1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
MIND — Verein zur Förderung der MINT Fächer
5500 Bischofshofen, pA TAZ Mitterberghütten, Werksgelände 26/Techno 5
Österreich — ZVR-Zahl 1322877055
Represented by: Bibiana Karina Ortner, Managing Director
No data protection officer is required under Art. 37 GDPR, as the association's core activities involve neither large-scale regular monitoring nor large-scale processing of special categories of data.
2. Data Collected, Purposes and Legal Bases
We process personal data only to the extent necessary for conducting the Summer School Bootcamp and for communication with participants, partner universities and interested parties.
- a) Visiting this website. When you access the website, our hosting provider's web server automatically records: IP address, date and time of access, page requested, data volume transferred, referrer URL, browser type and version, and operating system (server log files). Purpose: technical operation, stability and security of the website (defence against attacks, error analysis). Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is the secure and uninterrupted operation of the site (cf. Recital 49 GDPR). Log files are deleted after 7 days at the latest. They are not merged with other data sources or evaluated for marketing purposes.
- b) Contact by email. Name, email address and message content. Purpose: responding to the enquiry. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in communicating with enquirers). This website does not contain a contact form.
- c) Programme participation. Name, study programme, university email address, telephone number (for messenger groups, see section 4), attendance and performance data within the programme. The data is transmitted to us by the inviting university (NUST) or provided by participants themselves. Purpose: organisation and delivery of the Bootcamp, communication, issuing certificates of participation. Legal basis: Art. 6(1)(b) GDPR (participation agreement).
3. Hosting and Email
This website and our email mailbox (office@magic50methode.com) are operated by the following provider, acting for us under a data processing agreement pursuant to Art. 28 GDPR:
ALL-INKL.COM – Neue Medien Münnich, Inhaber: René Münnich
Hauptstraße 68, 02742 Friedersdorf, Deutschland
Server location: Germany (EU)
This website loads no external resources: fonts, images and scripts are served exclusively from our own webspace. No connection is made to Google Fonts, content delivery networks, analytics or advertising services.
4. Services and Processors Used
We use the following services to deliver the programme. For messenger services: participation in groups is voluntary; no one is added without prior consent, and all programme-relevant information is provided by email on request as an alternative.
WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Irland (Meta Platforms)
Telegram
Telegram FZ-LLC, Business Central Towers, Dubai, Vereinigte Arabische Emirate
Zoom
Zoom Video Communications, Inc., 55 Almaden Blvd, San Jose, CA 95113, USA
Gather Town
Gather Presence, Inc., San Francisco, CA, USA
The learning platform (LMS/Moodle) is operated by the partner university NUST; NUST is the controller for processing there (see section 5).
5. Cooperation Partner NUST and Transfer to Pakistan
The programme is conducted in cooperation with the National University of Sciences and Technology (NUST), Islamabad, Pakistan. NUST selects and invites participants and transmits their data to us; we transmit attendance and performance data and certificates of participation to NUST. Each partner is an independent controller for its own processing.
There is no EU Commission adequacy decision for Pakistan. The transfer is based on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR (part of the cooperation agreement between MIND and NUST) and — where necessary — on the explicit consent of participants under Art. 49(1)(a) GDPR, obtained during registration after being informed of the risks.
6. Retention and Deletion
- Server log files: 7 days at the latest.
- Email enquiries: until fully processed, no longer than 12 months.
- Messenger groups (WhatsApp/Telegram): dissolved no later than 3 months after the programme ends.
- Programme data (participant lists, performance data): 3 years after the programme ends, then deleted. Certificates of participation are retained for 7 years as proof of issue (§ 132 BAO).
- Photographs and quotations (section 9): until consent is withdrawn.
7. Your Rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where processing is based on your consent, you may withdraw it at any time with effect for the future (Art. 7(3)) without affecting the lawfulness of processing carried out before withdrawal.
To exercise your rights, contact:
office (at) magic50methode.comYou also have the right to lodge a complaint with the supervisory authority (Art. 77 GDPR): Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria, phone +43 1 52 152-0, dsb@dsb.gv.at, dsb.gv.at.
8. Cookies and Tracking
This website sets no cookies — neither technically necessary nor tracking or analytics cookies — and uses no comparable technologies (local storage, fingerprinting). No analytics tools, social media plugins or advertising services are used. A cookie banner is therefore not required (§ 165(3) TKG 2021).
9. Photographs and Testimonials
This website publishes photographs of participants, instructors and guests of previous cohorts, as well as testimonials attributed by name. Publication takes place solely with the prior written consent of the persons depicted or quoted (Art. 6(1)(a) GDPR, § 78 Austrian Copyright Act). Consent may be withdrawn at any time with effect for the future; the photograph or quotation concerned will then be removed without delay.
10. Updates to This Policy
This privacy policy is current as of September 2026. We update it when the legal framework or our processing practices change.