Privacy
Draft: The full postal address is still missing. The provider arrangements, retention periods and any international data transfers applicable to this project, as well as the grounds for publishing images, still need final confirmation. The information below describes the website’s current operation.
1. Controller and contact
ATZP - Verein für österreichisch-türkischen Zusammenhalt und Partnerschaft
ZVR: 1136287463
Wien, Österreich
Represented by chairwoman Gülnur Ala
info@atzp.at
+43 664 994 44 142
For privacy requests, contact info@atzp.at. The full postal address will be added once established.
2. Visiting the website
The site runs through OpenAI Sites on Cloudflare infrastructure. Technical connection data, including IP address, access time and requested page, is processed to deliver content and prevent attacks. Our legitimate interest is providing a secure, reliably accessible website (Article 6(1)(f) GDPR).
The website code set up by ATZP uses no analytics or advertising cookies and no tracking services. Images, video, music and fonts load from the website. Language selection uses the page address. Hosting providers’ technical security measures and logs are separate from this.
3. Email and phone
Contact buttons open your email or phone app. Opening an email draft alone does not send us a message. When you contact us, we process your contact details and enquiry to respond. Article 6(1)(b) GDPR applies to requests for membership or services; general enquiries rely on Article 6(1)(f), with the legitimate interest of answering association-related correspondence.
4. Membership applications
The online form requires first and last name, email address, date of birth, membership category and confirmation of the application after reading the statutes. Date of birth is used in particular to distinguish adult and youth membership. For applicants under 18, a parent or legal guardian’s name, email address and confirmation are also required. The online form cannot be submitted without these required details.
Phone number, citizenship, address, preferred start date and personal message are optional. The payment preference records bank transfer or interest in future SEPA direct debit; the application collects no bank account details. Please do not send health information or identity document copies through this form.
Details are used to review and process the application and, following admission, administer membership (Article 6(1)(b) GDPR). The board decides on admission. There is no automated admission decision or profiling. Submission alone creates neither membership nor an obligation to pay.
5. Delivery and recipients
For direct submission, the website server processes the details temporarily and sends the application through Zoho Mail to info@atzp.at. The configured integration uses Zoho’s EU endpoints. Application contents are not stored in the website database. If direct sending is unavailable, a draft can be prepared in your own email app and sent by you. The form notice identifies the available delivery method.
Application and contact details are subsequently processed in the association’s mailbox and, where applicable, membership records. Recipients are the association personnel responsible for handling them and the hosting and email providers to the extent needed for their tasks. Membership applications are not published on the website.
6. Retention and form protection
Enquiries and unsuccessful applications are retained only while needed for processing, necessary follow-up or specific legal claims. For accepted members, retention depends on membership administration and any continuing statutory record-keeping duties. Data must be deleted when its purpose ends and no other legal basis remains. Statutory retention relies on Article 6(1)(c) GDPR.
To prevent abuse and duplicate sending, the form stores pseudonymous counters, a random application reference and delivery status (Article 6(1)(f) GDPR). These records contain neither a raw IP address nor application text. Counters expire after one hour and submission references after 24 hours. Expired entries are technically deleted during a subsequent valid form submission, rather than automatically at the exact expiry time. Provider log and backup retention periods still require confirmation.
7. External links and WhatsApp
Instagram, Facebook, X, TikTok and WhatsApp appear as links rather than automatically loaded feeds. Opening a link allows that service to process connection and, where applicable, account details under its own privacy terms. If you voluntarily join the WhatsApp group, other members can see your phone number and shared profile details. Joining the group is not required for membership or for contacting ATZP.
8. Event photos and videos
Event images published on the website document the association’s activities and are publicly accessible. Publication requires, depending on the image, consent (Article 6(1)(a) GDPR) or an overriding legitimate interest assessed against the rights of those depicted (Article 6(1)(f)). The specific grounds and any necessary consents, particularly for children, still require final review for existing images. Please identify the relevant image when sending questions, objections or withdrawal of consent to info@atzp.at.
9. Donations and SEPA
Transfers are completed in your banking app or through your bank. The website receives no banking login credentials. When a payment arrives, the association receives details shown on its bank statement, such as sender name, account details, amount and reference. They are used to allocate payments and maintain accounts; required statutory retention relies on Article 6(1)(c) GDPR. The participating banks process the payment.
SEPA direct debit is not yet set up. Selecting it in the membership application records interest only and creates no mandate. Future use requires setup with the bank, a separate valid mandate and additional information about processing mandate data.
10. Providers and international processing
Hosting and form processing use OpenAI Sites and Cloudflare; email delivery uses Zoho Mail. These providers operate internationally. EU endpoints alone do not establish that all processing and access occur solely within the European Economic Area. The contracting entities, recipient countries, processing agreements and any transfer safeguards applicable to ATZP’s accounts still need confirmation and must be added here.
General provider information: OpenAI · Cloudflare · Zoho. This information does not replace checking the applicable contracts.
11. Your rights
Subject to the legal conditions, you may request access, correction, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation. You may withdraw consent at any time for future processing, without affecting the lawfulness of processing before withdrawal.
Contact ATZP at info@atzp.at. You may also complain directly to the Austrian Data Protection Authority. You do not need to contact ATZP first.
Draft updated: 7 September 2026.