Privacy & GDPR
GreekManage stores personal data on members and donors. This page summarizes what's stored, how it's protected, and the rights you have.
What's stored
About members
- Identity: name, email, phone (optional)
- Profile: bio, hometown, major, graduation year, photo, social links
- Org context: chapter, region, role, status
- Custom fields configured by your org
- Activity: forum posts, recognitions, election ballot timestamps (not contents), invoices, course progress
- Audit trail: sign-ins, profile changes, admin actions
About donors
- Identity, address, payment method tokens (no card numbers)
- Donation history (amounts, dates, campaigns)
- Tags and custom notes set by org admins
About admins
Same as members, plus their admin role and any sensitive actions they take (logged).
How it's protected
- Encryption in transit: TLS 1.2+ for all connections
- Encryption at rest: AES-256 for the database; storage providers encrypt at rest
- Access controls: row-level security per tenant; permissions enforced at API and UI layers
- Audit logs: every action logged
- Backups: encrypted, retained per policy
- Penetration testing: annually by independent assessors
- Vulnerability scanning: continuous
Your rights
Right to access
Export everything about yourself: Account Settings → Download My Data card → Request Export. The export runs in the background as a JSON file; once its status turns ready, click Download Export to fetch it via a presigned link (valid 24 hours). Nothing is emailed to you automatically — you download it in-app. Rate limit: one export request per 24 hours per account. Full walkthrough: Privacy, data export, and account (members).
Right to rectification
Update your profile fields directly. For fields you can't edit (status, role), ask an officer or org admin.
Right to erasure ("right to be forgotten")
This is fully self-service: Account Settings → Danger Zone → Delete My Account. Confirm the warning dialog, re-enter your password, and your account is deactivated immediately with a 30-day grace period before permanent deletion. While signed in, a Cancel Deletion Request button on the same page reverses it. If you're signed out or lose access before cancelling, there's no self-service recovery today — contact a platform or national admin to cancel the pending deletion on your behalf (regional admins cannot do this — that role can reactivate a merely-disabled account, below, but not cancel a pending deletion).
Once the grace period elapses and deletion runs:
- Your member profile record is permanently deleted (not merely blanked)
- Forum posts, comments, and attachments are reassigned to a sentinel "Deleted Member" account rather than showing your name
- Membership, admin-role, notification-preference, and push-token records are deleted; active JWT sessions are revoked
- Audit log entries you took remain, with the
userreference nulled (anonymized) rather than removed - Financial records (invoices, payment history) are not touched by the deletion job — they're retained under your org's ordinary financial retention policy regardless of account status
Right to restriction of processing
Pause processing without full deletion: Account Settings → Disable Account. Sign-ins are blocked immediately on every device; your membership records, profile, and org history stay intact. Re-enabling requires a platform admin, a national admin of your org, or a regional admin of your chapter's region.
Right to data portability
Same as access — the JSON export is portable.
Right to object
You can opt out of:
- Marketing emails and analytics/usage tracking (toggles on the Privacy Settings page, from the avatar menu)
- Directory visibility, per field (email, phone, work history, location) — available today to alumni members on the alumni privacy page; general (non-alumni) member profiles don't have a per-field visibility toggle in this release, since active members can see basic profile info for other active members of the same org by default
- AI features indexing your content — this is an org-wide setting (
ai_scope_*toggles an org admin controls on the org's AI config), not an individual per-member opt-out
Right to withdraw consent
For consent templates you accepted, you can withdraw via the Privacy Settings page (Marketing communications and Analytics & usage tracking toggles). Revoking creates a new dated record; the prior one is retained for compliance. Some withdrawals trigger access restrictions (e.g., withdrawing the membership agreement may end your membership).
Children's data
GreekManage is not directed at users under 13. If we learn we've collected data from a user under 13 without parental consent, we delete it.
International transfers
GreekManage may store and process data in:
- The United States (primary)
- The EU (where required by customer contract)
- The customer's chosen storage region for files
For EU customers, GreekManage signs Standard Contractual Clauses (SCCs) to authorize US transfers.
Data retention
| Data type | Retention |
|---|---|
| Profile data | Active membership; hard-deleted after the 30-day account-deletion grace period runs |
| Forum posts | Indefinite (author reassigned to a "Deleted Member" placeholder if the account is deleted) |
| Invoices and payment records | Retained under your org's financial/tax policy — not on an automated deletion schedule today |
| Audit logs | Org-configurable, 1–180 days (default and hard cap: 180 days). One window per org — there's no separate longer tier for financial actions. Org admins needing longer retention should periodically export the log to CSV and archive it externally. |
| Backups | Count-based, not calendar-based: the most recent daily, weekly, and monthly snapshots are kept per a configurable count (defaults: 7 daily / 4 weekly / 3 monthly) |
| Auth sessions | Access token 30 minutes, refresh token 24 hours |
Audit log retention is set by the platform team on request (per-org, 1–180 days); backup retention counts are set by platform admins. There's no per-org self-service control over either today.
Subprocessors
GreekManage uses these subprocessors (full list at greekmanage.com/legal/subprocessors):
- AWS / cloud infrastructure
- Stripe / payment processing
- Email delivery — the platform (or an org, if it's configured its own override) picks one of AWS SES, SMTP, SendGrid, or Google; SES, SendGrid, Postmark, and Mailgun bounce/complaint webhooks also feed the platform's address-suppression list
- AI providers (Anthropic, OpenAI, Google) for the AI chatbot and other AI features, only when AI Services is enabled
- Each subprocessor has a Data Processing Addendum (DPA) in place
Security incidents
In the event of a security incident affecting personal data:
- GreekManage notifies platform and org admins within 72 hours of confirmation
- Affected users are notified per applicable law
- Public security advisories are posted at greekmanage.com/security
DPO (Data Protection Officer)
Contact: privacy@greekmanage.com
For EU-specific inquiries: eu-privacy@greekmanage.com
Filing a complaint
You can file a complaint with:
- Your country's data protection authority (DPA)
- The U.S. Federal Trade Commission for U.S. users
- Your state attorney general (varies by state)
GreekManage cooperates fully with regulator inquiries.
Related
*Last verified against v0.65.25 (2026-07-05). Data export is an in-app JSON download (not emailed, no PDF option). Account deletion is fully self-service via Account Settings → Danger Zone → Delete My Account (password-confirmed, 30-day grace period); cancelling a pending deletion is available to platform or national admins, while reactivating a merely-disabled (non-deletion) account is also available to regional admins; deletion doesn't touch invoices. The marketing opt-out lives on Privacy Settings (not "Notifications"). Directory-visibility opt-out is alumni-only today, not a general profile-visibility control. AI content-indexing opt-out is an org-wide admin toggle, not an individual member opt-out. Audit log retention is a single 1–180-day org-configurable window (no separate "financial actions" tier), and backup retention is count-based, not calendar-based.