Effective date: October 2024

Table of Contents

  1. Introduction
  2. Collecting personal information
  3. Using personal information
  4. Disclosing personal information
  5. International data transfers
  6. Retaining personal information
  7. Security of personal information
  8. Oauth clients
  9. Amendments
  10. Your rights
  11. Third-party websites
  12. Updating information
  13. Deletion of information
  14. Cookies

Disclaimer

Erasmus Student Network (ESN) is an independent, non-partisan, non-political, and non-profit, international association which operates under Belgian law. ESN is supported as a Civil Society stakeholder by both the Council of Europe, through the European Youth Foundation and European Union, through the Civil Society Cooperation Grant, co-funded by the European Union. Disclaimer for the Co-funding of the European Union: Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Education and Culture Executive Agency (EACEA). Neither the European Union nor EACEA can be held responsible for them.

  1. Introduction

    1. We are committed to safeguarding the privacy of our website visitors; in this policy we explain how we will treat your personal information.

    2. By using our website and agreeing to this policy, you consent to our use of cookies in accordance with the terms of this policy.

    3. By using our website and agreeing to this policy, you also agree to the Terms and Conditions and Privacy Policy of those third parties

     

  2. Collecting personal information
    1. We may collect, store and use the following kinds of personal information:

      1. information about your computer and about your visits to and use of this website (including, but not limited to, your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths);

      2. information that you provide when registering with our website;

      3. information that you provide when completing your profile on our website (including, but not limited to, your name, profile pictures, gender, date of birth, nationality, social media profile URLs, ESN membership number, educational details and other information set in your profile fields);

      4. information that you provide for the purpose of subscribing to our email notifications and/or newsletters (including your name and email address);

      5. information that you provide when using the services on our website, or that is generated in the course of the use of those services (including the timing, frequency and pattern of service use);

      6. information relating to any purchases you make of our goods and/or services or any other transactions that you enter into through our website (including your name, address, telephone number, email address and card details);

      7. information that you publish into our website for publication on the internet and/or the intranet (including your user name, your profile pictures and the content provided);

      8. information contained in or relating to any communication that you send to us or send through our website (including the communication content and metadata associated with the communication); and

      9. any other personal information that you choose to send to us.

    2. Before you disclose to us the personal information of another person, you must obtain that person's consent to both the disclosure and the processing of that personal information in accordance with this policy.
       

  3. Using personal information
    1. Personal information submitted to us through our website will be used for the purposes specified in this policy or on the relevant pages of the website.

    2. We may use your personal information to:

      1. administer our website and Organisation;

      2. personalise our website for you;

      3. enable your use of the services available on our website;

      4. send you goods purchased through our website;

      5. supply to you services purchased through our website;

      6. send statements, invoices and payment reminders to you, and collect payments from you;

      7. send you non-marketing communications about ESN International and its bodies and members;

      8. send you email notifications that you have specifically requested;

      9. send you our email newsletter, under explicit request, to which you can automatically unsubscribe if you no longer want to receive it;

      10. send you marketing communications, under requirement of your explicit consent, relating to our Organisation and its associate members or the businesses of carefully-selected third parties which we think may be of interest to you by email or similar technology (you can inform us at any time if you no longer require marketing communications);

      11. provide third parties with statistical aggregated non-identifiable information about our users and services;

      12. provide third parties with personal data needed to comply with the purpose of this website, usability of its features and benefits offered to ESN Accounts users. This will be done only under previous and explicit consent provided by the user;

      13. deal with enquiries and complaints made by or about you relating to our website and the services provided in it;

      14. keep our website secure and prevent fraud; and

      15. verify compliance with the terms and conditions governing the use of our website.

      16. to facilitate contact between you and other users of the intranet and only within the intranet.

    3. By accepting this Privacy Policy you accept to be searchable in our search engine by any other authenticated user of the ESN Accounts intranet with, at least, one assigned role. Only the minimum information needed for the user-search functionality deliverables will be published, following the principles of minimisation and proportionality of the EU General Data Protection Regulation. Therefore,

    4. If you submit personal information for publication on our website, we will publish and otherwise use that information in accordance with the licence you grant to us.

    5. Your privacy settings can be used to limit the publication of your information on our website, and can be adjusted using privacy controls on the website.

    6. We will not, without your express consent, supply and/or transfer your personal information to any third party for the purpose of their or any other third party's direct marketing, with the exception of the ESN section and ESN country’s national bodies in which the user informed via its profile fields to be a current and/or former member of.

    7. In case of financial transactions happening on our website, these are handled through our payment services provider. ESN has no control over, and is not responsible for, their Privacy Policy and Terms and Conditions. We will share information with our payment services provider only to the extent necessary for the purposes of processing payments you make via our website, refunding such payments and dealing with complaints and queries relating to such payments and refunds. By accepting this Privacy Policy you are also accepting the additional terms established by the Terms of Use and Privacy Policies of these service providers.

  4. Disclosing personal information
    1. We may disclose your personal information to any of our employees, officers, insurers, professional advisers, agents, suppliers or subcontractors insofar as reasonably necessary for the purposes set out in this policy.

    2. We may disclose your personal information to any member of our organization and supporting organisms (this means: our Committees, Project Teams, National Boards, Sections and any other pre-existing or ulteriorly created internal body) insofar as reasonably necessary for the purposes set out in this policy and to guarantee the deliverables of the service offered by the ESN Accounts intranet.

    3. We may disclose your personal information:

      1. to the extent that we are required to do so by law;

      2. in connection with any ongoing or prospective legal proceedings;

      3. in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk);

      4. to any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information.

    4. Except as provided in this policy, we will not provide your personal information to third parties.

    5. The categories of personal information considered under this Article are the ones defined by Article 2.1 clauses (b), (c), (d), (g), (h) and (i).

    6. The purposes of the possible disclosure of your personal information as defined in Article 4.5 shall not be different from those mentioned in Article 4.3 and Article 3.2 in clauses (l) and (m) of this document, with the exception of those cases in which the user has previously, actively and expressly provide consent to do so.

  5. International data transfers
    1. Information that we collect may be stored and processed in and transferred between any of the countries in which we or our associate members operate in order to enable us to use the information in accordance with this policy.

    2. Information that we collect may be transferred to countries which do not have data protection laws equivalent to those in force in the European Economic Area. ESN International cannot guarantee the safety of your data in regards to such transfer.

    3. Personal information that you publish on our website or submit for publication on our website may be available, via the internet and/or the ESN Accounts intranet, around the world. We cannot prevent the use or misuse of such information by others.

    4. You expressly agree to the transfers of personal information described in this Section 5.

  6. Retaining personal information
    1. This Section 6 sets out our data retention policies and procedure, which are designed to help ensure that we comply with our legal obligations in relation to the retention and deletion of personal information.

    2. Personal information that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.

    3. Notwithstanding the other provisions of this Section 6, we will retain documents (including electronic documents) containing personal data:

      1. to the extent that we are required to do so by law;

      2. if we believe that the documents may be relevant to any ongoing or prospective legal proceedings; and

      3. in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk).

  7. Security of personal information
    1. We will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information.

    2. We will store all the personal information you provide on our secure (password- and firewall-protected) servers.

    3. All electronic financial transactions entered into through our website will be protected by encryption technology.

    4. You acknowledge that the transmission of information over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet, nor within the intranet.

    5. You refuse to held ESN International responsible for the improper or illegal use of your accessible information as set in clauses 3.2, 3.3 and 3.7 of this Privacy Policy. It’s the user’s obligation to consider the risks upon submission, management and publication of the user’s personal information on our platform.

    6. You are ultimately responsible for keeping the password you use for accessing our website confidential; we will never ask you for your password (except when you log in to our website - moment in which it is encrypted).

  8. Oauth clients
    1. This Privacy Policy outlines how we collect, use, and protect the information of our OAuth clients ("you", "your") who use our OAuth provider services.

    2. When you use our OAuth provider services, we may collect the following types of information:

      1. Client Information

        1. Registration Data: When you sign up as a client to use our OAuth services, we collect your organization or personal details, such as name, email address, phone number, company name, and website URL.

        2. OAuth Application Data: We collect data related to the applications you register, such as the name of the app, redirect URIs, and API usage details.

      2. Usage Data

        1. OAuth Transactions: We collect data on the OAuth transactions between your users and our OAuth provider, such as token generation, user authentication events, and API calls.
        2. Logs: Our servers automatically record certain information from your use of the service, such as the IP address, timestamps, browser type, and device information.
      3. End-User Data (Processed by You)

        1. As an OAuth client, you may collect and process personal information from end users through our services. You are responsible for ensuring the protection and privacy of your end users' data in compliance with applicable privacy laws. We do not store or use your end-users' data beyond facilitating OAuth transactions.

    3. We use the information we collect for the following purposes:

      1. Providing the OAuth Service: To facilitate the authentication and authorization process between your users and your application.
      2. Security and Fraud Prevention: To monitor, detect, and prevent fraudulent activities and ensure the security of our services.
      3. Communication: To contact you regarding important updates, technical support, and service-related notifications.
      4. Improving the Service: To analyze trends, usage patterns, and troubleshoot issues to improve the quality of our OAuth provider services.
    4. We do not share your personal information with third parties, except in the following circumstances:

      1. Service Providers: We may share your data with trusted third-party service providers who help us deliver our OAuth services (e.g., hosting providers, monitoring services). These third parties are bound by confidentiality agreements and do not have permission to use your data for any purposes beyond providing services to us.
      2. Legal Requirements: We may disclose your data when required to comply with applicable laws, regulations, legal processes, or government requests.
      3. Business Transfers: In the event of a merger, acquisition, or sale of all or part of our assets, your data may be transferred to the new entity as part of the transaction.
    5. We retain your personal information for as long as necessary to provide our services and comply with legal obligations. If you close your account, we will retain your data only as long as needed for legitimate business purposes or as required by law.
      1. Closing the account does not eliminate automatically the data shared through different Oauth clients or any other account created via Oauth clients. End users are responsible of closing any account created via the Oauth client in third-party platforms.
    6. We implement appropriate technical and organizational measures to safeguard your data from unauthorized access, disclosure, alteration, or destruction. While we strive to protect your information, no method of transmission over the internet is 100% secure. You are responsible for securing your OAuth client credentials.

       

  9. Amendments
    1. We may update this policy from time to time by publishing a new version on our website.

    2. You should check this page occasionally to ensure you are happy with any changes to this policy.

    3. We may notify you of changes to this policy by email or through a notification system on our website.

  10. Your rights
    1. You may instruct us to provide you with any personal information we hold about you by writing to wpa[at]esn.org; provision of such information will be subject to:

      1. the payment of a fee (currently fixed at €10); and

      2. the supply of appropriate evidence of your identity. For this purpose, we will usually accept a photocopy of your passport certified by a solicitor or bank plus an original copy of a utility bill showing your current address.

    2. We may withhold personal information that you request to the extent permitted by law.

    3. You may instruct us at any time to process or not to process your personal information for marketing purposes.

    4. In practice, you will usually either expressly agree in advance to our use of your personal information for marketing purposes.

    5. You have the right  to remove your ESN Accounts' account and all the information which is stored with it at any given time. You can do so by selecting “Delete” on your profile page. Alternatively, you can delete your account from ESN Accounts by e-mailing wpa[at]esn.org.

    6. When you account is deleted, all the personal information and other data linked to it is also deleted.

  11. Third party websites
    1. Our website includes hyperlinks to, and details of, third party websites.

    2. We have no control over, and are not responsible for, the privacy policies and practices of third parties.

  12. Updating information
    1. Please let us know if the personal information that we hold about you needs to be corrected or updated.

  13. Deletion of information
    1. ESN International and/or The National Representative of your country reserves the right to delete your account, upon identification of an illegitimate or fraudulent use of the account and/or our platform.

  14. Cookies
    1. Our website uses cookies.

    2. A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.

    3. Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.

    4. Cookies do not typically contain any information that personally identifies a user, but personal information that we store about you may be linked to the information stored in and obtained from cookies.

    5. We use both session and persistent cookies on our website.

    6. Most browsers allow you to refuse to accept cookies; for example:

      1. in Internet Explorer (version 11) you can block cookies using the cookie handling override settings available by clicking "Tools", "Internet Options", "Privacy" and then "Advanced";

      2. in Firefox (version 47) you can block all cookies by clicking "Tools", "Options", "Privacy", selecting "Use custom settings for history" from the drop-down menu, and unticking "Accept cookies from sites"; and

      3. in Chrome (version 52), you can block all cookies by accessing the "Customise and control" menu, and clicking "Settings", "Show advanced settings" and "Content settings", and then selecting "Block sites from setting any data" under the "Cookies" heading. 

      4. Please acknowledge that the location of these settings might change, as it is dependant on the correspondent service/product provider of the browser.

    7. ESN International will never share information collected using cookies without first securing the user’s explicit consent to do so.

    8. Blocking all cookies will have a negative impact upon the usability of many websites.

    9. If you block cookies, you will not be able to use all the features on our website.