Legal
This notice sets out what personal data MESA collects through this website, on what basis, who has access to it, how long it is kept, and what rights you can exercise. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
Last updated:
MESA (Milan Engineering Student Association) is a student association recognised by Politecnico di Milano and the Local Committee of EESTEC (Electrical Engineering STudents' European assoCiation) in Milan. MESA is the data controller for all processing described in this notice.
The association is represented by its Chairperson in office, elected for one academic year. MESA has no premises of its own, so the point of contact is by email. The mailboxes below are institutional and are handed over between successive boards, so they remain reachable independently of who currently holds office.
What we hold depends on how you use the site. Visitors who only browse the public pages provide no personal data beyond the technical server logs described below.
| Data subject | Data collected | Purpose |
|---|---|---|
| Visitor | Language and theme preference, stored in your browser. Our hosting provider records standard technical server logs, including the IP address. | Delivering the site in the correct language and keeping it available and secure. |
| Membership applicant | First and last name, email address, telephone number, Codice Persona, degree programme, level of study, exchange status, Telegram handle (optional), teams and position of interest, how you heard about the association, and the free-text answers you provide. | Assessing the application and contacting you about it. The data is accessible to the board. |
| Member | The above, together with: membership status and history, mandates by academic year (board, supervisory board, team leader), teams and projects, membership fee and t-shirt payment records, event attendance, any additional email addresses, and, where you choose to provide them, a profile photograph and a LinkedIn link. | Administering the membership relationship: registrations, teams, meetings and attendance records. |
| General Meeting attendee | First and last name, email address, and the fact of attendance. Non-members are recorded separately as guest attendees. | Maintaining an accurate attendance record of the association's meetings. |
| Board member | A log of administrative actions performed in the management panel, recording what was changed and when. | Internal accountability and traceability. Accessible only to board members. |
The site uses no tracking pixels, no advertising cookies and no analytics that profile users. The site sends no marketing email of any kind. Personal data is not sold or otherwise transferred for commercial purposes, and the site carries no advertising.
A limited set of information is published on the public pages: the names, positions, profile photographs, LinkedIn links and, where explicitly opted in, contact email addresses of current and former board members, shown on the About page. Telephone numbers, Codice Persona, personal email addresses and application answers are never published.
Providing your data is voluntary. Where fields are marked as required in the application form, failure to provide them prevents the application from being assessed.
Within MESA, access is limited to the board members whose role requires it. Team leaders may access the roster of their own team. All other access is restricted at database level through row-level security, and not merely hidden in the interface.
The following processors act on documented instructions from the controller under Article 28 GDPR:
| Processor | Service provided | Location |
|---|---|---|
| Supabase | Database, authentication, delivery of account email (login invitations and password resets), and storage of profile photographs. | Frankfurt, Germany |
| Microsoft Azure | Hosting of this website. | European Union |
No other recipients receive personal data collected through this site.
Personal data is processed within the European Union. The database, authentication accounts and profile photographs are hosted in Frankfurt, Germany, and the website runs on European infrastructure.
There is currently no transfer outside the European Economic Area. The site sends no email of its own; the only messages it causes to be sent are the account emails delivered by Supabase, our database and authentication provider, from the same European project. If an external email provider is adopted in future, this section must be revised before it is switched on.
Under Articles 15 to 22 GDPR you have the right to:
Requests should be sent to vc.ia@eestecmi.it and are answered within one month. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
The site is served exclusively over HTTPS. Access to member data is enforced at database level through row-level security, in addition to the checks performed by the application, so that a defect in one layer does not expose data through the other. Authentication is handled by the processor and passwords are never accessible to the controller. Administrative actions on member records are logged.
IP addresses used for abuse prevention are stored only as a salted hash and cannot be attributed to an individual visitor.
This site is directed at university students. Personal data is not knowingly collected from persons under the age of fourteen. If you believe that a minor has provided personal data, please contact us and it will be erased.
Any change to the processing described here will be reflected on this page, together with the date shown above. Where a change is substantial and affects current members, it will also be communicated by email.