Privacy Policy
How SAIESA collects, uses, and protects member data.
Last updated: September 1, 2026
1. Who this covers
This policy applies to saiesa.org and the member platform it hosts — public pages, registration and login, member profiles, the alumni directory, the community feed, chat, job board, event registrations, and donation records. It applies to visitors, registered members, and anyone whose information a member adds to the platform (e.g. tagging a classmate in a directory field).
2. What we collect
- Account information: name, email address, a hashed password (we never store your password in plain text), and your membership approval status.
- Profile information you provide: graduation details, contact information, bio, avatar, and any committee designation/tenure history.
- Content you create: feed posts, comments, reactions, chat messages, job postings, event registrations, and idea submissions.
- Uploaded media: images or files you attach to posts or your profile, stored in our object storage (Cloudflare R2), subject to a per-member storage limit.
- Technical information: session cookies needed to keep you logged in, and basic request logs (e.g. for security and abuse prevention).
- Donation information (if you donate): name, email, amount, and currency. Payment processing details are handled by a third-party payment provider once one is integrated — SAIESA does not store your card or bank credentials.
3. How we use it
- To operate your account: registration, login, membership approval, and password resets.
- To run the features you use: directory listings, the feed, chat, job board, events, and idea submissions.
- To enforce membership rules and community guidelines, including moderation.
- To communicate with you about your membership, events, or in response to a message you send us.
- To keep the platform secure — detecting abuse, enforcing rate limits, and maintaining an audit log of administrative actions.
We do not sell your personal information, and we do not use it for third-party advertising.
4. Who can see your information
- Public visitors only ever see what you've explicitly chosen to make public — e.g. opting your directory listing into the public teaser view. Everything else defaults to members-only or private.
- Other approved members can see your full directory entry (subject to your own visibility settings), your public feed posts, and anything you post in a chat room they share with you.
- Chat is invite-only. Only members who have actually been added to a chat room can read or post in it — there is no way to browse or preview a room you haven't been invited to.
- Admins and Support Admins can access what's needed to moderate content, approve members, and support the community, per a defined set of role permissions. Financial/donation records are restricted to Admins only. All administrative access to member data is logged.
- Service providers that host our infrastructure (Cloudflare for hosting, storage, and content delivery; Neon for our database) process data on our behalf under their own security commitments — they don't use your data for their own purposes.
5. Cookies and sessions
We use a single essential session cookie to keep you signed in. It's required for the platform to function and isn't used for advertising or cross-site tracking. You can end your session at any time by logging out, which invalidates it immediately.
6. Data retention
We keep your account and content for as long as your membership is active, plus a reasonable period afterward in case you return, unless you ask us to delete it sooner (see your rights below). Audit logs of administrative actions are retained longer, for accountability and security purposes, and are never editable — not even by an Admin.
7. Your rights
You can, at any time:
- Access and update your own profile information from your member settings.
- Control your directory visibility and what's shown publicly.
- Ask us to export or delete your personal data by contacting us (see below).
- Ask us to correct inaccurate information about you.
We'll respond to a data request in a reasonable timeframe. Some information (e.g. audit log entries about actions you took, or donation records required for our own accounting) may be retained even after account deletion where we have a legitimate reason to keep it.
8. Children's privacy
This platform is intended for alumni and current students of St. Andrews Institute engaging in an adult/alumni capacity. It is not directed at young children, and we don't knowingly collect personal information from children.
9. Security
Passwords are hashed, never stored in plain text. Sessions can be revoked server-side (e.g. if you report a compromised account). Access to sensitive data (financial records, audit logs) is restricted by role. No system is perfectly secure, and we'll notify affected members if we become aware of a data breach affecting their information.
10. Changes to this policy
If this policy changes materially, we'll update the "Last updated" date above and, where appropriate, let members know directly.
11. Contact us
Questions about this policy or your data? Email saiesa2025@gmail.com, or write to St Andrews Institute Ex Students Association, C/O St. Andrew’s Institute, Near St. Andrew’s Church, Vasco da Gama, Goa 403802.