Privacy Policy

This English version is provided for convenience. In case of doubt, the German version applies.

This privacy policy provides information under Art. 13 GDPR on which personal data is processed on this website, for which purposes, on which legal basis and for how long, and on the rights available to you.

At a glance

  • No cookies are set and no tracking or analytics services are used; a cookie banner is therefore not required.
  • Visiting the website only creates server logs, which are deleted after eight days at the latest.
  • Inquiries are used solely to handle and answer them.
  • The service providers used are based in Germany. Data is only transferred to third countries if WhatsApp is used.

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is Code & Concept Craftworks e.U., owner: Rafael Seidl, BSc., Austeingasse 16, 8020 Graz, Austria.

Email: office@codeandconcept.at, phone: +43 (0) 681 20558452

Visiting the website and server logs

This website is operated on a server of netcup GmbH (Karlsruhe, Germany) in a data centre in Germany.

Each time the website is accessed, the following data is logged: IP address, date and time, requested address, status code, amount of data transferred and response time. Information about the browser used or the previously visited page is not recorded. The data is not combined with other data and is not used to create profiles.

To defend against attacks, the logs are analysed automatically; suspicious IP addresses may be blocked temporarily. No data is passed on to third parties in the process.

Purpose
Providing the website, troubleshooting and defending against attacks.
Legal basis
Art. 6(1)(f) GDPR; the legitimate interest lies in operating the website securely and reliably.
Recipients
netcup GmbH (Karlsruhe, Germany) as processor (hosting).
Retention
The logs are deleted after eight days at the latest. Blocks of IP addresses are lifted automatically.

Contact form

When an inquiry is sent through the contact form, the data entered is processed: name, company (optional), email address, phone number (optional) and message. The language of the page is also transmitted so that the reply can be given in the same language.

The details are not stored on the web server; they are only forwarded by email to the controller and handled there. To protect against spam, an automatic security check is carried out before sending (see the next section).

Providing the data is neither a legal nor a contractual requirement. Without a name, email address and message, however, the inquiry cannot be answered.

Purpose
Handling and answering your inquiry.
Legal basis
Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract). Where the inquiry does not concern a possible contract: Art. 6(1)(f) GDPR; the legitimate interest lies in answering inquiries.
Recipients
IONOS SE (Montabaur, Germany) as processor for sending email and the email mailbox.
Retention
Inquiries that do not lead to an engagement are deleted six months after they have been dealt with. If a business relationship arises, the relevant correspondence is retained for seven years (§ 132 BAO, § 212 UGB, Austrian retention rules).

Security check of the contact form

The contact form is protected against abusive, automated submissions (spam) by an automatic security check. The check starts as soon as you start filling in the form and runs in your browser without any action on your part. Without a successful check, an inquiry is not processed.

The check sets no cookies, stores no data permanently on your device, does not analyse mouse or keyboard input and involves no third-party services. It is carried out solely via the web server of this website.

If JavaScript is disabled in your browser, the check cannot be carried out and the form cannot be sent. In that case, contact is possible by email, phone or WhatsApp.

Purpose
Protecting the contact form against abusive, automated submissions (spam).
Legal basis
Art. 6(1)(f) GDPR; the legitimate interest lies in keeping the contact form available for genuine inquiries and protecting it against abuse. The check is strictly necessary for sending the inquiry you requested and therefore requires no consent (§ 165(3) TKG 2021).
Recipients
None. The check is carried out solely via the web server of this website (netcup GmbH as processor).
Retention
The data used for the check is not stored permanently and is deleted after 20 minutes at the latest; it is not linked to your IP address. For accessing the website, the information on server logs applies.

Confirmation email

After the contact form has been submitted, an automatic confirmation is sent to the email address provided. It contains none of the content of the inquiry.

The confirmation contains a logo that is loaded from the web server of this website when the email is displayed. This records the data listed under “Visiting the website and server logs”. Whether or when the email is opened is not analysed.

Contact by email or phone

When contact is made by email to office@codeandconcept.at or by phone at +43 (0) 681 20558452, the details provided are processed for the same purposes, on the same legal basis and with the same retention period as for the contact form. The email mailbox is operated by IONOS SE as processor.

Contact via WhatsApp

This website contains buttons for contacting via WhatsApp. They are plain links; visiting the website does not transmit any data to WhatsApp.

WhatsApp is only opened once such a button is clicked. From that point on, WhatsApp Ireland Limited (Dublin, Ireland), a Meta company, processes your data as an independent controller under its privacy policy. By its own account, WhatsApp also transfers data to the United States and other third countries. The controller of this website has no influence over this processing.

Using WhatsApp is voluntary. Contact is equally possible by email, phone or the contact form.

Purpose
Handling and answering your inquiry.
Legal basis
Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract). Where the inquiry does not concern a possible contract: Art. 6(1)(f) GDPR; the legitimate interest lies in answering inquiries.
Recipients
WhatsApp Ireland Limited as an independent controller, not as a processor.
Retention
Chats about inquiries are deleted on the same principles as inquiries sent through the contact form.

Cookies and tracking

This website sets no cookies and stores no data permanently on your device. No tracking, analytics or advertising services are used and no third-party content, such as maps or videos, is embedded. Visiting the website opens no connections to third parties.

Consent under § 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) is therefore not required. The security check of the contact form only takes place when the form is used and is strictly necessary for sending the inquiry you requested; it therefore requires no consent either. For these reasons, no cookie banner is used.

Recipients and processors

The following processors are used; a data processing agreement under Art. 28 GDPR is in place with both:

  • netcup GmbH (Karlsruhe, Germany): hosting of this website
  • IONOS SE (Montabaur, Germany): sending email and the email mailbox

Beyond that, personal data is only disclosed where there is a legal obligation to do so. Data is neither sold nor used for advertising purposes.

Transfers to third countries

Personal data is not transferred to countries outside the EU or EEA; the processors used process the data within the EU or EEA. The only exception applies if WhatsApp is used (see above).

Retention periods at a glance

  • Server logs: deleted after eight days at the latest
  • Data of the contact form's security check: deleted after 20 minutes at the latest
  • Inquiries without an engagement (contact form, email, phone, WhatsApp): deleted six months after they have been dealt with
  • Correspondence within a business relationship: retained for seven years (§ 132 BAO, § 212 UGB)

No automated decision-making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The security check of the contact form produces no legal effects concerning you and does not similarly significantly affect you.

Your rights

You have the following rights:

  • right of access (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to data portability (Art. 20 GDPR)
  • right to object to processing based on a legitimate interest, such as the server logs or the security check of the contact form (Art. 21 GDPR)

To exercise these rights, an informal message to office@codeandconcept.at is sufficient. Requests are answered within the statutory time limits.

If you believe that the processing of your data infringes data protection law, you can lodge a complaint with the supervisory authority (Art. 77 GDPR): Österreichische Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40–42, 1030 Vienna, Austria, www.dsb.gv.at.

Changes

This privacy policy is updated whenever the data processing on this website changes. The version published here applies.

Last updated: September 2026