Legal & privacy

Privacy Policy

This policy explains what personal data AEGEE Toulouse collects, why, for how long, and who it's shared with, in line with the EU General Data Protection Regulation (GDPR).

Last updated

Who we are

This site and the services described below are operated by AEGEE Contact in Toulouse, a French non-profit association (association loi 1901 déclarée), registered office at 17 rue Sainte Catherine, 31400 Toulouse, France.

SIREN 944 174 051 · SIRET 944 174 051 00010 · RNA n° W313040502.

The data controller is the association itself, represented by its sitting President — not any named individual.

Your rights and how to reach us

You have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability, under Articles 15 to 22 of the GDPR.

To exercise any of these rights, contact us at dpo@aegeetoulouse.com.

The contact form

When you use the contact form on this site, we collect your name, email address, the subject you pick from the list, and your message.

We use this only to reply to your request — nothing more.

Legal basis
Our legitimate interest in responding to your request.
Retention
Up to 3 years from your last contact with us if no ongoing relationship develops. If you become a member, your data is then covered by the membership retention period below.

Newsletter

If you subscribe to our newsletter from the site footer, we collect your email address, the exact wording and version of the consent text you agreed to, the date and time of your sign-up, and your IP address, kept only as proof of consent and never included in any export.

That proof of consent stays in our own database, hosted by Cloudflare. Your email address — and only your email address — is also added to our sending list at Brevo, the provider we use to send the newsletter. The consent wording, the sign-up date and your IP address are never sent to Brevo: they are evidence we keep, not information a sending tool needs.

Every newsletter carries an unsubscribe link. Using it stops the emails immediately. We keep the record of your original consent for the retention period below, because we have to be able to demonstrate that consent was given — you can ask us to erase it sooner at dpo@aegeetoulouse.com.

Legal basis
Your consent.
Retention
3 years from the date you subscribed, the standard ceiling for a newsletter contact with no further activity.

Announcements to members

As a member, you can receive announcements from us by email: a new events calendar, a new activity, a change to how registrations work. They are separate from the emails that follow something you did yourself, such as a registration confirmation, a payment receipt or a cancellation link. Those confirm what you asked for and carry no measurement of any kind.

Every announcement carries an unsubscribe link. Using it stops these announcements straight away, and only these: the emails that follow your own actions keep coming.

An announcement contains a tracking pixel: an image of a single pixel, invisible in the email, which your email program downloads when it displays the message. The address of that image is unique to you, so it tells us whether you opened the announcement. We record your membership record, the date and time of the first and of the latest download, and how many there were. We do not record your IP address, your email program, your device or your location. The image is served by our own platform, not by an advertising or analytics provider, and nobody else learns that you opened the message.

We use this to check that our announcements reach the members they are meant for and to decide what is worth sending. We do not use it to build a profile of you or to decide anything about you.

It is an imperfect measure, and you can avoid it. If your email program blocks remote images, nothing is recorded. Some programs also download images by themselves, so an opening on record is not proof that you read the message.

Separately, and without any tracker, we can see how many of the people who received an announcement registered for an event afterwards, from the registrations we hold anyway.

Legal basis
Our legitimate interest in knowing whether our announcements reach the people they are addressed to, balanced against how little is recorded and how easily you can avoid it: block remote images, unsubscribe, or write to dpo@aegeetoulouse.com and we stop recording openings for you and delete what we already hold.
Retention
6 months after the announcement was sent, then deleted automatically. If your membership record is deleted, so is everything recorded about your openings.

Event registration and membership

You can become a member and book events directly on this site. The membership form asks for your first and last name, your email address, your phone number, your date of birth and your nationality.

It then asks what brings you to Toulouse: studies, an internship, work, or something else. If you are studying, it asks which university or higher education institution, at what level, and in which field. If you are working or interning, it asks in which sector. It asks everyone how long they are staying, roughly when they arrive, whether they have found accommodation, how they heard about us, what interests them about AEGEE, whether they want to hear from us about Erasmus Jobs, which now has its own application form described in the next section, and about Study Buddies, our WhatsApp group for studying together, and whether they would like to join the Event Facilitators list. Every question the form shows you has to be answered before it will submit, apart from the free-text box that appears when you pick Other, and the optional link to a social profile on the request form.

If you tell us you have found accommodation, temporary accommodation included, we also ask for the postal code where you live and how you are housed: alone, in a shared flat, in a university residence, or with family or a host. We ask for a postal code and never for a street address, because the only use we have for it is counting, in aggregate: how many members live in the commune of Toulouse and how many in the towns around it, which is a figure grant applications ask us for every year. The same goes for what brings you here and what you study or work in. We send no postal mail to anyone, and we hold nothing that would let us.

If you apply through the public request form, we also ask for a short motivation, an optional link to a social profile, and a photo of you. Only our volunteer board sees these, to review your request by hand before confirming membership and to help keep our community safe. We delete the photo as soon as that decision is made, whichever way it goes.

When you book an event or get on a waiting list we collect your email address and the record of which events you have booked.

Applying for membership asks you to agree to three things: our Statutes, our Membership Rules, and the use of your personal data for the association's activities. The first two are published in full on this site and linked from the form itself, so nothing asks you to confirm you have read something you cannot read. We record each agreement with the date and time you gave it, because otherwise we could not demonstrate later what you actually agreed to. Each of these documents carries its own version and date, and a revised one is published under a new name instead of replacing the file you accepted, so the text you were shown stays identifiable. That record stays in our own database and is never sent anywhere.

This runs on our own membership and events platform, stored in our database hosted by Cloudflare in the EU. The confirmation email for each registration carries a personal link you can use to cancel it.

For paid events, payment goes through Stripe Checkout: you enter your card details on a page hosted by Stripe and we never see or hold them. We keep the payment reference, amount and status in our accounting records.

BilletWeb, the ticketing platform we used before, still holds the records made through it. The membership records have been copied across to this platform so that your membership carries over and you do not have to join again: the name, email address, phone number, date of birth and nationality you gave BilletWeb, and the answers you gave to the same membership questions listed above. Your payment history and your event participation history were not copied and stay on BilletWeb.

Some events ask you a question or two of their own, and only what that event needs: a dietary requirement for a dinner, which language and level for a workshop, or a document proving you have bought your travel ticket for a day trip. Each answer is attached to that registration alone, used to run that event, and never reused for anything else.

A document you upload as proof carries more than we need to keep: a travel ticket shows your full name and a booking reference, a certificate of enrolment shows your identity and your school. We delete these files seven days after the event. The record that proof was provided stays, the document itself does not. Everything else you answer follows the retention period below.

Legal basis
Performance of the membership or event registration contract with you. A dietary requirement is health-adjacent data, so we only ever record what you choose to tell us, and only where you tell it to us. The same basis covers the motivation, social link and photo asked on the request form: they exist only to let us decide, by hand, whether to enter into that contract with you.
Retention
Membership and participation data for the duration of your membership plus 5 years afterwards (the standard civil limitation period). Answers to an event's own questions follow the same period; documents uploaded as proof are deleted 7 days after the event. Payment and accounting records are kept for 10 years, as required by French commercial law. If you apply through the request form, the photo is never kept past our decision on your request, whichever way it goes; the rest of the request (including your motivation and social link) is deleted entirely 30 days after that decision, whether it was accepted or declined — if accepted, your membership record itself lives on under the period above, independently of the request.

Erasmus Jobs applications

You can apply to Erasmus Jobs on this site to be put in touch with student jobs, internships and full-time roles in Toulouse. The application asks for your first and last name, your email address, your phone number and how you would like to be contacted, your date of birth, your gender and your nationality. It asks whether you are a citizen of the European Union and, if you are not, whether you have a residence permit. It asks whether you have a French bank account and which of these you already have: a social security number, workplace accident insurance, employer health insurance. We ask only whether you have them. We never ask for the numbers, and we never ask for your social security number itself.

It also asks where and what you study, when you arrived in Toulouse and when you plan to leave, what kind of work you are looking for and the conditions that matter to you, when you are available, which languages you speak and at what level, your work experience and any certifications, and, if you wish, a link to your LinkedIn profile or a portfolio. You upload your CV, which is required. You can also tick a separate box to receive job offers by email.

Only our volunteer board sees an application. We use it to decide whom to get in touch with when an opportunity fits. We do not send your CV or your profile to an employer without talking to you first. Your gender is stored for the board's internal use only: it is never included in an export and never passed on to anyone outside the board.

You give your consent by ticking a box on the last step of the form. We record the exact text you were shown, its version and the date and time, because otherwise we could not show later what you agreed to. If you apply again with the same email address, the new application replaces the previous one, and the earlier CV is deleted.

Your CV is kept in private file storage at Cloudflare and is never served from a public address: only the board can download it. Two emails are sent through Resend when you apply: a confirmation to you, which carries a personal link to withdraw your application, and a notification to the board. The link opens a page where one confirmation removes your application and your CV, with nothing further to send us.

Legal basis
Your consent, given by ticking a box on the last step of the form and recorded with the text you saw. You can withdraw it at any time.
Retention
12 months after our last contact with you. Applying again with the same email address restarts that period. Withdrawing deletes the application and your CV at once. When the 12 months are over, both are deleted automatically.

Analytics and cookies

We use PostHog Cloud (EU region) to understand how visitors use this site — page views, traffic sources, and which pages are popular.

By default, this runs in cookieless mode: no cookie or persistent identifier is stored on your device, and we cannot recognise you across visits. This includes basic device and location information (device type, browser, approximate location from your IP address) used only in aggregate — never to identify you individually.

This also includes aggregate interaction data — where on a page visitors tend to click or tap, and technical performance metrics like page load speed — used to spot usability issues and improve site performance. What you type into forms is never included: those fields are excluded from this collection entirely.

If you accept our cookie banner, we additionally record session replays (a playback of your on-page interactions, for spotting usability issues) and can recognise repeat visits from the same browser. This uses cookies and is only active with your consent, which you can withdraw at any time from the cookie preferences link in the footer.

While that consent is active, the page views and interaction data described above are linked to that browser identifier rather than kept aggregate-only, so we can follow a whole journey across pages and visits. The identifier is a random one generated for your browser: it is never linked to your name, your email or your membership record. Withdraw your consent and we go straight back to the anonymous measurement described above — we do not stop measuring, we stop recognising you.

Separately from anything running in your browser, our server counts two events when a form is submitted successfully: one for the contact form, one for a newsletter sign-up. These are counters and nothing else — a random one-off identifier that is never reused, no profile, and none of what you typed. Because they are sent by our server, they do not depend on the cookie banner and are recorded even if you refused it or block analytics scripts. We keep them because otherwise we cannot tell a working form from a broken one.

Legal basis for default tracking
Our legitimate interest in understanding site usage, balanced against the minimal, non-identifying nature of the data — no consent banner is required for this under GDPR/CNIL guidance.
Retention
Up to 7 years for aggregate analytics (page views, heatmaps, performance metrics); up to 30 days for session replays, which only exist if you consent.

Security and record-keeping

Separately from the analytics above, our hosting provider Cloudflare keeps short-lived technical logs of requests to our servers (Workers Logs), used only to debug problems when something breaks.

Cloudflare also applies its own protections to traffic arriving at the site, including always-on DDoS mitigation, a browser integrity check that refuses requests carrying known-abusive signatures, and a reputation-based security level that can challenge a visitor before any page is served. These see the IP address, the request headers and the request pattern of incoming traffic, in order to tell legitimate visitors from malicious or automated ones.

We do not filter automated visitors by the name they give themselves. Every public page of this site is served identically to everyone who asks for it: to a person's browser, to a search engine, to an assistant fetching a page because someone has just asked a question, and to the crawlers that copy pages in order to train AI models. This is a deliberate decision of the association, not an oversight. Our robots.txt allows everything, and we send no machine-readable signal reserving our rights against text and data mining, so the pages published here should be treated as freely collectable, training included. It follows that anything you see on our public pages may be read, copied and reused by an automated system — which is one more reason we never publish your membership record, your registration or anything you send us through a form.

The contact form, the newsletter sign-up, the membership application (including the eligibility check before you apply), the Erasmus Jobs application, and event registration are all protected by Cloudflare Turnstile, a human-verification challenge, to stop automated abuse. It doesn't publish or share anything beyond your IP address and whether you passed the check.

Your browser can also send us an automatic report when our content security policy blocks something on a page. This is a browser feature rather than a script of ours, and the report is sent to this site and nowhere else. We record the rule that fired, the file, line and column involved, and the address of the page you were on, cleaned first of anything that could carry a secret or a personal detail: the query string and the fragment are dropped, any secret carried in the path of a link is masked out, and the excerpt of blocked code that browsers offer to include is never stored.

The traffic counters Cloudflare produces for our domain are copied to Datadog, the monitoring service our volunteer board uses to see whether the site is up and how much traffic it is taking: numbers of requests, unique visitors, page views, bandwidth, and requests blocked as threats, broken down by country, response status and content type. Only those counts leave Cloudflare. No IP address, no page address, no form content and no membership record is sent to Datadog, and the access token used for this export is deliberately limited to traffic analytics so that it cannot read anything else. Datadog also runs uptime checks against our public pages from its own machines, which measure our servers and not our visitors.

None of this is used to build a profile of you, to track you across visits, or to personalise anything you see. It exists purely to keep the site working and secure.

Legal basis
Our legitimate interest in keeping the site secure and diagnosable when it breaks (GDPR Article 6.1.f), and our obligation under Article 32 to secure the data we process.
Retention
Workers request logs, including the content security policy reports described above: 3 days. The other protections (DDoS mitigation, browser integrity check, security level, Turnstile) run on Cloudflare's own operational retention for these features. The only thing we copy out of them is the aggregate traffic counters sent to Datadog, which carry no personal data.

How long we keep your data

In summary:

  • Contact form, no ongoing relationship: up to 3 years from last contact
  • Newsletter: 3 years from your subscription date
  • Membership and event participation: duration of membership plus 5 years
  • Erasmus Jobs application and CV: 12 months after our last contact, or immediately if you withdraw
  • Openings of an announcement to members (tracking pixel): 6 months after it was sent
  • Payment and accounting records: 10 years (legal requirement)

Who else sees your data

We share your data only with the service providers who help us run the association, each bound by a data processing agreement:

  • Cloudflare — hosting and database (EU data residency)
  • PostHog — analytics (page views, traffic sources, and, with your cookie consent, session replay), Cloud EU region
  • Datadog, the monitoring and uptime service used by our board, receives Cloudflare's aggregate traffic counters for our domain (requests, unique visitors, page views, bandwidth, threats blocked, broken down by country, response status and content type) and nothing else, so no personal data reaches it. It is listed here for transparency rather than because it holds anything about you. Processing takes place in the United States, in Datadog's US5 region
  • Resend — sends the association's transactional emails, most of them to you rather than to us: membership confirmation, event registration confirmations (carrying the personal link you use to cancel), payment confirmations, cancellation notices, and waitlist updates (invited, expired, or offered a place), plus the contact form notification to our team, and our announcements to members (Resend's own open and click tracking is switched off: the only measurement of openings is the pixel described under "Announcements to members"); account data is stored in the United States (sending can be routed from the EU, but account metadata stays in the US), covered by Standard Contractual Clauses for this transfer
  • Brevo (Sendinblue) — sends our newsletter (EU, France); receives your email address only, never the consent record or your IP address
  • BilletWeb — our previous ticketing and membership platform (France, with EU backups). It still holds the records made through it; the membership list has been migrated to our own platform
  • Stripe — processes payments for paid events, through Stripe Checkout hosted on Stripe's own pages; we never hold your card details ourselves
  • Google Workspace — our contact mailbox and internal documents (EU data residency)
  • Anthropic (Claude) — our volunteer board uses Claude, an AI assistant, as internal back-office tooling to help manage day-to-day association administration; this may involve processing some of the personal data described in this policy (US-based processing, under Anthropic's standard commercial terms)

Changes to this policy

We may update this policy as our services evolve. The date at the top of this page shows when it was last revised — please check back from time to time.

Contact

Questions about your data?

Reach out any time at dpo@aegeetoulouse.com and we'll get back to you.