Venue Logo

Privacy Policy & Your Data Rights

Last updated: 9/5/2026

1. Data Controller

Citywave Austria
[Your Address]
[Your Contact Information]
Email: privacy@citywave.app

2. Data We Collect

Personal Information:

  • Name, email address, telephone number
  • Salutation, title, customer type
  • Postal address (street, city, ZIP code, country)
  • Company/Club/School name (if applicable)

Booking Information:

  • Booking dates and times
  • Session preferences and participants
  • Payment information and credit balance

Technical Data:

  • IP address, browser type, device information
  • Login timestamps and activity logs

3. Legal Basis for Processing

Contract Performance (Art. 6(1)(b) GDPR): Processing booking information to provide surf sessions

Consent (Art. 6(1)(a) GDPR): Marketing communications and optional features

Legitimate Interest (Art. 6(1)(f) GDPR): Fraud prevention and service improvement

Legal Obligation (Art. 6(1)(c) GDPR): Tax and accounting requirements

4. How We Use Your Data

  • Process and manage your bookings
  • Send booking confirmations and reminders
  • Manage credit packages and payments
  • Provide customer support
  • Comply with legal obligations (invoicing, accounting)
  • Improve our services and user experience

5. Data Sharing

We do not sell your personal data. We may share data with:

  • Service Providers: base44 platform (data processor), payment processors
  • Legal Requirements: When required by law or legal process
  • Business Transfers: In case of merger or acquisition

6. Data Retention

We retain your personal data for:

  • Account data: As long as your account is active
  • Booking history: 7 years (tax law requirement)
  • Marketing consent: Until withdrawn
  • Inactive accounts: Deleted after 3 years of inactivity

7. Data Security

We implement appropriate technical and organizational measures including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security audits
  • Employee training on data protection

8. International Transfers

Your data is processed within the EU/EEA. If data is transferred outside the EU, we ensure adequate safeguards are in place (Standard Contractual Clauses, adequacy decisions).

9. Cookies and Tracking

We use essential cookies for authentication and session management. You can manage cookie preferences in your browser settings.

10. Children's Privacy

Our services are not directed to children under 16. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via email or prominent notice on our website.

Note: This privacy policy template should be reviewed and customized by a qualified Austrian/EU lawyer to ensure full compliance with GDPR, Austrian DSG (Datenschutzgesetz), and TKG (Telekommunikationsgesetz).