Community Terms of Use
These Community Terms of Use explain how people may participate in The Aris Club, its Discord server, GitHub Organization, Google Forms and Sheets, events, research and other club services. They are written in English first. A Vietnamese version may be prepared when required by HCMIU/HSV/CTSV.
1. Scope
These terms apply to:
- A club member.
- An applicant.
- A Trial member.
- A person who participates in a club activity or event.
- An external community participant.
- A partner, guest or observer.
- A person who contributes to a club project or repository.
- A person who uses an official club communication or collaboration service.
The terms apply alongside the code of conduct, the privacy and data policy, the charter and any applicable decision record or ADR. Those documents are held by the club and are available on request.
2. Acceptance
A person accepts these terms by:
- Joining onboarding.
- Accepting the server rules or a required form.
- Submitting a recruitment or access request.
- Using a club service after notice of these terms.
- Signing a required record where a later policy requires it.
The club must record the version and date of the terms accepted. It must not store a private signature or unnecessary identity document in Git or Discord.
A person may ask what the terms mean and may request a reasonable accessibility or communication adjustment before accepting a task or role.
3. Club status and authority
The club is a founding group preparing a proposed student organization. Nothing in these terms:
- Recognizes The Aris Club as an official HCMIU organization.
- Replaces HCMIU, HSV or CTSV authority.
- Allows the club to speak as a university authority.
- Allows the club to collect fees, sponsorship or donations without required approval.
- Allows the club to make medical, legal, educational or other professional decisions.
The club follows the authority and requirements that HCMIU/HSV/CTSV must exercise for a student club. The club may adopt stricter internal rules. Where an external rule, approval or decision applies, that external requirement controls.
Names, logos, links and public claims about HCMIU require written permission.
4. Eligibility and participation status
Until the competent authority confirms otherwise, voting and official membership rights are reserved for eligible students. Other people may participate as External Community members, Partners, Guests or Observers with limited access.
Participation status is not a rank:
- Community members are not Members.
- Partners are not Members by default.
- Guests and Observers are not Members.
- Alumni retain only the rights defined by the club.
- Bot, GitHub and Discord roles are access permissions, not legal titles.
5. Conduct
Everyone must:
- Respect people and differences.
- Ask before photographing, recording or sharing personal information.
- Keep confidential information confidential.
- Do not impersonate another person or organization.
- Do not harass, threaten, deceive, exploit or retaliate.
- Disclose conflicts of interest.
- Follow safety instructions for events, hardware, research and data.
- Report an incident through the approved channel.
- Accept reasonable access limits needed to protect people, systems and records.
The code of conduct defines the full expectations and escalation route.
6. Accounts, identity and access
A person must use an account they control. Do not share passwords, tokens, MFA codes, recovery keys or access to another person's account.
Access is limited to the minimum needed for a role. Leaving a role, leaving the club or ending a project may require access revocation. Members must complete handover before losing access.
The club may use a temporary personal account or transitional Gmail mailbox during setup. A production service must have a domain mailbox, service account, 2FA, recovery method and a documented backup owner.
7. Privacy and data
Do not submit to Git, Discord, a public Form or a shared Sheet:
- CCCD or an identity document.
- A full CV unless the approved restricted flow explicitly requests it.
- Student ID outside the restricted verification flow.
- Phone number, address or unnecessary personal data.
- Passwords, tokens, private keys, MFA codes or API keys.
- Health, student, research or other sensitive data without the required basis and protection.
The club collects the minimum data needed for the stated purpose. Data subjects may request access, correction or deletion where the law and the applicable policy allow.
Google Sheets used during the current operating phase are operational records, not official legal records. A restricted record must have an owner, access list, retention date and deletion procedure.
8. Content and intellectual property
A member keeps ownership of work they create unless a separate written agreement says otherwise. By submitting work to a club project, the contributor grants the club a non-exclusive, limited licence to store, run, review, display, maintain and hand over that work for the club's stated purpose.
The club must not:
- Reuse private work for unrelated training or commercial purposes.
- Remove authorship or license information.
- Publish a work that contains another person's confidential data.
- Claim ownership of external libraries, data or third-party content.
A work containing another person's data, a restricted dataset or an unclear license must not be published until the issue is resolved.
9. AI and automation
AI may assist with drafting, questions, summaries, translation, search, data-quality checks and routine reminders. It does not make final membership, recruitment, disciplinary, financial, legal, medical, educational or deployment decisions.
The club will not send personal data, student ID, full CVs, raw answers, scores, private channels or moderation records to an AI provider by default. Any AI interview dataset requires a separate policy, opt-in, de-identification, retention rule and human review.
A person may refuse an AI-assisted process without losing the right to a fair human review, unless the process is not used at all for that role.
A bot may prepare a draft, reminder or approval card. It may not independently accept, reject, promote, remove, discipline, vote, merge, deploy, spend money or bypass an approval.
10. Sponsorship and club funds
No sponsorship, donation or fee may be offered or accepted until the required approval and written terms exist.
Once a sponsorship is authorized:
- All received funds must be recorded in the club's approved financial process.
- The Treasurer/Secretary and the approved second controller maintain the records.
- Money received for one purpose must not be used for another purpose without approval.
- A monthly financial report is prepared for the members and Board.
- Receipts, approvals and unresolved items are recorded without unnecessary personal data.
- No public sponsor claim may be made beyond the written agreement.
A sponsorship does not give a sponsor control over research results, member decisions, confidential data or the club's internal governance.
11. Roles, projects and records
Roles are assigned for a scope and term. They are not ranks. A member may have one primary department, support another department with an explicit assignment, and hold a temporary task without gaining new authority.
Every project or activity must identify:
- Purpose and owner.
- Deliverable and acceptance criteria.
- Deadline and escalation contact.
- Safety and data check.
- Handover or closing decision.
The club's decision log, ADRs, meeting records and project records remain separate from informal chat. Discord is a communication and coordination surface, not a replacement for a formal record.
12. Moderation and safety
The club may use proportionate measures, including:
- A reminder or commitment.
- Training or an improvement plan.
- Temporary access limits.
- Suspension from an activity.
- Transfer to HCMIU/HSV/CTSV or another competent authority.
- Ending membership when a decision has a proper basis and an appeal route.
Moderators do not receive automatic removal authority. Bot automation does not remove or promote a member. Each measure records the reason, evidence, owner, duration and appeal route.
A serious safety risk may justify stopping a system or activity immediately. The action is recorded and confirmed later.
13. Complaints and appeals
A person may report a concern to a Department Lead, the Board, an Independent Report Recipient or the competent authority. A report should include enough information to understand the issue, without sending unnecessary sensitive data.
An appeal must follow the published route. The reviewer must not be the sole original decision-maker for the same case. A person acting in good faith must not be retaliated against.
14. External services and availability
Discord, GitHub, Google services, bots and other tools may be changed, paused or replaced. A service is not guaranteed to be always available. Important records must not exist only in a chat message or an unapproved tool.
Users must not use a club service to distribute malware, attack systems, scrape private data, or bypass access controls.
15. Changes and termination
These terms are versioned. A change record identifies:
- Version and date.
- What changed and why.
- Effective date.
- Person responsible.
- Any required approval.
- Where the new version is stored.
Material changes are announced before they take effect where practical. A person who does not accept a required change may have their access paused or ended under the applicable rule; access is not removed without a recorded reason and handover where the change is administrative.
16. Contact
Questions about these terms, data requests, complaints or appeals go through the approved club contact channel and the relevant HCMIU/HSV/CTSV authority where required. Until the club has a domain mailbox, write to the club contact address.
Do not send passwords, tokens, identity documents or unnecessary personal data in an informal message.