Privacy policy
Privacy policy
This English version is provided for information. Only the German version is legally binding.
Preamble
This privacy policy is intended to inform visitors to our website, in accordance with the Federal Data Protection Act and the Telemedia Act, about the nature, scope and purpose of the collection and use of personal data. Our statutes can be found here.
We take data protection very seriously and treat all personal data confidentially and in accordance with the statutory provisions.
Transmitting data over the internet can in general be subject to security gaps outside our sphere of influence. Complete protection is therefore not possible. We are working to provide as many services as possible ourselves, without third-party providers, and to keep developing.
To many, a privacy policy may sound very technical. In writing it, we have tried to describe the most important things as simply and clearly as possible.
You can find our statutes – which are in line with the data protection provisions – here.
Automatic storage of access data
When websites are visited, certain information is usually created, transmitted and stored automatically.
This is a common standard. Anyone viewing the website automatically passes data to the web server such as the IP address, the browser used, the screen resolution and the operating system sending the request. Based on this information, the display of the page is optimised and delivered for the respective device. During the visit, the web server also logs the addresses of the subpages visited with date and time. We do not actively evaluate this data. It is processed automatically in the background to optimise the user experience. This data – also called “server log files” – may be inspected if unlawful behaviour is suspected.
Google Analytics
We use Google Analytics 4 to measure which posts are read — on gaia-energy.org and in the members’ portal (member.gaia-energy.org).
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The sole purpose is audience measurement: we want to know which topics are read so that we can align the platform accordingly. We do not show advertising, and we have explicitly switched off the advertising features of Google Analytics (“Google signals”, ad personalisation).
The following is processed: the truncated IP address, a pseudonymous browser identifier (client ID), the pages viewed with time, information about device and browser, and the approximate location at city level. We do not link this to any person known by name.
For this purpose Google Analytics stores cookies on the device (_ga and
_ga_NX127RT5YP) with a lifetime of up to two years. The complete
list of what is stored on the device can be found in the
cookie policy.
The legal basis is our legitimate interest in designing the platform to meet needs, pursuant to Art. 6(1)(f) GDPR. You can object to measurement at any time — via the “Cookie settings” link at the very bottom of every page. The objection takes effect immediately: measurement is stopped during the current visit, and on further visits Google Analytics is no longer loaded at all.
If the browser signals “Global Privacy Control” or “Do Not Track”, we treat this as a refusal and do not measure, without asking further.
A transfer to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission found an adequate level of protection on 10 July 2023; the standard contractual clauses also apply.
How Google uses the data is described at https://policies.google.com/privacy and https://support.google.com/analytics/answer/6004245.
Beyond this, we use no other analysis tools — only the server log files described above.
Rights of visitors in general
Every visitor has, in principle, the rights of access, rectification, erasure, restriction, data portability, withdrawal and objection.
Anyone who believes that the processing of their data violates data protection law or that their data protection rights have otherwise been infringed can lodge a complaint with the supervisory authority. In Austria this is the Data Protection Authority, whose website is at https://www.dsb.gv.at/. Please note that, apart from the user data automatically transmitted in the server log file, we do not actively collect or separately store any data from anonymous visitors.
Rights of members in particular
Members can edit all data provided in their membership application at any time.
We store no data other than that provided in a membership application. In the “My data (edit)” area, all data is available to view, correct or delete on one’s own responsibility (except for the email address and the anonymous membership number), provided the request does not conflict with a legal obligation to retain data (e.g. data retention). After all, every user has the right to have incorrect data corrected and to have their personal data blocked or deleted. Deleting the member account is equivalent to leaving the association and must be submitted via the contact page.
Cookies
A cookie is a small text file that is exchanged between browser and server.
As such, it means nothing to either of them. A cookie only acquires meaning for the application, e.g. when logging in to a protected area or in the shopping cart of an online shop. We use cookies to make our website user-friendly for visitors. Some of these cookies remain on the visitor’s device until they are deleted there. Existing cookies make it possible, for example, to recognise returning visitors. Special targeting and advertising cookies can be used to recognise a repeat visit to our website or a visit to a website that is part of the GAIA Group’s advertising partner network. IP addresses are always stored anonymised and encrypted. The selection of information displayed can be based on the user’s interests or on which advertising they have viewed before. These cookies also ensure that advertising is displayed correctly and prevent the same advertisement from being shown too often. The efficiency of advertising campaigns is also measured using these cookies. These cookies are stored for three months. To view or delete the anonymised data stored about you (opt-out), please use the following link: http://me.adform.com. To view your digital footprint, enter a password of your choice. If you want to delete the data directly, click on the following link: http://site.adform.com/privacy-policy/en/. Every visitor can set up their browser so that it notifies them when cookies are set and only allows this in individual cases. Anyone can delete cookies that are already on their local computer or deactivate cookies at any time. How to do this differs from browser to browser. Anyone who prevents their computer from using cookies on our website must expect that some functions and pages will not work as expected (e.g. because a login status is “forgotten” when changing page or clicking a link).
Newsletter
When signing up for a newsletter, the visitor sends us an email address.
By clicking the confirmation link in the activation message, we obtain the right to send newsletters to this email address. If the visitor does not confirm their sign-up within 7 days, we irrevocably delete the email address. We use the name and email address data stored when signing up for the newsletter exclusively for sending newsletters automatically from our servers and do not pass it on to third parties for processing – e.g. external providers of newsletter systems.
Newsletters are also sent via the website as a service for members. For this purpose, the email address and, where applicable, the first and last names of the subscribers have been imported into our website’s newsletter system. In such cases, the author’s data protection provisions apply in addition to ours.
Payment processing (Stripe)
We process membership contributions paid by card via the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). When you take out a supporting membership, you are redirected to a page operated by Stripe; you enter your card details there and they are processed exclusively by Stripe — we ourselves neither receive nor store any card details.
Name, email address, the chosen contribution and the information technically required for payment (such as IP address and browser data to prevent fraud) are transmitted to Stripe. Stripe tells us whether and when a payment has been received; we store this information (amount, date, contribution period, Stripe identifiers) to manage the membership. The legal basis is the performance of the membership relationship (Art. 6(1)(b) GDPR); we keep payment records for seven years in accordance with § 132 BAO (Austrian Federal Fiscal Code).
Stripe may also process data in the USA; this is based on the EU standard contractual clauses and the EU-US Data Privacy Framework, to which Stripe belongs. More information in Stripe’s privacy policy: stripe.com/privacy. We do not show an overview of your payments in the members’ area; the board issues confirmations of contributions paid on request.
Comments
GAIA members can comment below posts. Comments are public — with the nickname chosen by the member, never with name or email address.
Comments are written in the members’ portal after logging in. For this we store the text, the nickname, the time and the link to the member account — in our database at Supabase (see above). Comments appear after approval by the board; we check a member’s first comments before publication, after that they appear immediately. Members can delete their own comments themselves at any time; deleted and rejected comments are no longer visible.
When you read a post, your browser loads the approved comments from our own server (admin.gaia-energy.org). No cookies are set and no data is transmitted to third parties; the only thing transmitted is which post you are reading — just as when calling up any other page. The legal basis is Art. 6(1)(b) GDPR (membership) or (f) (legitimate interest in a public discussion of our posts). Anyone wishing to complain about a comment can write to kontakt@gaia-energy.org.
Google Fonts privacy policy
To display fonts we use Google Fonts from Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA).
Google Fonts are used without authentication. No cookies are sent to the Google Fonts API. No Google account data is transmitted to Google while Google Fonts is used. Google only records the use of CSS (the elements that shape the website) and of the fonts used, and stores this data securely. More on these and other questions can be found at https://developers.google.com/fonts/faq. Which data Google collects and what it is used for can be read at https://www.google.com/intl/en/policies/privacy/.
Notes on Google Maps
To display maps we use “Google Maps” from Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA).
Using functions within maps transmits data to Google. If a visitor to the website is logged in to their Google account while a Google Maps service is loading on our pages, Google may show them personalised content in the map section. Which data Google collects and what it is used for can be read at https://www.google.com/intl/en/policies/privacy/.
Notes on YouTube
We use services of YouTube, the company YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.
Calling up pages of our website that embed YouTube videos transmits data to YouTube, where it is stored and evaluated. For users who have a YouTube account and are logged in, data is assigned to their personal account and the data stored in it. Which data YouTube (a Google service) collects and what it is used for can be read at https://www.google.com/intl/en/policies/privacy/.
Sharing functions
Below every post there are buttons for sharing. They are plain links — no code from the platforms is loaded.
This is expressly different from the widespread “Like” and “Share” widgets: such widgets load code from the respective provider when the page is opened and can transmit data before anyone uses them. On our site, nothing happens until you click. Only when you click one of the buttons does the respective platform open in a new window — and only then does it learn of your visit.
If you are logged in, the platform may link your action to your account. If you do not want this, log out there beforehand or use the “Copy link” button instead: it only copies the address to the clipboard, without any connection to the outside.
In detail, these are:
Notes on X (formerly Twitter)
The website allows publicly accessible posts to be shared on X, a social network of X Corp., 865 FM 1209, Building 2, Bastrop, TX 78602, USA.
The share button is a simple link: it loads no code from X and transmits nothing as long as nobody clicks on it. Only on clicking does X open in a new window, and personal data may then be transmitted to X. We do not monitor this data exchange and store nothing about it. More on X’s privacy policy at https://x.com/en/privacy; anyone with an X account can change their privacy settings at https://x.com/settings/account.
Notes on Facebook
The website allows publicly accessible posts to be shared on Facebook, operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
The share button is a simple link; no Facebook “Like” widget is embedded on the page. When you click, you yourself establish a connection to Meta’s servers, and personal data may be transmitted — including the IP address. We have no influence on the nature and scope of this. If you are logged in, your action may be linked to your Facebook account. More: https://www.facebook.com/privacy/policy
Notes on WhatsApp
The website allows publicly accessible posts to be shared on WhatsApp, operated by WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (Meta).
Here too the button is just a link. On clicking, WhatsApp opens with the prepared text; data may be transmitted to Meta. More: https://www.whatsapp.com/legal/privacy-policy-eea
Notes on Bluesky
The website allows publicly accessible posts to be shared on Bluesky, operated by Bluesky Social, PBC, 228 Park Ave S, PMB 79462, New York, NY 10003, USA.
The button is a link; on clicking, Bluesky opens with prepared text. More: https://bsky.social/about/support/privacy-policy
Notes on Telegram
The website allows publicly accessible posts to be shared on Telegram, operated by Telegram FZ-LLC, Dubai Media City, United Arab Emirates.
The button is a link; on clicking, Telegram opens with prepared text. More: https://telegram.org/privacy
Notes on Google Translate
At the bottom left of every page there is a “Translate” button. It is a plain link — no Google code is loaded on our site and no cookie is set.
Only when you select a language does the page open in Google Translate, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. To do this, Google fetches the page at its address and shows it to you translated; your browser connects to Google servers, which may receive your IP address, among other things, and set cookies. We have no influence on the nature and scope of this processing; Google may also process data in the USA (EU-US Data Privacy Framework). We ourselves learn nothing about who calls up which translation. The translation is machine-generated; the original text is authoritative. More: https://policies.google.com/privacy