Skip to content
Legal

Privacy Policy

Last updated: 11 August 2026

Who we are

BSS Startup is a student-run organisation at Aarhus BSS, Aarhus University. We are the data controller for the personal data described here. CVR: 44838486. Contact us any time at info@bssstartup.com.

What we collect

  • Account and membership: your name, email address, login identifiers, role, onboarding status and membership dates.
  • Profile details: study information, cohort, interests, skills, links, dietary notes, gender and other details you choose to provide.
  • Events: which events you register for, your RSVP status, ticket/check-in codes and, for guests, the name and email provided at sign-up.
  • Messages: anything you send us through the contact form.
  • Technical: authentication cookies, basic device and request data, and privacy-friendly analytics where enabled. We do not use advertising trackers.

How we use it

  • To create and maintain member accounts and membership cards.
  • To manage event registrations, reminders, cancellations and waitlists.
  • To respond to messages and sponsorship or press enquiries.
  • To send event and opportunity emails where you have opted in.
  • To keep the platform secure and understand aggregate site usage.

Our legal bases are contract or membership administration, consent, legal obligations, and our legitimate interest in operating a safe student association platform.

Who can see your data

Public pages do not expose member personal data. Member-to-member profile browsing is disabled in this launch version; admins can access member data only to run the association, events and support. We host application data with Supabase, host the website with Vercel, and send email through Brevo, Mailjet or Resend. These providers act as processors for the service they provide.

Your rights

Under the GDPR you can access, correct, export or delete your data, restrict or object to processing, and withdraw consent at any time. You can export or delete your account from Settings, and you can turn marketing emails off there or through an unsubscribe link. You can also email us and we'll handle the request.

Retention

We keep your data for as long as you have an account, and delete or anonymise it after you leave, except where we need records for legal, security, accounting or association-administration reasons. Contact messages are kept only as long as needed to handle the enquiry. Event attendance records may be kept in aggregate form after account deletion.

Cookies and security

We use essential cookies for sign-in and session security. We do not sell personal data. Access to admin tools is role-restricted, and membership QR verification pages require an admin login.