Privacy Policy

Last updated: September 2026

Who we are

UCMSA Universalis is a multicultural and multidisciplinary student association directly affiliated with University College Maastricht (UCM). It is run by UCM students, for UCM students, and contributes to both the academic and social life at UCM.

For the purposes of data protection law, UCMSA Universalis is the “data controller” responsible for the personal data described in this policy. Our website address is ucmsa-universalis.nl. If you have any questions about this policy or how we handle your personal data, you can reach us at ucmsa-secretary@maastrichtuniversity.nl.

What personal data we collect and why

Account & login

When you create an account, we collect the email address, username, and password you provide. Your password is never stored in plain text — it is hashed before being saved, so we cannot see or recover it ourselves. We use this information solely to let you log in, verify your identity, and access member-only areas of the site. Account creation is currently limited to Maastricht University email addresses (@maastrichtuniversity.nl or @student.maastrichtuniversity.nl) to confirm you are a member of the UCM community.

Board & committee information

Names, positions, terms, and photos of board members and committee contacts are published on our “Meet Our Team”, Previous Boards, and Committees pages. This information is added by admins and board members through the site, and is published in the public interest of transparent association governance — anyone taking on a board or committee role can expect their name and role to be publicly associated with UCMSA Universalis for as long as they hold that position, and afterwards as part of our historical record of past boards.

Media you upload

If you (as an admin or board member) upload images to the website — for example a member photo, a committee photo, or an announcement image — please avoid uploading images with embedded location data (EXIF GPS) included. These images are stored publicly and visitors to the website can, in principle, download them and extract any location data embedded in the file.

Technical & server data

Like virtually all websites, our hosting and infrastructure providers automatically record standard technical information for security and operational purposes — such as IP address, browser type, and request timestamps — in server logs. We do not use this information for advertising, profiling, or analytics, and we do not run any analytics or tracking scripts on this site.

Our legal basis for processing your data

Under the GDPR, we rely on the following legal grounds:

  • Performance of a contract — to create and maintain your account and provide you with the services of the website (Art. 6(1)(b) GDPR).
  • Legitimate interest — to publicly represent our board and committees, keep a historical record of past boards, and keep the site secure (e.g. limiting sign-up abuse) (Art. 6(1)(f) GDPR).
  • Consent — where you have separately given it, for example if you choose to upload optional content. You may withdraw consent at any time by contacting us.

Who we share your data with

We do not sell your personal data. We share it only with the service providers that help us run the website, acting on our instructions:

  • Supabase — hosts our database and handles account authentication (sign-up, login, password resets).
  • Amazon Web Services (S3) — stores uploaded images and documents, in our EU (Frankfurt) region.
  • Vercel — hosts the website itself.
  • Google Fonts— we load one icon font directly from Google's servers, which receives your device's IP address when the page loads. Our other fonts are self-hosted and do not contact Google.

Some of these providers may process data outside the European Economic Area (EEA). Where that is the case, they do so under an adequacy decision or appropriate safeguards (such as the EU Standard Contractual Clauses) as required by the GDPR.

How long we retain your data

We keep your account information (email address and hashed password) for as long as your account is active, and in any case no longer than five years. If your account has been inactive for 2–3 years, we may delete it and the personal data associated with it. Your account and its data are also deleted sooner, at any time, if you request this or delete your account yourself.

Content published through the site — such as member profiles, announcements, committee listings, and uploaded documents — is kept until it is edited or removed by an admin or board member, or as long as it remains relevant to our historical record (e.g. Previous Boards).

Cookies and similar technologies

We do not use cookies, and we do not run any advertising or analytics trackers on this site. We do use your browser's local storage for a small number of strictly necessary, functional purposes: to keep you logged in between visits, and to remember the homepage's background image so it loads instantly. This information stays on your own device, is never sent to advertisers, and is not used to track you across other websites.

Your rights

Under the GDPR, you have the right to:

  • Request access to the personal data we hold about you;
  • Request that we correct any inaccurate or incomplete data;
  • Request that we erase your personal data (“right to be forgotten”);
  • Request that we restrict or object to certain processing of your data;
  • Request a copy of your data in a portable, machine-readable format; and
  • Withdraw your consent at any time, where we rely on consent.

These rights are not unlimited — for example, we may need to keep some information for legitimate administrative, legal, or security purposes even after a deletion request. To exercise any of these rights, contact us at ucmsa-secretary@maastrichtuniversity.nl. We will respond within one month, as required by the GDPR.

If you believe we have not handled your personal data properly, you also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl.

How we protect your data

We use industry-standard measures to protect your data, including encrypted connections (HTTPS), password hashing, and access controls that restrict administrative actions to authorized board members and admins. No method of transmission or storage is completely secure, but we work to protect your personal data to the best of our ability.

Changes to this policy

We may update this privacy policy from time to time, for example to reflect changes in the services we use or in data protection law. We will update the “last updated” date at the top of this page whenever we do.

Contact us

If you have any questions about this privacy policy or how we handle your personal data, please contact our secretary at ucmsa-secretary@maastrichtuniversity.nl.