Privacy Notice

This notice explains how Astra Europa processes personal data when you use our website, subscribe to updates, apply to join or volunteer, use our account and community platforms, or otherwise interact with us.

1. Who We Are and Scope

Astra Europa is a political organisation working to build a sovereign, democratic Europe. For this notice, "Astra Europa", "we", "us" and "our" refer to Astra Europa Nederland VEVR, unless another Astra Europa entity or chapter is responsible for a specific activity.

Astra Europa Nederland VEVR is temporarily assuming responsibility for Astra Europa federal organisation functions until the federal organisation is incorporated. Once the federal organisation is incorporated, responsibility for those functions is intended to be transferred to it.

  • Date: 20 June 2026
  • Responsible organisation: Astra Europa Nederland VEVR
  • Registration: Chamber of Commerce (KvK): 99212625
  • Contact: info@astraeuropa.eu
  • Data Protection Officer: Appointment of a Data Protection Officer is not mandatory for Astra Europa; no Data Protection Officer is appointed at the time of this notice.

This notice explains how we process personal data when people visit our website, subscribe to updates, apply to volunteer or become a member, receive invitations or verification emails, create or use an Astra Europa account, access our single sign-on system, use the chat or forum, participate in optional voting, use bot-assisted tools, or collaborate on Astra Europa projects through Codeberg.

It applies to members, former members, volunteers, applicants, prospective members, supporters, newsletter subscribers, website visitors, internal platform users, administrators, contributors, forum users and people who otherwise interact with Astra Europa.

2. Shared Responsibility with National Chapters

In some contexts, Astra Europa and national chapters share responsibility for deciding why and how personal data is used, especially for membership administration, volunteering, applications, forums, chat, voting, events and communications.

Where Astra Europa and a national chapter share responsibility, their arrangements allocate responsibilities for privacy notices, privacy rights requests, how long data is kept, deletion, security measures, service-provider management, access controls and external disclosures.

In practice, Astra Europa manages shared systems and overarching data protection governance, while each national chapter is responsible for its own members and local activities.

You can contact Astra Europa using the details in this notice for questions or rights requests about shared systems. If your request mainly concerns a national chapter, we will coordinate with the relevant chapter.

3. Processing Overview

The table below gives a high-level overview of how we process personal data, including the categories of data, where they come from, how long they are kept, why they are used, which legal bases apply in different contexts, and which service providers or external recipients are involved. More detail about these categories, sensitive personal data, how long we keep data, sharing and your rights appears in the following sections.

Categories of personal dataSourceHow long we keep itPurposeLegal basisService providers / external recipients
Identity and contact data
  • Collected directly from you.
  • Received from application, invitation, newsletter, email delivery or account services where used.
  • Kept while the relevant relationship, account, subscription or application remains active.
  • Membership and affiliation records are kept for the duration of the relationship plus 2 years, then deleted or made anonymous.
  • Newsletter subscription data is deleted within 30 days after unsubscribe, except records needed to stop future emails, record the unsubscribe, track failed delivery or show that we respected the unsubscribe.
  • Post-application and other post-relationship records are kept where necessary for administration, security, audit or legal claims.
  • Identify you and contact you.
  • Respond to enquiries and administer invitations.
  • Support applications and provide member or volunteer services.
  • Keep contact details accurate.
  • Contract or pre-contract steps.
  • Consent for optional information and newsletter subscriptions.
  • Legitimate interests in service administration, identity security, access-control administration, audit, abuse prevention and security communications.
  • Service providers include application, newsletter, email, account, hosting or infrastructure providers, depending on the service used.
Account and access data
  • Collected directly from you.
  • Created by account, single sign-on, invitation, verification, role, permission, login session, temporary login link, audit and security systems.
  • Kept while your account or relationship with Astra Europa remains active.
  • Account records tied to membership or affiliation are kept for the duration of the relationship plus 2 years, then deleted or made anonymous.
  • Authentication and access logs are kept for 6 months where governed by Astra Europa's access-logging policy.
  • Email verification and password reset links expire after 30 minutes; membership onboarding links expire after 7 days.
  • Partly completed sign-in, verification or onboarding pages expire after 1 day if they are not completed.
  • User-created app access keys and related access records are kept where necessary to provide access, maintain security and keep audit records.
  • Sign-in and account-service logs are kept where necessary for security, reliability, troubleshooting, audit or legal claims.
  • Create and administer accounts.
  • Provide single sign-on and verify email ownership.
  • Manage roles, permissions, login sessions and temporary login links.
  • Secure accounts, administer access controls, prevent abuse and maintain audit records.
  • Contract or pre-contract steps for account services.
  • Legitimate interests in identity security, access-control administration, audit, reliability and abuse prevention.
  • Legal obligation where records are needed for compliance.
  • Service providers include hosting and infrastructure providers, depending on the service used.
Membership, role and participation data
  • Collected directly from you.
  • Created or received when Astra Europa teams or national chapters assign roles, record participation or administer optional participation.
  • Kept while your membership, volunteering or participation relationship remains active.
  • Membership, affiliation and role records are kept for the duration of the relationship plus 2 years, then deleted or made anonymous.
  • Optional voting data is kept where necessary to administer, verify or audit the vote.
  • Administer membership and volunteering.
  • Organise teams and chapters and assign roles.
  • Support governance and invite people to activities.
  • Run optional voting or participation.
  • Contract or pre-contract steps for membership or volunteering.
  • Consent for optional voting and optional participation.
  • Legitimate interests in organisational administration.
  • Service providers support governance or participation processes where those services are used.
  • Third parties receive data where required for legal or security reasons.
Community content and interaction data
  • Collected directly from you when you post, send messages, react, report content or interact with bots.
  • Created by community, moderation and bot systems.
  • Kept while the community space, topic or account remains active.
  • Forum email logs and rejected email records are kept for 90 days.
  • Forum search query logs, unmatched email records and unmatched IP records are kept for 365 days.
  • Forum drafts are deleted after 180 days; temporary placeholder topics are deleted after 7 days.
  • Unused temporary forum accounts are cleaned up after 365 days; unactivated accounts are deleted after a 14-day grace period.
  • Forum records after activity ends are kept where necessary for discussion continuity, moderation history, security, legal claims or backup restoration.
  • Provide Astra Europa internal online community spaces.
  • Enable discussion and collaboration.
  • Moderate content, handle reports, enforce code-of-conduct and moderation policies, and maintain trust and safety.
  • Operate community bots.
  • Contract or pre-contract steps for member, volunteer or community services.
  • Legitimate interests in code-of-conduct and moderation-policy enforcement, abuse prevention, community safety and service integrity.
  • Legal obligations where moderation, preservation or disclosure is required by law.
  • Consent where participation is optional.
  • Service providers include hosting or infrastructure providers, depending on the service used.
Application and onboarding data
  • Collected directly from you through application forms, uploads and follow-up communications.
  • Received from form or storage services.
  • Created as reviewer notes or onboarding records.
  • Kept while we assess your application.
  • Application information after assessment is kept where necessary for follow-up, onboarding, suitable future roles, administration or legal claims.
  • If accepted, relevant application data becomes part of your member or volunteer record and follows how long we keep that record.
  • Assess applications.
  • Understand interests, skills and availability.
  • Route people into appropriate onboarding and contact applicants.
  • Match applicants with suitable future roles where appropriate.
  • Consent for submitted information and optional uploads.
  • Contract or pre-contract steps for assessing membership, volunteering or participation.
  • Explicit consent or information you have clearly made public for sensitive personal data where relevant.
  • Legitimate interests in limited post-assessment retention, follow-up, future role consideration, organisational administration, queries and legal claims.
  • Service providers include Google Forms, hosting and infrastructure providers, depending on the service used.
Contribution and collaboration data
  • Collected directly from you when you contribute.
  • Received from collaboration platforms such as Codeberg.
  • Created as technical contribution history, such as commits, issues, pull requests, reviews, comments, timestamps and attribution information.
  • Git contribution history is generally kept in project history for project integrity, attribution and audit unless a project-specific history management rule applies.
  • Operational synchronisation logs are kept where necessary for operational and audit purposes.
  • Give access to Astra Europa projects.
  • Support code and content collaboration.
  • Attribute contributions, review work and maintain project history.
  • Protect project and organisational integrity.
  • Contract or pre-contract steps for collaboration.
  • Legitimate interests in project integrity, attribution, audit, security, organisational administration and legal protection.
  • For public Codeberg projects, contributions and related project activity, including commits, issues, pull requests, reviews, comments, timestamps and attribution information, are publicly visible according to the project settings and Codeberg's platform functionality.
  • For private Codeberg projects, access is limited according to project permissions.
  • Third-party recipients include recipients needed for security, legal or organisational protection where those circumstances arise.
Newsletter and communications data
  • Collected directly from you when you subscribe, unsubscribe, contact us or respond to communications.
  • Received or created through newsletter and email delivery services.
  • Kept while you remain subscribed.
  • After unsubscribe, subscription data is deleted within 30 days except for records needed to stop future emails, record the unsubscribe, track failed delivery or show that we respected the unsubscribe.
  • Send newsletters and updates.
  • Manage subscriptions and unsubscribes.
  • Deliver service messages and avoid sending unwanted messages.
  • Understand email delivery and engagement.
  • Consent for newsletter subscriptions.
  • Legitimate interests in email delivery integrity, anti-abuse, failed-delivery handling, unsubscribe suppression and engagement tracking.
  • Service providers include Brevo/Sibforms and Cloudflare Turnstile where used for forms.
Privacy preference data
  • Collected directly from you when you set preferences, unsubscribe, object, withdraw consent, make a rights request, or otherwise communicate privacy choices.
  • Created by systems that record those choices.
  • Privacy preference records are kept where necessary to honour choices, document requests, avoid unwanted messages and demonstrate compliance.
  • Additional records are kept where necessary for audit or legal claims.
  • Record, manage and honour privacy choices.
  • Record newsletter unsubscribe choices, consent withdrawals, objections and rights requests.
  • Maintain communication preferences and related compliance records.
  • Legal obligations relating to data protection rights and compliance.
  • Legitimate interests in respecting preferences, keeping accurate compliance records and avoiding unwanted communications.
  • Consent where the preference relates to optional processing.
  • Service providers include newsletter, account or form services, depending on the service used.
  • Third-party recipients include legal advisers, regulators or authorities where required.
Technical, security and administration data
  • Collected automatically when you use our website, account system, community spaces and internal services.
  • Received from Cloudflare, hosting, email and infrastructure providers.
  • Authentication and access logs are kept for 6 months where governed by Astra Europa's access-logging policy.
  • Chat client IP records are kept for 28 days.
  • Technical records of deleted or edited chat content are kept for 7 days.
  • Backup copies are kept on a rolling schedule: daily copies for the last 7 days, weekly copies for the last 4 weeks, and monthly copies for the last 6 months.
  • Server and service logs that contain personal data are kept where necessary for security, reliability, diagnostics, abuse prevention, compliance, audit or legal claims.
  • Additional records are kept where necessary for rights requests, compliance, audit or legal claims.
  • Serve the website and internal systems.
  • Protect against abuse, diagnose errors and maintain availability.
  • Understand aggregate website usage and administer infrastructure.
  • Handle rights requests and keep audit records.
  • Legitimate interests in security, availability, diagnostics, administration and summary analytics.
  • Legal obligation where processing is needed for compliance or rights requests.
  • Service providers include Cloudflare, hosting and infrastructure providers, depending on the service used.
  • Third-party recipients include legal advisers, regulators or authorities where required.
Optional media and profile data
  • Collected directly from you when you add, upload or share it.
  • Received through application, community or collaboration services where you choose to provide it.
  • Optional media and profile data is kept where necessary for the relevant profile, application, community or collaboration process.
  • In the forum, unused uploaded files are cleaned up after 48 hours and deleted uploaded files are removed after 30 days.
  • Other optional media and profile data is kept where necessary for removal, backup, audit, security or legal needs.
  • Let you personalise your profile.
  • Let you submit supporting information.
  • Let you provide optional files in community, application or collaboration processes.
  • Consent where the information is optional.
  • Contract or pre-contract steps where the information is needed for a service or application you request.
  • Service providers include the relevant service providers for the place where you provide the information.
Relevant data across the categories above
  • From the sources described above for each category.
  • Kept according to the period for the relevant category.
  • Longer keeping periods apply where necessary for legal obligations, security, audit, dispute resolution, archive integrity, rights requests or legal claims, except where a specific legal period applies.
  • Support operational administration, security and service continuity.
  • Support abuse prevention, auditing, troubleshooting and rights requests.
  • Support compliance, records management, dispute handling, organisational protection and legal claims.
  • Legal obligations where processing is needed for compliance.
  • Legitimate interests in security, service continuity, organisational administration, records management, dispute handling and legal protection.
  • Contract, pre-contract steps or consent where relevant to the underlying processing.
  • Service providers handle data for us where we use them for the relevant service.
  • Third-party recipients include independent platforms where relevant, legal advisers, regulators, authorities, courts or other recipients where required or permitted by law.

Service-provider handling under appropriate data processing arrangements is treated as processing for Astra Europa, not as an independent disclosure. More detail appears in the sharing and storage sections below.

4. Further Information on Processing

4.1. What Information Do We Process?

The descriptions below explain the categories used in the overview table and how we collect, create or receive that data. The same data can fall into more than one category depending on the context in which it is used.

Identity and contact data

This is information that helps us know who you are and how to reach you. We collect it directly from you when you fill in forms, create or use an account, subscribe to updates, submit an application, accept an invitation, contact us or otherwise communicate with us. We also receive it from services used to process applications, invitations, newsletters, email delivery or account processes.

Account and access data

This is information used to create, secure and operate accounts and single sign-on access. We collect it directly from you when you create or use an account, and we create it when our systems record sign-ins, login sessions, invitations, verification, roles, permissions, access-control administration, temporary login links, access keys, audit events or security activity.

Membership, role and participation data

This is information about your relationship with Astra Europa, including membership, volunteering, chapter involvement, team roles, governance participation and optional participation. We collect it directly from you when you apply, join, volunteer or take part in activities. We also create or receive it when Astra Europa teams or national chapters assign roles, record participation, manage internal processes or administer optional voting.

Community content and interaction data

This covers content and activity you create in Astra Europa internal online community spaces, including discussions, chat messages, forum posts, reactions, reports, moderation and code-of-conduct activity, and bot-assisted tools. We collect it directly from you when you post, send messages, react, report content, interact with bots or otherwise use community spaces. We also create technical and moderation records when those spaces process activity.

Application and onboarding data

This is information submitted when you apply to become a member, volunteer or participant in Astra Europa activities. We collect it directly from you through application forms, uploads and follow-up communications. We also receive it through form, storage or communication services used for applications, and we create reviewer notes, post-assessment follow-up records or onboarding records as applications are assessed.

Contribution and collaboration data

This is information connected to work on Astra Europa projects, including contributions to code, content, documents, project spaces, issues, reviews, project administration and project-integrity records. We collect it directly from you when you contribute to projects. We also receive it from collaboration platforms such as Codeberg, and project systems create records such as file-change history, issue activity, review history, timestamps, audit records and attribution information.

For public Codeberg repositories, contributions and related project activity, including commits, issues, pull requests, reviews, comments, timestamps and attribution metadata, are publicly visible according to the repository settings and Codeberg's platform functionality. For private repositories, access is limited according to repository permissions.

Newsletter and communications data

This is information used to send updates, manage subscriptions, honour unsubscribe choices, understand whether messages are delivered or engaged with, prevent abuse, handle failed deliveries and maintain the integrity of communication channels. We collect it directly from you when you subscribe, unsubscribe, contact us or respond to communications. We also receive or create delivery records, failed-delivery records, open and click records, anti-abuse records, unsubscribe-suppression records and records needed to stop future emails through newsletter and email delivery services.

Privacy preference data

This is information about privacy choices, communication preferences, unsubscribe choices, consent withdrawals, objections and rights requests. We collect it directly from you when you make or change a choice, and we create or receive records through newsletter, email, account, form or request-handling systems that help us honour those choices.

Technical, security and administration data

This is operational information generated when people use our website and systems. We collect it automatically when you use our website, account system, community spaces and internal services, including connection data, browser or device information, timestamps, requested pages, authentication events, error logs and security events. We also receive technical and security data from Cloudflare, hosting providers, infrastructure providers and other services that support our systems.

Optional media and profile data

This is information you choose to add, upload or share to personalise a profile, support an application, take part in a community process or contribute to a project. We collect it directly from you when you provide it, and we receive it through application, community or collaboration services where you choose to upload or share it.

Operational, security and compliance purposes

Any of the categories described above is also processed where necessary for operational, security, compliance or legal purposes such as service continuity, internal administration, audits, troubleshooting, rights requests, records management, dispute handling, organisational protection or legal claims.

4.2. What Is The Purpose And The Legal Basis Of The Processing?

We process personal data only where we have a legal basis for that processing. The main purposes and legal bases are explained below.

Providing requested services and taking pre-contract steps

When you apply to join, volunteer, request access, use an account, take part in Astra Europa platforms or collaborate on Astra Europa projects, processing is necessary to provide the requested service, perform the relevant membership, volunteering or participation terms, or take steps at your request before entering into such a relationship.

Optional processing

Some processing depends on choices you make, such as subscribing to newsletters, providing optional information, uploading optional media, or taking part in optional voting or participation. Where we process optional data with your consent, you can withdraw that consent, for example by unsubscribing from newsletters, removing optional information, or deleting optional media.

Organisational administration

We process data to administer memberships, volunteering, teams, chapters, roles, internal governance, invitations, onboarding and communications. Depending on the context, processing is necessary under the membership terms, or for the purposes of the legitimate interests of Astra Europa or its national chapters in administering and governing the organisation, coordinating members and volunteers, keeping internal records accurate, and communicating about Astra Europa activities.

Application assessment and post-assessment administration

We process application and onboarding data to assess membership, volunteering or participation requests, respond to applicants, route people into onboarding, answer follow-up queries, consider suitable future roles where appropriate, and keep records needed for administration or legal claims. Depending on the context, processing is necessary to take steps at your request before entering into membership, volunteering or participation terms, with your consent for optional information, or for the purposes of the legitimate interests of Astra Europa or its national chapters in fair application handling, organisational administration, follow-up, future role consideration and legal protection.

Contribution and project integrity

We process contribution and collaboration data to give access to Astra Europa projects, support code and content collaboration, attribute contributions, review work, maintain project history, administer projects and protect project integrity. Depending on the context, processing is necessary under the relevant participation or collaboration terms, or for the purposes of the legitimate interests of Astra Europa or its national chapters in project integrity, attribution, audit, security, organisational administration and legal protection.

Security, moderation and service integrity

We process account, technical, community and audit data to keep systems available, secure accounts, administer access controls, prevent abuse, enforce code-of-conduct and moderation policies, investigate reports, troubleshoot issues and protect Astra Europa services. Depending on the context, processing is necessary for the purposes of the legitimate interests of Astra Europa or its national chapters in identity security, access-control administration, audit, maintaining secure and reliable services, protecting internal community spaces, enforcing moderation standards, preventing abuse, and investigating service or security issues. It is also necessary to comply with legal obligations where moderation, preservation, disclosure or other records are required by law.

Communication and newsletter delivery

We process communications data to respond to messages, send service notices, manage subscriptions, deliver newsletters, maintain delivery integrity, handle failed deliveries, prevent abuse, understand email engagement, respect unsubscribe choices and avoid unwanted messages. Newsletter subscriptions and update emails are processed with your consent. Depending on the context, service communications and security communications are necessary under the relevant membership, volunteering or participation terms, or for the purposes of the legitimate interests of Astra Europa or its national chapters in providing updates, maintaining secure services, ensuring email delivery integrity, handling failed deliveries, suppressing unsubscribed addresses, preventing abuse, understanding email engagement and avoiding unwanted messages.

Privacy preferences and rights requests

We process privacy preference data to record, manage and honour privacy choices, unsubscribe choices, consent withdrawals, objections and rights requests. Depending on the context, processing is necessary to comply with data protection obligations, or for the purposes of the legitimate interests of Astra Europa or its national chapters in respecting preferences, keeping accurate compliance records and avoiding unwanted communications.

Compliance, rights requests and legal protection

We process data where necessary to respond to rights requests, keep audit records, meet legal obligations, preserve evidence, protect organisational interests, or establish, exercise or defend legal claims. Depending on the context, processing is necessary to comply with legal obligations or for the purposes of the legitimate interests of Astra Europa or its national chapters in protecting legal, organisational and security interests.

Operational, security and compliance processing

Any category described in this notice is processed where necessary for security, service continuity, internal administration, audits, troubleshooting, compliance, records management, dispute handling, organisational protection or legal claims. Depending on the context, processing is necessary to comply with legal obligations, under the relevant membership, volunteering or participation terms, with consent, or for the purposes of the legitimate interests of Astra Europa or its national chapters.

5. Sensitive Personal Data

Astra Europa is a political organisation. Membership, volunteering, forum participation, chat participation, voting, applications, group memberships, roles, campaign involvement and contributions to Astra Europa projects can reveal political opinions, political affiliation or political participation.

For members, former members and people who have regular contact with Astra Europa and/or one or more of its national chapters in connection with its purposes, processing is carried out in the course of our legitimate activities as an association or other not-for-profit body with a political aim, subject to appropriate safeguards.

Sensitive personal data is not disclosed outside Astra Europa and/or relevant national chapters without the consent of the person concerned.

For applicants and other people who are not yet members or regular contacts, sensitive personal data is processed based on the explicit consent of the person concerned, or because the person concerned clearly made that information public.

6. Storage and How Long We Keep Data

This section lists how long we keep the main categories of personal data. Where a concrete period has been adopted, it is stated. Where no specific period is stated, we keep personal data only for as long as necessary for the purposes described in this notice, including service delivery, security, compliance, rights requests, audit, dispute handling, backup restoration or legal claims.

Accounts, invitations, temporary login links and audit events

  • Account records are kept while your account or relationship with Astra Europa remains active.
  • Account records tied to membership or affiliation are kept for the duration of the relationship plus 2 years, then deleted or made anonymous.
  • Authentication and access logs are kept for 6 months where governed by Astra Europa's access-logging policy.
  • Email verification and password reset links expire after 30 minutes.
  • Membership onboarding links expire after 7 days.
  • Partly completed sign-in, verification or onboarding pages expire after 1 day if they are not completed.
  • User-created app access keys and related access records are kept where necessary to provide access, maintain security and keep audit records.
  • Server and account-service logs that contain personal data are kept where necessary for security, reliability, troubleshooting, audit or legal claims.

Chat and bot-assisted tools

  • Chat messages, media, room state, device data and bot records are kept where necessary to provide the chat and bot-assisted tools.
  • Chat and bot-assisted tool data is also kept where necessary for deletion, deactivation and backup cycles.
  • Chat client IP records are kept for 28 days.
  • Technical records of deleted or edited chat content are kept for 7 days.
  • Optional election or voting data is kept where necessary to administer, verify and, where necessary, audit the relevant vote.

Members-only forum

  • Forum posts, uploads and moderation records are kept while the forum, topic or account remains active.
  • Forum user sessions expire after 24 hours.
  • Forum email logs and rejected email records are kept for 90 days.
  • Forum search query logs, unmatched email records and unmatched IP records are kept for 365 days.
  • Forum drafts are deleted after 180 days; temporary placeholder topics are deleted after 7 days.
  • Unused temporary forum accounts are cleaned up after 365 days; unactivated users are deleted after a 14-day grace period.
  • Unused forum uploads are cleaned up after 48 hours and deleted uploads are deleted after 30 days.
  • Post-activity forum records are kept where necessary for thread integrity, moderation history, security, legal claims or backup restoration.

Codeberg and Git records

  • Codeberg synchronisation logs are kept where necessary for operational and audit purposes.
  • Git contribution history is generally kept in project history for project integrity, attribution and audit unless a project-specific history management rule applies.
  • Codeberg determines how long it keeps user accounts and platform records under its own privacy terms.

Email, website and infrastructure logs

  • Transactional email is kept for delivery only, with undelivered regular and failed-delivery mail queued for up to 5 days by the mailserver.
  • Authentication and access logs are kept for 6 months where governed by Astra Europa's access-logging policy.
  • Backup copies are kept on a rolling schedule: daily copies for the last 7 days, weekly copies for the last 4 weeks, and monthly copies for the last 6 months.
  • Server and service logs that contain personal data are kept where necessary for security, reliability, diagnostics, abuse prevention, compliance, audit or legal claims.
  • Other email delivery records, failed-delivery or error logs, service logs and backup-related records are kept where necessary for delivery, security, reliability, diagnostics, abuse prevention, backup restoration and legal claims.

Newsletter

  • Your newsletter email address is kept while you remain subscribed.
  • When you unsubscribe, newsletter subscription data is deleted within 30 days.
  • Records needed to stop future emails, record unsubscribes, track failed delivery or show that we respected the unsubscribe are kept where necessary for those purposes.

Privacy preferences and rights requests

  • Privacy preference records, unsubscribe choices, consent withdrawals, objections and rights-request records are kept where necessary to honour choices and respond to requests.
  • Additional records are kept where necessary to demonstrate compliance, avoid unwanted communications, or handle audit, dispute or legal-claim needs.

Applications

  • Application information is kept while we assess your application.
  • After assessment, application information is kept where necessary for follow-up, queries, onboarding, suitable future roles where appropriate, or legal claims.
  • If you are accepted, relevant application data becomes part of your member or volunteer record and follows how long we keep that record.
  • Membership and affiliation records are kept for the duration of the relationship plus 2 years, then deleted or made anonymous.

Exceptions

  • Longer keeping periods apply where necessary for legal obligations, security, audit, dispute resolution, archival integrity, backup restoration, or the establishment, exercise or defence of legal claims, except where a specific legal period applies.
  • Backup copies are kept on a rolling schedule: daily copies for the last 7 days, weekly copies for the last 4 weeks, and monthly copies for the last 6 months.
  • Other archive and deletion cycles apply where data is no longer needed in a form that identifies a person.

7. How Information Is Disclosed

This section explains which service providers process personal data for us and when information is disclosed outside Astra Europa. Service-provider handling under appropriate data processing arrangements is treated as processing for Astra Europa, not as an independent disclosure.

Service providers

  • We use service providers to operate our website, account systems, internal services, forms, newsletters, email delivery, hosting and infrastructure.
  • These providers include our VPS or hosting provider, Cloudflare for website delivery, security and analytics, Brevo/Sibforms for newsletter processing, Google Forms for application responses and uploaded files, and email delivery infrastructure.
  • Where a provider processes personal data for us, we use contractual and organisational safeguards designed to ensure that personal data is processed only on our documented instructions and protected appropriately.

External platforms you use directly

  • Public social media platforms and external platforms handle data under their own terms when you use their services directly.

Contribution Tracking

  • For public Codeberg repositories, contributions and related project activity is publicly visible according to repository settings and Codeberg's platform functionality. For private repositories, access is limited according to repository permissions.

Public or user-directed sharing

  • Information you choose to publish, submit to public repositories, post on public social media, or share through external platforms is visible according to the settings and terms of the place where you share it.
  • When you send information to another person or external service, the recipient and their service providers process that information independently.

Legal, security and rights recipients

  • We disclose personal data where required by law, court order, regulator, authority, subpoena or other legal process.
  • We disclose personal data to legal advisers, parties to proceedings, courts, regulators, authorities or security recipients where needed to protect rights, safety, security, organisational interests, or to establish, exercise or defend legal claims.
  • We disclose information where needed to respond to rights requests or complaints, provided the disclosure is permitted by law and proportionate.

Statistics and information that no longer identifies anyone

  • Where we share high-level statistics or other information that no longer identifies anyone, we do so only where it cannot reasonably be linked to an identifiable person.

International transfers

  • Where personal data is transferred outside the European Economic Area, we use an appropriate transfer mechanism such as an adequacy decision, Data Privacy Framework participation where applicable, Standard Contractual Clauses, or another valid safeguard.

8. Your Rights

Depending on the circumstances, your rights include the right to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, objection to processing, and withdrawal of consent where you have given consent.

Withdrawing consent does not affect processing that happened before the withdrawal. Some rights are limited where we need to comply with law, protect the rights and freedoms of others, preserve security, manage legal claims, keep required records, or maintain the integrity of collaborative records such as Git history.

To exercise your rights, contact us using the details in the contact section. If your request involves a national chapter or external platform, we will coordinate the response or direct you to the appropriate contact.

9. Changes to This Notice

We update this privacy notice when our processing changes, when we add or remove services, when legal requirements change, or when our responsibility, service-provider, chapter or data-storage arrangements are updated. The date at the top of this notice shows when it was last updated.

10. Contact and Complaints

If you have questions about this Privacy Notice or Astra Europa's privacy practices, or if you wish to make a complaint, please contact:

  • Responsible organisation: Astra Europa Nederland VEVR
  • Registration: Chamber of Commerce (KvK): 99212625
  • Email: info@astraeuropa.eu

Use the same email address if you want to exercise your data protection rights, withdraw consent, object to processing, or ask a question about the legal basis for processing your personal data.

If your request relates to a national chapter, we will handle the request under the relevant shared-responsibility arrangement or forward it to the appropriate chapter contact while keeping you informed.

You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with another competent supervisory authority in the European Economic Area.

Subscribe to Updates