Privacy Policy (English — reference translation)
Effective date 25 August 2026 / Last revised 25 August 2026 / Version 1.0
Preamble
The Japanese Student Club (registered with the Dutch Chamber of Commerce (KVK) under no. 42035208; the "Club") processes the personal data of members and other users (the "Users") of its member web platform (the "Service") in accordance with Regulation (EU) 2016/679 (the "GDPR"), the Dutch GDPR Implementation Act (UAVG), and other applicable law (together, "Applicable Law"). This Policy sets out the purposes, legal bases, scope and duration of the processing the Club carries out as controller, and the rights of Users.
Article 1 (Definitions)
In this Policy: (1) "personal data" means any information relating to an identified or identifiable natural person; (2) "processing" means any operation performed on personal data; (3) "special-category data" means personal data of the types listed in GDPR Art. 9(1) (including health data); (4) "processor" means a party that processes personal data on the Club's behalf and on its instructions; (5) "member" means a User who has completed registration, including free members and paying (subscription) members.
Article 2 (Controller and contact)
- The controller is the Club. Name: Japanese Student Club; KVK no.: 42035208; data-protection contact: contact@jsc-amsterdam.nl.
- The Club has not appointed a Data Protection Officer, as it does not meet the mandatory criteria under GDPR Art. 37(1) (public authority, large-scale regular and systematic monitoring, or large-scale processing of special-category data); data-protection matters are handled by the contact above.
Article 3 (Scope and eligible persons)
- This Policy applies to personal data the Club collects and processes in connection with use of the Service.
- The Service is intended for students in and around Amsterdam and is limited to persons aged 18 or over. The Club does not knowingly collect personal data from persons under 18.
Article 4 (Categories of personal data)
The Club may collect, to the extent necessary: (1) identity/membership data (name in Japanese and English, email, university, faculty, student number, expected graduation year, member number, referral code and relationships, member type); (2) contract/billing data (plan, start date, expiry date — expiring on 31 August each year under the academic cycle — past subscriptions, payment status, amount, transaction identifiers); (3) event data (registrations, attendance history, encrypted ticket token, check-in records, and voluntarily declared allergy/dietary information); (4) photo data (any opt-out request not to appear in event photos, purchase history, download-link issuance); (5) authentication/technical data (temporary hashed login codes, automatically generated technical logs); (6) information provided in enquiries.
Article 5 (Means of collection)
The Club collects the above through (1) registration, booking and input by Users, (2) automatic generation through use of the Service, and (3) User enquiries.
Article 6 (Purposes)
The Club uses personal data as necessary to: (1) register members and verify identity; (2) take event bookings and issue/manage tickets; (3) provide subscriptions and handle billing and accounting; (4) publish, preview and sell photos; (5) provide member benefits at partner shops; (6) send club announcements (event invites, club news) and, with consent, promotional emails (partner deals and offers); (7) prevent misuse and maintain the security of the Service; (8) comply with Applicable Law and handle disputes; (9) verify the accuracy of registration details each July.
Article 7 (Legal bases)
Corresponding to the purposes above, the Club relies on (GDPR Art. 6(1)): (1) performance of a contract (b) for the membership service, events, payments and photo sales; (2) consent (a) for promotional emails (partner deals and offers) and the allergy/dietary data under Article 8 (consent may be withdrawn at any time, including via the unsubscribe link in each email, without affecting prior lawful processing); (3) legitimate interests (f) for sending club announcements (event invites and club news — which members receive but can turn off anytime via the unsubscribe link or My Page), fraud prevention, security, improvement, and photographing events for record and promotion — attendees may appear in photos and can be excluded from future publication on request to privacy@jsc-amsterdam.nl — following a balancing test; (4) legal obligation (c) for accounting/tax retention and reporting.
Article 8 (Special-category data)
- Allergy/dietary information may constitute health data under GDPR Art. 9(1). The Club processes it solely to serve food safely at events and only on the User's explicit consent (Art. 9(2)(a)).
- Providing such information is optional; no disadvantage results from declining. The Club deletes it promptly after the purpose is fulfilled.
Article 9 (Processors and third parties)
- The Club engages the following processors, under GDPR Art. 28-compliant data-processing agreements, sharing only the minimum necessary: Google (Firebase / Google Cloud) for database (Firestore, stored in the European region "eur3"), authentication, storage and application runtime; Stripe for payment processing (the Club does not hold card numbers); Resend for sending codes, confirmations and notices; Google (Drive) for delivering purchased original photos via expiring share links; map services (e.g. MapLibre) for partner map display (no personal data sent).
- No member personal data is shared externally through partner-benefit/discount integrations.
- Except where required by law or with the User's consent, the Club shares personal data with no third parties other than the above, and does not sell personal data.
- A current list of processors (sub-processor list) is available on request via the contact above.
Article 10 (International transfers)
Some processors may process personal data outside the EEA. Where they do, the Club relies on appropriate safeguards under GDPR Chapter V (adequacy decisions, Standard Contractual Clauses, etc.). Copies of the safeguards are available via the contact above.
Article 11 (Retention)
The Club retains personal data only for as long as necessary for the purpose and as required by Applicable Law: (1) member data — retained while the membership relationship continues; if the User withdraws, or after 36 months of inactivity (no login), the Club anonymises name, email, student number and other identifiers and thereafter keeps only non-personal statistical data (accounting/tax records per (2)); (2) payment/accounting records — the statutory Dutch period (generally 7 years); (3) login codes — 10 minutes from issuance; (4) allergy/dietary data — promptly after the relevant event; (5) photos — excluded from future publication and sale once the person opts out.
Article 12 (Security measures)
The Club implements reasonable technical and organisational measures, including: (1) restricting database writes to server-side processing with admin credentials and blocking direct client writes; (2) encryption of tickets; (3) least-privilege access and authentication management. No internet transmission or storage can, however, be guaranteed absolutely secure.
Article 13 (Cookies)
The Club uses cookies/local storage as necessary to provide the Service (keeping Users logged in, remembering language). At present, the Club does not use any analytics or optional cookies. Should it introduce them, it will separately disclose their category and purpose and obtain the required consent beforehand.
Article 13-bis (Event photography, publication and sale)
- At events, gatherings, functions and other activities that the Club organises, co-hosts, supports or holds in its name (in this Article, "Events"), the Club may have photographs, still images and other images capturing the venue and its attendees ("Event Photos") taken by the Club's officers, members, engaged photographers or others the Club designates.
- By registering for, entering or attending an Event, an attendee acknowledges in advance that (i) their likeness, posture, the calling of their name and other outward or incidental features may be recorded in Event Photos, (ii) such recording will be processed in accordance with this Article and Articles 4, 7 and 11 of this Policy, and (iii) attendance constitutes the acknowledgement set out in this paragraph. This acknowledgement imposes no obligation on the attendee and does not limit the right to object under paragraph 5.
- The Club may, to the extent necessary for the purpose, collect, store, edit, curate, reproduce, publish, distribute, sell or otherwise process Event Photos for the following purposes:
- recording the conduct of the Event and the Club's internal archiving and administration;
- publication to members within the Service, provision of previews (including watermarked, reduced-size versions), and the paid distribution of high-resolution files to members;
- promotion of the Club's activities and member recruitment (including on the Club's official website, newsletters, notices, and posts on the Club's official social media); and
- presenting records of past Events and announcing future Events.
- The legal basis for the processing in the preceding paragraph is the legitimate interests under GDPR Art. 6(1)(f). The Club's legitimate interest lies in recording, running, sustaining and promoting its activities as a student community and in providing services to members. The Club carries out a balancing test as to whether that interest is overridden by the attendee's interests or fundamental rights and freedoms. Where information that may constitute special-category data can be inferred from Event Photos, Article 8 applies.
- An attendee who does not wish to appear may, for any reason, object to the processing at any time by contacting privacy@jsc-amsterdam.nl, stating information sufficient to identify themselves (name, member number, etc.) and the relevant Event. On receiving such a request and verifying identity, the Club will, within a reasonable period, exclude Event Photos in which that attendee is identifiable from future publication, preview and sale, or reasonably edit them (masking, blurring, etc.) so that the attendee cannot be identified. This does not apply to files whose distribution to members was already completed before the request was received, as they are beyond the Club's control.
- The Club does not make Event Photos in which a specific identifiable individual is the main subject available for advertising, marketing or other primarily commercial use by third parties without that individual's separate, explicit consent.
- Event Photos may incidentally include visitors other than attendees or third parties who are not Users of the Service. Where such a third party makes a request in the manner of paragraph 5, the Club treats it in the same way.
- The Club stores original Event Photos with the processor named in Article 9 and delivers purchased files to members via expiring share links. The retention of personal data contained in Event Photos follows Article 11.
- Nothing in this Article excludes or limits an individual's rights under the Dutch portrait right (portretrecht; Art. 21 of the Dutch Copyright Act (Auteurswet)) or other applicable law.
Article 14 (User rights)
- Under Applicable Law, Users have the rights of (a) access, (b) rectification, (c) erasure ("right to be forgotten"), (d) restriction, (e) data portability, (f) objection, and (g) withdrawal of consent.
- Rights are exercised by request to the contact in Article 2; the Club responds within the statutory period after verifying identity.
- Users may lodge a complaint with the Dutch supervisory authority, Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
Article 15 (Automated decision-making)
The Club does not carry out decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects on Users.
Article 16 (Data breaches)
On becoming aware of a personal-data breach, the Club will, in accordance with Applicable Law, notify the supervisory authority where required (in principle within 72 hours) and affected Users, and act to mitigate the impact.
Article 17 (Minors)
The Service is for persons aged 18 or over. If the Club learns it has collected personal data from a person under 18, it will promptly delete that data.
Article 18 (Changes)
The Club may revise this Policy in response to legal or operational changes and will notify material changes in the Service or by email.
Article 19 (Governing law and language)
This Policy is governed by Dutch law. The Japanese version is authoritative; in case of discrepancy, the Japanese version prevails.
Article 20 (Contact)
Enquiries regarding this Policy: contact@jsc-amsterdam.nl