Privacy Policy of Studo Campus Applications

last updated on 16.09.2026

This privacy policy applies to all mobile campus apps listed here. The list is updated regularly. The apps are operated by Student & Campus Services GmbH, A-8010 Graz, Joanneumring 3 (‘we’ or ‘us’).

The protection of your personal data is of particular importance to us.

We process your data exclusively in accordance with the relevant legal provisions. In this policy, we inform you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), about how we, as the data controller, process your personal data in connection with this app.

1. General information on data collection and cookies

Information is collected and stored as part of the app. Some of this information is stored in a database within the app, whilst some is stored in cookies.

A cookie is a small text file that may be stored on your device when you visit a website. Cookies are generally used to provide you with additional features on a website.

Further information: The app is a browser; as such, it can be used to access websites available on the internet or on closed intranet networks. The privacy policies of the respective websites apply, and these may process and store cookies, interactions and browser data in accordance with their own guidelines.

2. Technical information regarding the operation of the app (all versions of the app)

What data: When you use our app, we collect the following information: the date and time you access the app, your IP address, system data relating to the device and operating system you are using, your telephone number, and any information that you, as a user and/or customer, provide to us yourself via the app. When you log in to your university via our app, your login details are stored locally on your device in a secure area. You can delete this data yourself by logging out of the university within the app or by uninstalling the app. Login details are sent exclusively via encrypted (HTTPS) connections directly from your device to the relevant university network. We have no control over which data is stored by the university on its network and could therefore be accessed via the app.

As part of technical troubleshooting and quality assurance, we analyse data processing procedures in order to identify and rectify errors in data presentation or transmission.

Purpose of processing: We process this data

  1. to make this app available to you and to further improve, develop and promote it;

  2. to detect, prevent and investigate attacks on our app;

  3. to respond to your enquiries;

  4. to satisfactorily fulfil the contract with you (as well as to carry out pre-contractual measures);

  5. to provide the various app functionalities;

  6. to compile usage statistics;

  7. to retrieve and process information from university systems for mobile-optimised display within the app;

Legal basis: The processing is carried out to fulfil the user agreement with you.

Retention period: We will generally store your data for a period of three 3 months. Data will only be stored for longer where this is necessary to investigate identified attacks on our app. If you register on our app, we will store your data for as long as your account remains active and, thereafter, for as long as required by law (until the expiry of the tax retention period, 7 years).

Data recipients: We only transfer your data to the relevant university in order to ensure the app functions properly.

3. Transfer of personal data to data processors and other persons/organisations

We use external service providers to assist us in delivering our services. To this end, your data will in any event be transferred to the following IT service providers (data processors) that we use:

  • Scalingo SAS, 13 rue Jacques Peirotes, 67000 Straßburg, Frankreich
    Cloud infrastructure

  • Scaleway SAS, 8 Rue de la Ville-l'Évêque, 75008 Paris, Frankreich
    Cloud infrastructure

  • iBASIS Communications AG, Industriering 14, 9491 Ruggell, Liechtenstein
    Sending SMS verification codes for authentication

  • ONLINECITY.IO, Buchwaldsgade 50, 5000 Odense C, Denmark
    Sending SMS verification codes for authentication (Fallback/Backup)

  • ClickSend Pty Ltd., Level 8 150 Lonsdale Street Melbourne, VIC 3000, Australia
    Sending SMS verification codes for authentication (Fallback/Backup)

  • Intercom Inc., 55 2nd Street, 4th Fl., San Francisco, CA 94105, USA
    User support

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
    Push notifications, app security, prevention of misuse

  • BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia
    Storage, delivery and streaming of video content

  • Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA
    File storage, web/IT security & content delivery (CDN)

Where recipients are located in third countries that are not members of the EU-US Data Privacy Framework, we have entered into standard contractual clauses with the recipients in accordance with Article 46 of the GDPR to ensure an adequate level of protection for the transfer of data.

In specific cases, in addition to the recipients already listed above, we may transfer your data to partner universities and other recipients, such as the European Commission. This only occurs when certain app features are used and subject to prior consent; if these features are not used, no data will be transferred; the specific categories of data transferred can be found in the relevant consent form.

4. Your rights in relation to personal data

You are entitled (subject to the relevant legal conditions) to

  • check whether we hold any personal data about you and, if so, what data we hold, and to receive copies of this data;

  • to request the rectification, supplementation or erasure of your personal data that is incorrect or is being processed in breach of the law;

  • to request that we restrict the processing of your personal data;

  • to request data portability;

  • to object to the processing of your personal data under certain circumstances;

  • to withdraw any consent previously given for the processing;

  • to know the identity of third parties to whom your personal data is disclosed; and

  • to lodge a complaint with the competent supervisory authority (in Austria: the Data Protection Authority) if you believe that the processing of your data breaches data protection law or that your data protection rights have otherwise been infringed. In this regard, we also refer you to the Data Protection Authority’s website, which can be accessed via this link.

5. Our contact details

If you have any questions or concerns regarding the processing of your personal data, please contact:

Student & Campus Services GmbH
A-8010 Graz, Joanneumring 3
Tel.: +43 664 8351081
Email: support@studo.com

Alternatively, you are also welcome to contact our Data Protection Officer:

Data Protection Officer at Student & Campus Services GmbH
Mag. Markus Dörfler
Email: datenschutz@studo.com