Privacy policy
1. Introduction
Uppsala Furry Förening (also defined as “the association”, “we”, “us” or “our”) respects the privacy of its members, event participants, volunteers, and other individuals who interact with the association.
This privacy policy explains how Uppsala Furry Förening collects, uses, stores, shares, and protects personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Swedish data protection legislation.
The association aims to process only the personal data necessary for clearly defined purposes and to ensure that personal data is handled securely and responsibly.
2. Data controller
Uppsala Furry Förening is the data controller for the processing of personal data described in this privacy policy.
- Organisation: Uppsala Furry Förening
- Organisation number: 802554-7350
- Postal address: Flogstavägen 69 lgh 1101, 752 72, Uppsala
- Email: contact@uppsalafurry.se
- Website: https://uppsalafurry.se/
Questions concerning privacy or the processing of personal data may be directed to the above mentioned email.
3. Personal data we process
Depending on how an individual interacts with the Association, we may process personal data such as:
- Full legal name
- Username, nickname or online handle
- Contact information
- Membership information
- Payment and transaction information
- Event registrations
- Information provided when contacting the association
- Photographs and other media from association activities
- Information relating to volunteering or positions of trust within the association
The association will not collect personal data that is not reasonably necessary for its activities.
4. Why we process personal data
We may process personal data for purposes including:
- Administering membership in the association
- Collecting and administering membership fees
- Organising events and activities
- Communicating with members and participants
- Managing volunteers and elected representatives
- Fulfilling accounting and other legal obligations
- Maintaining the safety and proper functioning of association activities
- Publishing information, photographs or other material relating to association activities
- Responding to enquiries and requests
Personal data collected for one purpose will not normally be used for an incompatible purpose.
5. Legal bases for processing
The association processes personal data only when there is a legal basis under the GDPR.
Depending on the processing activity, the legal basis may include:
- Contract – where processing is necessary to administer membership or provide an activity or service requested by an individual
- Legal obligation – where processing is necessary to comply with Swedish law, for example accounting requirements
- Legitimate interests – where processing is necessary for a legitimate interest of the Association or another party and that interest is not overridden by the rights and interests of the individual
- Consent – where an individual has freely given specific and informed consent to a particular processing activity. Consent may be withdrawn at any time
The applicable legal basis for each processing activity is described in the GDPR, which can be found on IMY:s website.
6. UFF account
A UFF user account is required to register and attend the association’s events and meets. We process personal data necessary to create and manage accounts, registrations and access to services related to the events.
Account data is accessible only to persons who require access in order to perform their duties within the association.
Having a UFF account does not, by itself, constitute membership of the Association. Membership information is handled separately in section 7. Membership administration.
7. Membership administration
When an individual becomes a member of Uppsala Furry Förening, we process personal data necessary to administer their membership.
Membership data is accessible only to persons who require access in order to perform their duties within the association.
8. Events and activities
When individuals register for or participate in events organised by the association, we may process information necessary to organise and administer the event.
Where additional information is required for a specific event, participants will be informed about how that information will be used.
9. Payments and accounting
The association may process information concerning membership fees, event fees, reimbursements, purchases, donations, and other financial transactions.
Certain financial information must be retained in accordance with Swedish accounting legislation even if an individual is no longer a member of the association.
10. Photographs and media
Photographs, video recordings, or other media may be created during association events and activities.
This may also include pictures and other media uploaded to be associated with an UFF account.
The association will establish appropriate procedures for informing participants about photography and determining the appropriate legal basis before photographs or recordings containing identifiable individuals are published or otherwise processed.
Where consent is relied upon, individuals may withdraw their consent at any time.
11. Safety, conduct and incident management
The association may need to process personal data relating to violations of association rules, incidents, complaints, warnings, suspensions, or other measures necessary to maintain safe and orderly association activities.
Such information will only be processed where there is an appropriate legal basis and will be subject to restricted access and appropriate safeguards.
Any processing involving sensitive personal data or information concerning criminal offences will be subject to additional assessment and safeguards where required by law.
12. Communication and online platforms
The association may use third-party services and online platforms to communicate with members and organise its activities.
These may include:
- Telegram
- Discord
- Our website
- Twitter/X
- Bluesky
Where these providers process personal data on behalf of the association, appropriate data processing arrangements will be established where required.
Individuals should also be aware that third-party platforms may process personal data independently under their own privacy policies.
13. Sharing of personal data
The association does not sell personal data.
Personal data may be shared with third parties where necessary, including:
- Service providers processing data on behalf of the association
- Payment providers and financial institutions
- IT and hosting providers
- Accountants or auditors
- Public authorities where required by law
Access to personal data within the association is limited to individuals who require the information to perform their duties.
14. Transfers outside the EU/EEA
Some services used by the association may involve the transfer or processing of personal data outside the European Union or European Economic Area.
Where such transfers occur, the association will ensure that an appropriate legal mechanism and safeguards are in place in accordance with the GDPR.
15. Retention of personal data
Personal data is retained only for as long as necessary for the purpose for which it was collected or for as long as required by law.
The association regularly reviews the personal data it retains and deletes or anonymises information that is no longer required.
| Type of information | Retention period |
|---|---|
| UFF account information | Kept until it is requested to be deleted by the user. |
| Membership information | For the duration of membership. Following the end of membership, information is kept but a request to delete it may be made at any point. |
| Event registrations | Kept until it is requested to be deleted by the user. |
| Accounting records | To keep in line with Swedish legislation regarding bookkeeping. |
| General communication | During the time of the enquiry and for up to 30 days after the enquiry has been resolved. |
| Photographs/media | Normally for no more than two years from publishing, with an annual review of continued use in general. |
| Incident/conduct records | For up to 12 months after the matter has been closed. |
16. Information security
The association takes appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction.
Measures may include access controls, secure authentication, restricted permissions, backups, encryption where appropriate, and procedures for handling personal data breaches.
Access to personal data is limited according to the responsibilities of the relevant board member or other authorised person.
17. Cookies and website analytics
Uppsala Furry Förening uses cookies and similar technologies to operate, secure, and improve its website and online services.
We may use cookies for purposes including:
- Maintaining user sessions and keeping users logged in
- Remembering cookie and privacy preferences
- Protecting user accounts, forms, and other website functionality
- Collecting website usage statistics and analytics
- Identifying and troubleshooting technical problems
- Improving the functionality and usability of our website
Optional analytics cookies are only activated where the user has provided the required consent. Users may reject these cookies and may change or withdraw their consent at any time.
18. Personal data breaches
If a personal data breach occurs, the association will assess the incident and take appropriate measures to limit its consequences.
Where required by the GDPR, the association will notify the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) and, where applicable, affected individuals.
19. Your rights
Under the GDPR, individuals may have the right to:
- Request information about how their personal data is processed
- Request access to their personal data
- Request correction of inaccurate or incomplete personal data
- Request deletion of personal data in certain circumstances
- Request restriction of processing
- Object to certain processing based on legitimate interests
- Withdraw consent where processing is based on consent
- Request data portability where applicable
- Lodge a complaint with a supervisory authority
These rights are subject to the conditions and limitations established by the GDPR.
To exercise your rights, contact the association at:
- Uppsala Furry Förening - contact@uppsalafurry.se
The association will need to verify your identity before fulfilling a request.
20. Complaints
If you believe that Uppsala Furry Förening is processing your personal data incorrectly, you are encouraged to contact us so that we can investigate the matter.
Contact the association at:
- Uppsala Furry Förening - contact@uppsalafurry.se
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection:
- Integritetsskyddsmyndigheten (IMY) Website: www.imy.se
21. Changes to this privacy policy
The Board of Uppsala Furry Förening may update this privacy policy when the association's processing activities, services, legal obligations, or technical systems change.
The current version of the privacy policy will be made available through our website.
Material changes affecting UFF accounts, members or participants will be communicated through appropriate channels.
