This explains what we do with your personal information, why, how long we keep it, and what you can ask us to do about it.
1. Who we are
The Association of Value Webs (“the Association”, “we”, “us”) operates tavws.org and decides how the personal data described here is used. That makes us the data controller, and accountable for it.
The Association is established in Switzerland, so Swiss data protection law applies to us. We also offer membership to people in the European Union, so the EU General Data Protection Regulation applies to us as well. Where the two differ, we use whichever gives you more protection.
You can reach us about anything on this page at accounts@tavws.org.
We are appointing a representative in the European Union under Article 27 of the GDPR, so that members in the EU can raise data protection matters without contacting us in Switzerland. We will publish their details here once they are appointed. In the meantime, please write to us at the address above and we will deal with it.
2. What we collect, and why
| What | Why | Our legal basis |
|---|---|---|
| Name, email, username, password (stored scrambled — nobody here can read yours) | To create and run your account | Contract |
| Phone, postal address, country | To administer your membership and invoice you | Contract |
| Organisation, membership tier, join and renewal dates, status | To run your membership and apply the right tier | Contract |
| Payment amount, status, invoice number, Stripe reference | To take and record payment | Contract, and legal obligation for the accounting records |
| Event registration and attendance | To run the event | Contract |
| Your posts, comments and contributions | To run the member community | Contract |
| Which members-only resources you open | To enforce members-only access and protect licensed content | Our legitimate interest in protecting content we may only share with members |
| Your name, email and message when you contact us | To answer you | Our legitimate interest in replying to people who write to us |
| IP address, browser, pages requested, timestamps, failed logins — in server logs | To keep the site running and block attacks | Our legitimate interest in keeping the site and your data secure |
We never see or store your card details. Payment happens on Stripe’s own pages; your card number goes straight to them.
If a field is marked required on the application form, we cannot process your application without it. That is a condition of joining, not a legal requirement.
We do not use analytics or advertising trackers, make automated decisions about you, or sell your data. We never have and we will not.
3. Sensitive information and children
We do not set out to collect data about your health, ethnicity, religion, politics, trade union membership or sexuality. Please do not put such information in free-text fields or messages unless it is necessary. If you share it publicly in the community, you are making it public yourself.
Our services are for adults working professionally in the field. You must be 18 or over, and we do not knowingly collect data from anyone younger. If you think a child has given us data, email us and we will delete it.
4. Who we share it with
We use these service providers. Most act only on our instructions, under a contract that meets the legal requirements.
| Provider | What they do | Country |
|---|---|---|
| TransIP | Hosts the website, database and backups | Netherlands |
| Stripe | Takes card payments | Ireland and the United States |
| Sends our service emails | Ireland and the United States | |
| Cloudflare | Resolves our domain name (DNS only — your traffic is not routed through them) | United States |
Stripe is a partial exception, and we would rather say so than gloss it. It acts on our instructions when taking a payment, but it also uses payment data for its own fraud prevention and regulatory obligations — and for that part it decides what it does, not us. Stripe’s own privacy policy covers that.
We also share your data when you ask us to or make it public yourself (your profile and posts are visible to other members); when you hold a published role (office-holders’ names, roles, photographs and biographies appear on the public site and are indexed by search engines — tell us if you would rather not be listed); when the law requires it; when we need to defend legal claims; or if the Association merges or restructures, in which case your data goes to the successor under the same protections.
One thing we are in the middle of fixing. Our pages currently load fonts and code libraries from Google and the OpenJS Foundation. When your browser fetches them, your IP address is sent to those providers, who decide for themselves what they do with it rather than acting on our behalf. We are moving these files onto our own server so this stops.
5. Sending data abroad
If you are in the EU or EEA, your data reaching us in Switzerland needs no special safeguard — the European Commission has formally recognised Swiss data protection as adequate. Our Dutch hosting is likewise covered by Switzerland’s own adequacy list.
For our providers in the United States, we rely on the Swiss–US and EU–US Data Privacy Frameworks, and on the European Commission’s standard contractual clauses. We record which applies to each provider and review it when the law changes. Ask us for a copy.
6. How long we keep it
| Your member record, while you are a member | For as long as your membership is active |
| After your membership ends | 24 months, then deleted or anonymised |
| Payment and invoice records | 10 years — required by Swiss accounting law, not our choice |
| Event registrations | 12 months after the event |
| Enquiries | 12 months after the matter is closed |
| Server and security logs | 90 days |
| Your posts | Until you delete them or close your account — see section 8 |
| Backups | Overwritten automatically on a rolling 14-day cycle |
About backups: if you ask us to delete your data we remove it from live systems straight away. Backups are not edited one record at a time — they are overwritten on the cycle above, after which it is gone from those too. Meanwhile they are held securely and only ever used to restore the service after a failure.
7. Your rights
You can ask us to: give you a copy of your data and explain how it is used; correct anything wrong or incomplete; delete it where we have no good reason to keep it; pause using it while a dispute is sorted out; send you a machine-readable copy or pass it to another organisation; or stop processing based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time, as easily as you gave it.
Email us and we will respond within 30 days. It is free, and we will not treat you differently for asking. We may need to check it is really you — usually just confirming you control the email address on your account. You can also view and correct most of your details yourself in your member profile.
If something is wrong, please tell us first — it is usually quicker. But you can always complain to a data protection authority without going through us:
- In the EU or EEA: we have no establishment in the EU, so there is no single “lead” authority for us. Complain to the authority in the country where you live, where you work, or where you think the problem happened.
- In Switzerland: the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern — edoeb.admin.ch.
8. If you leave
We remove your personal details. Posts you made in shared discussions may stay, with your name replaced by an anonymous label, so conversations other members took part in are not broken. Want a specific post gone entirely? Tell us and we will do it.
9. Keeping your data safe
Traffic to the site is encrypted. Passwords are stored scrambled and nobody here can see yours. Card data never reaches our servers. Administrative access is limited by role and deliberately few people have it. The server is firewalled, blocks intrusion attempts automatically, updates itself for security, and only accepts administrative logins by cryptographic key. Backups are automatic and tested. We have a written procedure for handling any data breach, including notifying the authorities where required.
No system is perfectly secure, but we take this seriously and review it.
10. Cookies, and changes to this policy
See our Cookie Policy — there are three, all necessary.
If we change this policy we will update the date below. If a change materially affects how we use your data, we will email members before it takes effect.
Questions
Email accounts@tavws.org.
The Association of Value Webs · Last updated 18 August 2026