Privacy Policy
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and especially on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offering").
The terms used are not gender-specific.
Status: April 26, 2026
Table of Contents
Preamble
Controller
Overview of Processing Activities
Relevant Legal Bases
Security Measures
Transfer of Personal Data
International Data Transfers
General Information on Data Storage and Deletion
Rights of Data Subjects
Provision of the Online Offering and Web Hosting
Use of Cookies
Registration, Login and User Account
Plugins and Embedded Functions and Content
Privacy Information for Whistleblowers
Changes and Updates
Definitions
Controller
Mario Elsnig
Schörgenhub Street 38
4030 Linz
Austria
Email address: mario.elsnig@gmail.com
Legal notice: https://privacy.programar.io/impressum
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects concerned.
Types of data processed: Master data. Employee data. Contact data. Content data. Usage data. Meta, communication and procedural data. Log data.
Categories of data subjects: Employees. Users. Third parties. Whistleblowers.
Purposes of processing: Provision of contractual services and fulfillment of contractual obligations. Security measures. Organizational and administrative procedures. Provision of our online offering and user-friendliness. Information technology infrastructure. Whistleblower protection.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or registered office.
Consent (Art. 6 para. 1 sentence 1 lit. a GDPR) - The data subject has given consent to the processing of personal data concerning them for one or more specific purposes.
Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR) - Processing is necessary for the performance of a contract or for the implementation of pre-contractual measures.
Legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR) - Processing is necessary to fulfill a legal obligation.
Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) - Processing is necessary for the purposes of legitimate interests pursued by the controller or a third party.
National data protection regulations in Austria: In addition to the GDPR, national regulations apply, in particular the Austrian Data Protection Act.
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements to ensure a level of protection appropriate to the risk.
These measures include ensuring confidentiality, integrity and availability of data, as well as procedures for data deletion and handling risks.
Securing online connections through TLS/SSL encryption (HTTPS): We use encryption technologies to protect user data during transmission.
Transfer of Personal Data
As part of our processing of personal data, data may be transferred to other entities, companies, or persons. In such cases, we comply with legal requirements and conclude appropriate agreements to protect your data.
International Data Transfers
Data processing in third countries: If we transfer data outside the EU or EEA, this is done in compliance with legal requirements.
For transfers to the USA, we rely on the Data Privacy Framework (DPF).
More information: https://www.dataprivacyframework.gov/
EU Commission info: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de
General Information on Data Storage and Deletion
We delete personal data as soon as the purpose for processing no longer applies.
Certain data must be retained due to legal obligations.
7 years: Data relevant for tax purposes is stored for seven years.
3 years: Data for legal claims is stored for three years.
Retention periods generally begin at the end of the calendar year.
Rights of Data Subjects
Under the GDPR, you have various rights.
Right to object.
Right to withdraw consent.
Right of access.
Right to rectification.
Right to erasure and restriction.
Right to data portability.
Right to lodge a complaint with a supervisory authority.
Provision of the Online Offering and Web Hosting
We process user data to provide our online services.
Types of data: Usage data; communication data; log data.
Data subjects: Users.
Purposes: Provision of services and infrastructure.
Legal basis: Legitimate interests.
Hosting services and server infrastructure are used.
Access data is logged in server log files.
We use content delivery networks (CDN).
Hosting provider: Hetzner Online GmbH.
Use of Cookies
Cookies store and read information on user devices.
Processing may be based on consent or legitimate interests.
Temporary cookies are deleted after session end.
Permanent cookies remain stored.
Users can withdraw consent at any time.
We use consent management solutions.
Registration, Login and User Account
Users can create accounts.
We store IP addresses and timestamps for security reasons.
Users may receive emails about account activities.
Data types include personal, contact and usage data.
Legal bases: Contract performance and legitimate interests.
Users may use pseudonyms.
Data is deleted after account termination.
Plugins and Embedded Functions and Content
We integrate third-party content such as graphics or scripts.
This requires processing of IP addresses.
Processing is based on consent or legitimate interests.
Data types: Usage and communication data.
Google Fonts is used for fonts.
Provider: Google Ireland Limited.
Privacy Information for Whistleblowers
We process data from whistleblowers and involved parties.
Legal basis: Austrian Whistleblower Protection Act.
Various types of personal data may be collected.
Anonymous reporting is possible.
Data may be shared with authorities if required.
Data is deleted when no longer needed.
We implement technical and organizational safeguards.
Changes and Updates
We ask you to regularly review this privacy policy.
We update it when necessary.
Contact information may change over time.
Definitions
Employees: Persons in an employment relationship.
Master data: Data necessary for identification.
Content data: Data related to created content.
Contact data: Information for communication.
Meta and communication data: Data about processing context.
Usage data: Information about how services are used.
Personal data: Information relating to an identifiable person.
Log data: Records of system activities.
Controller: Entity determining purposes of processing.
Processing: Any operation performed on personal data.
Created with Datenschutz-Generator.de by Dr. Thomas Schwenke