Protecting your data
Privacy information
This notice covers two separate surfaces: the static event website and the separately provided volunteer portal.
Last updated: 11 August 2026
Giveaway, website and tablet entry, and newsletter
10.09.2026
The controller is Ruderverein Villach von 1881, Ossiachersee-Süduferstraße 67, 9523 Villach-Landskron, Austria, ZVR 186547003. Contact: office@wrmr2028.com. The website and tablet entry routes record your name, email, birth year, country, preferred accommodation, companions, optional free-text answer, language, timestamp, entry source and accepted terms version. Do not include health information or other people’s personal data in the free-text answer.
The publicly visible profile, comment and contact details supplied for prize fulfilment are processed to run the giveaway. Data is disclosed only to service partners required for fulfilment and deleted after completion, subject to statutory retention duties. Further information is available in the website privacy policy.
Name, email, age information and acceptance of the terms are processed to run the giveaway (GDPR Article 6(1)(b)). Country, accommodation and companion preferences and the optional answer support event planning based on our legitimate interest (Article 6(1)(f)). You can object at office@wrmr2028.com. These answers do not determine your chance of winning or any automated winner selection. After completion, planning information is used only anonymously; personal giveaway data is deleted unless required for prize fulfilment, statutory retention or specific legal claims.
The newsletter requires separate, voluntary consent (Article 6(1)(a)). Subscription becomes active only after email confirmation. We store your email, name if provided, language and consent evidence. Withdraw at any time using the unsubscribe link or office@wrmr2028.com. Withdrawal does not affect past lawful processing or giveaway entry. Unconfirmed subscriptions become inactive after 7 days and receive no newsletter. After withdrawal, data is no longer used for newsletters; necessary consent evidence is retained only for legal accountability.
We use Cloudflare for hosting, database and abuse prevention and Brevo for email delivery as processors. Cloudflare Turnstile processes technical device and connection information to prevent automated entries (legitimate interest, Article 6(1)(f)). Processing outside the EEA is covered by appropriate safeguards such as EU standard contractual clauses or an applicable adequacy decision. Only authorised administrators can access entries; there is no public participant list. Tablet inputs are cleared after successful submission or an inactivity warning.
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection and may complain to the Austrian Data Protection Authority (dsb.gv.at). The required fields are necessary for entry through the website or tablet form; the social entry route remains available under the terms. The separate newsletter sign-up form on our website does not enter you into the giveaway.
Controller
Ruderverein Villach von 1881 · Ossiachersee-Süduferstraße 67 · 9523 Villach-Landskron · Austria
ZVR 186547003 · Email: office@rvvillach.at · Telephone: +43 660 8471575
Static event website and hosting
The public event website is delivered as a static website through Cloudflare. When accessed, technically necessary connection data is processed, in particular IP address, time, requested resource, amount of data transferred, browser and operating-system information and referrer. This supports secure, reliable and efficient delivery and abuse prevention.
Processing is based on our legitimate interest in a secure and functional website under Article 6(1)(f) GDPR. The event website currently uses no audience analytics, advertising trackers or non-essential cookies.
Volunteer portal, abuse prevention and necessary cookies
The volunteer portal is provided as a separate application linked from the event website. Cloudflare Turnstile protects expressions of interest, repeated verification messages and login against automated submissions. The verification token and technically necessary connection data, including the IP address, are transmitted to Cloudflare. Turnstile is not used for advertising or audience measurement.
After successful login, the portal sets only necessary session and CSRF cookies protected by Secure and SameSite=Strict. The session cookie is HttpOnly; the CSRF cookie supports verification of state-changing requests. Sign-in and protected portal functions cannot work without these cookies. They are not used for tracking or newsletters.
Volunteer expression of interest and required fields
An initial expression of interest requires first name, last name, date of birth, email address, language and the accepted version of the volunteer terms. Without these required fields, the expression of interest cannot be submitted or the email address verified. Date of birth supports age-appropriate communications, safeguarding and assessment of possible roles.
Later portal stages may request clearly identified profile data where needed, including telephone number, address, languages, experience, availability, preferred tasks, clothing size, emergency contact and support needs. Required and optional details are identified. Missing information required for a particular role may leave an application incomplete or prevent assignment.
The data is used solely to assess and organise possible volunteering, allocation, training, accreditation, equipment, safety and operational event communications. An expression of interest is non-binding and does not guarantee a role.
Depending on the specific step, processing is based on action requested under Article 6(1)(b) GDPR where applicable or legitimate interests in reliable event and workforce planning under Article 6(1)(f). Where required, separate consent under Article 6(1)(a) is obtained for expressly optional details or functions.
Email verification, login and security records
A personal time-limited verification link is sent to confirm an expression of interest. Later passwordless login uses a time-limited six-digit one-time code sent to the verified email address. Challenge identifier, cryptographically protected token or code, expiry, failed attempts and consumption time are processed for this purpose.
For rate limiting, evidence of accepted terms and security-relevant audits, the application uses keyed IP hashes rather than storing the clear IP in those application records. Cloudflare may still process the IP address in its necessary network and security logs. Terms/consent, audit, email-delivery and error records may include timestamps, document version, source, actor, action, affected record, delivery status and technical references.
Internal access, roles and exports
Authorised members of the organising team access only data required for their role. Roles include administrators, coordinators and team leaders with global or area-limited permissions. Access and material changes are logged.
Specifically authorised roles may export filtered volunteer data as CSV where necessary for event planning and delivery. The export is logged. Once downloaded, the file also exists on the device used and must be protected and deleted when no longer needed.
Children and young people
Younger people may express an interest; being under 14 is not technically blocked at the initial stage. Before any possible assignment, the organiser separately determines what age-appropriate information, involvement and legally required verifiable approval by a parent or guardian are necessary. Initial acceptance of the volunteer terms is neither parental approval nor the child’s GDPR consent.
Any later role for a minor also depends on suitability, the task, safeguarding, supervision and applicable law.
Storage and service providers
Volunteer data is stored in a Cloudflare D1 database with EU jurisdiction. This setting applies to D1 and does not mean that every Cloudflare service is provided only in the EU. Cloudflare also supports hosting, Turnstile, security and technical logging. Brevo is used for transactional emails and operational messages.
When these service providers are used, data may be processed outside the European Economic Area or accessed from there. The applicable data-processing terms and any required transfer mechanisms or supplementary safeguards apply.
No newsletter linkage
Volunteer registration is not linked to a newsletter. Contact details are not automatically added to a marketing or newsletter list. Any future newsletter would be a separate, voluntary process with its own information and consent.
Retention and logs
We retain personal data only for as long as it is needed for the relevant purpose and necessary evidence, or as required by legal obligations or the establishment, exercise or defence of legal claims. Relevant criteria include the status of the expression of interest, withdrawal, the end of the relevant organisational purpose, the lifetime of a session or security challenge, and statutory retention duties.
Data that is no longer required is deleted or anonymised. Downloaded export files must also be deleted from the device used once their organisational purpose ends.
Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn for the future. Send data-protection requests to office@rvvillach.at; operational volunteer questions may be sent to volunteers@wrmr2028.com. We may request appropriate proof of identity.
You may also lodge a complaint with a data protection authority. In Austria, this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at.
Changes to this notice
We update this privacy notice when features, providers or the legal framework change. Information required for any new processing will be provided before the relevant feature is used.
