top of page

Privacy Policy

Last updated: 27 August 2026

We respect your privacy. This policy explains our processing of personal data under the EU General Data Protection Regulation (GDPR), Austrian Data Protection Act (DSG) and Telecommunications Act 2021 (TKG).

1. Who is responsible for your data?

Amit Rathee — Quantum Nexus International (QNI)
Fernkorngasse 25/36
1100 Vienna, Austria
Email: office@qunexus.com

2. Website, technical infrastructure, and cookies

Our website is hosted by external web platform and infrastructure providers (including Wix.com Ltd.). Technical information—including IP addresses, browser specifications, operating system details, requested URLs, referrer headers, and access timestamps—is processed to securely deliver website content and prevent cyberattacks.

  • Legal Basis: Article 6(1)(f) GDPR (our legitimate interest in operating a functional, secure website).

We utilize a centralized consent management tool (Usercentrics GmbH) to manage cookie preferences and record legally required consent records under Article 6(1)(c) GDPR.

Strictly necessary technical cookies support essential site navigation, security, and consent logging. Optional tracking and analytics technologies require prior explicit opt-in consent pursuant to Article 6(1)(a) GDPR and § 165(3) of the Austrian Telecommunications Act (TKG 2021). You may manage or revoke your optional consent at any time through our website’s Cookie Settings.

  • Essential Session Cookies: Functional session cookies (e.g., hs, XSRF-TOKEN, client-session-bind) ensure secure browsing and expire upon closing your browser session.

  • Security & Anti-Abuse Cookies: Security cookies (e.g., __cf_bm) protect against automated abuse and expire after 30 minutes of inactivity.

  • Consent Storage Cookies: Preference cookies (e.g., consent-policy) retain your privacy choices for up to 12 months.

(Note: Real-time dynamic cookie inventories are managed directly via our consent management tool)

3. Contact, administration, and professional research

When you contact us via email, telephone, or web forms, we process your contact details, message contents, attachments, and communication metadata.

  • Legal Basis: Article 6(1)(b) GDPR for communications concerning pre-contractual steps or contractual fulfillment; Article 6(1)(f) GDPR for handling general business inquiries.

We use cloud business suites (including Google Workspace) for internal productivity, document storage, and communication management.

Professional Research & Outreach:

To identify potential academic contributors, speakers, and collaboration partners, we process publicly available professional details (e.g., names, roles, affiliations, public contact details) obtained from professional platforms like LinkedIn.

  • Legal Basis: Article 6(1)(f) GDPR (our legitimate interest in academic and professional networking).

  • Direct Outreach Compliance: Electronic contact based on professional research is restricted to individual, non-promotional correspondence concerning specific academic or research collaborations, strictly adhering to anti-spam requirements under § 174 TKG 2021.

4. Submissions, published works, and account management

We process submitted manuscripts, editorial communications, author biographies, and metadata to review, edit, and publish articles, research, and educational media.

Legal Basis: Article 6(1)(b) GDPR for publication agreements; Article 6(1)(f) GDPR for editorial administration and protecting legal authorship rights.

Optional profile details, such as contributor photos, extended biographies, or social links—are published strictly based on voluntary consent under Article 6(1)(a) GDPR.

Published works and author profiles are publicly accessible globally and indexed by search engines. Revoking consent for optional profile features does not retroactively mandate the deletion of published editorial articles governed by separate contracts or legitimate archival interests. Where member account features are activated, registration details are processed under Articles 6(1)(b) and 6(1)(f) GDPR to secure account functionality.

5. Virtual sessions, webinars, and public media releases

We conduct virtual workshops, webinars, and live events using external video conferencing infrastructure (such as Zoom Communications, Inc.). Processed data may include names, email addresses, registration details, attendance timestamps, IP addresses, audio/video feeds, and text chat logs.

  • Session Delivery: Registration and session delivery rely on Article 6(1)(b) GDPR (contractual performance/event registration) and Article 6(1)(f) GDPR (operational security).

  • Public Recording & Distribution: Selected educational sessions are recorded and published on public video hosting channels (such as YouTube/Google). Capturing and publishing identifiable attendee contributions (video streams, audio input, or named chat messages) rely on separate, explicit consent under Article 6(1)(a) GDPR.

Event registration alone does not constitute consent to appear in public recordings. Non-consenting participants are permitted to attend with cameras and microphones disabled and anonymous display names. Published recordings remain online while serving their intended educational purpose.

If consent is withdrawn post-publication, we will undertake reasonable technical steps (such as video blurring or audio redaction) to remove identifiable contributions. We are not legally accountable for independent third-party downloads or external indexers executed prior to consent withdrawal.

6. Promotional communications and embedded third-party media

Promotional updates, project news, and electronic newsletters are sent exclusively to recipients who have provided explicit opt-in consent pursuant to Article 6(1)(a) GDPR and § 174 TKG 2021. You may revoke your consent at any time via the unsubscribe link in each email or by contacting office@qunexus.com.

Embedded Media & Joint Controllership Notice:

Our website may display embedded third-party media elements (such as Instagram feeds or video players). Loading pages containing active third-party widgets automatically transmits technical data (IP address, browser metadata, URL visited) to the respective platform operators (e.g., Meta Platforms Ireland Ltd. or Google Ireland Ltd.). Where mandatory under Article 26 GDPR, we act as joint controllers solely for the initial collection and transmission phase of such technical data. Further data processing by third-party platforms is governed strictly by their independent privacy policies. Any non-essential tracking via embedded third-party media requires your prior approval through our consent banner.

7. Recipients and international data transfers

Personal data may be shared with or accessed by the following categories of recipients to fulfill statutory, technical, and operational purposes:

 

Web Hosting & Security Infrastructure Providers (e.g., Wix.com Ltd., Cloudflare, Inc.); Consent Management Vendors (e.g., Usercentrics GmbH); Cloud Productivity & Email Service Providers (e.g., Google Workspace / Google Ireland Ltd.); Video Conferencing & Video Streaming Platforms (e.g., Zoom Communications, Inc., YouTube); Embedded Social Media Platforms (e.g., Meta Platforms Ireland Ltd).

 

Non-Employee Project Leadership & Global Technical Collaborators: Authorised non-employee co-founders, independent contractors, and remote technical personnel (including team members operating outside the European Economic Area in countries like India) who process data to deliver system maintenance, editorial administration, and user management. Legal Advisers, Auditors, & Public Authorities where required by law or necessary to establish, exercise, or defend legal claims.

International Transfer Safeguards:

Where personal data is accessed by or transferred to personnel, contractors, or service providers located outside the European Economic Area (EEA) in third countries lacking an EU Adequacy Decision (such as India or non-certified US entities), processing is safeguarded pursuant to Chapter V GDPR through:

  1. Contractual Safeguards: Execution of European Commission Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR and formal Data Processing Agreements (DPAs) prior to data access.

  2. Technical & Operational Safeguards: Technical security controls under Article 32 GDPR—including end-to-end encryption in transit and at rest, role-based access controls (RBAC), and mandatory Multi-Factor Authentication (MFA).

  3. Framework Compliance: Reliance on formal Adequacy Decisions or certified transfer frameworks (such as the EU–U.S. Data Privacy Framework) where applicable.

8. Data retention periods

Personal data is retained only for as long as necessary to fulfill the specific processing purposes for which it was collected, or to comply with applicable statutory legal obligations. General business inquiries, preliminary project submissions, and routine communication records are erased within 12 months following their final resolution or operational closure under our legitimate interest pursuant to Article 6(1)(f) GDPR. Event registration details and participant administrative records are similarly retained strictly for event execution and deleted within 12 months post-event under Article 6(1)(b) GDPR. Professional contact data gathered for research, academic exchange, and networking is stored only as long as an active, mutual, or reasonably anticipated professional collaboration exists, after which it is purged.

Where content is publicly published—including articles, research papers, project entries, and necessary authorship attribution—data is maintained for the duration of publication availability to preserve scientific integrity, legal authorship rights, and historical public archives under Article 6(1)(f) GDPR and applicable publishing agreements. Data processed for electronic marketing updates or optional contributor profile displays is retained until voluntary consent is revoked under Article 6(1)(a) GDPR or until the underlying presentation purpose expires. Account credentials and user registration details remain active for as long as needed to deliver secure account functionality.

Notwithstanding operational retention limits, statutory archiving duties under Austrian commercial and tax law mandate longer retention periods. Accounting records, invoices, tax documents, bank statements, business correspondence, and relevant financial files must be retained for a statutory period of seven years following the end of the relevant calendar year pursuant to § 132 of the Austrian Federal Fiscal Code (BAO). Furthermore, specific communication or transactional data may be preserved beyond standard periods where strictly necessary to establish, exercise, or defend against legal claims, subject to civil statutory limitation periods of up to 30 years under §§ 1478 and 1489 of the Austrian General Civil Code (ABGB). Once applicable statutory retention windows expire or legal interests cease, the data is permanently erased or anonymized. Providing personal information is voluntary, though failure to supply data required for contractual fulfillment or legal compliance prevents access to the corresponding service or publication.

9. Your statutory rights

Under the GDPR, you possess statutory rights regarding your personal data, including the rights to access your data, request rectification of inaccurate records, or demand erasure ("right to be forgotten"), subject to statutory retention duties. You may also request restriction of processing, obtain your data in a portable format (data portability), or object at any time to processing grounded in legitimate interests or direct marketing. Where processing relies on your consent, you may withdraw consent free of charge at any time via website cookie settings, unsubscribe links, or by emailing office@qunexus.com.

If you believe our data processing infringes applicable data protection laws, you maintain the legal right under Article 77 GDPR to lodge a complaint with a competent supervisory authority. In Austria, the responsible regulatory body is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde – DSB), located at Barichgasse 40–42, 1030 Vienna, Austria (Email: dsb@dsb.gv.at | Website: dsb.gv.at).

bottom of page