Privacy Policy
Information according to Art. 13 and 14 GDPR
If you have questions about data protection, you can contact us at any time: office@defendnato.org
Controller
The controller for data processing on this website is: Austrian Committee for NATO Enlargement Mag. Günther Fehlinger-Jahn Vienna, Austria office@defendnato.org
Server log files
When you visit the website, the hosting infrastructure processes standard technical access data (for example IP address, date and time, requested page, referrer, browser type) for operational security and troubleshooting. Tracking or advertising cookies are not currently embedded.
Contact and application forms
If you contact us by form or email or apply for membership, we process the data you provide (name, email, location, affiliation, message and optional details) for handling and review.
Membership
Membership is currently offered as a free application. Technical administration uses Supabase and the member portal (OpenMember). The current form does not request card details. If a paid plan is later activated, Stripe may process payment data.
Purposes of processing
Data is used to operate the website, communicate, review expressions of interest, organise chapters and administer the association.
Legal basis
Processing is based, depending on the process, on Art. 6(1)(a) GDPR (consent in the form), Art. 6(1)(b) GDPR (membership and pre-contractual steps) and Art. 6(1)(f) GDPR (legitimate interest in secure operation).
Processors and recipients
This currently includes:
- Supabase (database, authentication, membership catalogue)
- OpenMember / member portal at openmember.io
- Vercel (hosting, according to the configured site URL)
TODO: Only list further providers (newsletter, analytics, CRM) if they are actually used.
Transfers to third countries
Supabase, Vercel and — if payments are enabled — Stripe may transfer data to third countries, in particular the United States.
TODO: Add the applicable transfer mechanism (adequacy decision / EU-US Data Privacy Framework and/or standard contractual clauses).
Storage period
Data is stored only as long as required for the purpose, organisational records, security or legal obligations.
Your rights
You have the right at any time to:
- Obtain information about your data stored with us (Art. 15 GDPR)
- Request correction of incorrect data (Art. 16 GDPR)
- Request deletion of your data stored with us (Art. 17 GDPR)
- Request restriction of data processing (Art. 18 GDPR)
- Object to the processing of your data (Art. 21 GDPR)
- Request data portability (Art. 20 GDPR)
- Lodge a complaint with a data protection supervisory authority (Art. 77 GDPR)
Supervisory authority
The competent supervisory authority for the controller established in Austria is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at/.
Data protection officer
No data protection officer is named in the association details currently on file.
TODO: If a data protection officer has been or must be appointed, add the name and contact details. Otherwise remove this section.
Cookies and device storage
This website sets a strictly necessary cookie for the language preference (name: i18next) where language selection is used. Tracking or advertising cookies are not embedded.