A. Controller
B. General data processing
Personal data is processed only where necessary for operating this website, ensuring its security, handling communication, or initiating and performing pre-contractual or contractual services.
No profiling for advertising or marketing purposes takes place.
No solely automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR takes place.
C. Hosting and server log files
This website is hosted on a VPS of Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany. Where Contabo acts as a processor, a data processing agreement pursuant to Art. 28 GDPR is to be concluded and documented in a verifiable manner.
When the website is accessed, technical request data may be processed.
Processing takes place for technical delivery of the website, stable and secure operation, abuse prevention, and error analysis.
The legal basis is Art. 6(1)(f) GDPR.
Server log data is stored only for as long as necessary for these purposes and is then deleted or anonymized unless statutory retention duties or a security-related review require otherwise.
- IP address
- date and time of the request
- requested URL or file
- referrer URL, if transmitted
- user agent and browser information
- HTTP status code
- transferred data volume
D. Cloudflare / CDN and security functions
This website uses services provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, where the domain is delivered through Cloudflare's proxy.
Cloudflare is used as a CDN, proxy, and security service to deliver the website securely, reliably, and efficiently, defend against attacks, and detect abusive or automated access.
Data processed may include the IP address, time and destination of the request, requested URL, HTTP headers, referrer, user-agent and browser information, technical connection data, security events, and results of automated security checks.
Cloudflare functions such as Bot Fight Mode, Block AI Bots, and AI Labyrinth may be used to protect the website against automated access, provided they are enabled in the live configuration. Which functions are actually active is verified live before a corresponding public statement is made.
Bot Fight Mode analyzes technical access signals and may block automated requests or subject them to a security check. For this purpose, Cloudflare may execute invisible JavaScript and, where the function is enabled, set technically required cookies such as "__cf_bm" and "cf_clearance". Block AI Bots targets known AI crawlers and crawlers identified through technical characteristics. AI Labyrinth may add links with generated content that are hidden from normal users and marked with nofollow so that non-compliant crawlers can encounter them.
Processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, reliable, and efficient provision of the website and its protection against attacks, scraping, spam, and other abusive automated access.
Where Cloudflare acts as a processor, a Data Processing Addendum or data processing agreement is to be concluded and documented in a verifiable manner.
Processing in the United States cannot be excluded. According to Cloudflare, relevant transfers are based on the EU-US Data Privacy Framework and, where this is not applicable, on Standard Contractual Clauses and supplementary safeguards.
The retention period depends on the type and purpose of the security event and the contractual configuration. According to Cloudflare, the "__cf_bm" cookie expires after 30 minutes of continuous inactivity. Security verification information stored in the "cf_clearance" cookie is retained temporarily according to the applicable security configuration.
E. Contact requests / contact form
When the contact form is used, the website processes name, reply email, an optional project or inquiry category, and the message.
The technical field "company" is used as a honeypot for spam prevention. It is not intended for regular users and should remain empty.
Processing takes place to answer the inquiry, handle project communication, and, where applicable, initiate or perform pre-contractual or contractual steps.
The legal basis is Art. 6(1)(b) GDPR where the inquiry relates to pre-contractual or contractual steps. Otherwise, processing is based on Art. 6(1)(f) GDPR for general communication, spam prevention, abuse prevention, and technical security.
Providing this data is neither legally nor contractually required. However, without reachable contact details and a sufficiently specific message, the inquiry cannot be processed.
Contact form inquiries are forwarded for processing by email to the configured recipient address.
Transmission takes place via the technical infrastructure used for website and email operations.
Recipients or categories of recipients are technical service providers for hosting, email/SMTP delivery, security services, maintenance, and website operations; this includes the hosting provider, the email/SMTP provider, and Cloudflare where requests are processed through Cloudflare infrastructure.
Inquiry data is deleted when it is no longer required for handling the request unless statutory retention duties apply.
F. Technically required cookies and preferences
The website uses functional preferences and technically required security cookies.
The cookies "site-language" and "site-theme" retain the selected language and theme for up to twelve months.
When Cloudflare Bot Fight Mode is enabled, the security cookies "__cf_bm" and "cf_clearance" may also be set. They are used for bot detection, performing or storing security checks, and avoiding unnecessary repeated checks. They are not used for advertising or cross-site tracking.
Personal data is processed on the basis of Art. 6(1)(f) GDPR. Storage of or access to information on end-user devices takes place in accordance with Section 165(3) of the Austrian Telecommunications Act 2021 where strictly necessary to provide the expressly requested website and operate it securely.
No marketing or tracking cookies are currently used. No consent banner is displayed because only technically required security cookies and functional preferences selected by the user are used.
No third-party embeds such as maps or video services are loaded without prior user interaction.
G. Cloudflare Web Analytics
Server-side aggregated usage metrics derived from traffic running through the Cloudflare proxy/CDN (see section D) are evaluated via the Cloudflare dashboard. No JavaScript beacon is deployed on the website itself for this purpose, and no cookies or localStorage are used. The legal basis is Art. 6(1)(f) GDPR.
The "Cloudflare Web Analytics" JavaScript beacon is not embedded. A privacy statement and any required consent logic will be reviewed again before a later activation.
H. Data subject rights
Subject to the statutory requirements, data subjects have the following rights in particular:
- access to processed personal data
- rectification of inaccurate data
- erasure of personal data
- restriction of processing
- data portability, where applicable
- objection to processing based on legitimate interests
- withdrawal of consent with future effect where processing is based on consent
- complaint to a supervisory authority
I. Supervisory authority
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Austria
Website: dsb.gv.at