team, and our announcements to members (Resend's own open and click tracking is switched off: the only measurement of openings is the pixel described under "Announcements to members"); account data is stored in the United States (sending can be routed from the EU, but account metadata stays in the US), covered by Standard Contractual Clauses for this transfer
- Brevo (Sendinblue) — sends our newsletter (EU, France); receives your email address only, never the consent record or your IP address
- BilletWeb — our previous ticketing and membership platform (France, with EU backups). It still holds the records made through it; the membership list has been migrated to our own platform
- Stripe — processes payments for paid events, through Stripe Checkout hosted on Stripe's own pages; we never hold your card details ourselves
- Google Workspace — our contact mailbox and internal documents (EU data residency)
- Anthropic (Claude) — our volunteer board uses Claude, an AI assistant, as internal back-office tooling to help manage day-to-day association administration; this may involve processing some of the personal data described in this policy (US-based processing, under Anthropic's standard commercial terms)
Changes to this policy
We may update this policy as our services evolve. The date at the top of this page shows when it was last revised — please check back from time to time.
Contact
Questions about your data?
Reach out any time at dpo@aegeetoulouse.com and we'll get back to you.