Privacy Policy
Last updated: September 2026
This policy explains which personal data we process when you use the BLCKSHIFT Session platform, why we do it and which rights you have under the General Data Protection Regulation (GDPR) and the Austrian Datenschutzgesetz (DSG). Information required by § 165 Telekommunikationsgesetz 2021 (TKG) on cookies is included.
1. Controller
Blckshift - Verein zur Förderung der Drum & Bass Kultur in Wien
ZVR-Zahl: 1693729727
Maria-Lassnig-Straße 33/1/29
1100 Vienna
Austria
Email: alex@blckshift.at
Phone: +43 676 3110198
We have not appointed a data protection officer, as we are not legally required to do so. Please direct all privacy requests to the e-mail address above.
2. What we process, why, and on which legal basis
a) Your account
When you register we store your first and last name, e-mail address and a hashed password (never the password itself), together with the time of registration and e-mail verification. If you sign in with Google we receive your Google account ID, name, e-mail address and profile picture URL from Google and store them, together with the access token needed for the login, in encrypted form. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
b) Event registrations, draws and tickets
When you enter the draw for a session we store your registration, whether you registered solo or with a crew, the draw result, your confirmation or decline, your ticket with its QR code, and the time your ticket was scanned at the door. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
c) Reliability score
To allocate the limited spots fairly we keep a record of confirmed spots that were not used (no-shows), declined spots and successful check-ins. From this history a reliability score is calculated automatically and used to weight your chances in future draws. The score is visible to administrators and can be reset by them; the draw itself remains random. Legal basis: our legitimate interest in a fair allocation of spots (Art. 6(1)(f) GDPR). You can object to this processing at any time (see section 7); we will then assess your objection against our interest.
d) Crews
If you create or join a crew, your name and e-mail address are visible to the other crew members. If you invite someone by e-mail we store the invited address until the invitation is accepted or expires (7 days). Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and, for invited persons, our legitimate interest in delivering the invitation (Art. 6(1)(f) GDPR).
e) Invitations to join the platform
Members can invite friends by e-mail; we then store the friend's e-mail address and, if given, first name, and send one invitation e-mail. We may also invite contacts from our newsletter list who already agreed to hear from us. Invited persons who do not register can request deletion of their data at any time. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) and, for newsletter contacts, the consent given for the newsletter (Art. 6(1)(a) GDPR).
f) E-mails
We send transactional e-mails (verification, password reset, registration received, draw result, confirmation reminders, tickets, changes made by administrators) and announcements of new sessions to all members. Legal basis: performance of a contract (Art. 6(1)(b) GDPR); for announcements our legitimate interest in informing members about the association's events (Art. 6(1)(f) GDPR). We do not use marketing tracking in e-mails.
g) Administration and security
Administrators of the association can see the registrations, draw results, tickets and reliability scores of all members in order to run the events and the door check-in. Our servers log the IP address, browser type, requested page and time of each request to keep the platform secure and to diagnose errors. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
3. Cookies and local storage
We only use cookies that are strictly necessary for the platform to work, which do not require your consent (§ 165(3) TKG 2021):
- Session cookie – keeps you logged in during your visit; deleted when the session expires.
- XSRF token – protects forms against cross-site request forgery.
- Remember-me cookie – only if you tick "Remember me" at login; keeps you logged in on this device.
The browser's local storage holds a single flag so that the celebration animation after winning a draw is shown only once. We do not use analytics, advertising or tracking cookies.
4. Recipients and third parties
We share personal data only with the following recipients, and only as far as necessary:
- Hosting: the platform and its database are hosted by Code & Comments KG on our behalf (processor, Art. 28 GDPR).
- E-mail delivery: e-mails are sent through Code & Comments KG (processor, Art. 28 GDPR).
- Google (Google Ireland Ltd.): only if you choose "Sign in with Google". Google then processes your login according to its own privacy policy. Data may be transferred to the USA; Google is certified under the EU-US Data Privacy Framework.
- Content delivery networks: our web font is loaded from Bunny Fonts (BunnyWay d.o.o., Slovenia, EU), and two small scripts (confetti animation, ticket image export) from jsDelivr. When your browser loads these files, your IP address is transmitted to the respective provider. No cookies are set by them.
- WhatsApp: the "share" button on an event page only opens WhatsApp if you click it; nothing is transmitted before.
We do not sell personal data and do not share it with other third parties unless we are legally obliged to.
5. Retention
- Account data, registrations, tickets and attendance history are kept as long as your account exists. When you delete your account (Profile → Delete Account) all of it is deleted immediately.
- Invitations to join the platform are kept until they are accepted or deleted on request.
- Crew invitations expire after 7 days.
- Server logs are deleted after 30 days at the latest.
- Data we must keep for legal reasons (e.g. accounting) is retained for the statutory period only.
6. Security
All traffic is encrypted (TLS). Passwords are stored as one-way hashes, login tokens from Google are stored encrypted, and access to administrative functions is restricted to authorised members of the association.
7. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent you may withdraw it at any time with effect for the future.
You can update your name and e-mail address and delete your account yourself on the Profile page. For everything else, write to alex@blckshift.at.
If you believe your data is processed unlawfully you may lodge a complaint with the Austrian data protection authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
8. Changes
We may update this policy when the platform or the law changes. The current version is always available at this address; the date of the last update is shown at the top.