Controller

CyberKreuz, ZVR 1623935589, Alsegger Str. 59/3, 1180 Vienna, Austria. Privacy contact: info@cyberkreuz.eu.

Data and purposes

CyberKreuz processes contact details, account identifiers, certificate name, membership plan and status, course and certification records, event registrations, communications, technical security logs, truncated or hashed network identifiers, and Stripe customer, subscription and transaction references. CyberKreuz does not receive or store complete card numbers.

Data is processed to conclude and perform membership contracts, authenticate users, provide restricted content and certifications, administer events, answer inquiries, maintain platform and examination integrity, prevent abuse, document consent and transactions, comply with accounting or legal obligations, and establish or defend legal claims. Depending on the activity, the legal basis may be contract performance, legal obligation, legitimate interests in secure and accountable operation, or consent.

Payment provider

Stripe processes checkout, recurring billing, payment methods, invoices, fraud prevention and the customer billing portal. Stripe may act as a processor or as an independent controller for particular payment and compliance activities. Stripe identifiers are stored in CyberKreuz systems to synchronize entitlement status through cryptographically signed webhooks.

Recipients and transfers

Data is disclosed only as necessary to authorized CyberKreuz personnel and service providers such as hosting, email delivery and payment providers, or to authorities where legally required. Some providers may process data outside the EEA using legally recognized transfer safeguards.

Retention

Account and membership data is retained while the account is active and afterwards as required for contract, accounting, certification integrity, dispute and legal-retention purposes. Payment references and invoices may be retained for statutory periods. Security logs and failed authentication records are retained for proportionate periods. Expired activation and reset tokens are deleted or rendered unusable. Contact messages are retained only as long as needed for follow-up and documentation.

Rights

Subject to applicable conditions, data subjects may request access, correction, deletion, restriction, portability, objection, and withdrawal of consent. They may lodge a complaint with the Austrian Data Protection Authority. Requests should be sent to info@cyberkreuz.eu; identity verification may be required.

Cookies and security

The website uses essential session and consent-preference cookies. Optional analytics and marketing cookies are not enabled. CyberKreuz uses access controls, password hashing, encrypted transport, CSRF protection, rate limiting, audit logging and other proportionate controls. No internet service can eliminate all risk.

See also the Cookie Policy and Coordinated Vulnerability Disclosure policy.