With the following privacy policy we would like to inform you about how we process your personal data in accordance with the European General Data Protection Regulation (GDPR). This privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and, in particular, our web application “Sobbatical” (available at app.sobbatical.com).
The controller within the meaning of the GDPR is:
Sobbatical Impact Travel e.U., Managing Director: Axel Menzel, Märzstraße 88/16, 1150 Vienna, Austria. Email: [email protected]
You can reach our Data Protection Officer as follows:
SECJUR GmbH, Email: [email protected]
You may contact our Data Protection Officer directly at any time with all questions and suggestions regarding data protection and the exercise of your rights.
This privacy policy is based on the terminology of the GDPR. For ease of understanding, we would like to explain some key terms in this context.
Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Data subject means any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing.
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Recipient means a natural or legal person, public authority, agency or another body to which personal data is disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients.
Third party means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process the personal data.
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed:
Categories of data subjects:
Purposes of processing:
Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.
Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
Legal obligation (Art. 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany and Austria. These include, in particular, the German Federal Data Protection Act (BDSG) and the Austrian Data Protection Act (DSG). The BDSG and the DSG contain special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases, including profiling. Furthermore, the data protection laws of the individual federal states may apply.
When you use our web application by visiting the website, we collect technically necessary data via server log files that is automatically transmitted to our server, including:
The temporary storage of the data is necessary for the course of a website visit in order to display our website to you. This processing is technically necessary to ensure the functionality of the website and the security of the information technology systems. The legal basis for the processing is therefore Art. 6(1)(f) GDPR, in order to guarantee the provision, security and stability of our website.
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the provision of the website, this is the case when the respective session has ended. Log files are kept for a maximum of 24 hours, directly and exclusively accessible to administrators. After that, they are only available indirectly through the reconstruction of backup tapes and are permanently deleted after four weeks.
For the provision of our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from the server provider Amazon Web Services (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg).
The data is processed in the AWS Europe (Stockholm, Sweden) region. Personal data may also be transferred to the USA. The European Commission has issued an adequacy decision pursuant to Art. 45(3) GDPR for the EU-U.S. Data Privacy Framework. On the basis of this decision, data transfers to organisations based in the USA that are certified accordingly are permitted. Amazon Web Services is certified under the EU-U.S. Data Privacy Framework.
You can find more information on AWS data protection provisions at: https://aws.amazon.com/privacy/
We process the data of our contractual and business partners, e.g. B2C customers, B2B contractual partners of the platform and interested parties (collectively referred to as “contractual partners”), within the framework of contractual and comparable legal relationships and associated measures, and in the course of communication with the contractual partners (or pre-contractually), e.g. to respond to inquiries.
We process this data in order to fulfil our contractual obligations. These include, in particular, the obligations to provide the agreed services, any updating obligations and remedies in the event of warranty and other performance disruptions. In addition, we process the data to safeguard our rights and for the purposes of the administrative tasks associated with these obligations, as well as company organisation. Furthermore, we process the data on the basis of our legitimate interests in proper and efficient business management and in security measures to protect our contractual partners and our business operations. Within the framework of applicable law, we only pass on the data of contractual partners to third parties insofar as this is necessary for the aforementioned purposes or to fulfil legal obligations. Contractual partners will be informed about further forms of processing, e.g. for marketing purposes, within the scope of this privacy policy.
We inform contractual partners which data is required for the aforementioned purposes before or during data collection, e.g. in online forms, by means of special markings (e.g. colours) or symbols (e.g. asterisks), or in person.
We delete the data after the expiry of statutory warranty and comparable obligations, i.e. in principle after 4 years, unless the data is stored in a customer account or must be retained for statutory archiving reasons. The statutory retention period is ten years for documents relevant under tax law as well as for commercial books, inventories, opening balance sheets, annual financial statements and accounting vouchers, and six years for commercial and business letters received and reproductions of commercial and business letters sent.
Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and data protection notices of the respective third-party providers or platforms apply in the relationship between the users and the providers.
We use services, platforms and software from Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for the purposes of organisation, administration, planning and provision of our services.
In this context, personal data may be processed and stored on Google’s servers. This may affect various data that we process in accordance with this privacy policy. This data may include, in particular, master data and contact data of users, data on transactions, contracts, other processes and their contents. The processing is carried out on the basis of a data processing agreement with Google.
Contractual partners must create an account within our online offering (e.g. a customer or user account, “customer account” for short). Customer accounts are not public and cannot be indexed by search engines. As part of registration and subsequent logins and use of the customer account, we store the IP addresses of customers together with the access times, master data (e.g. names, addresses) and contact data (e.g. email, telephone numbers) in order to be able to prove registration and prevent any misuse of the customer account.
If customers have terminated their customer account, the data relating to the customer account will be deleted, subject to any retention required for statutory reasons. It is the responsibility of customers to back up their data upon termination of the customer account.
If you have forgotten your password, you have the option of resetting your password and creating a new one. To create a new password, you will receive a system email to the email address you provided.
The email contains a link. By clicking on this link, you will be redirected to a website where you can create a new password for your user account.
The legal basis for this processing is Art. 6(1)(b) GDPR, the performance of the contract with you for the use of the app. This function and the data processing are necessary to continue to grant you access to our app services.
To make it easier for you to access our app, we offer you the option of signing in via single sign-on (social login) with your account at Google, Meta (Facebook) or LinkedIn. This sign-in process allows you to use the same account you already use with the respective provider.
If you choose to sign in via single sign-on, we retrieve some information from the provider you selected. This usually includes your name, your email address, your profile ID and possibly your profile picture. We use this information to create or verify your account and to grant you access to our web app. We do not store any further personal data from your provider.
The legal basis for this processing is your consent pursuant to Art. 6(1)(a) GDPR and, insofar as the sign-in serves the performance of the user contract, Art. 6(1)(b) GDPR.
Please note that data protection and data processing in connection with single sign-on are subject to the data protection provisions of the respective selected provider. We have no influence on how the selected provider collects and processes your personal data. We recommend that you read the providers’ privacy policies: Google (https://policies.google.com/privacy), Meta (https://www.facebook.com/privacy/policy) and LinkedIn (https://www.linkedin.com/legal/privacy-policy).
When you contact us (e.g. via contact form, email, telephone or social media) and within the framework of existing user and business relationships, the information provided by the inquiring persons is processed insofar as this is necessary to respond to the contact inquiries and any measures requested. The following data:
is transmitted to us. The legal basis for the processing is Art. 6(1)(b) and (f) GDPR.
For our users and partners, we offer online chats as a means of communication (referred to as “chat services”). A chat is an online conversation conducted with a certain immediacy. When you use our chat functions, we may process your personal data.
Here, users and partners can use the chat to clarify the specific terms and circumstances of their relationships that have arisen through our platform by means of the matching system.
For this purpose, your identification number is additionally stored within our web application. We may also collect information about which users interact with our chat services and when. Furthermore, we store the content of your conversations via the chat services and log registration and consent processes in order to be able to prove these in accordance with legal requirements.
The legal basis for our processing is the performance of a contract (Art. 6(1)(b) GDPR).
We send newsletters, emails and other electronic notifications (hereinafter “newsletter”) only with the consent of the recipients or with legal permission. If the contents of the newsletter are specifically described upon registration, they are decisive for the users’ consent. Otherwise, our newsletters contain information about our services and about us.
To subscribe to our newsletters, it is generally sufficient to provide your email address. However, we may ask you to provide a name for the purpose of a personal salutation in the newsletter, or further information if this is necessary for the purposes of the newsletter.
To send our newsletters, we use the service MailerLite (MailerLite, UAB, Paupio g. 46, 11341 Vilnius, Lithuania). MailerLite processes the newsletter data on our behalf within the EU on the basis of a data processing agreement.
The legal basis for sending the newsletter is your consent pursuant to Art. 6(1)(a) GDPR.
You can find the further data protection provisions of MailerLite at: https://www.mailerlite.com/legal/privacy-policy
Registration for our newsletter generally takes place in a so-called double opt-in procedure. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary so that no one can register with someone else’s email address. Newsletter subscriptions are logged in order to be able to prove the registration process in accordance with legal requirements. This includes storing the time of registration and confirmation as well as the IP address. Changes to your data stored with the dispatch service provider are also logged.
We may store the unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove a previously given consent. The processing of this data is limited to the purpose of a possible defence against claims. An individual request for deletion is possible at any time, provided that the former existence of consent is confirmed at the same time.
The logging of the registration procedure is based on the obligation to provide proof of consent under Art. 7(1) GDPR. Insofar as we commission a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure dispatch system.
The newsletters contain a so-called web beacon, i.e. a pixel-sized file that is retrieved from the server of our dispatch service provider (MailerLite) when the newsletter is opened. As part of this retrieval, technical information such as information about the browser and your system, as well as your IP address and the time of retrieval, is initially collected. This analysis also includes determining whether the newsletters are opened, when they are opened and which links are clicked. The evaluations serve to help us recognise the reading habits of our users and to adapt our content to them.
The measurement of open and click rates and the storage of the measurement results in the users’ profiles are based on consent pursuant to Art. 6(1)(a) GDPR. A separate revocation of the performance measurement is unfortunately not possible; in this case, the entire newsletter subscription must be cancelled. In this case, the stored profile information is deleted.
We conduct surveys and polls in order to collect information for the respective communicated survey or polling purpose. The surveys and polls we conduct (hereinafter “surveys”) are evaluated anonymously. Personal data is only processed insofar as this is necessary for the provision and technical implementation of the surveys (e.g. processing of the IP address in order to display the survey in the user’s browser).
To conduct surveys, we use our dispatch service provider MailerLite (MailerLite, UAB, Paupio g. 46, 11341 Vilnius, Lithuania). This service provider receives your email address and other necessary data in order to carry out the survey operationally. The processing is carried out on our behalf within the EU.
The legal basis for the processing is your consent pursuant to Art. 6(1)(a) GDPR.
You can find the further data protection provisions of MailerLite at: https://www.mailerlite.com/legal/privacy-policy
Web analytics (also referred to as “reach measurement”) serves to evaluate the visitor flows of our online offering and may include behaviour, interests or demographic information about visitors as pseudonymous values. With the help of reach analysis, we can, for example, recognise at what time our online offering or its functions or content are used most frequently. We can also determine which areas require optimisation.
In addition to web analytics, we may also use testing procedures, e.g. to test and optimise different versions of our online offering or its components.
Unless otherwise stated below, profiles, i.e. data summarised for a usage process, may be created for these purposes and information may be stored in and read from a browser or end device. The data collected includes, in particular, visited websites and the elements used there, as well as technical information such as the browser used, the computer system used and information on usage times.
The IP addresses of users are also stored. However, where possible, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear-text data of users (such as email addresses or names) is stored within the framework of web analytics, A/B testing and optimisation, but rather pseudonyms.
We use Microsoft Clarity, an analytics service provided by Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). With Microsoft Clarity, we can understand how users interact with our application (e.g. mouse movements, clicks, scrolling behaviour, as well as so-called heatmaps and session replays in aggregated form) in order to make our application more user-friendly.
Microsoft Clarity is only activated after your explicit consent. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You can revoke your consent at any time with effect for the future.
In this context, personal data may also be transferred to the USA. Microsoft is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision pursuant to Art. 45 GDPR. Further information: https://privacy.microsoft.com/en-us/privacystatement
For the convenient and correct entry of addresses, we use the Google Places API service (address completion/autocomplete) provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). When you type in an address field, your entries are transmitted to Google in order to display suitable address suggestions to you.
In this context, the IP address may be processed and data may be transmitted to Google. Google is certified under the EU-U.S. Data Privacy Framework. The legal basis is our legitimate interest in the correct and efficient capture of addresses pursuant to Art. 6(1)(f) GDPR and, where necessary, the performance of a contract pursuant to Art. 6(1)(b) GDPR.
Maps are displayed exclusively via Mapbox (see section 17.1); for address completion we use Google. Further information: https://policies.google.com/privacy
We offer partner organisations (NPOs) an optional “Generate Preview” feature, which can automatically create a short preview or summary (approx. 150–200 characters) from the descriptions of assignments and activities. This feature is only activated when a partner organisation explicitly triggers it.
To create these summaries, we use the service of OpenAI, L.L.C. (3180 18th Street, San Francisco, CA 94110, USA). The description text entered by the organisation is transmitted to OpenAI for processing. The descriptions relate to publicly visible assignment and activity content; the input fields are free-text fields. We advise partner organisations not to enter any personal or confidential data in these fields.
The legal basis is our legitimate interest in efficiently creating appealing content pursuant to Art. 6(1)(f) GDPR. The data is also transferred to the USA; the transfer is safeguarded by appropriate guarantees (including EU standard contractual clauses). Further information: https://openai.com/policies/privacy-policy
We maintain publicly accessible profiles on various social networks. Your visit to these profiles triggers a large number of data processing operations. Below we give you an overview of which of your personal data is collected, used and stored by us when you visit our profiles.
When you visit our profiles, your personal data is collected, used and stored not only by us but also by the operators of the respective social network. This also happens if you yourself do not have a profile in the respective social network. The individual data processing operations and their scope differ depending on the operator of the respective social network and are not necessarily comprehensible to us.
When you visit our Facebook/Instagram page, certain information about you is processed. We can only view the information stored in your public Facebook/Instagram profile, and only if you have such a profile and are logged into it while you visit our Facebook/Instagram page.
In addition, the platform operator Meta (Meta Platforms Ireland Limited, Serpentine Avenue, Block J, Dublin 4, Ireland) provides us with statistics and insights for our Facebook/Instagram page in anonymised form (Page Insights). These are created on the basis of certain information about persons who have visited our page.
The processing of your personal data in connection with the operation of our Facebook/Instagram company profile is based on a balancing of interests pursuant to Art. 6(1)(f) GDPR, in order to offer you a contemporary and supportive means of information and interaction. If the contact is aimed at concluding a contract, the legal basis is Art. 6(1)(b) GDPR.
The processing of Page Insights is carried out by Meta and us as joint controllers. We have concluded an agreement with Meta on processing as joint controllers. With regard to this data processing, you have the option of asserting your data subject rights against Meta as well.
Please note that, in accordance with the Meta data protection provisions, user data is also processed in the USA or other third countries. Meta is certified under the EU-U.S. Data Privacy Framework. Further information: https://www.facebook.com/privacy/policy
When you visit our LinkedIn company profile, certain information about you is processed. In the case of direct messages to us or comments on our LinkedIn company profile or under our posts, we receive the message, the comments and your username.
In addition, LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland), as operator, processes personal data when you visit our LinkedIn company profile, follow this page or engage with the page, in order to provide us with statistics and insights in anonymised form (Page Insights). With the Page Insights, LinkedIn does not provide us with any of your personal data; we only have access to the aggregated Page Insights.
The processing of your personal data in connection with the operation of our LinkedIn company profile is based on a balancing of interests pursuant to Art. 6(1)(f) GDPR. This processing within the framework of the Page Insights is carried out by LinkedIn and us as joint controllers; we have concluded a corresponding agreement with LinkedIn. According to this, LinkedIn is responsible for ensuring your rights under the GDPR.
Further information on the processing of personal data by LinkedIn can be found at: https://www.linkedin.com/legal/privacy-policy
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter “third-party providers”). These may be, for example, graphics, videos or maps (hereinafter uniformly referred to as “content”).
The integration always requires that the third-party providers of this content process the IP address of the users, since without the IP address they could not send the content to their browser. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only content whose respective providers use the IP address solely for the delivery of the content.
To provide location data of volunteers on our web app, we use the map service Mapbox (Mapbox, Inc., 740 15th St NW, Suite 500, Washington, DC 20005, USA). This allows us to show users the location of the respective volunteering assignment in real time.
Through the use of Mapbox, information about the use of our web app, including your IP address, is collected. The map content is transmitted by Mapbox directly to your browser and integrated by it into the website. According to the Mapbox privacy policy, the following data is collected:
The data transfer takes place regardless of whether the end user has a Mapbox user account. The legal basis for the use of the maps is the performance of a contract, Art. 6(1)(b) GDPR.
The personal data is also transferred to the USA. Mapbox is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision pursuant to Art. 45(3) GDPR.
To offer our users the option of booking accommodation in the context of their volunteering assignment, we use the Uniplaces API (Uniplaces Ltd., London, United Kingdom) to integrate the Uniplaces offering into our web application. The offering is displayed to the end user in an embedded interface. Users can be redirected to the Uniplaces website by interacting with the interface and book their accommodation there. The booking process takes place entirely on the servers of Uniplaces. When our web application is accessed, a connection to the Uniplaces servers is established; for this purpose a cookie is set that allows the redirection back to us to be traced. Upon redirection, we transmit the following personal data to Uniplaces:
The legal basis for the use of the service is the performance of a contract, Art. 6(1)(b) GDPR. The personal data is also transferred to the United Kingdom. The European Commission has issued an adequacy decision pursuant to Art. 45(3) GDPR for the United Kingdom; on this basis, corresponding data transfers are permitted.
You can find further information on the data protection provisions of Uniplaces at: https://www.uniplaces.com/de/terms/privacy-policy
To offer our users the option of booking travel insurance in the context of their volunteering assignment, we use the Genki API (Genki UG, Dorothee-Sölle-Platz 2, 50672 Cologne, Germany; Genki acts as an insurance intermediary) to integrate the Genki offering into our web application. The offering is displayed to the end user in an embedded interface. Users can be redirected to the Genki website by interacting with the interface and book their insurance there. The booking process takes place entirely on the servers of Genki. When our web application is accessed, a connection to the Genki servers is established; for this purpose a cookie is set that allows the redirection back to us to be traced. Upon redirection, we transmit the following personal data to Genki:
The legal basis for the use of the service is the performance of a contract, Art. 6(1)(b) GDPR.
You can find further information on the data protection provisions of Genki at: https://genki.world/privacy-policy
To enable our users to book travel (e.g. train, bus, flight) in the context of their assignment, we integrate the Omio API (GoEuro Travel GmbH, Prinzessinnenstraße 20, 10969 Berlin, Germany) into our web application. The Omio offering is displayed to the end user in an embedded interface. Users can be redirected to the Omio website by interacting with the interface and book their trip there. The booking process takes place entirely on the servers of Omio.
When our web application is accessed, a connection to the Omio servers is established; in this context, personal data such as the IP address may be transmitted. The legal basis is the performance of a contract or the implementation of pre-contractual measures pursuant to Art. 6(1)(b) GDPR.
You can find further information on the data protection provisions of Omio at: https://www.omio.com/privacy
In the course of our processing of personal data, it may happen that the personal data is transmitted to or disclosed to other recipients. The recipients of this personal data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the legal requirements and, in particular, conclude corresponding contracts or agreements (including data processing agreements) that serve to protect your personal data with the recipients of your personal data.
The personal data processed by us will be deleted in accordance with the legal requirements as soon as the consent granted for the processing is revoked or other permissions no longer apply (e.g. when the purpose of processing this personal data no longer applies or it is not required for the purpose). If you, as a user, delete your user account at Sobbatical, all data that you have transmitted in the course of our contractual services will be completely deleted by us after 7 days.
Our data protection notices also contain further information on the retention and deletion of personal data that takes precedence for the respective processing operations.
As a data subject, you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR. If you wish to exercise one of your rights, please contact us using the contact addresses given above or our Data Protection Officer.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing for the purpose of such advertising. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
You have the right to request confirmation as to whether personal data concerning you is being processed, and to obtain information about this personal data as well as further information and a copy of the personal data in accordance with the legal requirements.
In accordance with the legal requirements, you have the right to request the completion of the personal data concerning you or the rectification of inaccurate personal data concerning you.
You have the right to demand that personal data concerning you be deleted without delay if one of the legally provided reasons applies and insofar as the processing or storage is not necessary.
You have the right to request the restriction of processing from us if one of the legal requirements is met.
You have the right to receive personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
You have the right to withdraw consent you have given at any time with effect for the future.
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the provisions of the GDPR.
We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an action on your part (e.g. consent) or other individual notification.
If we further develop our website and our offerings or if legal or regulatory requirements change, it may be necessary to amend these data protection notices. You can access the respective current data protection notices at any time in our app.
Version: July 2026.