This notice explains how Astra Europa processes personal data when you use our website, subscribe to updates, apply to join or volunteer, use our account and community platforms, or otherwise interact with us.
1. Who We Are and Scope
Astra Europa is a political organisation working to build a sovereign, democratic Europe. For this notice, "Astra Europa", "we", "us" and "our" refer to Astra Europa Nederland VEVR, unless another Astra Europa entity or chapter is responsible for a specific activity.
Astra Europa Nederland VEVR is temporarily assuming responsibility for Astra Europa federal organisation functions until the federal organisation is incorporated. Once the federal organisation is incorporated, responsibility for those functions is intended to be transferred to it.
- Date: 20 June 2026
- Responsible organisation: Astra Europa Nederland VEVR
- Registration: Chamber of Commerce (KvK): 99212625
- Contact: info@astraeuropa.eu
- Data Protection Officer: Appointment of a Data Protection Officer is not mandatory for Astra Europa; no Data Protection Officer is appointed at the time of this notice.
This notice explains how we process personal data when people visit our website, subscribe to updates, apply to volunteer or become a member, receive invitations or verification emails, create or use an Astra Europa account, access our single sign-on system, use the chat or forum, participate in optional voting, use bot-assisted tools, or collaborate on Astra Europa projects through Codeberg.
It applies to members, former members, volunteers, applicants, prospective members, supporters, newsletter subscribers, website visitors, internal platform users, administrators, contributors, forum users and people who otherwise interact with Astra Europa.
3. Processing Overview
The table below gives a high-level overview of how we process personal data, including the categories of data, where they come from, how long they are kept, why they are used, which legal bases apply in different contexts, and which service providers or external recipients are involved. More detail about these categories, sensitive personal data, how long we keep data, sharing and your rights appears in the following sections.
| Categories of personal data | Source | How long we keep it | Purpose | Legal basis | Service providers / external recipients |
|---|---|---|---|---|---|
| Identity and contact data |
|
|
|
|
|
| Account and access data |
|
|
|
|
|
| Membership, role and participation data |
|
|
|
|
|
| Community content and interaction data |
|
|
|
|
|
| Application and onboarding data |
|
|
|
|
|
| Contribution and collaboration data |
|
|
|
|
|
| Newsletter and communications data |
|
|
|
|
|
| Privacy preference data |
|
|
|
|
|
| Technical, security and administration data |
|
|
|
|
|
| Optional media and profile data |
|
|
|
|
|
| Relevant data across the categories above |
|
|
|
|
|
Service-provider handling under appropriate data processing arrangements is treated as processing for Astra Europa, not as an independent disclosure. More detail appears in the sharing and storage sections below.
4. Further Information on Processing
4.1. What Information Do We Process?
The descriptions below explain the categories used in the overview table and how we collect, create or receive that data. The same data can fall into more than one category depending on the context in which it is used.
Identity and contact data
This is information that helps us know who you are and how to reach you. We collect it directly from you when you fill in forms, create or use an account, subscribe to updates, submit an application, accept an invitation, contact us or otherwise communicate with us. We also receive it from services used to process applications, invitations, newsletters, email delivery or account processes.
Account and access data
This is information used to create, secure and operate accounts and single sign-on access. We collect it directly from you when you create or use an account, and we create it when our systems record sign-ins, login sessions, invitations, verification, roles, permissions, access-control administration, temporary login links, access keys, audit events or security activity.
Membership, role and participation data
This is information about your relationship with Astra Europa, including membership, volunteering, chapter involvement, team roles, governance participation and optional participation. We collect it directly from you when you apply, join, volunteer or take part in activities. We also create or receive it when Astra Europa teams or national chapters assign roles, record participation, manage internal processes or administer optional voting.
Community content and interaction data
This covers content and activity you create in Astra Europa internal online community spaces, including discussions, chat messages, forum posts, reactions, reports, moderation and code-of-conduct activity, and bot-assisted tools. We collect it directly from you when you post, send messages, react, report content, interact with bots or otherwise use community spaces. We also create technical and moderation records when those spaces process activity.
Application and onboarding data
This is information submitted when you apply to become a member, volunteer or participant in Astra Europa activities. We collect it directly from you through application forms, uploads and follow-up communications. We also receive it through form, storage or communication services used for applications, and we create reviewer notes, post-assessment follow-up records or onboarding records as applications are assessed.
Contribution and collaboration data
This is information connected to work on Astra Europa projects, including contributions to code, content, documents, project spaces, issues, reviews, project administration and project-integrity records. We collect it directly from you when you contribute to projects. We also receive it from collaboration platforms such as Codeberg, and project systems create records such as file-change history, issue activity, review history, timestamps, audit records and attribution information.
For public Codeberg repositories, contributions and related project activity, including commits, issues, pull requests, reviews, comments, timestamps and attribution metadata, are publicly visible according to the repository settings and Codeberg's platform functionality. For private repositories, access is limited according to repository permissions.
Newsletter and communications data
This is information used to send updates, manage subscriptions, honour unsubscribe choices, understand whether messages are delivered or engaged with, prevent abuse, handle failed deliveries and maintain the integrity of communication channels. We collect it directly from you when you subscribe, unsubscribe, contact us or respond to communications. We also receive or create delivery records, failed-delivery records, open and click records, anti-abuse records, unsubscribe-suppression records and records needed to stop future emails through newsletter and email delivery services.
Privacy preference data
This is information about privacy choices, communication preferences, unsubscribe choices, consent withdrawals, objections and rights requests. We collect it directly from you when you make or change a choice, and we create or receive records through newsletter, email, account, form or request-handling systems that help us honour those choices.
Technical, security and administration data
This is operational information generated when people use our website and systems. We collect it automatically when you use our website, account system, community spaces and internal services, including connection data, browser or device information, timestamps, requested pages, authentication events, error logs and security events. We also receive technical and security data from Cloudflare, hosting providers, infrastructure providers and other services that support our systems.
Optional media and profile data
This is information you choose to add, upload or share to personalise a profile, support an application, take part in a community process or contribute to a project. We collect it directly from you when you provide it, and we receive it through application, community or collaboration services where you choose to upload or share it.
Operational, security and compliance purposes
Any of the categories described above is also processed where necessary for operational, security, compliance or legal purposes such as service continuity, internal administration, audits, troubleshooting, rights requests, records management, dispute handling, organisational protection or legal claims.
4.2. What Is The Purpose And The Legal Basis Of The Processing?
We process personal data only where we have a legal basis for that processing. The main purposes and legal bases are explained below.
Providing requested services and taking pre-contract steps
When you apply to join, volunteer, request access, use an account, take part in Astra Europa platforms or collaborate on Astra Europa projects, processing is necessary to provide the requested service, perform the relevant membership, volunteering or participation terms, or take steps at your request before entering into such a relationship.
Optional processing
Some processing depends on choices you make, such as subscribing to newsletters, providing optional information, uploading optional media, or taking part in optional voting or participation. Where we process optional data with your consent, you can withdraw that consent, for example by unsubscribing from newsletters, removing optional information, or deleting optional media.
Organisational administration
We process data to administer memberships, volunteering, teams, chapters, roles, internal governance, invitations, onboarding and communications. Depending on the context, processing is necessary under the membership terms, or for the purposes of the legitimate interests of Astra Europa or its national chapters in administering and governing the organisation, coordinating members and volunteers, keeping internal records accurate, and communicating about Astra Europa activities.
Application assessment and post-assessment administration
We process application and onboarding data to assess membership, volunteering or participation requests, respond to applicants, route people into onboarding, answer follow-up queries, consider suitable future roles where appropriate, and keep records needed for administration or legal claims. Depending on the context, processing is necessary to take steps at your request before entering into membership, volunteering or participation terms, with your consent for optional information, or for the purposes of the legitimate interests of Astra Europa or its national chapters in fair application handling, organisational administration, follow-up, future role consideration and legal protection.
Contribution and project integrity
We process contribution and collaboration data to give access to Astra Europa projects, support code and content collaboration, attribute contributions, review work, maintain project history, administer projects and protect project integrity. Depending on the context, processing is necessary under the relevant participation or collaboration terms, or for the purposes of the legitimate interests of Astra Europa or its national chapters in project integrity, attribution, audit, security, organisational administration and legal protection.
Security, moderation and service integrity
We process account, technical, community and audit data to keep systems available, secure accounts, administer access controls, prevent abuse, enforce code-of-conduct and moderation policies, investigate reports, troubleshoot issues and protect Astra Europa services. Depending on the context, processing is necessary for the purposes of the legitimate interests of Astra Europa or its national chapters in identity security, access-control administration, audit, maintaining secure and reliable services, protecting internal community spaces, enforcing moderation standards, preventing abuse, and investigating service or security issues. It is also necessary to comply with legal obligations where moderation, preservation, disclosure or other records are required by law.
Communication and newsletter delivery
We process communications data to respond to messages, send service notices, manage subscriptions, deliver newsletters, maintain delivery integrity, handle failed deliveries, prevent abuse, understand email engagement, respect unsubscribe choices and avoid unwanted messages. Newsletter subscriptions and update emails are processed with your consent. Depending on the context, service communications and security communications are necessary under the relevant membership, volunteering or participation terms, or for the purposes of the legitimate interests of Astra Europa or its national chapters in providing updates, maintaining secure services, ensuring email delivery integrity, handling failed deliveries, suppressing unsubscribed addresses, preventing abuse, understanding email engagement and avoiding unwanted messages.
Privacy preferences and rights requests
We process privacy preference data to record, manage and honour privacy choices, unsubscribe choices, consent withdrawals, objections and rights requests. Depending on the context, processing is necessary to comply with data protection obligations, or for the purposes of the legitimate interests of Astra Europa or its national chapters in respecting preferences, keeping accurate compliance records and avoiding unwanted communications.
Compliance, rights requests and legal protection
We process data where necessary to respond to rights requests, keep audit records, meet legal obligations, preserve evidence, protect organisational interests, or establish, exercise or defend legal claims. Depending on the context, processing is necessary to comply with legal obligations or for the purposes of the legitimate interests of Astra Europa or its national chapters in protecting legal, organisational and security interests.
Operational, security and compliance processing
Any category described in this notice is processed where necessary for security, service continuity, internal administration, audits, troubleshooting, compliance, records management, dispute handling, organisational protection or legal claims. Depending on the context, processing is necessary to comply with legal obligations, under the relevant membership, volunteering or participation terms, with consent, or for the purposes of the legitimate interests of Astra Europa or its national chapters.
5. Sensitive Personal Data
Astra Europa is a political organisation. Membership, volunteering, forum participation, chat participation, voting, applications, group memberships, roles, campaign involvement and contributions to Astra Europa projects can reveal political opinions, political affiliation or political participation.
For members, former members and people who have regular contact with Astra Europa and/or one or more of its national chapters in connection with its purposes, processing is carried out in the course of our legitimate activities as an association or other not-for-profit body with a political aim, subject to appropriate safeguards.
Sensitive personal data is not disclosed outside Astra Europa and/or relevant national chapters without the consent of the person concerned.
For applicants and other people who are not yet members or regular contacts, sensitive personal data is processed based on the explicit consent of the person concerned, or because the person concerned clearly made that information public.
6. Storage and How Long We Keep Data
This section lists how long we keep the main categories of personal data. Where a concrete period has been adopted, it is stated. Where no specific period is stated, we keep personal data only for as long as necessary for the purposes described in this notice, including service delivery, security, compliance, rights requests, audit, dispute handling, backup restoration or legal claims.
Accounts, invitations, temporary login links and audit events
- Account records are kept while your account or relationship with Astra Europa remains active.
- Account records tied to membership or affiliation are kept for the duration of the relationship plus 2 years, then deleted or made anonymous.
- Authentication and access logs are kept for 6 months where governed by Astra Europa's access-logging policy.
- Email verification and password reset links expire after 30 minutes.
- Membership onboarding links expire after 7 days.
- Partly completed sign-in, verification or onboarding pages expire after 1 day if they are not completed.
- User-created app access keys and related access records are kept where necessary to provide access, maintain security and keep audit records.
- Server and account-service logs that contain personal data are kept where necessary for security, reliability, troubleshooting, audit or legal claims.
Chat and bot-assisted tools
- Chat messages, media, room state, device data and bot records are kept where necessary to provide the chat and bot-assisted tools.
- Chat and bot-assisted tool data is also kept where necessary for deletion, deactivation and backup cycles.
- Chat client IP records are kept for 28 days.
- Technical records of deleted or edited chat content are kept for 7 days.
- Optional election or voting data is kept where necessary to administer, verify and, where necessary, audit the relevant vote.
Members-only forum
- Forum posts, uploads and moderation records are kept while the forum, topic or account remains active.
- Forum user sessions expire after 24 hours.
- Forum email logs and rejected email records are kept for 90 days.
- Forum search query logs, unmatched email records and unmatched IP records are kept for 365 days.
- Forum drafts are deleted after 180 days; temporary placeholder topics are deleted after 7 days.
- Unused temporary forum accounts are cleaned up after 365 days; unactivated users are deleted after a 14-day grace period.
- Unused forum uploads are cleaned up after 48 hours and deleted uploads are deleted after 30 days.
- Post-activity forum records are kept where necessary for thread integrity, moderation history, security, legal claims or backup restoration.
Codeberg and Git records
- Codeberg synchronisation logs are kept where necessary for operational and audit purposes.
- Git contribution history is generally kept in project history for project integrity, attribution and audit unless a project-specific history management rule applies.
- Codeberg determines how long it keeps user accounts and platform records under its own privacy terms.
Email, website and infrastructure logs
- Transactional email is kept for delivery only, with undelivered regular and failed-delivery mail queued for up to 5 days by the mailserver.
- Authentication and access logs are kept for 6 months where governed by Astra Europa's access-logging policy.
- Backup copies are kept on a rolling schedule: daily copies for the last 7 days, weekly copies for the last 4 weeks, and monthly copies for the last 6 months.
- Server and service logs that contain personal data are kept where necessary for security, reliability, diagnostics, abuse prevention, compliance, audit or legal claims.
- Other email delivery records, failed-delivery or error logs, service logs and backup-related records are kept where necessary for delivery, security, reliability, diagnostics, abuse prevention, backup restoration and legal claims.
Newsletter
- Your newsletter email address is kept while you remain subscribed.
- When you unsubscribe, newsletter subscription data is deleted within 30 days.
- Records needed to stop future emails, record unsubscribes, track failed delivery or show that we respected the unsubscribe are kept where necessary for those purposes.
Privacy preferences and rights requests
- Privacy preference records, unsubscribe choices, consent withdrawals, objections and rights-request records are kept where necessary to honour choices and respond to requests.
- Additional records are kept where necessary to demonstrate compliance, avoid unwanted communications, or handle audit, dispute or legal-claim needs.
Applications
- Application information is kept while we assess your application.
- After assessment, application information is kept where necessary for follow-up, queries, onboarding, suitable future roles where appropriate, or legal claims.
- If you are accepted, relevant application data becomes part of your member or volunteer record and follows how long we keep that record.
- Membership and affiliation records are kept for the duration of the relationship plus 2 years, then deleted or made anonymous.
Exceptions
- Longer keeping periods apply where necessary for legal obligations, security, audit, dispute resolution, archival integrity, backup restoration, or the establishment, exercise or defence of legal claims, except where a specific legal period applies.
- Backup copies are kept on a rolling schedule: daily copies for the last 7 days, weekly copies for the last 4 weeks, and monthly copies for the last 6 months.
- Other archive and deletion cycles apply where data is no longer needed in a form that identifies a person.
8. Your Rights
Depending on the circumstances, your rights include the right to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, objection to processing, and withdrawal of consent where you have given consent.
Withdrawing consent does not affect processing that happened before the withdrawal. Some rights are limited where we need to comply with law, protect the rights and freedoms of others, preserve security, manage legal claims, keep required records, or maintain the integrity of collaborative records such as Git history.
To exercise your rights, contact us using the details in the contact section. If your request involves a national chapter or external platform, we will coordinate the response or direct you to the appropriate contact.
9. Changes to This Notice
We update this privacy notice when our processing changes, when we add or remove services, when legal requirements change, or when our responsibility, service-provider, chapter or data-storage arrangements are updated. The date at the top of this notice shows when it was last updated.
10. Contact and Complaints
If you have questions about this Privacy Notice or Astra Europa's privacy practices, or if you wish to make a complaint, please contact:
- Responsible organisation: Astra Europa Nederland VEVR
- Registration: Chamber of Commerce (KvK): 99212625
- Email: info@astraeuropa.eu
Use the same email address if you want to exercise your data protection rights, withdraw consent, object to processing, or ask a question about the legal basis for processing your personal data.
If your request relates to a national chapter, we will handle the request under the relevant shared-responsibility arrangement or forward it to the appropriate chapter contact while keeping you informed.
You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with another competent supervisory authority in the European Economic Area.