Privacy policy
Protecting your data matters to us. Here you can find out which data the website and app of our association (Kultur und Sportverein Bambi) process, why, and what your rights are.
1. Controller
Kultur und Sportverein Bambi, Huttengasse 81/6, 1160 Wien, ZVR number 802868214, represented by Milan Stojkovic. For data protection questions contact us at [email protected]. We have not appointed a data protection officer because the club is not required to (Art. 37 GDPR).
2. What data we process
Account: name, email address and password (stored only as a hash, not readable). Membership: group, phone number for emergencies (optional). Profile photo (optional). Club life: training attendance, absence reports with an optional reason, replies to events, poll votes. Fees: which months are paid. Technical: login sessions with a device label (browser type) and the time of your last login, failed login attempts (email and IP address), the time you agreed to the terms of use and this privacy policy and – if you enable push notifications – your device's push address. Membership card: card number, first and last name, date of birth, member since, passport photo and which yearly fees are paid.
3. Where the data comes from
You enter most data yourself. Some data is entered by club officials as part of their club task: the treasurer records your fee payments, trainers your attendance, the administrator your role and group. Parents enter their children's name and group themselves; the administrator approves the entries. The membership card data and photo are entered by the club (the administrator takes the photo); the treasurer confirms the yearly fees.
4. Purposes and legal bases
Membership administration, organising rehearsals and performances, attendance, polls, event replies and fees: to perform the membership under the club's statutes (Art. 6(1)(b) GDPR). Keeping payment records: legal obligation (Art. 6(1)(c) GDPR with § 132 BAO). Push notifications and profile photo: your consent (Art. 6(1)(a) GDPR), which you can withdraw in your profile at any time with effect from then. Login protection, session data, last login and device list: legitimate interest in the security of the app and of your account (Art. 6(1)(f) GDPR).
5. Who sees your data within the club
Only as much as each task requires: trainers see their groups' attendance, the treasurer sees fee payments, the secretary sees who voted how in polls and event replies (everyone else only sees the numbers there), the administrator sees everything for administration. We do not sell data or share it for advertising. Your membership card is only seen by you (for children: the parents), the treasurer and the administrator.
6. Service providers and transfers to third countries
The app runs on a computer operated by the club in Austria, which also holds the database. Access from the internet goes through Cloudflare, Inc. (USA) as a processor; Cloudflare forwards the encrypted connection and may process technical data such as your IP address. Push notifications are delivered through the push service of your browser or device (e.g. Google, Apple, Mozilla); the content is end-to-end encrypted and cannot be read by these services. These providers may process data in third countries such as the USA; where they are certified under the EU-US Data Privacy Framework, an adequacy decision of the European Commission applies (Art. 45 GDPR). Fonts are loaded from our own server – there is no connection to Google Fonts or other third parties. The start page embeds a Google Maps map (Google Ireland Limited, Ireland) showing where we are. When the page loads, your IP address and technical browser data are sent to Google, which may also process them in the USA; Google may also set cookies. If you do not want this, you can find our address on the Contact page as well.
7. Cookies and storage on your device
We only use one technically necessary cookie that keeps you signed in (members 30 days, club officials 7 days). So that the app also works without internet, it stores the pages you last opened on your device; they are deleted when you sign out. Your device also remembers whether you already answered the push notification question. All of this is required for the service you asked for (§ 165(3) TKG 2021). There are no ads, no Google Analytics and no other tracking or analytics services – which is why there is no cookie banner.
8. How long we keep data
As long as your membership lasts. After you leave we delete your account and data unless the law requires us to keep it (accounting records of fee payments: seven years, § 132 BAO). Failed login attempts are deleted after one day, expired sessions automatically. Rejected registrations are deleted immediately.
9. Do you have to give us data?
We need your name, email address and group to run your account – without them you cannot use the app. Phone number, profile photo and push notifications are optional.
10. No automated decisions
We do not make decisions based solely on automated processing and do not create profiles (Art. 22 GDPR). A person always decides about approving accounts and about roles.
11. Children and young people
The app can be used at any age. For children under 14, parents or guardians decide about optional details such as the profile photo (§ 4(4) DSG). Please don't give detailed health information in absence reports – a short note like “ill” is enough. Parents can add their children to their own account without a separate email address; they then see their children's timetable, fees and attendance and can report them absent.
12. Security
The connection is encrypted (HTTPS), passwords are stored only as a hash, logins are protected against guessing, and access to data is limited by role and checked on the server with every request.
13. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21 GDPR), as well as to withdraw consent. Contact [email protected]. If you think we process your data unlawfully, you can complain to the Austrian Data Protection Authority (Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at).
14. Changes to this policy
If anything about the processing changes (e.g. a new service provider), we update this policy and let you know in the app.
Last updated: 3 October 2026 · The German version is legally binding.
