Privacy Policy

We are delighted that you have shown an interest in our organisation. Data protection is of particular importance to the management of the University of Innsbruck SMT – FairCare. It is generally possible to use the University of Innsbruck SMT – FairCare website without providing any personal data. However, if a data subject wishes to make use of specific services offered by our organisation via our website, the processing of personal data may become necessary. Where the processing of personal data is necessary and there is no statutory legal basis for such processing, we generally obtain the consent of the data subject.

The processing of personal data, such as the name, postal address, email address or telephone number of a data subject, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to the University of Innsbruck SMT – FairCare. By means of this Privacy Policy, our organisation aims to inform the public about the nature, scope and purpose of the personal data we collect, use and process. Furthermore, this Privacy Policy informs data subjects of the rights to which they are entitled.

As the controller responsible for processing, the University of Innsbruck SMT – FairCare has implemented numerous technical and organisational measures to ensure the most comprehensive protection possible for the personal data processed through this website. Nevertheless, internet-based data transmissions may generally contain security vulnerabilities, meaning that absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example by telephone.

1. Definitions

The Privacy Policy of the University of Innsbruck SMT – FairCare is based on the terminology used by the European legislator when adopting the General Data Protection Regulation (GDPR). Our Privacy Policy is intended to be easy to read and understand for the public, as well as for our customers and business partners.

a) Personal Data

Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

b) Data Subject

A data subject is any identified or identifiable natural person whose personal data are processed by the controller.

c) Processing

Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Restriction of Processing

Restriction of processing means the marking of stored personal data with the aim of limiting their future processing.

e) Profiling

Profiling means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

f) Pseudonymisation

Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information.

g) Controller

Controller, or the controller responsible for processing, means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

h) Processor

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

i) Recipient

Recipient means a natural or legal person, public authority, agency or another body to which personal data are disclosed, regardless of whether that person or body is a third party.

j) Third Party

Third party means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

k) Consent

Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.

2. Name and Address of the Controller

The controller for the purposes of the General Data Protection Regulation (GDPR), other data protection legislation applicable in the Member States of the European Union, and other provisions relating to data protection is:

University of Innsbruck
Institute of Strategic Management and Marketing
FairCare

Universitätsstraße 15
6020 Innsbruck
Austria

Website: www.fair-care.eu

3. Cookies

The website of the University of Innsbruck SMT – FairCare uses cookies. Cookies are text files that are placed and stored on a computer system via an internet browser.

Numerous websites and servers use cookies. Many cookies contain a so-called Cookie ID. A Cookie ID is a unique identifier assigned to a cookie. It consists of a string of characters that enables websites and servers to assign the cookie to the specific internet browser in which it has been stored. This allows the browser concerned to be recognised and identified.

Through the use of cookies, the University of Innsbruck SMT – FairCare can provide users of this website with more user-friendly services that would not be possible without the use of cookies.

The data subject may prevent the setting of cookies by our website at any time by selecting the appropriate setting in the internet browser they use and may thus permanently object to the setting of cookies. Furthermore, cookies that have already been set may be deleted at any time via an internet browser or other software programs. If the data subject disables the setting of cookies in the browser they use, not all functions of our website may be fully available.

3a. Consent Management with Real Cookie Banner

Our website uses the consent management tool Real Cookie Banner (devowl.io GmbH, August-Bebel-Str. 26–53, 14482 Potsdam, Germany) to obtain and document consent for cookies and similar technologies relevant under data protection law.

When you visit our website, Real Cookie Banner stores a technically necessary cookie to document and verify your consent decision. This is required pursuant to Article 6(1)(c) GDPR, as we are legally obliged, in our capacity as controller, to maintain verifiable records of consent (accountability pursuant to Article 5(2) GDPR). Without this storage, we would be unable to fulfil our statutory documentation and accountability obligations.

No personal data are transferred to devowl.io. Processing takes place exclusively on our own server.

4. Collection of General Data and Information

The website of the University of Innsbruck SMT – FairCare collects a series of general data and information whenever it is accessed by a data subject or an automated system. These general data and information are stored in the server log files. The data collected may include: (1) the browser types and versions used; (2) the operating system used by the accessing system; (3) the website from which an accessing system reaches our website (so-called referrers); (4) the sub-pages accessed on our website; (5) the date and time of access to the website; (6) an Internet Protocol (IP) address; (7) the internet service provider of the accessing system; and (8) other similar data and information used to protect against threats in the event of attacks on our information technology systems.

When using these general data and information, the University of Innsbruck SMT – FairCare does not draw any conclusions about the data subject. Instead, this information is required in order to: (1) correctly deliver the content of our website; (2) optimise the content of our website and the advertising for it; (3) ensure the long-term functionality of our information technology systems and website technology; and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyberattack.

The anonymous data contained in the server log files are stored separately from any personal data provided by a data subject.

4a. Security: Wordfence

Our website uses Wordfence, a security plugin provided by Defiant Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA. Wordfence protects our website against unauthorised access, malware, brute-force attacks and other security threats.

For the purpose of ensuring website security, Wordfence processes technical access data (IP address, browser type, URLs accessed and timestamps) to detect and prevent attacks. These data may be transferred to servers operated by Defiant Inc. in the United States. Defiant Inc. is certified under the EU–US Data Privacy Framework, thereby ensuring an adequate level of data protection for such transfers.

The legal basis for this processing is Article 6(1)(f) GDPR (legitimate interests). Our legitimate interest lies in maintaining the security of our IT systems, protecting our website, and safeguarding our users’ data against unauthorised access and misuse.

Further information can be found in Defiant Inc.’s Privacy Policy:

https://www.wordfence.com/privacy-policy/

5. Subscription to Our Newsletter

Users are given the opportunity to subscribe to our organisation’s newsletter via the website of the University of Innsbruck SMT – FairCare. The personal data transmitted to the controller when subscribing to the newsletter are determined by the input form used for this purpose.

The University of Innsbruck SMT – FairCare regularly informs its customers and business partners about the organisation’s offers and activities by means of a newsletter. Our newsletter can only be received by a data subject if: (1) the data subject has a valid email address; and (2) the data subject has registered for the newsletter distribution service. For legal reasons, a confirmation email using the double opt-in procedure is sent to the email address entered by the data subject when first registering for the newsletter.

The personal data collected during registration for the newsletter are used exclusively for sending our newsletter. The personal data collected as part of the newsletter service are not disclosed to third parties. The subscription to our newsletter may be cancelled by the data subject at any time. Every newsletter contains a corresponding link enabling the data subject to withdraw their consent.

5a. Newsletter Distribution via Brevo (formerly Sendinblue)

Our newsletters are distributed via the email marketing platform Brevo (formerly Sendinblue), operated by Brevo SAS, 7 Rue de Madrid, 75008 Paris, France.

The email addresses of our newsletter subscribers, together with other data associated with the newsletter service (such as the date and time of registration and the IP address), are stored on Brevo’s servers within the European Union.

Brevo acts as a processor on our behalf and processes your personal data solely for the purpose of distributing our newsletters. Brevo is contractually obliged not to use your data for its own purposes and to comply with the GDPR.

The legal basis for this processing is your consent pursuant to Article 6(1)(a) GDPR. You may withdraw your consent at any time by using the unsubscribe link included in every newsletter.

Further information is available in Brevo’s Privacy Policy:

https://www.brevo.com/en/legal/privacypolicy/

6. Newsletter Tracking

The newsletters of the University of Innsbruck SMT – FairCare contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in HTML emails, enabling log file recording and analysis. This allows a statistical evaluation of the success or failure of online marketing campaigns.

Using the embedded tracking pixel, the University of Innsbruck SMT – FairCare can determine whether and when an email has been opened by a data subject and which links contained within the email have been accessed.

The personal data collected through the tracking pixels contained in newsletters are stored and analysed by the controller in order to optimise the newsletter service and to adapt the content of future newsletters more closely to the interests of the data subject. These personal data are not disclosed to third parties.

Data subjects are entitled to withdraw the separate declaration of consent relating to newsletter tracking at any time. Unsubscribing from the newsletter is automatically interpreted by the University of Innsbruck SMT – FairCare as a withdrawal of consent.

7. Contact via the Website

The website of the University of Innsbruck SMT – FairCare contains information required by law that enables rapid electronic contact with our organisation and direct communication with us, including a general electronic mail (email) address.

Where a data subject contacts the controller by email or via a contact form, the personal data transmitted by the data subject are stored automatically. Personal data voluntarily transmitted by a data subject to the controller are stored solely for the purpose of processing the enquiry or contacting the data subject. Such personal data are not disclosed to third parties.

7a. Contact Forms: HappyForms

We use the HappyForms plugin provided by HappyForms LLC, 340 S Lemon Ave #5168, Walnut, CA 91789, USA, for the contact forms on our website.

When you complete and submit a contact form on our website, the information you enter (for example, your name, email address and message) is transmitted to HappyForms LLC and processed there.

HappyForms LLC acts as a processor and processes your personal data solely for the purpose of providing the contact form service and transmitting your enquiry to us.

For transfers of personal data to the United States, Standard Contractual Clauses (SCCs) pursuant to Article 46(2)(c) GDPR have been concluded.

The legal basis for this processing is Article 6(1)(b) GDPR (performance of a contract or implementation of pre-contractual measures) and Article 6(1)(f) GDPR (legitimate interest in the efficient and secure management of enquiries).

Further information is available at:

https://happyforms.io/privacy/

7b. Email Transmission via WP Mail SMTP

To ensure the reliable delivery of emails (for example, contact form notifications and registration confirmations), we use the WP Mail SMTP plugin provided by WPForms LLC, 1621 Central Ave, Cheyenne, WY 82001, USA.

The plugin routes outgoing WordPress emails through a configured SMTP service.

Please note: You should specify the SMTP service provider actually used (for example, Gmail / Google Workspace, Outlook / Microsoft 365, SendGrid, Mailgun or a similar provider) and supplement this Privacy Policy with the relevant privacy information relating to that provider.

Until this information has been specified, the following applies:

Only the technical metadata required for email transmission (sender, recipient, subject line and timestamp) are processed.

The legal basis for this processing is Article 6(1)(f) GDPR (legitimate interest in ensuring reliable email delivery).

8. Routine Erasure and Restriction of Personal Data

The controller processes and stores personal data relating to the data subject only for the period necessary to achieve the purpose of storage, or where this is required by the European legislator or another legislator in laws or regulations applicable to the controller.

Once the storage purpose no longer applies, or if a statutory retention period prescribed by the European legislator or another competent legislator expires, the personal data are routinely restricted or erased in accordance with the applicable legal provisions.

9. Rights of the Data Subject

a) Right to Confirmation

Every data subject has the right to obtain confirmation from the controller as to whether personal data relating to them are being processed.

If a data subject wishes to exercise this right of confirmation, they may contact any member of staff of the controller at any time.

b) Right of Access

Every data subject has the right to obtain, free of charge and at any time, information from the controller concerning the personal data stored about them, together with a copy of those personal data.

Furthermore, the data subject has the right to obtain information concerning:

  • the purposes of the processing;
  • the categories of personal data being processed;
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed;
  • where possible, the envisaged period for which the personal data will be stored;
  • the existence of the right to request rectification, erasure or restriction of processing;
  • the existence of the right to lodge a complaint with a supervisory authority;
  • the existence of automated decision-making, including profiling.

c) Right to Rectification

Every data subject has the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning them.

d) Right to Erasure (“Right to be Forgotten”)

Every data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay where one of the following grounds applies and insofar as the processing is not required:

  • the personal data are no longer necessary for the purposes for which they were collected;
  • the data subject withdraws their consent and there is no other legal basis for the processing;
  • the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
  • the personal data have been processed unlawfully;
  • the personal data must be erased in order to comply with a legal obligation.

e) Right to Restriction of Processing

Every data subject has the right to obtain restriction of processing from the controller where the conditions laid down in Article 18 GDPR are fulfilled.

f) Right to Data Portability

Every data subject has the right to receive the personal data concerning them in a structured, commonly used and machine-readable format and to transmit those data to another controller.

g) Right to Object

Every data subject has the right, on grounds relating to their particular situation, to object at any time to the processing of personal data concerning them.

Following such an objection, the University of Innsbruck SMT – FairCare will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject.

h) Automated Individual Decision-Making, Including Profiling

Every data subject has the right not to be subject to a decision based solely on automated processing, including profiling, where such a decision produces legal effects concerning them or similarly significantly affects them.

i) Right to Withdraw Consent

Every data subject has the right to withdraw their consent to the processing of personal data at any time.

If a data subject wishes to exercise this right, they may contact any member of staff of the controller at any time.

10. Data Protection Provisions on the Use of Google Fonts

Our website uses Google Fonts, a service for integrating fonts provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For users within the European Union, the responsible entity is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When you access our website, your browser loads the required fonts directly from Google’s servers. In doing so, your IP address and certain technical information (such as browser type and operating system) are transmitted to Google. Google is certified under the EU–US Data Privacy Framework.

The legal basis for this processing is your consent pursuant to Article 6(1)(a) GDPR, which you provide via our cookie consent tool. You may withdraw your consent at any time with future effect by changing your preferences within the cookie consent tool.

Further information regarding Google’s privacy practices is available at:

https://policies.google.com/privacy


11. Data Protection Provisions on the Use of Google reCAPTCHA

Where Google reCAPTCHA is enabled on our website, we use this service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (for users within the EU: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to protect our online forms against automated access by bots.

Google reCAPTCHA analyses the behaviour of website visitors using various characteristics, including the IP address, time spent on the website, mouse movements and browser information. The data collected may be transmitted to Google servers, including servers located in the United States. Google is certified under the EU–US Data Privacy Framework.

The legal basis for this processing is your consent pursuant to Article 6(1)(a) GDPR. You may withdraw your consent at any time via our cookie consent tool.

Please note: If Google reCAPTCHA is not currently active on your website, this section may be removed or disabled.

Further information is available at:

https://policies.google.com/privacy


12. Data Protection Provisions on LinkedIn

LinkedIn is operated by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. For data protection matters outside the United States, the responsible entity is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.

Important note regarding implementation: This Privacy Policy applies only where LinkedIn content (for example, a LinkedIn Share Button or LinkedIn Plugin) is actively integrated into this website. If your website merely contains a standard hyperlink to your LinkedIn profile without loading LinkedIn scripts or plugins, this section is not applicable and may be removed. Please verify which method of integration is used on your website.

Each time a page of our website containing a LinkedIn component (LinkedIn plugin) is accessed, that component causes the browser used by the data subject to download the corresponding LinkedIn component.

As part of this technical process, LinkedIn receives information about which specific page of our website has been visited by the data subject.

If the data subject is simultaneously logged into LinkedIn, LinkedIn recognises which particular page of our website is visited whenever the data subject accesses our website.

If the data subject does not wish such information to be transmitted to LinkedIn, they may prevent this transmission by logging out of their LinkedIn account before accessing our website.

LinkedIn’s Privacy Policy is available at:

https://www.linkedin.com/legal/privacy-policy


13. Data Protection Provisions on the Use of Matomo

The controller has integrated the Matomo web analytics platform into this website. Matomo is an open-source web analytics application that enables the collection, recording and analysis of data relating to the behaviour of visitors to websites.

The software is hosted on a server operated by the University of Innsbruck (ilbi.eu). Log files containing data relevant for data protection purposes are stored exclusively on this university server and are not disclosed to third parties. This is a self-hosted installation, and no data are transferred to third countries.

Matomo places a cookie on the data subject’s information technology system. Whenever an individual page of this website is accessed, the internet browser automatically transmits data to our server for the purposes of website analytics. During this technical process, we obtain knowledge of personal data, including the IP address of the data subject.

The cookie stores personal information such as the time of access, the location from which access originated and the frequency of visits to our website. We do not disclose these personal data to third parties.

The data subject may prevent the setting of cookies by adjusting the settings of the internet browser they use at any time. Furthermore, the data subject may object to the collection of data generated by Matomo by enabling the “Do Not Track” function in their browser or by withdrawing consent via our cookie consent tool.

Further information and Matomo’s Privacy Policy are available at:

https://matomo.org/privacy/


14. Legal Basis for Processing

Article 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose (for example, newsletter distribution, Google Fonts and Google reCAPTCHA).

Article 6(1)(b) GDPR serves as the legal basis for processing operations necessary for the performance of a contract or the implementation of pre-contractual measures.

Article 6(1)(c) GDPR applies where processing is necessary for compliance with a legal obligation (for example, tax obligations or the documentation of consent via the Real Cookie Banner consent management tool).

Article 6(1)(f) GDPR applies where processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject (for example, IT security through Wordfence, reliable email delivery and the efficient management of contact enquiries).


15. Legitimate Interests Pursued by the Controller

Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is the conduct of our activities in the interests of our staff and stakeholders, together with the protection of our IT systems and the safeguarding of our users against unauthorised access and misuse.


16. Period for Which Personal Data Are Stored

The criterion used to determine the storage period for personal data is the applicable statutory retention period.

Once the relevant retention period has expired, the corresponding personal data are routinely erased, provided they are no longer required for the fulfilment of a contract or for the initiation of a contractual relationship.


17. Statutory or Contractual Requirements to Provide Personal Data

We inform you that the provision of personal data may in part be required by law (for example, under tax legislation) or may arise from contractual provisions (for example, information relating to a contractual partner).

In some cases, it may be necessary for a data subject to provide us with personal data in order to conclude a contract. Those personal data must subsequently be processed by us.

Failure to provide the required personal data may result in the contract with the data subject not being concluded.

Before personal data are provided, the data subject may contact a member of our staff, who will explain on a case-by-case basis whether the provision of the personal data is required by law or contract, whether it is necessary for the conclusion of a contract, whether there is an obligation to provide the personal data, and what the consequences of failing to do so would be.


18. Existence of Automated Decision-Making

As a responsible organisation, we do not use automated decision-making or profiling.


Last updated: June 2025

This Privacy Policy is based on the template published by the German Society for Data Protection (Deutsche Gesellschaft für Datenschutz) and has been adapted and supplemented for the University of Innsbruck SMT – FairCare.