Privacy
This page explains which personal data we process when you visit unipass.at, write a practice exam or join the waitlist, for what purpose, on what legal basis and for how long, and what rights you have (Art. 13 GDPR). This is a translation; the German version applies.
1. Controller
Ilya Belov und Emir Takhaviev, Nußwaldgasse 1, 1190 Wien, Austria. E-mail: support@unipass.at. We have not appointed a data protection officer; send any question to this address.
2. Visiting the website
The website is a set of static pages. When you open it, our hosting provider processes technically necessary data: your IP address, date and time, the address requested and your browser identifier. This is needed to deliver the page and protect it from abuse (legitimate interest, Art. 6(1)(f) GDPR). We do not keep access logs of the website ourselves.
We set no cookies. In your browser's storage (localStorage and, for your notes, IndexedDB) the pages keep only what they need to work: which articles you have read, your choices in the guides, an unfinished practice exam, your notes for it and the IDs of your recent practice exams (section 5). This stays on your device; only when you start a practice exam does your browser send us these IDs, and when you hand it in, your answers and, if you write on screen, the details of how you worked. You can delete this data at any time in your browser settings. Fonts and formula rendering are loaded from our own domain; there are no requests to Google Fonts or other font providers. The website calls no other third-party servers.
3. Audience measurement
We currently do not measure use of the website. If we introduce measurement, we will update this section first.
4. Waitlist
When you join the waitlist, we store your e-mail address, the page language, the interest you selected (optional), the wording and version of the consent you saw, time, IP address and browser identifier of the sign-up, time and IP address of the confirmation, and the times of the last confirmation e-mails. The purpose is to send you e-mails with news about the launch of unipass courses, reminders of WU admission deadlines and unipass offers, at most two a month. The legal basis is your consent (Art. 6(1)(a) GDPR, § 174(3) TKG 2021). We store time, IP address and wording to be able to prove consent (Art. 7(1) GDPR).
We use double opt-in: after you submit the form you get an e-mail with a confirmation link. Only when you confirm on the linked page are you on the list. The link expires after 72 hours; unconfirmed entries are deleted automatically after 7 days (for technical reasons this can take a few days longer). The confirmation e-mail contains no advertising.
You can withdraw consent at any time, via the unsubscribe link in every e-mail or by writing to support@unipass.at. After you unsubscribe we delete the interest you selected and the browser identifier. We keep the address with the time of unsubscribing and, as evidence of your consent and its withdrawal, its wording and version, the language, time and IP address of sign-up and confirmation, and the times of the last e-mails, so that we reliably send you nothing more (legitimate interest, Art. 6(1)(f) GDPR). You can ask for complete deletion at any time. An unsubscribed address cannot be signed up again through the form, so that nobody else can re-subscribe you; to rejoin, write to support@unipass.at. Confirmed entries without unsubscription are deleted when we stop running the waitlist.
To prevent abuse (automated mass sign-ups) we count sign-ups per IP address (for IPv6, per /64 network) and hour. We store not the IP address but a shortened hash of it; the counter is deleted automatically after about two hours (legitimate interest, Art. 6(1)(f) GDPR). Per address we store the times of the last confirmation e-mails so that at most three are sent per day. Running the waitlist produces technical logs that are kept for 30 days. They contain no e-mail addresses, only a shortened hash of them (pseudonymised), so we can match errors to an entry.
Consent is voluntary and not a condition for using the website.
5. Practice exam
The practice exam Mathematik (CBK) works without sign-up and without an e-mail address. When you start it, our server creates an attempt with a random ID and stores the time of the start and which tasks, in which version, you get. When you hand in, we store your answers, the result (right, wrong and blank answers, points, passed or not) and the time of handing in. We do not store your IP address, your e-mail address or an identifier of your browser with the attempt.
If you write on screen, we also store how you worked: how long each task was on screen while the page was visible, the window was in front, and you were doing something (after 5 minutes without input this time stops counting), how often you opened a task and changed your answer, which answer you ticked first, which answers you struck out, how sure you were, which tasks you marked for later, and whether the training aids were on.
The purpose is to show you your result with worked solutions, also when you request it again after a lost connection, and to make your review more precise with the details of how you worked; to give you other tasks where possible in a later practice exam (with the list of your recent attempts, see below); and anonymous statistics on which tasks are often answered wrongly or take particularly long, so that we can improve the tasks. The legal basis is our legitimate interest in this (Art. 6(1)(f) GDPR). We delete an attempt that was not handed in automatically after 2 days and a handed-in attempt after 400 days (for technical reasons this can take a few days longer). The details of how you worked belong to the attempt and are deleted with it. Only someone who knows its ID can retrieve an attempt; as described above, the attempt itself contains no IP address, no e-mail address and no identifier of your browser.
To prevent abuse we count starts and hand-ins per IP address (for IPv6, per /64 network) and hour. We store not the IP address but a shortened hash of it, formed with a secret key that changes daily (HMAC); the counter for that hour expires at the latest two hours after the last access to it and is then deleted automatically (for technical reasons this can take a few days). The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). Running it produces technical logs that are kept for 30 days; they contain neither your IP address nor your answers.
While you write, your browser keeps the attempt's ID, the tasks of this attempt, your answers and flags, the details of how you worked named above, your settings on the page (for example whether the training aids are on and which task you have open) and, after handing in, the result in its storage (localStorage, under keys with the prefix unipass_probe_v1_), so that reloading the page loses nothing. For each task it also keeps the order in which you have answered so far (the first 20 answers). For the attempt as a whole it also keeps whether you are writing the exam on screen or on a printed sheet, and whether you have hidden the clock; your browser does not send this to us. This is strictly necessary for the practice exam you start yourself; it needs no consent (§ 165(3) TKG 2021). If you write on screen, your browser sends us these details only when you hand in. This data stays on your device until you start a new practice exam or delete it in your browser; the list of your recent attempts is kept (see below).
If you open the notepad, or the page opens it by itself because it has detected a pen, your browser keeps your strokes per attempt and task in its own database (IndexedDB, under unipass_probe_v1_notes). In browsers that cannot list their databases, opening the practice exam page already creates this database, empty, so that old notes can be cleaned up.
Even without opening the notepad, the page remembers, once you have started a practice exam, under unipass_probe_v1_notes_prefs: whether it has shown you the tablet hint once (it tells a tablet by the kind of input and the screen size; that itself is neither stored nor sent), and whether it has detected a pen, hovering included, and whether the notepad should open by itself for that, and the attempt for which it last opened by itself. If you choose a tool or change its settings in the notepad, it also remembers the tool you last chose (Pen, Highlighter, Eraser, Shapes or Lasso) and that tool's own settings: colour and stroke width for the pen and the highlighter, mode and size for the eraser, the chosen shape and whether the axes have a scale, and also the previous tool together with its colour. Your browser sends none of this to us, not even when you hand in. This is strictly necessary for the practice exam you start yourself; it needs no consent (§ 165(3) TKG 2021). These settings stay on your device until you delete them in your browser; your notes are deleted together with their attempt when you start a new practice exam, our server finally refuses the hand-in or you delete them in your browser.
So that your next practice exam brings other tasks where possible, your browser also keeps the IDs of your last 20 attempts (under unipass_probe_v1_seen) and sends them when you start. Storing this list is strictly necessary so that the next practice exam you start brings tasks you have not had yet; it needs no consent (§ 165(3) TKG 2021). The IDs stay on your device until you delete them in your browser. At a start our server only reads which tasks you had in those attempts, and picks others where possible; attempts it cannot find (any more) are skipped. We do not store the list itself. The legal basis for this is our legitimate interest (Art. 6(1)(f) GDPR), for the purpose named above.
6. Contact by e-mail
If you write to support@unipass.at, we process your message and address to reply (Art. 6(1)(b) or (f) GDPR) and delete them once the request is settled and no retention duty applies.
7. Recipients and processors
- Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg: website hosting, the waitlist and practice exam databases and e-mail delivery, data centre in Frankfurt am Main. Pages are delivered through a worldwide network of servers.
- GoDaddy (contract partner) and Microsoft Ireland Operations Ltd. (Microsoft 365): the support@unipass.at mailbox.
Amazon, Microsoft and GoDaddy have parent companies in the USA. A transfer to the USA cannot be ruled out; it relies on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), under which Amazon and Microsoft are certified. We do not pass on or sell data beyond this.
8. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15 to 21 GDPR), and the right to withdraw consent at any time with effect for the future. Write to support@unipass.at.
You can lodge a complaint with the supervisory authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
9. Age
In Austria you can consent to the processing of your data for such a service yourself from the age of 14 (§ 4(4) DSG).
10. No automated decisions
We make no automated decisions and do not profile you.
Last updated: 27 September 2026