Privacy policy
Last updated: 1 September 2026
This policy explains what personal data Delft AI Hub collects when you use this website, why we collect it, how long we keep it, and the rights you have over it. It is written to meet our obligations under the EU General Data Protection Regulation (GDPR) and the Dutch Uitvoeringswet AVG.
Who is responsible
Delft AI Hub, a student-led association based in Delft, the Netherlands, is the data controller for the processing described here. For any privacy question, or to exercise a right, contact us at info@delftaihub.nl.
What we collect and why
Account and profile data
When you sign in, our authentication provider gives us your name, email address, and a unique account identifier. In your dashboard you may additionally provide a display name, profile picture, role, field of study, year of study, a LinkedIn URL, and a CV. Everything beyond name and email is optional.
Legal basis: performance of our agreement with you as a member (Art. 6(1)(b) GDPR). Your profile is private by default; it becomes visible to other members only if you switch it to public, which we treat as your consent (Art. 6(1)(a) GDPR) and which you can withdraw at any time.
Applications and project requests
If you apply for a position or submit a project idea, we process what you send us (your motivation, the project description, and the skills you list) together with your account details and the status of the application.
Legal basis: steps taken at your request prior to entering an agreement (Art. 6(1)(b) GDPR).
Mailing list
If you join our mailing list, we will email you about upcoming events, new projects, and opportunities to get involved, roughly once a week. We only do this if you have opted in; it is off unless you switch it on, and it is entirely separate from the messages we send about an application or project request you have made.
Legal basis: your consent (Art. 6(1)(a) GDPR). We record the moment you gave it so that we can show the mail was wanted. You can withdraw at any time from your dashboard settings, or by using the unsubscribe instructions in any message we send, and withdrawing is as easy as opting in was. It does not affect anything else about your account.
Technical data
Our hosting provider records standard server information such as IP address, browser type, operating system, request time, and the page requested. We also use a privacy-focused, cookie-free analytics tool that reports aggregate visit counts and page performance; it does not store your IP address, set identifiers on your device, or track you across sites.
Legal basis: our legitimate interest in keeping the site secure, available, and usable (Art. 6(1)(f) GDPR).
Cookies and local storage
We do not use advertising or tracking cookies, and we do not sell or share your data with advertisers.
- Strictly necessary cookies keep you signed in after you log in. Without them the site cannot recognise your session.
- Functional local storage remembers small preferences inside your own browser: that you have dismissed the welcome banner, that the intro animation has already played, and a short-lived hint of your sign-in state. This never leaves your device.
Both categories are exempt from the prior-consent requirement in Article 11.7a of the Dutch Telecommunications Act, which is why you are not asked to accept cookies. You can clear them at any time through your browser settings.
Who else processes your data
We rely on a small number of service providers, who act as processors under written agreements and may use your data only on our instructions:
- Auth0 (Okta): sign-in and account security.
- Supabase: database, and storage for profile pictures and CVs.
- Vercel: website hosting, analytics, and performance monitoring.
- Resend: sending transactional email, such as confirmations and status updates.
Beyond these, we disclose personal data only where the law requires it, or where it is necessary to establish or defend a legal claim.
Transfers outside the EEA
Some of these providers are established in the United States. Where data is transferred outside the European Economic Area, it is covered by the European Commission's adequacy decision for the EU-US Data Privacy Framework, or by Standard Contractual Clauses together with supplementary safeguards. You may request a copy of the relevant safeguards from us.
How long we keep it
- Account and profile data: for as long as your account exists. If you ask us to delete it, we remove it within 30 days.
- Applications and project requests: up to 12 months after a decision, so that we can answer questions about it and consider you for similar openings.
- Mailing list consent: for as long as you stay on the mailing list. If you withdraw, we stop mailing you and clear the record of your consent.
- Server logs: retained by our hosting provider for a short, rolling period for security and diagnostics.
- Aggregate analytics: retained in a form that cannot be linked back to you.
Your rights
Under the GDPR you have the right to:
- ask what data we hold about you, and get a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we use it;
- receive the data you gave us in a portable, machine-readable form;
- withdraw consent at any time, without affecting processing carried out before you withdrew it.
Email delftaihub@gmail.com to exercise any of these. We will respond within one month. You can also edit or delete most of your profile yourself from your dashboard.
If you believe we are handling your data improperly, you have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens .
Automated decision-making
We do not use automated decision-making or profiling that produces legal effects for you. Applications and project submissions are reviewed by people.
Children
This site is aimed at university students and is not directed at children under 16. We do not knowingly collect their data; if you believe we have, contact us and we will delete it.
Security
Data is transmitted over encrypted connections and stored with providers that offer encryption at rest and access controls. Administrative access to member data is limited to committee members who need it. No system is completely secure, but we take reasonable technical and organisational measures to protect your data.
Changes to this policy
We may update this policy as the site changes. The date at the top shows when it was last revised, and material changes will be announced on the site.