Privacy Policy Internal Login Service

The protection of your personal data is a major concern to us. We treat your data confidentially and in accordance with the statutory data protection regulations (GDPR, TKG 2021) as well as this privacy policy.

This privacy policy applies exclusively to our authentication and login provider (Single Sign-On / Identity & Service Provider). This service is available exclusively to members as well as functionaries of the Independent Students Associations of Austria and associated university groups in order to gain access to internal working areas, platforms, and IT resources of the association.

The controller responsible for data processing is:

Unabhängige Fachschaftslisten Österreichs
Gusshausstraße 27-29
1040 Vienna

kontakt@fachschaftslisten.at

Authorized Founders: Paul Koo, Lennart Borchers, Luca Eichler, Timo Hilger, Alexander Zauner, Helena Fitze, Lukas Wurth, Lukas Ertl, Gleb Grinevich

Non-profit association
Competent Association Authority: LPD Vienna
ZVR: 1429212598

Name and description of the service

  • Service name: Independent Students Associations of Austria (FLÖ)
  • Description: Central login service for internal services of FLÖ

Hosting & Server Log Files

Our login service is hosted at:

ALL-INKL.COM – New Media Münnich
Hauptstraße 68
02742 Friedersdorf, Germany

(Server location: Germany / European Union)

We have concluded a data processing agreement (DPA) with ALL-INKL in accordance with Art. 28 GDPR. This ensures that the service provider processes the data of our visitors only according to our instructions and in compliance with strict EU security standards.

Collection of server log files

With every login process, the server automatically records technical connection information. The following data is stored in so-called server log files:

  • Your IP address
  • Date and time of the authentication request
  • Internal target service accessed
  • HTTP status code / transmission status
  • Browser type, version, and operating system

Purpose & Legal Basis

The storage of log files is technically necessary to ensure the availability and integrity of our service as well as to defend against disruptions or attacks on the authentication infrastructure. The legal basis is our legitimate interest in secure and error-free operation pursuant to Art. 6 (1) (f) GDPR.

Storage Duration

For security reasons, log files are stored by default for a maximum of 7 days and then deleted or anonymized, unless longer retention is required to clarify a specific security incident.

Authentication & Member Data

In order for you to gain access to internal systems as an association member, we process personal data. This data either comes directly from your university/home organization or is generated during your use.

If you log in via your university or another home organization, the latter transmits the following authorization data to us:

Mandatory attributes

These attributes are transmitted to all services

  • eduPersonPrincipalName: Unique, persistent user identifier in the format kennung@organisation.at. Is mandatory to uniquely identify your association account with every login.
  • eduPersonScopedAffiliation: Your role or status at the home organization (e.g. student@..., member@...). Is required to verify authorization to use the association's internal resources.
  • mail: Your official email address. Is processed for security-related notifications, account management, and association-related communications.

Optional attributes

These attributes are transmitted to certain services to improve the display of the person in the service and to enable certain features.

  • givenName: Your first name (for personal address in the systems).
  • sn: Your last name / family name (for better display in the systems).
  • displayName: Your full display name (for better display in the systems).

Purpose of data processing

  • For authorization and management of your access rights to internal IT systems, computing resources, and platforms.
  • To ensure the reliability and integrity of our association-internal data.

Legal bases

  • Performance of a contract / membership relationship (Art. 6 (1) (b) GDPR): The processing is strictly necessary to provide you with the access to the member systems that you have requested.
  • Legitimate interest (Art. 6 (1) (f) GDPR): For administrative tasks, resource allocation, and system security.
  • Consent (Art. 6 para. 1 lit. a GDPR): If you store additional voluntary information in your profile.

Storage duration & account deletion

  • Your user data will be stored for the duration of your active membership or association activity.
  • Your access will be deleted or anonymized when you leave the association, you request deletion, or if you have not used the service for more than 18 months.

Disclosure to third parties & visibility within the association

Your data will be treated confidentially and will not be shared for advertising purposes. Transmission only occurs in the following cases:

  • Internal association services: During login, necessary identity attributes are transmitted to the respective platform accessed (e.g., internal association wiki, Nextcloud, chat). Please note that your name or profile may be visible to other authorized members in these systems (e.g., in the version history: „Last edited by First Name Last Name“).
  • Legal obligation: If we are legally, officially, or judicially obligated to disclose data.
  • Enforcement of terms of use: For investigating abusive use or for preventing damages.
  • Third-country transfer: No transfer to third countries outside the EU or EEA takes place. Should this be necessary in exceptional cases, it will occur exclusively in compliance with EU data protection standards (e.g., through adequacy decisions or EU standard contractual clauses).

Notice of Your Right to Withdraw Consent

Insofar as data processing is based on your separate consent, you have the right to withdraw this consent at any time informally by email to kontakt@fachschaftslisten.at without affecting the lawfulness of the processing carried out on the basis of the consent until withdrawal.

Your Rights as a Data Subject

Under the GDPR, you have the following rights regarding your data processed by us:

  • Right of Access (Art. 15 GDPR): You can request information about whether and which personal data we process about you.
  • Right to Rectification (Art. 16 GDPR): If incorrect or incomplete data is stored, you can request its correction. Data that is transmitted directly by your university or home organization (such as your matriculation number, official university email, or name in the identity management system) can only be corrected via the IT helpdesk or the self-service portal of your own higher education institution.
  • Right to Erasure („Right to Be Forgotten,“ Art. 17 GDPR): You have the right to erasure of your data, provided that no legal obligation or overriding grounds prevent this.
  • Right to Restriction of Processing (Art. 18 GDPR): Under certain conditions, you can request that your data only be processed in a restricted manner.
  • Right to Data Portability (Art. 20 GDPR): You can request to receive data that you have provided to us in a structured, commonly used, and machine-readable format.

Insofar as we process your personal data to safeguard legitimate interests in accordance with Art. 6 (1) (f) GDPR process (in particular when operating the web server and for web analysis), you have the right, to object to this processing at any time on grounds relating to your particular situation.

If you would like to exercise your rights under the GDPR, contact us via: kontakt@fachschaftslisten.at.

Right to Lodge a Complaint with the Supervisory Authority

If you believe that the processing of your data violates data protection law, you can contact us or the competent supervisory authority at any time:

Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna

Phone: +43 1 52 152 0
Email: dsb@dsb.gv.at
Website: dsb.gv.at