Legal
Privacy policy
How this website handles personal data. In short: as little as possible, and none of it for advertising.
Last updated
Controller
The controller for the purposes of the General Data Protection Regulation (GDPR) is:
- Name
- Bernhard Siegl
The full details including the postal address are in the imprint. Questions about data protection are answered at the email address given there. We are not required to appoint a data protection officer, as none of the conditions in Art 37 GDPR apply.
What this website does not do
Most of what a privacy policy is usually needed for does not happen here:
- No analytics tool, no audience measurement, no visitor counter.
- No cookies for analysis or advertising — and therefore no consent banner.
- No fonts, maps, videos or scripts loaded from someone else's servers when the page opens.
- No social network buttons and no embedded third-party content.
- No automated decision-making and no profiling.
Opening the site, and server logs
When a page is opened, the data a browser has to transmit for delivery to be possible at all is processed: IP address, time of the request, the address requested, the status code, the amount of data transferred, the program and version your browser reports, and, where it is sent, the page visited before.
This data serves only to deliver the page, to keep it running safely and to fend off automated attacks. It is not combined with other data and is not used to recognise individuals.
The legal basis is Art 6(1)(f) GDPR. Our legitimate interest is being able to run the website reliably and protected against attack. Our provider's logs are deleted or anonymised after a short period under its own rules; we keep no separate copy.
Hosting and delivery
This website consists of finished files with no server-side application and is delivered over the infrastructure of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. In doing so Cloudflare processes the access data described above as a processor on our behalf; a contract under Art 28 GDPR is in place.
Delivery normally happens from locations inside the European Union. Access from the United States cannot be ruled out. Cloudflare is certified under the EU-U.S. Data Privacy Framework, and the European Commission's standard contractual clauses apply in addition. The transfer is based on Art 45 and Art 46(2)(c) GDPR.
Contact form
If you write to us through the form on the contact page, your message goes, encrypted, to an application we develop ourselves and run on our own server in Austria. The connection to it runs over Cloudflare's network, like the website itself (see “Hosting and delivery”).
What is stored is your name, your email address, your message, the language of the page and the time it arrived, and also your IP address and the identification your browser sends. We remove the IP address and the browser identification from the message after a week. An email tells us that a message has arrived; it contains only your name, not your message.
The legal basis is your consent under Art 6(1)(a) GDPR, which you give by ticking the box before sending. You can withdraw it at any time with effect for the future; an informal message to the email address in the imprint is enough.
To guard against abuse, we record every attempt to send, with its IP address, time and outcome, for 30 days and then delete it. The legal basis for this is Art 6(1)(f) GDPR; our legitimate interest is protecting the form against automated mass submissions.
The message is deleted no later than twelve months after it arrived, and earlier if you ask. It is not passed on and not published. If we answer you by email, the next section applies to the correspondence that follows.
Getting in touch by email
If you write to us, we process your email address, your name and whatever you tell us in the message — solely to answer your enquiry and to prepare a possible project.
The legal basis is Art 6(1)(b) GDPR where the message serves to prepare or perform a contract, otherwise Art 6(1)(f) GDPR, based on our interest in answering enquiries.
Enquiries that do not turn into work are deleted no later than twelve months after the last exchange. Where work does follow, the correspondence falls under the seven-year retention obligations of Austrian commercial and tax law (§212 UGB, §132 BAO).
Email is an open medium. Between your mailbox and ours we cannot guarantee confidentiality. Please do not send us credentials or particularly sensitive information by email; for anything like that we will agree on another route.
Cookies
We set no cookies. There is nothing on this website we would need one for, and therefore no window for you to dismiss.
Our provider may set technically necessary cookies as part of fending off attacks, for instance after a request has been classified as automated. Cookies of that kind serve only the security of the transmission and do not require consent under §165(3) of the Austrian Telecommunications Act 2021.
Fonts
The Geist and Geist Mono typefaces are served from our own server. Opening this page sends no request to Google Fonts or any other outside service, and no IP address is passed to a third party in the process.
Recipients
We pass personal data on only where it is necessary to run the site or where the law requires it:
| Recipient | For what | Basis |
|---|---|---|
| Cloudflare, Inc. | Delivering the website, fending off automated attacks | Art 6(1)(f), processing agreement under Art 28 |
| Email provider | Receiving and delivering your messages | Art 6(1)(b) and (f), processing agreement under Art 28 |
| Tax adviser, tax office | Bookkeeping and statutory retention, once work is commissioned | Art 6(1)(c) |
Data is not sold, and it is not passed on for advertising purposes.
Your rights
You have the following rights in relation to us:
- Access to whether and what data we hold about you (Art 15 GDPR).
- Rectification of inaccurate data (Art 16 GDPR).
- Erasure, unless a retention obligation stands in the way (Art 17 GDPR).
- Restriction of processing (Art 18 GDPR).
- A copy of the data you provided, in a common format (Art 20 GDPR).
- Objection to processing we base on a legitimate interest (Art 21 GDPR).
An informal message to the email address in the imprint is enough. We answer within one month. Where we have doubts about who is writing, we ask before we disclose anything — that protects you, not us.
Complaints to the supervisory authority
If you believe we are processing your data unlawfully, you can complain to the supervisory authority. The competent one is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.
Changes to this policy
When the website changes, this policy changes with it. The version published here is the one that applies; the date is at the top of the page.