Skip to main content

Privacy Policy

Last updated: 4 September 2026

1. Overview

Sociora helps university societies plan events, manage members and coordinate their committee. This Privacy Policy explains what personal data we collect, why we process it, how long we keep it and what rights you have.

2. Data controller

The legal entity responsible for operating Sociora and its registered or service address are pending formal confirmation. They will be published in this section before any live pilot processes personal data.

For data-protection questions, contact our Data Protection contact at the Sociora privacy team.

If we are required to appoint a UK representative or Data Protection Officer under UK GDPR, those details will be added here and made available on request.

3. Data we collect

  • Account information: email address, display name, university or school affiliation, avatar and bio.
  • Membership and role data: the societies you belong to, your committee role and permissions.
  • Event data: registrations, check-ins, seating assignments, competition results, league standings and attendance records.
  • Optional specialist-module data: records and training progress created inside a Society module you choose to use.
  • Communication data: emails, Discord notifications and in-app messages sent through the platform.
  • Technical data: IP address, browser type, device type, session cookies and security logs.
  • Pilot applications: contact details, university, society, committee role, expected event size and date when you explicitly apply.

4. How we use data and our lawful basis

We process personal data only where we have a valid lawful basis under UK GDPR:

  • Contract: to provide your account, run the societies you join, manage event registrations and deliver league or competition results.
  • Legitimate interests: to keep the platform secure, prevent abuse, improve performance, respond to support requests and analyse aggregate usage.
  • Consent: for optional marketing emails, cookies that are not strictly necessary and connecting third-party services such as Discord or Google Calendar. You can withdraw consent at any time in Settings or through the unsubscribe link in emails.
  • Legal obligation: to comply with applicable law, respond to lawful requests and enforce our Terms of Service.

5. Sharing and processors

We do not sell personal data. We share data only as described below:

  • Within your society: organisers and committee members can see member names, emails and event participation for their own society. Members cannot see each other's data outside the same society.
  • Public profiles: only information you set to public visibility is shown to visitors.
  • Service providers (processors): we use carefully selected providers to host, secure and operate the service. Current categories include:
    • Cloudflare (hosting, security, DNS and edge caching)
    • Google (OAuth sign-in, optional Calendar integration and analytics)
    • Microsoft (OAuth sign-in and optional Calendar integration)
    • Discord (OAuth sign-in and optional notifications)
    • Email delivery providers (transactional and support messages)
    We have data-processing agreements or rely on appropriate safeguards for any transfer outside the UK.

6. International transfers

Data is primarily processed and stored on Cloudflare's network in regions close to users. Where a processor stores or processes data outside the UK, we rely on appropriate safeguards such as UK-approved Standard Contractual Clauses or adequacy decisions.

7. Retention

We keep personal data only as long as necessary for the purpose it was collected:

  • Account data: retained while your account is active and for up to 90 days after deletion, unless a longer retention period is required by law or for security logs.
  • Event and society data: retained while the society is active; deleted or anonymised when the society closes or you leave, subject to legitimate dispute-retention needs.
  • Security logs: retained for up to 12 months to investigate abuse and support law enforcement requests.
  • Pilot application contact details: deleted 90 days after submission unless you become an active user or ask us to keep them longer.
  • Backups: encrypted and rotated according to a schedule that reflects these retention periods.

8. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request erasure ("right to be forgotten") in certain circumstances.
  • Restrict or object to processing based on legitimate interests or direct marketing.
  • Request a portable copy of your data in a machine-readable format.
  • Withdraw consent for optional processing at any time.

To exercise any right, contact the Sociora privacy team. We may need to verify your identity before acting on your request.

If you believe we have not handled your data correctly, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

9. Cookies and similar technologies

We use essential cookies to keep you signed in and secure. Optional analytics or preference cookies are used only with your consent. You can manage your choices through the cookie banner or browser settings.

10. Security

We use encryption in transit (HTTPS/TLS), encrypted backups, access controls and regular security reviews. While we take these measures seriously, no online service can guarantee complete security.

11. Changes to this policy

We may update this Privacy Policy as the service evolves. We will post the new version with a revised "Last updated" date and, where the changes are significant, notify users by email or through the platform.

12. Contact us

Questions about this policy or your data should be sent to the Sociora privacy team.