Compliance & Trust

Our commitment to protecting your privacy and data

Your Privacy is Our Priority

As a not-for-profit alumni association, we are committed to maintaining the highest standards of data protection. We comply with both Australian Privacy Principles (APPs) under the Privacy Act 1988 and the EU General Data Protection Regulation (GDPR) for our international members.

GDPR Compliant

European Union

  • Lawful basis for all data processing
  • Data subject rights (access, rectification, erasure)
  • Privacy by design and default
  • Data breach notification procedures

APPs Compliant

Privacy Act 1988 (Cth)

  • Open and transparent management of personal information
  • Collection of solicited personal information
  • Use and disclosure limitations
  • Access and correction rights

Security Measures

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Passwords are hashed using industry-standard algorithms.

Two-Factor Authentication

Optional 2FA using TOTP-based authenticator apps adds an extra layer of security to your account.

Access Controls

Role-based access controls ensure only authorized personnel can access sensitive data.

Your Data Rights

Right to Access

Request a copy of all personal data we hold about you.

Right to Rectification

Correct any inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Right to Portability

Export your data in a machine-readable format.

Exercise Your Rights: Visit your profile settings to access data export and account deletion options, or contact us for any data-related requests.

How We Process Your Data

Data We Collect

  • • Account information (name, email)
  • • Profile details (university info, profession)
  • • Event registrations and attendance
  • • Communication preferences
  • • Technical data (IP, device info for security)

How We Use It

  • • Member services and communications
  • • Event management and registration
  • • Community features (member directory)
  • • Security and fraud prevention
  • • Legal compliance

Third-Party Services

We use the following services to operate our platform:

Supabase

Database & Authentication

Cloudflare

Security & CDN

Resend

Email Delivery

Data Retention

Data TypeRetention PeriodReason
Account DataUntil account deletionService provision
Event Registrations7 yearsLegal/financial records
Contact Submissions2 yearsSupport follow-up
Security Logs90 daysSecurity monitoring
Consent Records7 yearsCompliance audit trail

Privacy Inquiries

For any privacy-related questions, concerns, or to exercise your data rights, please contact us: