Loading…
We use cookies to improve your experience and analyze website traffic. By clicking "Accept", you agree to our use of cookies as described in our Privacy Policy.
Last updated: 19 September 2026
The Albanian Student Association at the University of St.Gallen (“ASA”, “we”) is the controller responsible for the personal data described here.
Albanian Student Association at the University of St.Gallen
Dufourstrasse 50
9000 St. Gallen, Switzerland
E-mail: albanianstudents@shsg.ch
We are based in Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies to us. Because we have members and visitors in the EU and use processors established in the EU, the GDPR applies in addition where its conditions are met. Where the two differ, we apply the stricter standard.
Our hosting provider records technical request data such as your IP address, the page requested, the time, the referring page, and your browser and operating system. This is what makes it possible to serve the site and to investigate faults and abuse. The legal basis is our legitimate interest in operating a secure, working website (Art. 6(1)(f) GDPR; Art. 31(1) FADP).
We do not use advertising cookies, and we do not profile visitors. Nothing that is not strictly necessary runs until you accept cookies.
Our contact form, membership application, board application, mentor registration and event registration collect what each form asks for: typically your name, e-mail address, study programme and semester, and whatever you choose to write in the free-text fields. We use this to answer you and to assess the application. The legal basis is your consent and, once you apply, the steps taken at your request before entering into a membership (Art. 6(1)(a) and (b) GDPR; Art. 31(2)(a) FADP).
A member account additionally holds your membership status and paid- through date, and anything you choose to add to your profile: a photo, a LinkedIn address, and a CV if you upload one. Depending on what you use, we also store your event RSVPs and attendance, mentorship and buddy-system applications, practice-quiz attempts and scores, and any job postings or tips you submit to the career hub.
Board members can attach private notes to a member record for administrative purposes. These are visible only to board and admin accounts. You can ask to see any notes held about you.
Payments are handled by Stripe. We never see or store your card details. What we retain is a payment record: the amount, the currency, the period it covers, its status, and the Stripe identifiers needed to find the transaction and issue a receipt. The legal basis is performance of the membership agreement and our legal obligation to keep accounting records.
When you place a pre-order in our shop we collect your name, your e-mail address, the item, size and quantity you choose and, only if you give them, a phone number and a note. We give each order a reference and store its status (awaiting payment, paid, handed over or cancelled) with the dates it changed. We use this to take your order, match your payment to it, tell you when it is confirmed, arrange pickup, and place one bulk order with our supplier. We may send you one reminder if an order is still unpaid after a day, and a message when your order is confirmed or ready for pickup. The legal basis is performance of your order and, for payment records, our legal obligation to keep accounting records (Art. 6(1)(b) and (c) GDPR; Art. 31(2)(a) FADP).
You pay in the TWINT app to our TWINT Business account. We never see your TWINT login or your bank details. What we see is what TWINT shows us about the payment: the amount, the name and reference you enter, and a transaction identifier.
The page that shows the status of your order is reachable only through a link containing a long random code that we e-mail to you. Anyone who has that link can view your order, so please do not share it. The page asks search engines not to index it.
We store your e-mail address, and your name if you gave one, until you unsubscribe. Every newsletter contains a one-click unsubscribe link. The legal basis is your consent, which you may withdraw at any time.
We use the following processors. Each one is listed because it genuinely handles data for this site.
Some of these are US companies. Where data reaches the United States we rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework and, where applicable, Standard Contractual Clauses, together with the corresponding Swiss framework.
If you sign in, Supabase sets a session cookie so that you stay signed in. We also store your cookie choice, so we can stop asking, and your light/dark theme preference. These are necessary for the site to work and are not used to track you.
PostHog and Vercel Analytics are loaded only after you accept cookies. If you decline, they are never initialised and no analytics request is made. Withdrawing consent stops collection and clears the identifier PostHog stored.
PostHog and Sentry can record a reconstruction of a browsing session to help us diagnose faults. Text you type into inputs and the contents of uploaded documents are masked before the recording leaves your browser: what is captured is the structure of the page and the sequence of interactions, not your keystrokes.
You have not yet made a choice. The cookie banner is currently shown.
You can ask us for a copy of the data we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on your consent, you can withdraw it at any time without affecting what we did before you withdrew it.
Write to albanianstudents@shsg.ch and we will respond. If you are not satisfied, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or, if you are in the EU, to your local supervisory authority.
This site is served over HTTPS. Access to member data is restricted by role, uploaded files are held in private storage and served through short-lived links rather than public URLs, and administrative actions are written to an audit log. No system is perfectly secure, but we take these measures seriously and fix problems when we find them.
We update this policy when what we do changes. The date at the top always reflects the current version.