Privacy Policy
Privacy Policy AOAAS – Academic Organization and Association System Last updated: [03/08/026]
1. Introduction
AOAAS (“we”, “us”, “the Association”) is registered in Sweden and is committed to protecting the privacy of its members and website visitors. This Privacy Policy explains what personal data we collect, how we use and store it, and what rights you have under applicable law, including the EU General Data Protection Regulation (GDPR).
By using our website or applying for membership, you acknowledge this Policy.
2. Data Controller
The data controller is:
AOAAS Registered in Sweden Website: https://aooas.org Email: [official contact email]
3. Personal Data We Collect
a) Membership and account data When you register or when an administrator creates an account, we may collect:
- Full name and display name
- Email address
- Password (stored in encrypted form)
- Membership type (Full Member / Honorary Member)
- Organisation or affiliation
- Application statement / personal background
- Optional supporting document (e.g. PDF or Word file)
- Membership status (pending, approved, rejected)
b) Profile data Members may provide or update:
- Biography (separately for English, Persian/Dari and Swedish)
- Research area
- Country
- Website
- Phone number (optional)
- Social or academic identifiers (e.g. ORCID)
- Profile photo
- Privacy preferences (hide email or hide public profile from the members directory)
c) Content and activity
- Research items, publications, projects and events linked to the account
- Files uploaded by the member (public or private)
d) Technical data
- IP address, browser type, device information and pages visited (via server logs and, where used, cookies)
- Language preference (via cookie or the lang parameter)
4. Purposes of Processing
We process personal data in order to:
- Review and decide on membership applications
- Administer membership and user roles
- Display public member profiles (only for approved members who have not hidden their profile)
- Provide website services (dashboard, file uploads, search, multilingual interface)
- Communicate about membership, events and Association activities
- Maintain security and prevent misuse
- Improve technical performance and user experience
We do not sell personal data or use it for commercial advertising.
5. Legal Bases (GDPR)
Processing is based on one or more of the following:
- Performance of a contract – membership administration and delivery of Association services
- Consent – e.g. making a profile or uploaded file public
- Legitimate interests – secure operation of the website, prevention of abuse, and orderly management of academic activities (balanced against your rights)
- Legal obligation – where retention or disclosure is required by law
6. Public Display and Sharing
- Public profiles: Only members with status “approved” appear in the members directory and on individual public profile pages, unless the member has chosen to hide their profile.
- Email: Shown on the public profile only if the member has not enabled “Hide email on public profile”.
- Files: Files marked public are visible on the profile; private files are accessible only to the member and authorised administrators.
- Service providers: Data may be processed by hosting, email or other technical providers strictly necessary for operation; such providers are bound by confidentiality and data-protection obligations.
- Legal requirements: We may disclose limited information if required by competent authorities under applicable law.
7. Data Retention
- Account and membership data are retained for as long as the account is active and thereafter for a reasonable period for administrative and legal purposes.
- If membership is rejected or an account is deleted, personal data will be deleted or anonymised within a reasonable time, unless longer retention is required by law or for the establishment, exercise or defence of legal claims.
- Technical backups may be retained for a limited period.
8. Security
We apply appropriate technical and organisational measures (including access controls, encrypted password storage and upload restrictions) to protect personal data. No online system can be guaranteed completely secure.
9. Your Rights
Under the GDPR and Swedish law you have the right to:
- Access your personal data
- Rectify inaccurate or incomplete data
- Request erasure (“right to be forgotten”), subject to legal and administrative limits
- Restrict or object to certain processing
- Data portability where applicable
- Withdraw consent where processing is based on consent
- Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY) or another supervisory authority in your country of residence
To exercise these rights, contact us using the details in section 2.
10. Cookies and Language Preference
We may use essential cookies to maintain login sessions and language preference (English, Persian/Dari, Swedish). These are necessary for core functionality. If we introduce optional analytics cookies, this Policy will be updated accordingly.
11. Children
Our services are not directed at persons under the applicable age of majority. We do not knowingly collect personal data from children.
12. International Transfers
If personal data are transferred outside the EU/EEA, we will ensure appropriate safeguards (such as standard contractual clauses or an adequacy decision) in accordance with the GDPR.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The revised version will be published on this page with an updated date. Continued use of the website after publication constitutes notice of the changes.
14. Contact
For privacy-related questions or requests:
AOAAS Website: https://aooas.org Email: [infoataoaas.org]
You may also contact the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY): https://www.imy.se