Skip to content

A. Controller

Florian Josef Altendorfer

Zeller Straße 12/1

6330 Kufstein

Austria

Email: [email protected]

B. General data processing

Personal data is processed only where necessary for operating this website, ensuring its security, handling communication, or initiating and performing pre-contractual or contractual services.

No profiling for advertising or marketing purposes takes place.

No solely automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR takes place.

C. Hosting and technical logs

This website is hosted by Contabo GmbH on a server in the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with Contabo.

The Next.js application and upstream Traefik service keep no general access logs. Limited technical operational and error logs may arise for operation, security, and error analysis.

The legal basis is Art. 6(1)(f) GDPR.

Technical logs are limited to what is necessary for these purposes and are then deleted or anonymized unless statutory retention duties or a security-related review require otherwise.

D. Cloudflare / CDN and security functions

This website uses Cloudflare for DNS, CDN, and as a reverse proxy.

Managed security rules, bot protection, JavaScript Detections, AI Labyrinth, and AI crawler policies are enabled to protect the website.

Data processed may include the IP address, timestamp, hostname, HTTP method, URL or path, HTTP headers, referrer, user agent, connection information, rule or score values, the action taken, and its result.

AI Labyrinth may inject nofollow links only for traffic identified as bots. These links are not visible to ordinary visitors.

Processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, reliable, and efficient provision of the website and its protection against attacks, scraping, spam, and other abusive automated access.

E. Contact requests / contact form

When the contact form is used, the website processes name, reply email, an optional project or inquiry category, and the message.

The technical field "company" is used as a honeypot for spam prevention. It is not intended for regular users and should remain empty.

Processing takes place to answer the inquiry, handle project communication, and, where applicable, initiate or perform pre-contractual or contractual steps.

The legal basis is Art. 6(1)(b) GDPR where the inquiry relates to pre-contractual or contractual steps. Otherwise, processing is based on Art. 6(1)(f) GDPR for general communication, spam prevention, abuse prevention, and technical security.

Providing this data is neither legally nor contractually required. However, without reachable contact details and a sufficiently specific message, the inquiry cannot be processed.

Contact form inquiries are sent by SMTP as email to the configured recipient address. The application does not store contact inquiries in its own database.

Normally submitted form fields are not written to general application logs. Limited technical operational or delivery errors may be recorded without a general log of message contents.

Recipients or categories of recipients are technical service providers for hosting, email/SMTP delivery, security services, maintenance, and website operations; this includes the hosting provider, the email/SMTP provider, and Cloudflare where requests are processed through Cloudflare infrastructure.

Inquiry data is deleted when it is no longer required for handling the request unless statutory retention duties apply.

F. Technically required cookies and preferences

The website uses functional preferences and technically required security cookies.

The selected language is determined by the requested URL path. For appearance, the website may store the light or dark selection under the key "site-theme" in the browser's local storage (localStorage). The website does not set its own language or theme cookies.

The "__cf_bm" cookie supports bot protection. "cf_clearance" temporarily stores proof of a completed security check or JavaScript detection. Both are technically required security cookies and are not used for marketing.

Personal data is processed on the basis of Art. 6(1)(f) GDPR. Storage of or access to information on end-user devices takes place in accordance with Section 165(3) of the Austrian Telecommunications Act 2021 where strictly necessary to provide the expressly requested website and operate it securely.

No marketing cookies are currently used. No consent banner is displayed.

No third-party embeds such as maps or video services are loaded without prior user interaction.

G. Cloudflare Web Analytics

Cloudflare Web Analytics uses a lightweight JavaScript RUM beacon that may be injected at the edge for eligible traffic proxied through Cloudflare.

Data handled may include a page-load identifier, referrer and landing path, navigation and resource timings, First Contentful Paint (FCP), Largest Contentful Paint (LCP), Cumulative Layout Shift (CLS), Time to First Byte (TTFB), and Interaction to Next Paint (INP).

According to Cloudflare, Web Analytics uses no cookies, localStorage, sessionStorage, or IndexedDB. The source IP address is received during HTTP handling, discarded at the nearest Cloudflare edge, and not stored in the RUM service's core databases or logs.

The current setting excludes visitor data in the European Union. Web Analytics is not a cookie. The legal basis is Art. 6(1)(f) GDPR.

H. Data subject rights

Subject to the statutory requirements, data subjects have the following rights in particular:

  • access to processed personal data
  • rectification of inaccurate data
  • erasure of personal data
  • restriction of processing
  • data portability, where applicable
  • objection to processing based on legitimate interests
  • withdrawal of consent with future effect where processing is based on consent
  • complaint to a supervisory authority

I. Supervisory authority

Austrian Data Protection Authority

Barichgasse 40-42

1030 Vienna

Austria

Website: dsb.gv.at