Privacy Policy

Organic Forward
Last Updated: November 2025

This Privacy Policy explains how Organic Forward("we," "us," or "our"), a student-run association and university project, collects, uses, and discloses information about you when you access or use our platform and services (the "Services").

We take your privacy seriously. As this is a student project, our goal is data minimization—we only collect what is strictly necessary to make the project work.

1. Who is the Data Controller?

For the purposes of the General Data Protection Regulation (GDPR), the Joint Data Controllers responsible for your personal information are the individual student members of the Organic Forward project team.

Contact Information: You can contact the student team regarding your data privacy at: [email protected].

Note: Malmö University is generally NOT the controller unless stated otherwise.

2. Information We Collect

We collect information you provide directly to us, as well as some information automatically when you use our Services.

2.1 Information You Provide

Account Information: When you register, we collect your email address, username, and password (encrypted).

Profile Information: If you choose to add it, we may collect a profile picture or bio. (Please do not upload sensitive personal data here).

Communications: If you email us, we collect your email address and the content of your message.

User Content: Any text, images, or videos you voluntarily post on the platform.

2.2 Information Collected Automatically

Log Data: We may collect server logs including IP addresses, browser type, and timestamps to monitor system stability and security.

Usage Data: We may collect anonymous data on how users interact with the site (e.g., which pages are visited) for project analytics.

3. Legal Basis for Processing

Under GDPR, we must have a legal basis to process your data. We rely on the following bases:

Contractual Necessity: We need your email and password to create your account and provide the Service you signed up for (as outlined in our Terms of Service).

Legitimate Interests: We process data to secure our Services, prevent fraud, and fulfill the academic requirements of our university project (e.g., demonstrating to professors that the app works).

Consent: If we send you non-essential newsletters or marketing, we will ask for your explicit consent first. You can withdraw this consent at any time.

4. How We Use Your Information

We use your information to:

- Provide, maintain, and improve our Services.

- Authenticate your identity and secure your account.

- Respond to your comments, questions, and requests.

Academic Assessment: Anonymized or aggregated usage data may be presented to university faculty for the purpose of grading this project. Your personal contact details will not be publicly exposed in academic presentations.

5. Data Sharing and Third Parties

We are a non-commercial student project and we do not sell your personal data. However, we may share data with:

- Service Providers (Processors): We use third-party services to host our platform and database (e.g., Google Cloud Run, GoHighLevel). These providers only process data on our instructions.

- University Faculty: Limited access may be granted to course instructors solely for the purpose of - verifying the functionality of the project for grading.

Legal Requirements: If required by law, we may disclose information to public authorities.

6. International Data Transfers

If our hosting providers are located outside the European Economic Area (EEA), your data may be transferred internationally. We rely on these providers' adherence to Standard Contractual Clauses (SCCs) or the Data Privacy Framework to ensure your data remains protected.

7. Data Retention

We practice Data Minimization. We will retain your personal data only for as long as is necessary to:

- Fulfill the educational goals of this project.

- Comply with university coursework timelines.

Project End Date: Upon the conclusion of this university course (estimated: June 2026), all personal data will be permanently deleted or anonymized, unless you request deletion sooner.

8. Your Rights (GDPR)

You have the following rights regarding your personal data:

- Right to Access: You can ask for a copy of the personal data we hold about you.

- Right to Rectification: You can ask us to correct inaccurate or incomplete data.

- Right to Erasure ("Right to be Forgotten"): You can ask us to delete your account and data.

- Right to Restrict Processing: You can ask us to stop using your data in certain ways.

- Right to Data Portability: You can ask for a copy of your data in a machine-readable format.

- Right to Withdraw Consent: If you subscribed to emails, you can unsubscribe at any time.

To exercise any of these rights, please email us at [email protected]. We will respond within 30 days.

9. Security

We take reasonable measures to help protect information about you from loss, theft, misuse, and unauthorized access. However, please acknowledge that as a student project, we do not have enterprise-level security infrastructure. You provide your personal information at your own risk.

10. Children

Our Services are not intended for individuals under the age of 16 (or the digital age of consent in your country). We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete such information.

11. Changes to this Policy

We may update this Privacy Policy. If we make changes, we will notify you by revising the date at the top of the policy and, in some cases, we may provide you with additional notice (such as adding a statement to our homepage or sending you an email).

Let's connect: [email protected]

© 2025 Organic Forward. All Rights Reserved.