🛡️Privacy Policy

SurThriveAll Institute – Association for Sustainability Research and Social Innovation
4715 Taufkirchen an der Trattnach, Austria
Email: surthriveall@gmail.com

Last updated: 25.05.2025


1. Who We Are

Our website address is: https://surthriveall.org.
We are a nonprofit organization committed to research, education, and social innovation in the field of sustainable development.


2. Contacting Us

When you contact us via email or contact form, we store your message and contact details for up to six months to respond to your inquiry and handle follow-up questions. We do not share this information without your consent.


3. Membership Data Processing

If you sign up for one of our memberships (e.g. free, supporting, or honorary), we store your name, email address, address, and payment details for administrative and communication purposes.

This processing is based on:

  • Article 6(1)(b) GDPR (contract fulfillment)
  • Article 6(1)(f) GDPR (legitimate interest in managing memberships)

4. Newsletter

You can subscribe to our newsletter via our website. We use a double opt-in process and store your email address and IP address for verification purposes.

You can unsubscribe at any time by clicking the link in the newsletter or by emailing us. Your data will be deleted upon unsubscribing.

Our newsletter is managed by MailPoet.


5. Cookies

Our website uses cookies to improve usability and functionality. Cookies are small text files stored on your device via your browser.

Cookie Use Includes:

  • Saving your preferences
  • Recognizing logged-in users
  • Handling language settings
  • Consent management via Complianz

When you first visit our website, we ask for your consent via a cookie banner (opt-in). You may adjust or withdraw your consent at any time.

Login & Session Cookies:
If you log in, we store cookies to manage sessions and display preferences. Login cookies last for two days, screen preference cookies for one year. Selecting “Remember Me” extends login to two weeks.

If you log out, login cookies are deleted.

Comment Cookies:
If you leave a comment, you may opt to save your name, email, and website in cookies — these last for one year.


6. Comments

When visitors leave comments on the site, we collect the data entered in the form, as well as the IP address and browser user agent to detect spam.

An anonymized hash of your email address may be sent to the Gravatar service to display your avatar. You can find their privacy policy here: https://automattic.com/privacy/


7. Media Uploads

If you upload images to the website, please avoid including embedded location data (EXIF GPS). Visitors can download and extract this data from images.


8. User Accounts & Member Area

If you register on our site (e.g. for a membership), your personal data is stored in your user profile. You can view, edit, or delete your data at any time — except your username. Administrators can also view and manage this data.

Account data is retained as long as your membership is active, or as required by law.


9. Embedded Content from Third-Party Sites

Some pages may include embedded content (e.g. YouTube videos, maps, articles). These behave as if the user has visited the third-party site directly.

These providers may collect your data, use cookies, and track your interaction with the embedded content — especially if you are logged in to their service.

Such content is only loaded after you have given explicit consent via the cookie banner.


10. Data Retention

We store:

  • Contact form data: up to 6 months
  • Newsletter subscription data: until you unsubscribe
  • Comment metadata: indefinitely (to recognize follow-up comments)
  • User account data: as long as your account is active
  • Membership-related data: according to legal retention periods

11. Automated Spam Detection

Visitor comments may be checked through an automated spam detection service (e.g. Akismet or CleanTalk). This may include processing your IP address and browser data.


12. Your Rights Under GDPR

You have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request deletion (“right to be forgotten”)
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time

To exercise these rights, please contact us at: surthriveall@gmail.com

You may also file a complaint with your national data protection authority (e.g. Datenschutzbehörde Austria).


13. Changes to This Policy

We may update this privacy policy from time to time. Please revisit this page regularly to stay informed of any changes.

en_USEnglish