Privacy Policy
Privacy Policy in accordance with Art. 13 of the General Data Protection Regulation (GDPR)
Controller Information
Data Protection Officer: We are not required to appoint a Data Protection Officer under Art. 37 GDPR and §38 DSG.
Contact: You can contact us about any data protection matters at privacy@whereimatcommunity.com for all data matters.
WIA Community e.U Neulinggasse 34-36/st2/14 1030 Vienna Controller to Art. 4 No. 7 GDPR
You can also find more information in the imprint. VAT number: No UST billing. Firmenbuchnummer FN 641363g
Platform nature & disclaimer
Where I’m At Community is a free, members-only peer-support and lived-experience education platform for working professionals affected by burnout, chronic stress, and related work or life disruption. The platform is not a therapy, crisis, or clinical care service and does not provide medical, psychiatric, legal, financial, HR, employment, or one-to-one coaching services. Specific features, areas and content types available may vary over time and by membership plan; these are described on the platform.
I. Data processing on my website
I would like to point out that data transmission over the internet can have security gaps. Complete protection of data against access by third parties is not possible. In order to protect your data as comprehensively as possible from unwanted access, I take so-called technical and organisational measures. Specifically, I use an encryption process on my website. Your data is transmitted from your computer to my computer and vice versa via the Internet using what is known as TLS encryption. TLS stands for “Transport Layer Security” and is an encryption protocol for data transmission on the Internet. You can usually recognise “TLS” by the fact that the lock symbol in the status bar of your browser is closed and the address begins with https://.
1. Server data and hosting
When you visit our website, the hosting provider automatically collects server log information, such as:
- Referrer (previously visited website)
- Requested page/file
- Browser type/version
- Operating system
- Device type
- Time of access
- IP address (in anonymised form where supported by the hosting configuration)
Purpose: security, stability, and detecting unlawful use.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation and abuse prevention).
Hosting provider: Hostinger International Ltd. (EU datacentre), with deployment managed via Coolify. We have concluded a data processing agreement (Art. 28 GDPR) with our hosting provider where applicable.
International transfers: Where data is processed outside the EU/EEA, transfers are safeguarded via adequacy decisions (where applicable) and/or Standard Contractual Clauses (SCCs) and other measures used by the provider.
Retention:
- Standard server logs: retained only for as long as needed for security monitoring, troubleshooting and abuse prevention, and rotated automatically on a rolling basis. We state the criteria rather than a fixed period, as permitted by Art. 13(2)(a) GDPR, because log rotation is volume-based rather than time-based.
- Extended retention: only if required for investigating security incidents, attacks, or suspected legal violations (retained only as long as necessary to preserve evidence)
Domain Provider: In addition, we use services from IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, for domain services. In this context, IONOS processes server log data as described above on our behalf on the basis of a data processing agreement in accordance with Art. 28 GDPR. The legal basis is our legitimate interest in the secure and reliable provision of our website (Art. 6 para. 1 lit. f GDPR).
2. Enquiries by e-mail, telephone, contact form
If you contact us, we process the data you provide (e.g., name, email address, message content) to handle your enquiry.
Purpose: responding to enquiries and maintaining customer support.
Legal bases:
- Art. 6(1)(b) GDPR (pre-contractual/contractual measures), and/or
- Art. 6(1)(f) GDPR (legitimate interest in responding effectively)
Recipients: We do not disclose enquiry data to third parties except service providers acting as our processors (Art. 28 GDPR). Submissions from the website contact form pass through Make (EU instance) before reaching our Google Workspace inbox.
Retention: We delete or anonymise enquiry data no later than 180 days after final resolution, unless legal retention obligations apply.
3. International users & under-18 protections
Our services are available globally. We process personal data in accordance with GDPR standards.
Adults only (18+): Membership is restricted to users aged 18 or over. If an account is found to belong to a minor, it will be removed and data handled in line with legal obligations.
4. Use of cookies and comparable technology for processing usage data
This website sets no cookies. We do not use cookies for analytics, advertising, or functionality, and we do not use tracking pixels or fingerprinting. Because there is no non-essential processing to consent to, there is no cookie banner and no consent management tool.
Fonts are self-hosted on our own server, so no data is passed to a font provider. Third-party services you choose to visit or activate, for example the community platform, the newsletter provider, or an embedded video, set their own cookies on their own domains under their own privacy policies. Nothing loads before you act.
Website analytics with Umami
We use Umami, an open-source analytics tool that we host ourselves on our own server in the EU. No data is sent to a third-party analytics company.
Data processed: page views and navigation paths, referral source, browser and device type, and country-level location (not city, not precise location). All aggregated.
Umami sets no cookies, does not track visitors across other websites, does not store full IP addresses, and does not build profiles. We cannot identify an individual visitor from this data.
Purpose: understanding which pages are useful in order to improve the website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our own website using a method that does not identify anyone).
Retention: 90 days, after which data is automatically deleted.
Transfers: none. Umami runs on our own server in the EU.
Use of Swarm community platform
We use Swarm to provide our members-only community platform (spaces, posts, messaging, profiles, events, courses). Swarm processes personal data on our behalf as a processor. Swarm’s privacy policy also applies.
Data processed: Email addresses, display names/aliases, optional profile photos/bios, posts/comments/reactions, user reports, direct messages (if enabled), event RSVPs, course access logs, downloads, device/session data, moderation/audit logs.
Privacy-first features: Users may post using aliases or anonymous features. Other members cannot see account identities, but administrators, moderators and Swarm may access account data where necessary for safety, compliance or operations. We recommend avoiding identifying details (full names, workplaces, addresses).
Purposes: We process this data to provide the community and course services, maintain platform security, moderate content and respond to reports, and maintain records of membership status and purchases. The legal bases are Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(f) GDPR (legitimate interests in platform security, moderation and service improvement), and Art. 6(1)(c) GDPR (legal obligations, where applicable).
We minimise sensitive data processing and encourage alias use.
Transfers: EU/UK servers (UK adequacy decision). Other transfers via Swarm’s contractual safeguards.
Use of Google
Google Workspace (Email & Productivity)
We use Google Workspace (provided by Google Ireland Limited and Google LLC) for business email (privacy@…, support@…, legal@…), document storage, and collaboration. This includes processing of customer support emails, partner communications, and internal operational documents containing personal data.
Data processed: Names, email addresses, support queries, partner contact details, document content (where we store customer/partner info).
Purposes: Business communications, record-keeping, internal collaboration.
Legal basis: Art. 6(1)(b) and (f) GDPR (contract/service delivery, legitimate business operations).
Transfers: EU (Ireland) + US via EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses as detailed in Google’s Data Processing Terms.
Use of Notion
We use Notion (Enterprise account on EU servers) for internal productivity, partner relationship management (CRM), and moderation reporting. Notion processes:
- Partner data: Names, emails, organisations, contact notes
- Moderation data: Member display names/aliases, reported post URLs/content excerpts, incident timestamps, moderator notes, health/safety-related reports (where voluntarily disclosed by users)
Purposes: Partner management, project tracking, community moderation documentation, incident reporting, audit trails.
Legal bases:
- Art. 6(1)(f) GDPR (legitimate interests in efficient operations and community safety)
- Art. 6(1)(c) GDPR (legal obligations under DSA for moderation records)
- Art. 9(2)(e) GDPR (health/safety data voluntarily made public in reports)
Location: EU servers (no third-country transfers).
Retention:
- Partner: Relationship duration + 12 months
- Moderation records: Minimum 18 months (DSA compliance + legal claims)
Access: Restricted to authorised moderators/administrators only.
Further details: Notion Enterprise GDPR page and Data Processing Addendum.
Partner and collaboration applications
If you apply through our partner or collaboration form, we process the data you provide in that form.
Data processed: Name, email address, website, social or LinkedIn profile (where provided), application responses (interests, experience, proposed collaboration), and our internal review notes and decision.
Purposes: Assessing whether a collaboration is a fit, contacting you about it, and maintaining a record of our decisions.
Legal bases:
- Art. 6(1)(b) GDPR (steps taken at your request prior to entering a contract)
- Art. 6(1)(f) GDPR (legitimate interests in assessing fit and keeping a record of decisions)
Recipients: Submissions pass through Make (EU instance) and are stored in Notion. Confirmation emails are received in Google Workspace.
Special category data: Applicants sometimes mention their own burnout or mental health experience as context. We do not ask for it and do not assess it. Where it appears, it is processed only as background to the collaboration question.
Retention:
- Accepted applicants: relationship duration + 12 months
- Declined applicants: archived after 30 days
- Pending review: name and email anonymised after 30 days
These steps run automatically every 30 days.
Location: EU (Make EU instance, Notion EU servers).
Integration of external content
We embed videos or other external content on our websites that are not stored on our servers. These are blocked so that accessing our websites with embedded videos/content does not automatically result in the third-party provider’s content being reloaded. This means that the third-party provider does not receive any information.
Content from the third-party provider is only loaded after you click the preview image. As a result, the third-party provider receives the information that you have accessed our site, as well as the usage data technically required in this context. We have no influence on further data processing by the third-party provider. By clicking on the preview image, you give us your consent to load content from the third-party provider. The embedding takes place on the basis of your consent in accordance with Art. 6 para. 1 lit. a) GDPR. There is an adequacy decision for the USA, so that the data transfer can take place without further measures.
Provider of the video service:
- Google Ireland Limited/Google LLC (USA) (“YouTube”)
- Spotify AB / Anchor: episode audio. There is no embedded Spotify player: episodes play in our own audio player on our page, and Spotify appears elsewhere on the site only as an outbound link you can choose to follow. The audio file itself is streamed from
anchor.fmwhen you press Play, so Spotify receives your IP address and the usual technical request data at that moment, and only then. Nothing is requested from Spotify before you press Play, and this request sets no cookies. Pressing Play also registers an anonymous download count with the podcast host, which is how podcast listener statistics work generally.
Affiliate marketing & embedded partner content
Some content on the website or platform may include affiliate links, embedded media, external tools, partner resources, or referral pathways (for example Amazon, YouTube, Spotify, or third-party experts and providers). If you interact with these external services, they may process your personal data under their own privacy policies and may transfer data internationally.
Where external experts, partner programmes, workshops, or referral pathways are mentioned, they are independent third parties. Any separate engagement, purchase, booking, participation, or contract with them is governed by their own terms and privacy policies.
Amazon Affiliate Links
We participate in the Amazon Associates program. When you click Amazon affiliate links, Amazon sets tracking cookies on their domain to record referral data for 24 hours (extendable to 90 days for carted items). Amazon processes this independently under their privacy policy. Legal basis: Consent (Art. 6(1)(a) GDPR), given by clicking the link.
We may earn commissions from some affiliate or referral links. This does not alter your rights or the impartiality of recommendations.
Third-party services and referrals
From time to time, the platform may refer Users to external experts, facilitators, service providers, or partner programmes through Reinvent Partners or other areas of the Service. Any such third parties act independently from Where I’m At / WIA Community e.U. and are solely responsible for their own services, privacy practices, terms, and legal compliance.
If you engage with a third party, any separate processing of your personal data will be governed by that third party’s own privacy policy and terms.
Independence of expert-led content
Where the platform includes guest sessions, expert-led workshops, partner pathway pages, or educational contributions by external experts, such content is provided by independent third parties from their own professional or educational perspective. Unless expressly stated otherwise, such persons do not act as employees, agents, or representatives of WIA Community e.U. in relation to their separate services.
Workflow automation (Make)
We use Make on its EU instance (eu2.make.com, hosted in Frankfurt) to route website form submissions to the correct inbox, to sync membership status between Swarm and internal systems, to log data subject requests, and to run scheduled deletions. Data: name/alias, email, membership status, message content, timestamps. Purposes: Operational efficiency and automated compliance with our retention schedule. Legal bases: Art. 6(1)(b)(f), and Art. 6(1)(c) where the automation carries out a legal obligation. Transfers: none, processing takes place within the EU. Retention: 30 days.
Sub-processor updates and notification
Please note that our service providers (Mailchimp, Swarm, Make, Notion, and any payment provider we activate in future, etc.) may engage additional sub-processors. We remain vigilant and update this policy promptly whenever providers change their sub-processing arrangements, as per their published privacy notices.
Data retention overview
We retain personal data only as long as necessary for the purposes described above, and longer only where required by law.
- Website server logs (Hostinger, IONOS): rotated automatically, retained only as long as needed for security and troubleshooting (longer for security incidents). Legal basis: Art. 6(1)(f) GDPR
- Contact enquiries (Make, Google Workspace): 180 days after resolution. Legal basis: Art. 6(1)(b)(f) GDPR
- Community platform (Swarm): Membership duration + 12 months. Legal basis: Art. 6(1)(b) GDPR
- Course participation logs (Swarm): Membership duration + 12 months. Legal basis: Art. 6(1)(b) GDPR
- Moderation/reporting/appeals (Notion, Swarm): 18 months minimum (longer for DSA/legal claims). Legal basis: Art. 6(1)(c)(f) GDPR
- Newsletter subscriptions (Mailchimp): Unsubscribe + 12 months, then permanently deleted. Legal basis: Art. 6(1)(a) GDPR
- Analytics (Umami, self-hosted): 90 days. Legal basis: Art. 6(1)(f) GDPR
- Payments/transactions (if and when payments are accepted): 7+ years (Austrian tax/accounting law). Legal basis: Art. 6(1)(c) GDPR
- Workflow automation (Make, EU instance): 30 days (90 days max for troubleshooting). Legal basis: Art. 6(1)(b)(f) GDPR
- Business productivity (Google Workspace email/docs): Relationship duration + 12 months. Legal basis: Art. 6(1)(b)(f) GDPR
- Partner CRM (Notion): Relationship duration + 12 months. Legal basis: Art. 6(1)(f) GDPR
Notes:
- All retention periods comply with GDPR Art. 5(1)(e) data minimisation
- Legal retention overrides purpose-based retention (e.g., tax records)
- Pseudonymised/anonymised data may be retained longer for analytics
Your rights as a data subject
You have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR) where processing is based on Art. 6(1)(e) or (f) GDPR
- Withdraw consent at any time (Art. 7 GDPR) where processing is based on consent
You also have the right to lodge a complaint with a supervisory authority.
Austria: Österreichische Datenschutzbehörde (DSB): www.dsb.gv.at
To exercise your rights, contact: privacy@whereimatcommunity.com
Sub-processor overview
Our key service providers and their sub-processor documentation:
| Provider | Purpose | Link |
|---|---|---|
| Hostinger | Website and analytics hosting | https://www.hostinger.com/legal/privacy-policy |
| IONOS SE | Domain services | https://www.ionos.com/terms-gtc/privacy-policy/ |
| Umami (self-hosted) | Website analytics | Runs on our own server, no third party involved |
| Make (EU instance) | Automation | https://www.make.com/en/legal/sub-processors |
| Mailchimp | Newsletters | https://mailchimp.com/legal/sub-processors |
| Google Workspace | Email/docs | https://workspace.google.com/terms/dpa_terms |
| Notion | CRM/moderation | https://www.notion.com/help/gdpr-at-notion |
| Swarm | Community Platform | Available on request |
| Stripe | Payments, if and when activated | https://stripe.com/legal/end-customers-subprocessors |
| PayPal | Payments, if and when activated | https://www.paypal.com/legalhub/pp-subprocessor-list |
We maintain data processing agreements with all processors above and monitor their sub-processor lists quarterly. All international transfers use approved mechanisms (SCCs, DPF, adequacy decisions).
5. Newsletters
You can subscribe to our email newsletter, which contains information about our services and offers. For this purpose we process your email address and, if you provide them, optional details such as your name. We use a double opt-in process to verify your subscription.
The newsletter is sent via Mailchimp (The Rocket Science Group LLC, USA) under a data processing agreement in accordance with Art. 28 GDPR. Data may be transferred to the USA on the basis of the EU-US Data Privacy Framework and, where applicable, additional safeguards. Mailchimp may use sub-processors, which are listed in its own documentation.
We may measure newsletter performance (for example whether emails are opened and which links are clicked) in order to improve our content. The legal basis for sending the newsletter and performance measurement is your consent (Art. 6(1)(a) GDPR and § 174 TKG 2021).
You can withdraw your consent at any time with effect for the future by clicking the “Unsubscribe” link in any email.
6. Use of PayPal as a payment method
We do not currently accept payments. The following applies if and when we offer payments via PayPal.
We offer payments via PayPal (PayPal Europe S.à r.l. et Cie, S.C.A., Luxembourg). When you choose PayPal, PayPal receives the personal data required to process the payment and perform identity and fraud checks (for example name, address, email, payment information and transaction details). PayPal processes this data as an independent controller under its own privacy policy.
The legal basis for transmitting data to PayPal is Art. 6(1)(b) GDPR (contract performance) and, where applicable, Art. 6(1)(c) GDPR (legal obligations). For further details see PayPal’s privacy statement.
7. Use of Stripe as a payment method
We do not currently accept payments. The following applies if and when we use Stripe as a payment processor.
We use Stripe as a payment processor for card and other electronic payments. When you complete a payment, Stripe processes your payment data (such as card details, bank information and transaction IDs) and certain contact details (such as name, email and billing address) to execute the transaction, prevent fraud and comply with financial regulations.
The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligations in tax and financial law). Stripe processes data as an independent controller for some purposes and as our processor for others; further information and its list of sub-processors are available in Stripe’s own documentation.
Mailchimp (newsletters) and Ko-fi (donations): See retention table and sub-processor documentation above.
8. Appeals, escalation, and contact information
For questions, complaints, appeals against moderation decisions, or to escalate urgent safety issues, contact us via:
- Support Email: support@whereimatcommunity.com
- Appeals: support@whereimatcommunity.com
- Contact Form: Contact form
Appeals regarding moderation actions must be submitted within 14 days; all appeals are reviewed by a senior moderator or administrator within 10 business days. For urgent issues, mark your correspondence as “URGENT” for immediate prioritisation.
9. Use of Ko-fi.com for donations and support
Ko-fi is currently disabled. The following applies if and when it is reactivated.
We use Ko-fi to enable supporters to make donations or purchase selected goods or services. In doing so, Ko-fi and its payment providers (for example Stripe or PayPal) process your data as independent controllers under their own privacy policies. We receive only the information needed to recognise the payment and, where applicable, to deliver any goods or services (for example display name, email, and shipping details). The legal bases are Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (legal obligations).
10. Refund policy & complaints
For refunds/complaints, see our Terms & Conditions.
II. Information about my social media presence
We maintain pages on Instagram, YouTube, LinkedIn, Facebook, X. Platforms process data per their policies. We receive anonymized page insights (Art. 6(1)(f)).
- Instagram: https://www.instagram.com/whereimatcommunity/
- YouTube: https://www.youtube.com/@whereimatcommunity
- LinkedIn: https://www.linkedin.com/company/whereimatcommunity/
- Facebook: https://www.facebook.com/profile.php?id=61570531855629
- X: https://x.com/whereim_at_comm
Full details in each platform’s privacy policy.
III. Notice to California residents (CPRA): your privacy choices
If California law applies, California residents may have additional rights (for example to request access, deletion or correction of personal information and to opt out of certain data “sales” or “sharing”). Where relevant, these can be exercised via our cookie and privacy settings or by contacting us. We honour Global Privacy Control (GPC) signals for applicable web tracking.
IV. No automated decision-making
No automated decision-making or profiling takes place.
V. Provision
Unless otherwise stated, the provision of personal data is neither legally nor contractually required or necessary for the conclusion of a contract. If you do not provide your personal data, I may not be able to respond to your enquiry, for example.
11. Policy review & updates
This privacy policy, cookie policy and related procedures are reviewed annually and updated to reflect changing laws, technology, user feedback, and operational needs. We will notify members of material changes through the website and, where appropriate, by email. The most recent version is always available at www.whereimatcommunity.com/privacy-policy.