Legal

Privacy Policy

In accordance with Regulation (EU) 2016/679 (GDPR), the Austrian Data Protection Act (DSG) and § 165 TKG 2021

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

MIND — Verein zur Förderung der MINT Fächer

5500 Bischofshofen, pA TAZ Mitterberghütten, Werksgelände 26/Techno 5

Österreich — ZVR-Zahl 1322877055

Represented by: Bibiana Karina Ortner, Managing Director

No data protection officer is required under Art. 37 GDPR, as the association's core activities involve neither large-scale regular monitoring nor large-scale processing of special categories of data.

2. Data Collected, Purposes and Legal Bases

We process personal data only to the extent necessary for conducting the Summer School Bootcamp and for communication with participants, partner universities and interested parties.

  • a) Visiting this website. When you access the website, our hosting provider's web server automatically records: IP address, date and time of access, page requested, data volume transferred, referrer URL, browser type and version, and operating system (server log files). Purpose: technical operation, stability and security of the website (defence against attacks, error analysis). Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is the secure and uninterrupted operation of the site (cf. Recital 49 GDPR). Log files are deleted after 7 days at the latest. They are not merged with other data sources or evaluated for marketing purposes.
  • b) Contact by email. Name, email address and message content. Purpose: responding to the enquiry. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in communicating with enquirers). This website does not contain a contact form.
  • c) Programme participation. Name, study programme, university email address, telephone number (for messenger groups, see section 4), attendance and performance data within the programme. The data is transmitted to us by the inviting university (NUST) or provided by participants themselves. Purpose: organisation and delivery of the Bootcamp, communication, issuing certificates of participation. Legal basis: Art. 6(1)(b) GDPR (participation agreement).

3. Hosting and Email

This website and our email mailbox (office@magic50methode.com) are operated by the following provider, acting for us under a data processing agreement pursuant to Art. 28 GDPR:

ALL-INKL.COM – Neue Medien Münnich, Inhaber: René Münnich

Hauptstraße 68, 02742 Friedersdorf, Deutschland

Server location: Germany (EU)

all-inkl.com/datenschutzinformationen

This website loads no external resources: fonts, images and scripts are served exclusively from our own webspace. No connection is made to Google Fonts, content delivery networks, analytics or advertising services.

4. Services and Processors Used

We use the following services to deliver the programme. For messenger services: participation in groups is voluntary; no one is added without prior consent, and all programme-relevant information is provided by email on request as an alternative.

WhatsApp

WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Irland (Meta Platforms)

Purpose: Group communication with participants during the programme
Data: Telephone number, name/profile name, message content, usage metadata
Legal basis: Art. 6(1)(a) GDPR (consent), revocable at any time by leaving the group
Third-country transfer: USA — based on the EU-U.S. Data Privacy Framework (Commission adequacy decision of 10 July 2023); Meta Platforms, Inc. is certified

Telegram

Telegram FZ-LLC, Business Central Towers, Dubai, Vereinigte Arabische Emirate

Purpose: Group communication with participants during the programme
Data: Telephone number, name/username, message content, usage metadata
Legal basis: Art. 6(1)(a) GDPR (consent), revocable at any time by leaving the group
Third-country transfer: United Arab Emirates — no EU adequacy decision. Transfer solely on the basis of your explicit consent under Art. 49(1)(a) GDPR after being informed of the risks (no level of data protection comparable to the EU, limited enforceability of your rights).
Provider privacy policy: telegram.org/privacy

Zoom

Zoom Video Communications, Inc., 55 Almaden Blvd, San Jose, CA 95113, USA

Purpose: Delivery of online courses (video conferencing)
Data: Name, email, audio/video stream, chat messages, connection data
Legal basis: Art. 6(1)(b) GDPR (programme delivery)
Third-country transfer: USA — EU-U.S. Data Privacy Framework (Zoom is certified) and Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Provider privacy policy: explore.zoom.us/de/privacy/

Gather Town

Gather Presence, Inc., San Francisco, CA, USA

Purpose: Virtual workspace for teamwork and the evening Lab
Data: Name, email, avatar, audio/video stream, chat, connection data
Legal basis: Art. 6(1)(b) GDPR (programme delivery)
Third-country transfer: USA — Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Provider privacy policy: www.gather.town/privacy-policy

The learning platform (LMS/Moodle) is operated by the partner university NUST; NUST is the controller for processing there (see section 5).

5. Cooperation Partner NUST and Transfer to Pakistan

The programme is conducted in cooperation with the National University of Sciences and Technology (NUST), Islamabad, Pakistan. NUST selects and invites participants and transmits their data to us; we transmit attendance and performance data and certificates of participation to NUST. Each partner is an independent controller for its own processing.

There is no EU Commission adequacy decision for Pakistan. The transfer is based on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR (part of the cooperation agreement between MIND and NUST) and — where necessary — on the explicit consent of participants under Art. 49(1)(a) GDPR, obtained during registration after being informed of the risks.

6. Retention and Deletion

  • Server log files: 7 days at the latest.
  • Email enquiries: until fully processed, no longer than 12 months.
  • Messenger groups (WhatsApp/Telegram): dissolved no later than 3 months after the programme ends.
  • Programme data (participant lists, performance data): 3 years after the programme ends, then deleted. Certificates of participation are retained for 7 years as proof of issue (§ 132 BAO).
  • Photographs and quotations (section 9): until consent is withdrawn.

7. Your Rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where processing is based on your consent, you may withdraw it at any time with effect for the future (Art. 7(3)) without affecting the lawfulness of processing carried out before withdrawal.

To exercise your rights, contact:

office (at) magic50methode.com

You also have the right to lodge a complaint with the supervisory authority (Art. 77 GDPR): Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria, phone +43 1 52 152-0, dsb@dsb.gv.at, dsb.gv.at.

8. Cookies and Tracking

This website sets no cookies — neither technically necessary nor tracking or analytics cookies — and uses no comparable technologies (local storage, fingerprinting). No analytics tools, social media plugins or advertising services are used. A cookie banner is therefore not required (§ 165(3) TKG 2021).

9. Photographs and Testimonials

This website publishes photographs of participants, instructors and guests of previous cohorts, as well as testimonials attributed by name. Publication takes place solely with the prior written consent of the persons depicted or quoted (Art. 6(1)(a) GDPR, § 78 Austrian Copyright Act). Consent may be withdrawn at any time with effect for the future; the photograph or quotation concerned will then be removed without delay.

10. Updates to This Policy

This privacy policy is current as of September 2026. We update it when the legal framework or our processing practices change.