Plain language Privacy notice

What the public site does with information.

The website supports password-free accounts and a separate UBRobotics identity roster. It does not take payments or store interest-form submissions. Microsoft and the form owner handle information submitted through the embedded or linked interest form.

Browsing these public pages

The public pages do not set an application login session while you browse them. The web server may record network and request details needed to operate and protect the service, such as an IP address, time, requested path, response status and browser identifier.

Detailed authentication, delivery, rate-limit and operational logs are retained for up to 90 days. The Website Maintainer is the primary privacy and incident owner, backed up by the CS Lead and Technical Director.

Microsoft interest form

The Join page embeds a form hosted by Microsoft and keeps a direct link visible. Loading or opening it connects your browser to Microsoft. Microsoft may set third-party cookies for the form session and organisational-account workflow. Information submitted there is handled by the form owner and Microsoft rather than stored by this website.

Open the interest form directly

Map and contact directory

The Join page embeds OpenStreetMap. Loading the map sends a request to OpenStreetMap; the written location and an external link remain available if the embed is blocked. Following the social/contact link connects your browser to Linktree.

Open the location on OpenStreetMap

Corrections and removal requests

Email the committee at ubrobotics@outlook.com to ask about correcting or removing information. The society’s social and contact directory remains available for general enquiries.

Signing in and connected accounts

You may sign in through personal Microsoft, Google or Discord. Opening a provider sign-in page connects your browser to that provider. We store a random website account ID, the provider’s stable account identifier, connected-method and security timestamps, account status and minimal authentication audit events. We do not store passwords, provider emails, names, profiles or provider tokens.

Essential secure cookies keep your website session and protect forms. Sessions expire after 30 minutes of inactivity or 12 hours. Login verification state expires after five minutes. You can review and remove connected methods, retain at least one available method, and sign out all sessions in account settings.

Temporary authentication abuse-control counters use protected digests and expire after at most 20 minutes. Expired login state, counters and sessions are removed by daily maintenance. Website-account deletion is separate from erasing a society identity. Use the contact route above to request either review.

UBRobotics identities and University email proof

The private roster stores a preferred first name, complete University email, membership lifecycle state, role grants, import source and administration timestamps. Social sign-in alone gives no private society access. A signed-in person can link only by proving control of the complete University address already held in an eligible, pre-provisioned identity. We store challenge digests rather than raw links or codes; challenges expire after 15 minutes and cleanup removes them within 24 hours.

Verification email is sent through Oracle Cloud Infrastructure Email Delivery from verify@ubrobotics.co.uk. We send only the destination address and minimum verification content. This address is send-only and replies are not monitored. Privacy-minimized delivery and import summaries are retained for up to 12 months; identifying administration, role, import-commit and deletion audit records are retained for up to 24 months unless identity erasure removes their identifying references sooner.

Each September, current Members become Old members and prior Old members become candidates for deletion. Nothing is deleted automatically. An Administrator must review and select candidates. Confirmed identity erasure removes the stored name and University email, unlinks the website account, revokes roles and sessions, and leaves only a non-identifying marker on the separate website account. Encrypted local rollback snapshots age out under the 14 daily, 8 weekly and 12 monthly schedule; restored data must have completed erasures reapplied before service returns.

Enlarged photograph