Privacy Policy

Information according to Art. 13 and 14 GDPR

If you have questions about data protection, you can contact us at any time: office@defendnato.org

01

Controller

The controller for data processing on this website is: Austrian Committee for NATO Enlargement Mag. Günther Fehlinger-Jahn Vienna, Austria office@defendnato.org

02

Server log files

When you visit the website, the hosting infrastructure processes standard technical access data (for example IP address, date and time, requested page, referrer, browser type) for operational security and troubleshooting. Tracking or advertising cookies are not currently embedded.

03

Contact and application forms

If you contact us by form or email or apply for membership, we process the data you provide (name, email, location, affiliation, message and optional details) for handling and review.

04

Membership

Membership is currently offered as a free application. Technical administration uses Supabase and the member portal (OpenMember). The current form does not request card details. If a paid plan is later activated, Stripe may process payment data.

05

Purposes of processing

Data is used to operate the website, communicate, review expressions of interest, organise chapters and administer the association.

06

Legal basis

Processing is based, depending on the process, on Art. 6(1)(a) GDPR (consent in the form), Art. 6(1)(b) GDPR (membership and pre-contractual steps) and Art. 6(1)(f) GDPR (legitimate interest in secure operation).

07

Processors and recipients

This currently includes:

  • Supabase (database, authentication, membership catalogue)
  • OpenMember / member portal at openmember.io
  • Vercel (hosting, according to the configured site URL)

TODO: Only list further providers (newsletter, analytics, CRM) if they are actually used.

08

Transfers to third countries

Supabase, Vercel and — if payments are enabled — Stripe may transfer data to third countries, in particular the United States.

TODO: Add the applicable transfer mechanism (adequacy decision / EU-US Data Privacy Framework and/or standard contractual clauses).

09

Storage period

Data is stored only as long as required for the purpose, organisational records, security or legal obligations.

10

Your rights

You have the right at any time to:

  • Obtain information about your data stored with us (Art. 15 GDPR)
  • Request correction of incorrect data (Art. 16 GDPR)
  • Request deletion of your data stored with us (Art. 17 GDPR)
  • Request restriction of data processing (Art. 18 GDPR)
  • Object to the processing of your data (Art. 21 GDPR)
  • Request data portability (Art. 20 GDPR)
  • Lodge a complaint with a data protection supervisory authority (Art. 77 GDPR)
11

Supervisory authority

The competent supervisory authority for the controller established in Austria is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at/.

12

Data protection officer

No data protection officer is named in the association details currently on file.

TODO: If a data protection officer has been or must be appointed, add the name and contact details. Otherwise remove this section.

13

Cookies and device storage

This website sets a strictly necessary cookie for the language preference (name: i18next) where language selection is used. Tracking or advertising cookies are not embedded.

Cookies