Privacy
Last updated: 12 September 2026
This policy describes which personal data are processed when you visit this website, for what purpose and on what legal basis. The applicable law is the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
1. Data Controller and Contact
The controller responsible for the processing of personal data on this website is:
Association Zeit am See Sailing (operating as "Zeit am See Sailing Team")ZVR number: 1427035842 (registration authority: Bezirkshauptmannschaft Vöcklabruck)Mühlbach 714864 Attersee am AtterseeAustria
Represented by its chairman, Tobias Böckl.
Contact:Email: office@zeitamseesailing.atPhone: +43 664 42 20 937
2. Hosting via Cloudflare
Our website is delivered through Cloudflare's content delivery network and the "Cloudflare Workers" platform, provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Every time you visit our website, your browser automatically sends data to Cloudflare's servers. This includes your IP address, the exact time of access, the requested resource (URL), your user agent (browser type and version), and the referrer (the previously visited page). Cloudflare requires this data to deliver the website, route traffic, and protect the site against attacks.
The legal basis is our legitimate interest in delivering the website securely and quickly (Art. 6 (1) (f) GDPR).
We receive no access logs from Cloudflare: the logging feature required for this (Logpush for HTTP requests) is only available on the Enterprise plan. Our website consists exclusively of static files; we run no program of our own on Cloudflare's servers. Cloudflare itself states that it processes connection data for a limited period of time, in data centres in the US and in Europe.
Processing on our behalf is governed by Cloudflare's data protection addendum, which forms part of the terms of service; no separate contract is required. Data may be transferred to the US; that transfer relies on the European Commission's standard contractual clauses. Cloudflare also states that it is certified under the EU-US Data Privacy Framework.
3. Image CDN (Sanity)
All images on this website are loaded via an external content delivery network (cdn.sanity.io). The provider of this service is Sanity US Inc., 351 California Street, Suite 650, San Francisco, CA 94104, USA.
With every page load, your browser establishes direct connections to Sanity's servers to fetch images (resulting in numerous simultaneous requests on the homepage, for example). This inevitably transmits your IP address to Sanity. The dataset for our website is configured to be publicly readable.
The legal basis is our legitimate interest in delivering our images quickly and reliably (Art. 6 (1) (f) GDPR).
Sanity's data processing agreement forms part of its terms of service automatically — no separate signature is required — and incorporates the European Commission's standard contractual clauses. The transfer to the US relies on those clauses.
4. No Audience Measurement
This website does not use any tools for audience measurement, analytics or advertising. Apart from the images from Sanity (section 3), it does not embed content from any other provider.
5. Contact, Collection Orders, and Association Support
Email and Telephone
When you contact us via email or telephone, we process your details to answer your inquiry. This is based on Art. 6 (1) (b) GDPR (pre-contractual/contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest). We delete the data once the request is fully resolved and no legal retention periods apply.
Collection Orders
We do not offer a direct purchase function on the website. The order button simply opens a pre-filled email in your email client, asking for the design, size, quantity and your name and address. If you send us this email, we process the data strictly to handle your order (Art. 6 (1) (b) GDPR).
Association Support via Bank Transfer
Our bank details are publicly available on the homepage. If you transfer a support contribution to us, your bank transmits your name and account details on our bank statements. We process this data for accounting purposes and to issue a receipt upon request. The legal basis is the fulfilment of legal and tax obligations (Art. 6 (1) (c) GDPR) and the processing of the donation (Art. 6 (1) (b) GDPR). We keep accounting records for seven years as required by § 132 of the Austrian Federal Fiscal Code (BAO).
6. Fonts
The fonts we use ("Source Serif 4" and "Jost") are served locally from our server. No requests are made to font services run by Google or other providers, so your IP address is not passed on to anyone in this context.
7. Admin Interface
The website includes an editorial environment at /studio intended solely for the association, not for visitors. Opening it connects your browser to Sanity's servers (see section 3); when you log in, Sanity stores login information in your browser. The editorial environment is not loaded when you visit the rest of the website.
8. Data Subject Rights and Supervisory Authority
Under the GDPR, you have the following rights:
- Access (Art. 15 GDPR): Right to information about your processed data.
- Rectification (Art. 16 GDPR): Correction of inaccurate data.
- Erasure (Art. 17 GDPR): Deletion of your data, provided no legal retention duties oppose it.
- Restriction (Art. 18 GDPR): Restricting the processing of your data under certain conditions.
- Objection (Art. 21 GDPR): Objecting to processing based on our legitimate interest.
- Data Portability (Art. 20 GDPR): Receiving your data in a commonly used format.
To exercise these rights, an email to office@zeitamseesailing.at is sufficient.
Right to Lodge a Complaint
If you believe that our processing violates data protection laws, you can contact the supervisory authority:
Österreichische DatenschutzbehördeBarichgasse 40–42, 1030 ViennaEmail: dsb@dsb.gv.at
9. No Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects concerning you.
