EFARPrivacy notice

How EFAR handles your personal data.

EFAR collects, stores and erases personal data under the GDPR. This notice sets out, in plain language, what we collect, why, where it lives, and how you exercise your rights.

1. What we collect

When you submit an application via /join, you provide your name, email address, institutional affiliation, country of institution, and a free-text statement of your reason for joining. We also capture the IP address from which the application was sent and the user agent string; both are retained for 60 days after submission (the same window as the application itself) for abuse detection and the GDPR audit trail described in §3.

You give us two separate consent decisions: one for storing your data, one for receiving EFAR communications. They are recorded independently in an immutable audit log so we can prove, on request, what you consented to and when. Providing the data-storage consent is necessary to apply for membership; providing the marketing consent is optional. The application will not be processed without the data-storage consent.

2. Lawful basis

We process your personal data on the basis of your explicit consent (GDPR Art. 6 (1)(a)). The consent to data storage is a precondition of membership; the consent to receive communications is optional and you may decline it without affecting your application.

3. How long we keep your data

  • Approved membersUntil you request deletion (see §6).
  • Pending applications60 days from submission, then automatically and permanently deleted.
  • Rejected applications30 days from rejection (for appeal), then automatically and permanently deleted.
  • Consent audit logRetained as a record of the consent decisions we relied on (your email, the consent type, the value, and the timestamp). When your member record is hard-deleted, the audit row's link to your account is severed, but the row itself is kept so we can demonstrate compliance to a supervisory authority. To request erasure of these audit rows specifically, email privacy@agingfederation.eu.

4. Where your data lives

All EFAR systems are hosted on infrastructure located within the European Economic Area. We do not transfer your personal data outside the EU/EEA. Transactional email (sign-in links, application updates) is delivered through a processor with an EU-region option enabled.

5. Who can see your data

Application contents are reviewed by the EFAR executive board, currently two named members. We do not share your data with third parties for marketing purposes, and we do not sell or rent it under any circumstance.

We engage the following categories of data processors, each bound by a written data-processing agreement and each operating from EU/EEA infrastructure:

  • EU-region hosting provider: Postgres database, Redis cache, and the API server compute. The current host is Morten Scheibye-Knudsen's institutional infrastructure in Copenhagen, Denmark.
  • one.com (email delivery): used solely to deliver application-status notifications and sign-in links to the address you provided. EU provider (Denmark).

6. No automated decision-making

Membership applications are reviewed by human members of the EFAR board. We do not use automated decision-making, profiling, or any algorithm that would produce legal or similarly significant effects on you.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you: visit /me while signed in, or email us for a copy;
  • rectify incorrect data: edit your name, institution and country directly from /me;
  • eraseyour account: click "Delete my account" on /me. Your record is deactivated immediately and permanently and irrevocably erased after a 30-day grace period. You may cancel the deletion during that window by signing in again or by writing to privacy@agingfederation.eu;
  • withdraw your consent for marketing communications at any time, without affecting the lawfulness of processing carried out before that point. Withdrawing the data-storage consent is equivalent to closing your account;
  • restrict or object to particular forms of processing: email us;
  • data portability: request an export of the fields associated with your account in a machine-readable format. Email us; we will respond within 30 days.

You also have the right to lodge a complaint with your national data protection authority. In Denmark this is Datatilsynet.

8. Cookies and analytics

/join sets no cookies. The signed-in member area (/me, /admin) sets a single first-party session cookie used to keep you logged in; it is HTTP-only, Secure, and SameSite=Lax. We run no third-party analytics and embed no third-party fonts or trackers on the public pages.

9. Changes to this notice

Material changes will be communicated to current members by email. The revision date in the margin reflects the most recent update.