Prometheus is student society that processes personal data according to GDPR .
This text serves to show how Prometheus treats personal data. We recommend reading this declaration of privacy attentively.
By taking part in our activities you share certain personal data to us. We only process the personal data directly provided by you or which are clearly provided for us to process. When for an example a member tells us that they are allergic to latex, we will take note of this and save this information. This way we can take precautions at our activities by for example not using balloons as decorations.
At the start of every academic year (honorary) members sign up to join the student society. With their written consent we then save their full name, course of study and email address at which we can reach them. This information is saved by the society's data processor in a Word or Excel document. Data can be viewed on a need to know basis and can only be consulted by members of the elected core committee. The elcted member of presidium with the function of vice president will take on the role of data processor.
We use this data to see who is a(n honorary) member of this society. The email addresses will not be used to send emails, with the exception of important information that cannot be shared via other channels (Instagram, Facebook, the website,...) and for which permission was granted during the sign-up.
The sign-up sheet clearly states that, should the (honorary) member wish to, they can have their email address removed or changed at any point. The removal of the member's full name is only possible when said member leaves the student society.
When we organise acitivities that require signing up, we save the data from the sign-up. We do this to see how many people are coming, how much space and any potential food and drinks need to be provided. For certain activities involving food or drink we will ask to choose a meal (meat, vegetarian or vegan) ahead of time.
All of this data will be deleted after a period of one month following the end of the acitvity. However, members can contact the data processor to have their data removed earlier.
The sign-up will ask for permission for photos to be taken of the members during activities to be posted on social media later.
If any members refuse to be in pictures, the data processor will keep a list of their names. Before any photo is shared or published, this list will be consulted to make sure no accidental photos slipped in of people who didn't want to be photographed. Once noticed, the photo will be deleted immediately.
If members grant permission to appear in photos, they still have the ability to ask for any photos of them to be deleted. They can do this by notifying the data processor who will delete the photo(s) within thirty days from the day of the request.
In some cases non-members will take part in activities. It is made clear at the beginning of each activity that photos will be taken. Non-members (who have not granted permission) will be asked to notify the data processor whether or not they consent to photos being taken and/or published of them. The data processir will keep a list of those who did not consent. This list will be used to filter out photos that were accidentally taken. After posting or publishing photos of the activity, the list will be deleted after six months.
We take measures to avoid misuse of or illegal access to personal data. More specifically, only members of the elected presidium will be granted access to the data, supervised by the data processor, on need-to-know basis.
Prometheus ensures that your data is not passed on to third parties, barring cases where you gave prior permission or where the acess, usage, maintenance or disclosure of your personal data is reasonably deemed necessary (for example to comply with applicable legislation, to detect security problems, to protect the rights, properties or security of Prometheus, etc.)
Prometheus takes the appropriate technical and organisational measures to secure your personal data against any form of loss or illegitimate processing.
Should an incident occur in which your personal data are involved, you will be personally notified under the legal cirumstances.
Members can access their data whenever they want. To gain acces, an e-mail (info@prometheusgent.com) or a message via one of our social meda channels (Instagram, Discord or Facebook) suffices.
After consulting the data, members have the ability to adapt ir delete their data. This is of course also possible without consulting the data. The data processor will ensure this happens no later than 30 days following the request.
For some activities we also collect data from non-members. For them the above still applies.
Prometheus reserves the right to refuse requests issued in an unreasonable manner, that require unequal technical effort (such as developing a new system or fundamentally altering the existing processing method) or jeopardizes the privacy of others
We reserve the right to adapt this policy text. In order to stay up to date with any possible changes we recomment reading this text regularly. In the case of big adaptations we will notify you via e-mail.
“Last edited on 29/05/2026”