Back

Privacy Policy

Last updated: 3 September 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

TSC Labs e.U. Peschekgasse 3b A-3100 St. Pölten, Austria Email: hello@tsc-labs.eu

2. Collection and processing of personal data

Personal data is only collected when voluntarily provided during a contact request or course registration (e.g. name and email address via the contact form). This data is used exclusively to process the request and to handle course enrolment. Data is stored for the duration of the contract and thereafter for 7 years for tax purposes. If you start a registration but never confirm your email address, that data is automatically deleted after 30 days. If a registration is confirmed but no contract is ultimately concluded (for example, a course does not reach its minimum number of participants), the data is kept until that outcome is known and deleted once the enquiry has been fully processed, unless statutory retention obligations apply.

When you visit this website, your browser transmits technically necessary data (IP address, browser type, pages accessed, timestamp) to our hosting infrastructure. This data is processed solely for operational and security purposes.

Processing of contact form data is based on Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures at your request).

4. Service providers and data processors

The following third-party service providers are used and may process data on our behalf. Each has been assessed as providing sufficient guarantees under GDPR Art. 28.

AhaSend B.V. Registered in the Netherlands (EU), Chamber of Commerce number 99533111. Used for transactional email delivery (course registration confirmation, office/order notifications, and lab feedback). Your name, email address, and message are transmitted to AhaSend solely to deliver these emails. Open/click tracking is disabled for all sends. Message metadata (e.g. delivery status) is retained for 30 days; the message content itself (body and attachments) is retained for only 3 days. Privacy policy: https://ahasend.com/privacy

Cloudflare, Inc. Registered in the United States. Used as our content delivery network, edge computing platform (Cloudflare Workers and Pages), and bot protection (Cloudflare Turnstile). Cloudflare processes IP addresses and connection metadata at the network edge. An adequacy decision (EU-US Data Privacy Framework) is in place and Cloudflare Inc. is certified under it. Standard Contractual Clauses are available at https://www.cloudflare.com/cloudflare-customer-scc/. Server logs are retained for a maximum of 7 days (see also Section 9). Privacy policy: https://www.cloudflare.com/privacypolicy/

Umami Software, Inc. Registered in the United States. Used for privacy-friendly website analytics via Umami Cloud. Umami collects anonymised page view data (pages visited, referrer, browser type, OS, device category, approximate region). Analytics traffic is relayed through this site’s own server-side proxy so a slow connection to Umami cannot delay page navigation; as part of that relay, your IP address is passed to Umami solely to determine your approximate region. Umami does not use cookies, does not store IP addresses, and cannot identify individual visitors. An adequacy decision (EU-US Data Privacy Framework) is in place, but Umami Software Inc. is not certified under it. Data transfers are therefore based on Standard Contractual Clauses, available at https://umami.is/umami-dpa.pdf. Aside from that momentary geolocation lookup, no personal data is retained, so no retention period applies. Privacy policy: https://umami.is/privacy

SimplyMeet.me / SimplyBook.me Operated by SimplyBook Ltd., registered in Cyprus (EU). Used for scheduling introductory calls when you click the booking link. SimplyMeet.me is ISO 27001 certified and hosts all data on European servers. A Data Processing Agreement is available at https://simplymeet.me/en/dpa. SimplyMeet.me processes your name, email address, and selected appointment time when you make a booking. Booking data is retained for the duration of the business relationship and in accordance with statutory retention periods. Privacy policy: https://simplymeet.me/en/policy

5. Disclosure to third parties

Personal data is not passed to third parties beyond the processors listed in Section 4, unless we are legally required to do so.

6. Retention period

Data is stored only for as long as necessary to fulfil the respective purpose, or as required by statutory retention periods. Specific retention durations are stated in Section 2 and for each individual processor in Section 4.

7. Your rights

You have the right to:

  • Access the data we hold about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing (Art. 21 GDPR)

Please contact us at: hello@tsc-labs.eu

8. Right to lodge a complaint

You have the right to lodge a complaint with the competent data protection supervisory authority. In Austria, this is the Datenschutzbehörde (DSB): https://www.dsb.gv.at

9. Cookies and server logs

This website does not use tracking cookies or fingerprinting.

When you visit the site, technically necessary server logs (IP address, timestamp, page accessed) are processed by Cloudflare as our hosting provider for a maximum of 7 days for security and operational purposes.

When you submit the contact form, a Cloudflare Turnstile bot-protection widget is activated. Turnstile communicates with Cloudflare servers and analyses browser signals (user-agent, interaction patterns) to distinguish humans from bots. This process does not set cookies and does not track you across websites.

10. Analytics

This website uses Umami Cloud for aggregate, anonymised analytics. Analytics traffic is relayed through this site’s own server-side proxy, which passes your IP address to Umami solely to determine your approximate region. Umami does not use cookies, does not store IP addresses, and cannot identify individual users. Only aggregate statistics (e.g. number of page views, referrer domain, device category, region) are recorded. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in understanding aggregate usage patterns to improve the website). No personal data is retained for this purpose.

11. Sign-in via third-party identity providers

The course portal (and other Learn Cloud Native applications that offer account sign-in) lets you sign in using an existing account with one of the following identity providers: Google, GitHub, or Microsoft. The provider you choose is the source of the sign-in; no separate account password is collected or stored.

When you sign in this way, the identity provider shares a limited set of profile data: your name, email address, a profile identifier / account ID, and, where the provider returns one, a profile picture. This corresponds to what the identity providers return for their basic OpenID/email/profile sign-in scopes; no data beyond this is requested.

This data is used to authenticate you and to create and maintain your course-portal account. Processing is based on Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures at your request, i.e. providing the account you signed up for). Your account and identity data is retained for as long as your account exists and is deleted afterwards, subject to any statutory retention obligations. This data is not sold and is not shared with third parties beyond what is necessary to operate the course portal (see Section 5).

Google, GitHub, and Microsoft are independent controllers of the account you hold with them; their processing of that account is governed by their own privacy policies, not this one:

Google API Services User Data Policy. The course portal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.