Legal

Privacy Notice

This notice sets out what personal data MESA collects through this website, on what basis, who has access to it, how long it is kept, and what rights you can exercise. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated:

1. Data controller

MESA (Milan Engineering Student Association) is a student association recognised by Politecnico di Milano and the Local Committee of EESTEC (Electrical Engineering STudents' European assoCiation) in Milan. MESA is the data controller for all processing described in this notice.

The association is represented by its Chairperson in office, elected for one academic year. MESA has no premises of its own, so the point of contact is by email. The mailboxes below are institutional and are handed over between successive boards, so they remain reachable independently of who currently holds office.

  • vc.ia@eestecmi.itrequests concerning personal data: access, rectification, erasure, restriction, objection, portability.
  • chairperson@eestecmi.itthe Chairperson in office, for formal correspondence.
EESTEC International is a separate organisation and acts as an independent controller under its own privacy notice. This applies, for instance, when you take part in an international event.

2. Data collected and purposes

What we hold depends on how you use the site. Visitors who only browse the public pages provide no personal data beyond the technical server logs described below.

Data subjectData collectedPurpose
VisitorLanguage and theme preference, stored in your browser. Our hosting provider records standard technical server logs, including the IP address.Delivering the site in the correct language and keeping it available and secure.
Membership applicantFirst and last name, email address, telephone number, Codice Persona, degree programme, level of study, exchange status, Telegram handle (optional), teams and position of interest, how you heard about the association, and the free-text answers you provide.Assessing the application and contacting you about it. The data is accessible to the board.
MemberThe above, together with: membership status and history, mandates by academic year (board, supervisory board, team leader), teams and projects, membership fee and t-shirt payment records, event attendance, any additional email addresses, and, where you choose to provide them, a profile photograph and a LinkedIn link.Administering the membership relationship: registrations, teams, meetings and attendance records.
General Meeting attendeeFirst and last name, email address, and the fact of attendance. Non-members are recorded separately as guest attendees.Maintaining an accurate attendance record of the association's meetings.
Board memberA log of administrative actions performed in the management panel, recording what was changed and when.Internal accountability and traceability. Accessible only to board members.

The site uses no tracking pixels, no advertising cookies and no analytics that profile users. The site sends no marketing email of any kind. Personal data is not sold or otherwise transferred for commercial purposes, and the site carries no advertising.

A limited set of information is published on the public pages: the names, positions, profile photographs, LinkedIn links and, where explicitly opted in, contact email addresses of current and former board members, shown on the About page. Telephone numbers, Codice Persona, personal email addresses and application answers are never published.

4. Retention periods

  • Applications not acceptederased within twelve months of the decision.
  • Member dataretained for the duration of the membership.
  • Alumni dataname, years of activity and roles held are retained indefinitely as the association's historical record, unless erasure is requested. This is the only category retained without a fixed term, and it is stated here explicitly for that reason.
  • Attendance and fee recordsretained for the administrative and accounting requirements of the association, then erased.
  • Server and security logsretained for the period applied by the hosting provider.

5. Recipients and processors

Within MESA, access is limited to the board members whose role requires it. Team leaders may access the roster of their own team. All other access is restricted at database level through row-level security, and not merely hidden in the interface.

The following processors act on documented instructions from the controller under Article 28 GDPR:

ProcessorService providedLocation
SupabaseDatabase, authentication, delivery of account email (login invitations and password resets), and storage of profile photographs.Frankfurt, Germany
Microsoft AzureHosting of this website.European Union

No other recipients receive personal data collected through this site.

6. Transfers outside the EEA

Personal data is processed within the European Union. The database, authentication accounts and profile photographs are hosted in Frankfurt, Germany, and the website runs on European infrastructure.

There is currently no transfer outside the European Economic Area. The site sends no email of its own; the only messages it causes to be sent are the account emails delivered by Supabase, our database and authentication provider, from the same European project. If an external email provider is adopted in future, this section must be revised before it is switched on.

7. Cookies

This site uses only cookies that are strictly necessary for its operation. There are no profiling cookies, no advertising cookies and no third-party analytics, and for this reason no consent banner is required under the applicable guidance.

CookiePurposeDuration
mesa_langStores the selected interface language.1 year
nuxt-color-modeStores the selected light or dark theme.1 year
sb-…-auth-tokenMaintains the authenticated session in the members' area. Set only after signing in.Until sign-out

These cookies may be deleted at any time through your browser settings. Deleting the session cookie signs you out; deleting the other two resets the language and theme to their defaults.

8. Rights of the data subject

Under Articles 15 to 22 GDPR you have the right to:

  • Accessobtain confirmation of the processing and a copy of the data held.
  • Rectificationhave inaccurate or outdated data corrected.
  • Erasureobtain the deletion of your data where no overriding ground for retention applies.
  • Restriction and objectionlimit or object to a specific processing operation.
  • Portabilityreceive your data in a structured, machine-readable format.
  • Withdrawal of consentwithdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.

Requests should be sent to vc.ia@eestecmi.it and are answered within one month. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).

9. Security measures

The site is served exclusively over HTTPS. Access to member data is enforced at database level through row-level security, in addition to the checks performed by the application, so that a defect in one layer does not expose data through the other. Authentication is handled by the processor and passwords are never accessible to the controller. Administrative actions on member records are logged.

IP addresses used for abuse prevention are stored only as a salted hash and cannot be attributed to an individual visitor.

10. Minors

This site is directed at university students. Personal data is not knowingly collected from persons under the age of fourteen. If you believe that a minor has provided personal data, please contact us and it will be erased.

11. Changes to this notice

Any change to the processing described here will be reflected on this page, together with the date shown above. Where a change is substantial and affects current members, it will also be communicated by email.

For any question about this notice, or to exercise your rights, write to vc.ia@eestecmi.it