Privacy notice
This explains what AIESEC Pulse collects about you, why, how long it is kept, and what you can ask us to do about it.
Last updated: 17 August 2026
Who is responsible
AIESEC International is the data controller for AIESEC Pulse. The platform is operated by the Information Management portfolio. For anything in this notice, or to exercise a right described below, use the controls on your Privacy & your data page or contact your Member Committee's IM lead.
What we collect, and why
Your identity, mirrored from AIESEC
When you sign in, Pulse reads your name, email address, profile photo and current positions from AIESEC's Global Information System (GIS) and stores a copy. We do this so the platform knows which entity you belong to and what you are allowed to publish or moderate. Pulse never edits this data — EXPA and GIS remain the source, and a correction made there flows through at your next sign-in.
What you publish
Posts, comments and reactions, together with the entity you published on behalf of and the AIESEC term in which you published. This is the organisational record the platform exists to keep.
What you read
Which posts you opened, roughly how far you scrolled, and roughly how long you spent. Publishers see this as aggregate reach and read rate for their own posts — never as a list of who read what. Aggregate reporting suppresses small counts so individual reading behaviour cannot be inferred from a dashboard.
This is personal data and we are telling you about it deliberately, because the honest alternative to disclosure is not collecting it.
Your sessions
A session record per device, holding a description of the browser and a keyed one-way hash of the network address you signed in from. We store the hash rather than the address itself so that the record is useful for spotting suspicious access without being a directly identifying location trail.
Your AIESEC access tokens
Encrypted, on our servers, never in your browser. They let Pulse refresh your details from GIS without asking you to sign in again. Signing out everywhere discards them.
Why we are allowed to do this
- Legitimate interest — running internal communications for a global organisation you are a member of. This covers your profile, your published content, and reach measurement.
- Consent — web push notifications and any non-essential analytics. You can withdraw consent at any time without losing access to the platform.
How long we keep it
| Data | Kept for |
|---|---|
| Published posts and comments | Indefinitely — organisational record |
| Drafts you never published | 12 months after you last touched them |
| Reading history | 13 months, then aggregated and deleted |
| Notifications | 6 months |
| Email delivery records | 12 months |
| Sessions | 30 days after expiry |
| AIESEC access tokens | Until you sign out, or 90 days of inactivity |
| Moderation and administration records | 7 years |
| Reports and appeals | 3 years after resolution |
Your rights
You can ask for access, a copy, correction, erasure, restriction, or object to processing. Use Privacy & your data. Export is immediate; everything else is handled by a person within 30 days.
On erasure and our records. If you ask us to erase your data, your account is anonymised, your reading and engagement history is deleted, and you choose whether your posts and comments stay published under “Former member” or are removed. Records of moderation decisions are kept for seven years as required for accountability — but your identity is removed from them, replaced by an irreversible pseudonym. The events remain; you do not appear in them.
You also have the right to complain to a supervisory authority in your country of residence.
Where your data is held, and who else sees it
Our database and file storage are hosted in the European Union. We use the following processors, each under a data processing agreement:
- Vercel — application hosting
- Supabase — database and file storage (EU region)
The current list, and what each one processes, is maintained in the platform's data map. AIESEC entities do not receive your data through Pulse beyond what is visible in the product itself.
Confidentiality
Pulse is not for confidential material. Audience targeting decides what is relevant to whom; it is not a security boundary, and you should assume anything you post can reach any AIESEC member. Do not put personal data about other people, commercially sensitive material, or anything under an obligation of confidence into a post or a comment.
Members under 18
AIESEC has no members under 18, in any entity. Pulse therefore applies no age-gating, parental-consent basis, or other under-18 safeguards to any account.
If something goes wrong
We have a documented procedure for assessing and, where required, reporting a personal data breach within 72 hours. If a breach affects you and is likely to present a high risk, we will tell you directly.
Changes
Material changes will be announced in the feed before they take effect, not applied quietly. The date at the top of this page always reflects the current version.