Privacy Policy
Last updated:
This policy explains what personal information the Cloud Security Alliance Uttarakhand Chapter (“the chapter”, “we”, “us”) collects through uk.cloudsecurityalliance.in, why we collect it, who processes it on our behalf, and what you can ask us to do with it. It applies to this website only.
The chapter is a volunteer-run community chapter based in Dehradun, Uttarakhand, India. It is affiliated with the Cloud Security Alliance, which operates its own separate websites under its own privacy policy. Nothing here governs data you give to the global organisation directly.
Information we collect
Membership applications and contact enquiries
When you submit the form on Become a Member or Contact, we receive the details you type into it:
- the type of membership you are applying for (student, professional, or board);
- your first and last name;
- your email address;
- your phone number;
- your institution, company, or organisation;
- the subject and message you write.
Alongside those, and separately from what you typed, we record the IP address and browser user-agent string the submission arrived from. These two are kept for one reason only: so that spam and abusive submissions can be identified and blocked. They are not used to build a profile of you and are not shared for any other purpose.
Newsletter subscriptions
If you subscribe using the form in the site footer, we collect your email address and nothing else. Newsletter addresses are held in our email provider’s mailing list and are not written into the website’s own database.
Technical logs
Our hosting provider keeps standard server logs of requests to the site — IP address, timestamp, requested URL, response status, and user-agent. These are generated automatically for every website and are used for security, error diagnosis, and capacity planning.
What we do not collect
We do not run advertising networks, behavioural tracking pixels, or third-party analytics on this site. We do not ask for, or knowingly store, sensitive personal data such as government identity numbers, financial account details, health information, or biometric data. Please do not include such details in a form message.
How we use your information
- To respond to you. Membership applications and enquiries are reviewed by chapter volunteers, who reply by email.
- To administer membership. Applications are kept so we can assess them, follow up, and keep a record of chapter membership.
- To send you what you asked for. Newsletter subscribers receive chapter news, event announcements, and community updates. We do not sell or rent the list.
- To keep the site working and safe. Logs and the abuse metadata described above support rate limiting, spam prevention, and debugging.
Submitting an application does not create any membership, obligation, or entitlement. See our Terms and Conditions.
Who processes your information
We keep the list of third parties short and use each one for a single, stated job. Every provider below acts as a processor on our instructions:
- Vercel — hosts and serves this website, and generates the technical logs described above.
- A managed PostgreSQL database provider — stores membership applications, chapter news items, and blog articles.
- Mailgun — sends the acknowledgement email you receive, sends the notification email to chapter volunteers, and holds the newsletter mailing list.
- Google Sheets — receives a mirror copy of membership applications so volunteers can review them without database access.
Some of these providers operate infrastructure outside India, which means your information may be stored or processed abroad. We only use established providers that offer contractual data-protection commitments.
We do not sell personal information. We disclose it outside the chapter and the processors above only where we are legally required to, or where it is necessary to investigate abuse of the site or protect someone’s safety.
Cookies
This site sets one cookie, named ukcsa_session. It is created only when a chapter administrator signs in to the private admin panel, it holds a signed session token, and it expires after eight hours. It is strictly necessary for that sign-in to work.
Ordinary visitors browsing the public pages are not given a cookie, and there are no analytics, advertising, or cross-site tracking cookies anywhere on this site. That is why you are not shown a cookie consent banner: there is nothing optional to consent to.
How long we keep it
- Membership applications and enquiries— retained while the application is under review and thereafter as part of the chapter’s membership record, until you ask us to delete it.
- Newsletter addresses — retained until you unsubscribe, after which the address is removed from the mailing list.
- Technical logs — retained on a short rolling window by our hosting provider and then overwritten.
Your choices and rights
India’s Digital Personal Data Protection Act, 2023 gives you rights over your personal data. Regardless of where you are, you can ask us to:
- confirm what information about you we hold, and give you a copy of it;
- correct or complete anything that is inaccurate or out of date;
- delete your information, where we are not required to keep it;
- stop sending you email.
To exercise any of these, use the contact formand say which request you are making. We will respond within a reasonable period and may ask you to confirm the email address the request relates to, so that we do not act on someone else’s behalf by mistake.
Every newsletter we send carries an unsubscribe link that works without you having to contact anyone. Using it removes your address from the list.
Security
The site is served over HTTPS with strict transport security. Administrator passwords are stored only as salted hashes, admin sessions are signed and short-lived, form endpoints are rate limited, and author-submitted content is sanitised before it is rendered. No system is perfectly secure, but access to submitted information is limited to chapter volunteers who need it in order to act on it.
Children and students
Much of the chapter’s work is with universities, so many of the people who contact us are students. This site is not directed at children, and we ask that anyone under 18 obtain a parent or guardian’s consent before submitting personal details through it. If you believe a child has sent us information, contact us and we will delete it.
External links
Our pages link to the global Cloud Security Alliance, partner universities, news coverage, and social platforms. Once you follow a link off this site, the destination’s own privacy policy applies and this one no longer does.
Changes to this policy
If this policy changes, we will publish the revised version on this page and update the date at the top. Material changes to how we use information already collected will be flagged here rather than made quietly.
Contact us
Questions about this policy, or about information you have already submitted, can be sent through the contact form. The chapter is based in Dehradun, Uttarakhand, India.