Skip to main content

Privacy & GDPR

GreekManage stores personal data on members and donors. This page summarizes what's stored, how it's protected, and the rights you have.

What's stored

About members

  • Identity: name, email, phone (optional)
  • Profile: bio, hometown, major, graduation year, photo, social links
  • Org context: chapter, region, role, status
  • Custom fields configured by your org
  • Activity: forum posts, recognitions, election ballot timestamps (not contents), invoices, course progress
  • Audit trail: sign-ins, profile changes, admin actions

About donors

  • Identity, address, payment method tokens (no card numbers)
  • Donation history (amounts, dates, campaigns)
  • Tags and custom notes set by org admins

About admins

Same as members, plus their admin role and any sensitive actions they take (logged).

How it's protected

  • Encryption in transit: TLS 1.2+ for all connections
  • Encryption at rest: AES-256 for the database; storage providers encrypt at rest
  • Access controls: row-level security per tenant; permissions enforced at API and UI layers
  • Audit logs: every action logged
  • Backups: encrypted, retained per policy
  • Penetration testing: annually by independent assessors
  • Vulnerability scanning: continuous

Your rights

Right to access

Export everything about yourself: Account Settings → Download My Data card → Request Export. The export runs in the background as a JSON file; once its status turns ready, click Download Export to fetch it via a presigned link (valid 24 hours). Nothing is emailed to you automatically — you download it in-app. Rate limit: one export request per 24 hours per account. Full walkthrough: Privacy, data export, and account (members).

Right to rectification

Update your profile fields directly. For fields you can't edit (status, role), ask an officer or org admin.

Right to erasure ("right to be forgotten")

This is fully self-service: Account Settings → Danger Zone → Delete My Account. Confirm the warning dialog, re-enter your password, and your account is deactivated immediately with a 30-day grace period before permanent deletion. While signed in, a Cancel Deletion Request button on the same page reverses it. If you're signed out or lose access before cancelling, there's no self-service recovery today — contact a platform or national admin to cancel the pending deletion on your behalf (regional admins cannot do this — that role can reactivate a merely-disabled account, below, but not cancel a pending deletion).

Once the grace period elapses and deletion runs:

  • Your member profile record is permanently deleted (not merely blanked)
  • Forum posts, comments, and attachments are reassigned to a sentinel "Deleted Member" account rather than showing your name
  • Membership, admin-role, notification-preference, and push-token records are deleted; active JWT sessions are revoked
  • Audit log entries you took remain, with the user reference nulled (anonymized) rather than removed
  • Financial records (invoices, payment history) are not touched by the deletion job — they're retained under your org's ordinary financial retention policy regardless of account status

Right to restriction of processing

Pause processing without full deletion: Account Settings → Disable Account. Sign-ins are blocked immediately on every device; your membership records, profile, and org history stay intact. Re-enabling requires a platform admin, a national admin of your org, or a regional admin of your chapter's region.

Right to data portability

Same as access — the JSON export is portable.

Right to object

You can opt out of:

  • Marketing emails and analytics/usage tracking (toggles on the Privacy Settings page, from the avatar menu)
  • Directory visibility, per field (email, phone, work history, location) — available today to alumni members on the alumni privacy page; general (non-alumni) member profiles don't have a per-field visibility toggle in this release, since active members can see basic profile info for other active members of the same org by default
  • AI features indexing your content — this is an org-wide setting (ai_scope_* toggles an org admin controls on the org's AI config), not an individual per-member opt-out

For consent templates you accepted, you can withdraw via the Privacy Settings page (Marketing communications and Analytics & usage tracking toggles). Revoking creates a new dated record; the prior one is retained for compliance. Some withdrawals trigger access restrictions (e.g., withdrawing the membership agreement may end your membership).

Children's data

GreekManage is not directed at users under 13. If we learn we've collected data from a user under 13 without parental consent, we delete it.

International transfers

GreekManage may store and process data in:

  • The United States (primary)
  • The EU (where required by customer contract)
  • The customer's chosen storage region for files

For EU customers, GreekManage signs Standard Contractual Clauses (SCCs) to authorize US transfers.

Data retention

Data typeRetention
Profile dataActive membership; hard-deleted after the 30-day account-deletion grace period runs
Forum postsIndefinite (author reassigned to a "Deleted Member" placeholder if the account is deleted)
Invoices and payment recordsRetained under your org's financial/tax policy — not on an automated deletion schedule today
Audit logsOrg-configurable, 1–180 days (default and hard cap: 180 days). One window per org — there's no separate longer tier for financial actions. Org admins needing longer retention should periodically export the log to CSV and archive it externally.
BackupsCount-based, not calendar-based: the most recent daily, weekly, and monthly snapshots are kept per a configurable count (defaults: 7 daily / 4 weekly / 3 monthly)
Auth sessionsAccess token 30 minutes, refresh token 24 hours

Audit log retention is set by the platform team on request (per-org, 1–180 days); backup retention counts are set by platform admins. There's no per-org self-service control over either today.

Subprocessors

GreekManage uses these subprocessors (full list at greekmanage.com/legal/subprocessors):

  • AWS / cloud infrastructure
  • Stripe / payment processing
  • Email delivery — the platform (or an org, if it's configured its own override) picks one of AWS SES, SMTP, SendGrid, or Google; SES, SendGrid, Postmark, and Mailgun bounce/complaint webhooks also feed the platform's address-suppression list
  • AI providers (Anthropic, OpenAI, Google) for the AI chatbot and other AI features, only when AI Services is enabled
  • Each subprocessor has a Data Processing Addendum (DPA) in place

Security incidents

In the event of a security incident affecting personal data:

  • GreekManage notifies platform and org admins within 72 hours of confirmation
  • Affected users are notified per applicable law
  • Public security advisories are posted at greekmanage.com/security

DPO (Data Protection Officer)

Contact: privacy@greekmanage.com

For EU-specific inquiries: eu-privacy@greekmanage.com

Filing a complaint

You can file a complaint with:

  • Your country's data protection authority (DPA)
  • The U.S. Federal Trade Commission for U.S. users
  • Your state attorney general (varies by state)

GreekManage cooperates fully with regulator inquiries.

*Last verified against v0.65.25 (2026-07-05). Data export is an in-app JSON download (not emailed, no PDF option). Account deletion is fully self-service via Account Settings → Danger Zone → Delete My Account (password-confirmed, 30-day grace period); cancelling a pending deletion is available to platform or national admins, while reactivating a merely-disabled (non-deletion) account is also available to regional admins; deletion doesn't touch invoices. The marketing opt-out lives on Privacy Settings (not "Notifications"). Directory-visibility opt-out is alumni-only today, not a general profile-visibility control. AI content-indexing opt-out is an org-wide admin toggle, not an individual member opt-out. Audit log retention is a single 1–180-day org-configurable window (no separate "financial actions" tier), and backup retention is count-based, not calendar-based.