Skip to content
MaaSec

Privacy

Last updated August 2026

MaaSec is a student organisation, not a company. We collect as little personal data as we can get away with, and never sell it or use it for advertising. This page explains what we collect, why, and what you can do about it — in line with the EU General Data Protection Regulation (GDPR), as we’re based in the Netherlands.

Who’s responsible for your data

MaaSec, Maastricht University’s student cybersecurity organisation and ACM chapter, is the data controller for the information described on this page. Reach us at acm@maasec.com for anything below.

What we collect

The only place this site asks you for personal information is the Join form. If you use it, we receive:

That’s the complete list. This site sets no cookies, runs no analytics, and has no tracking pixels or advertising scripts — there is nothing else being collected in the background.

How we use it, and who sees it

Submitting the Join form sends your details, over an encrypted connection, straight to an email inbox the board reads — MaaSec’s own website has no database that stores your submission. That email is delivered via Resend, an email-sending service acting only on our instructions as a data processor; we don’t use it for anything beyond delivering your application. We keep applications only for as long as it takes to process them (typically a few weeks), then delete them.

If you message us on Discord, WhatsApp, or by email instead, that conversation is governed by that platform’s own privacy policy, not this one.

Your rights

Under GDPR, you can ask us at any time to:

Email acm@maasec.com for any of these — we’ll respond within a month. If you think we’ve mishandled your data, you can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Contact

Questions, or a request about your data? Write to acm@maasec.com.