Legal

Privacy

What we do not collect, do not store and do not share — and the short part we are required to do.

This English text is a convenience translation; the German version is legally binding.

In one sentence

This website collects no personal data, sets no cookies, embeds no external resources (Google Fonts, Analytics, Tag Manager) and shares no data with third parties.

What happens technically

When the website is requested, your browser sends — as is necessary for every website — its IP address and the user-agent string to the hosting server, so that the HTML page can come back. This request is not logged to any place where it would be retrievable by us. The Cloudflare Pages host keeps a short 24-hour error log for technical-infrastructure reasons; after that, IP information is discarded automatically.

Processor under Art 28 GDPR

For hosting we use Cloudflare International Unlimited Company (Dublin, Ireland) as a processor. Cloudflare Pages performs the TLS termination and briefly processes connection metadata (IP, user agent) under Art 6(1)(f) GDPR (legitimate interest in the secure operation of the website). There is a data processing agreement with Cloudflare using EU standard contractual clauses (SCCs 2021/914/EU). Details: Cloudflare DPA .

No cookies, no profiling

No cookies are set. There is a single localStorage entry (gewerbecheck-theme) — it stores only whether you manually chose light or dark mode, so the setting is correct on your next visit. This entry stays exclusively in your browser and is never sent.

Reach measurement — cookieless

For anonymous reach measurement we use Cloudflare Web Analytics — deliberately chosen because it sets no cookies, builds no cross-device profiles and sells no personal data. Only aggregated metrics are recorded (page viewed, referrer, rough performance), not individual persons. Legal basis: legitimate interest in a data-minimising reach measurement (Art 6(1)(f) GDPR). The processor is Cloudflare (DPA/SCCs see above).

No invasive third-party scripts

Apart from the cookieless analytics beacon mentioned above, all fonts, SVGs and data are served from the same server as the HTML page. There are no requests to Google Fonts, Google Analytics, the Facebook pixel, Hotjar, Intercom or similar personal tracking services.

External links

The website links to external data and information sources (data.gv.at, Statistik Austria, OpenStreetMap, RIS). These are loaded only once you click the link manually; the operators of those sites have their own privacy policies.

Ordering the Pro Report

For the handling of the Pro Report (€49 one-time) payment runs via SEPA bank transfer. In doing so we collect only the data necessary for the invoice and payment reconciliation (name, email, optionally a billing address for the VAT note under the small-business scheme, IBAN to match the transfer). This data is used exclusively for handling the contract, is not shared with third parties, and is deleted after the statutory retention periods expire (§ 132 (1) BAO: seven years).

Your rights under GDPR

  • Right of access (Art 15 GDPR)
  • Right to rectification (Art 16 GDPR)
  • Right to erasure (Art 17 GDPR)
  • Right to restriction (Art 18 GDPR)
  • Data portability (Art 20 GDPR)
  • Right to object (Art 21 GDPR)
  • Complaint to the data protection authority dsb.gv.at

Contact

Contact details see Imprint.

As of April 2026. Subject to change.