Privacy policy

From Dreams Knowledge Platform
Jump to: navigation, search

DREAMS Knowledge Platform

Last updated 22 September 2026

This privacy policy explains how personal data is processed when you use the DREAMS Knowledge Platform (the "Platform"), accessible at dreams15mc.eu.

The Platform is part of the DREAMS research project, funded under the Driving Urban Transitions Partnership. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Austrian Data Protection Act (DSG).


1. Who is responsible for your data (controller)

The Platform is operated by mobyome KG, which is the controller for the processing described in this policy.

  • Controller: mobyome KG, Lerchenfelder Straße 65/4, 1070 Vienna, Austria
  • Data protection contact: office@mobyome.at

2. What personal data we process

We limit the processing of personal data to what is necessary to run the Platform.

Technical data. When you open a page, our web server records your IP address, the date and time of the request, the requested page, the referring page, and your browser and operating system.

Editor accounts. Accounts cannot be registered publicly. Administrators create them for members of the DREAMS project team. For each account we store

  • the username
  • the password in hashed form
  • an email address, if provided
  • the preferences set by the account holder

Page history. Every page keeps a public version history showing the username and time of each edit. Editing without an account is not possible, so no IP addresses appear in the history. We do not store the IP addresses from which edits are made.

Emails. If you email us, we process your address and the content of your message.

Browser storage. Checklists on some pages save your progress in your browser's local storage. This data stays on your own device and is never sent to us.

We do not process special categories of personal data within the meaning of Art. 9 GDPR through the Platform.


3. Why we process your data and the legal basis

  • To deliver and secure the Platform (server logs, session cookies), based on our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
  • To give project members editing access (editor accounts), based on our legitimate interest in organising the joint editorial work of the project (Art. 6(1)(f) GDPR).
  • To document authorship and changes (page history), based on our legitimate interest in transparent and traceable content (Art. 6(1)(f) GDPR).
  • To answer enquiries (emails), based on our legitimate interest in communicating with you (Art. 6(1)(f) GDPR).

4. How long we keep your data

  • Server logs are deleted after 30 days, unless a security incident requires us to keep specific entries for longer.
  • Account data is kept for as long as the account exists. When an account is closed, contributions remain on the Platform, but the account can be renamed so that it no longer identifies its holder.
  • Emails are deleted once they are no longer needed, unless legal retention periods apply.

5. Who has access to your data

Access to personal data is limited to the Platform administrators.

  • Hosting provider. The Platform is hosted by helloly GmbH, which processes data on our behalf under a data processing agreement (Art. 28 GDPR).
  • External websites. The Platform links to external websites, for example partner organisations, LinkedIn and the MinuteMap tool. These are plain links. No data is sent to these sites until you click a link, and all fonts, scripts and images of the Platform are delivered from our own server.

We do not sell personal data and do not use it for advertising.


6. International data transfers

Personal data processed through the Platform is not transferred to countries outside the European Economic Area.


7. Cookies

The Platform uses only strictly necessary cookies. Reading the Platform sets none. When editors log in, MediaWiki sets session cookies that keep them logged in and protect their edits against forgery. If an editor chooses to stay logged in, a login cookie is kept for up to 30 days. These cookies are strictly necessary for a service the user requests, so they do not require consent (§ 165(3) Austrian Telecommunications Act 2021).

The Platform does not use analytics, advertising or tracking cookies. If this ever changes, we will update this policy and ask for your consent before any such cookie is set.


8. Where your data is stored and how it is secured

The Platform is hosted on servers in Austria by helloly GmbH, Rainerstraße 25, 4020 Linz, Austria.

We protect personal data with appropriate technical and organisational measures, including

  • encrypted connections (HTTPS)
  • individual editor accounts with hashed passwords, created only by administrators
  • no storage of editors' IP addresses
  • regular software updates

In the event of a personal data breach, we notify the Austrian Data Protection Authority without undue delay and, where feasible, within 72 hours, and inform affected persons where the breach is likely to result in a high risk to them (Art. 33 and 34 GDPR).


9. Your rights

Under the GDPR you have the following rights regarding your personal data.

  • Right of access to confirmation of whether we process your data and a copy of it (Art. 15)
  • Right to rectification of inaccurate or incomplete data (Art. 16)
  • Right to erasure where there is no reason to keep your data (Art. 17)
  • Right to restriction of processing in certain circumstances (Art. 18)
  • Right to data portability for data you provided (Art. 20)
  • Right to object to processing based on our legitimate interests (Art. 21)

To exercise any of these rights, contact office@mobyome.at.


10. Right to lodge a complaint

If you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence, place of work or of the alleged infringement.

In Austria, the competent authority is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna (www.dsb.gv.at).


11. Research data of the DREAMS project

This policy covers only the use of the Platform. The Platform publishes research results in aggregated or anonymised form and contains no data from which survey or workshop participants can be identified.

The surveys and workshops of the DREAMS project are carried out by the research partners, who process the participants' data as joint controllers under Art. 26 GDPR. If you took part in a DREAMS survey or workshop, the information you received with your consent form applies. For questions about that data, contact the partner named there or the project coordinator at the University of Twente.


12. Changes to this privacy policy

We update this policy when the Platform or the legal requirements change. The current version, with its date, is always available on this page.

See also the Legal notice.