Protecting your data
Privacy information
This notice covers two separate surfaces: the static event website and the separately provided volunteer portal.
Last updated: 11 August 2026
Controller
Ruderverein Villach von 1881 · Ossiachersee-Süduferstraße 67 · 9523 Villach-Landskron · Austria
ZVR 186547003 · Email: office@rvvillach.at · Telephone: +43 660 8471575
Static event website and hosting
The public event website is delivered as a static website through Cloudflare. When accessed, technically necessary connection data is processed, in particular IP address, time, requested resource, amount of data transferred, browser and operating-system information and referrer. This supports secure, reliable and efficient delivery and abuse prevention.
Processing is based on our legitimate interest in a secure and functional website under Article 6(1)(f) GDPR. The event website currently uses no audience analytics, advertising trackers or non-essential cookies.
Volunteer portal, abuse prevention and necessary cookies
The volunteer portal is provided as a separate application linked from the event website. Cloudflare Turnstile protects expressions of interest, repeated verification messages and login against automated submissions. The verification token and technically necessary connection data, including the IP address, are transmitted to Cloudflare. Turnstile is not used for advertising or audience measurement.
After successful login, the portal sets only necessary session and CSRF cookies protected by Secure and SameSite=Strict. The session cookie is HttpOnly; the CSRF cookie supports verification of state-changing requests. Sign-in and protected portal functions cannot work without these cookies. They are not used for tracking or newsletters.
Volunteer expression of interest and required fields
An initial expression of interest requires first name, last name, date of birth, email address, language and the accepted version of the volunteer terms. Without these required fields, the expression of interest cannot be submitted or the email address verified. Date of birth supports age-appropriate communications, safeguarding and assessment of possible roles.
Later portal stages may request clearly identified profile data where needed, including telephone number, address, languages, experience, availability, preferred tasks, clothing size, emergency contact and support needs. Required and optional details are identified. Missing information required for a particular role may leave an application incomplete or prevent assignment.
The data is used solely to assess and organise possible volunteering, allocation, training, accreditation, equipment, safety and operational event communications. An expression of interest is non-binding and does not guarantee a role.
Depending on the specific step, processing is based on action requested under Article 6(1)(b) GDPR where applicable or legitimate interests in reliable event and workforce planning under Article 6(1)(f). Where required, separate consent under Article 6(1)(a) is obtained for expressly optional details or functions.
Email verification, login and security records
A personal time-limited verification link is sent to confirm an expression of interest. Later passwordless login uses a time-limited six-digit one-time code sent to the verified email address. Challenge identifier, cryptographically protected token or code, expiry, failed attempts and consumption time are processed for this purpose.
For rate limiting, evidence of accepted terms and security-relevant audits, the application uses keyed IP hashes rather than storing the clear IP in those application records. Cloudflare may still process the IP address in its necessary network and security logs. Terms/consent, audit, email-delivery and error records may include timestamps, document version, source, actor, action, affected record, delivery status and technical references.
Internal access, roles and exports
Authorised members of the organising team access only data required for their role. Roles include administrators, coordinators and team leaders with global or area-limited permissions. Access and material changes are logged.
Specifically authorised roles may export filtered volunteer data as CSV where necessary for event planning and delivery. The export is logged. Once downloaded, the file also exists on the device used and must be protected and deleted when no longer needed.
Children and young people
Younger people may express an interest; being under 14 is not technically blocked at the initial stage. Before any possible assignment, the organiser separately determines what age-appropriate information, involvement and legally required verifiable approval by a parent or guardian are necessary. Initial acceptance of the volunteer terms is neither parental approval nor the child’s GDPR consent.
Any later role for a minor also depends on suitability, the task, safeguarding, supervision and applicable law.
Storage and service providers
Volunteer data is stored in a Cloudflare D1 database with EU jurisdiction. This setting applies to D1 and does not mean that every Cloudflare service is provided only in the EU. Cloudflare also supports hosting, Turnstile, security and technical logging. Brevo is used for transactional emails and operational messages.
When these service providers are used, data may be processed outside the European Economic Area or accessed from there. The applicable data-processing terms and any required transfer mechanisms or supplementary safeguards apply.
No newsletter linkage
Volunteer registration is not linked to a newsletter. Contact details are not automatically added to a marketing or newsletter list. Any future newsletter would be a separate, voluntary process with its own information and consent.
Retention and logs
We retain personal data only for as long as it is needed for the relevant purpose and necessary evidence, or as required by legal obligations or the establishment, exercise or defence of legal claims. Relevant criteria include the status of the expression of interest, withdrawal, the end of the relevant organisational purpose, the lifetime of a session or security challenge, and statutory retention duties.
Data that is no longer required is deleted or anonymised. Downloaded export files must also be deleted from the device used once their organisational purpose ends.
Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn for the future. Send data-protection requests to office@rvvillach.at; operational volunteer questions may be sent to volunteers@wrmr2028.com. We may request appropriate proof of identity.
You may also lodge a complaint with a data protection authority. In Austria, this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at.
Changes to this notice
We update this privacy notice when features, providers or the legal framework change. Information required for any new processing will be provided before the relevant feature is used.