1. Who we are
GoAustria operates the community platform at https://goaustria.org, serving international education and mobility to Austria. For data protection purposes, GoAustria is the data controller for personal data processed through this website unless stated otherwise.
- Privacy enquiries: privacy@goaustria.org
- Data Protection Officer: dpo@goaustria.org
- General support: support@goaustria.org
2. Scope
This Privacy Policy applies to visitors and registered members worldwide who use goaustria.org. It is designed to meet the requirements of the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), UK GDPR, and comparable international privacy laws. It does not cover third-party websites linked from our platform (such as official university portals).
3. Personal data we collect
3.1 Information you provide
- Account data: email address, password (stored hashed), display name, phone number, username
- Community content: questions, discussions, comments, uploads, tags
- Ambassador program data: legal name, country, phone, email, and government-issued identity or residency document (for members living in Austria)
- Free profile evaluation applications: study plans, qualifications, answers to assessment questions, PDF documents
- Communications you send to our team
3.2 Information collected automatically
- Technical data: IP address, browser type, device information, timestamps
- Security signals processed by Cloudflare Turnstile to prevent abuse
- Session and authentication cookies (see our Cookie Policy)
- Usage data where you have consented to analytics cookies
4. Purposes and legal bases (GDPR)
We process personal data only where a lawful basis applies:
| Purpose | Legal basis |
|---|---|
| Providing the platform, accounts, and community features | Contract (Art. 6(1)(b) GDPR) |
| Security, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f) GDPR) |
| Moderation and enforcement of community standards | Legitimate interests / legal obligation |
| Ambassador program review and badge approval | Contract and consent where required |
| Transactional emails (verification codes, account notices) | Contract / legitimate interests |
| Analytics to improve the service | Consent (Art. 6(1)(a) GDPR) via cookie preferences |
| Compliance with law and responding to authorities | Legal obligation (Art. 6(1)(c) GDPR) |
5. Processors and international transfers
We use trusted service providers who process data on our instructions:
- Supabase, authentication, database and file storage (EU/US regions depending on project configuration)
- Cloudflare, security, Turnstile bot protection and content delivery
- Resend, transactional email delivery
- Vercel, website hosting and edge delivery
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses and supplementary measures required under GDPR Chapter V.
6. Retention
We retain personal data only as long as necessary for the purposes above:
- Account data: for the life of your account plus a reasonable period after deletion
- Community posts: until you delete them or they are removed under our moderation policy
- Verification documents: reviewed promptly; retained only as long as needed for audit and legal compliance
- Server logs: typically up to 90 days unless required for security investigations
- Cookie consent records: up to 12 months, then we ask again
7. Your rights
Depending on your location, you may have the following rights under GDPR and comparable laws:
- Access: obtain a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion ("right to be forgotten")
- Restriction: limit how we use your data
- Portability: receive data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Withdraw consent: at any time for consent-based processing (e.g. analytics cookies)
To exercise your rights, email privacy@goaustria.org. We respond within one month as required by GDPR. You may also lodge a complaint with the Austrian Data Protection Authority (DSB) or your local supervisory authority.
8. Children
GoAustria is intended for users aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child has provided personal data, contact us and we will delete it promptly.
9. Security
We implement technical and organisational measures including encryption in transit, access controls, moderated publishing workflows, and staff-only admin tools. No method of transmission over the Internet is 100% secure; we encourage strong passwords and protecting your account credentials.
10. Changes
We may update this policy to reflect legal or operational changes. Material updates will be noted on this page with a revised "Last updated" date. Continued use after changes constitutes acceptance where permitted by law.



