MBB Websolutions e.U.
Johann-Weitzer-Weg 24/6
8041 Graz, Austria
01Controller and scope
The controller within the meaning of Article 4(7) GDPR is MBB Websolutions e.U., Johann-Weitzer-Weg 24/6, 8041 Graz, Austria. MBB Websolutions e.U. is an Austrian registered sole proprietorship (company register no. FN 687006d; company register court: Regional Court for Civil Matters Graz). This privacy policy applies to the company’s publicly accessible web services, in particular the corporate website and its contact and information functions.
02Processing principles
Personal data is processed in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. Data is not reused for purposes incompatible with the original purpose.
03Technical delivery and server logs
When the website is accessed, technically necessary connection and log data may be processed, including IP address, date and time, requested URL, referrer, browser/user agent, hostname, HTTP status and technical error information.
04Contact form and project enquiries
When you use the contact form, we process the information you enter. The form currently provides for name, email address, company, phone number, service area, optional budget range and your message. For abuse prevention and technical traceability, the IP address and browser/user agent are also processed.
Enquiry data is retained for as long as necessary to handle the request, establish a business relationship, document communication or pursue/defend possible legal claims. If a contract is formed, statutory business, tax and accounting retention duties may also apply.
05Email communication
If you contact us by email, we process the sender and recipient addresses, subject, message content, technical message information and any attachments you voluntarily provide. Processing is carried out to handle the communication, take pre-contractual steps or perform a contract, and where necessary document business communications.
06Customer, contract, support and billing data
If an enquiry develops into a customer or contractual relationship, we may process master data, contact data, contract and service data, support information, payment and invoice data. Legal bases include Article 6(1)(b) GDPR (contract performance/pre-contractual steps), Article 6(1)(c) GDPR (legal obligations) and Article 6(1)(f) GDPR (documentation, IT security and legal claims).
07Cookies, local storage and tracking
The public website is currently designed so that marketing, profiling or behavioural tracking cookies are not required for normal presentation. Technically necessary storage mechanisms may be used where required for a function expressly requested by the user.
If non-essential analytics, marketing, social-media, video or other third-party technologies are introduced in the future, they will only be activated after consent where legally required. This policy and any consent interface will then be updated accordingly.
08Hosting, infrastructure and processors
Specialist service providers may be used for hosting, email, backups, infrastructure, maintenance and technical communications. Where such providers process personal data on our behalf, this takes place under a data-processing agreement in accordance with Article 28 GDPR and on documented instructions.
Recipient categories may include hosting/data-centre providers, email/communications providers, IT maintenance, backup/security providers and, where legally required, public authorities, courts or tax/legal advisers.
09Transfers outside the EU/EEA
Personal data is transferred to countries outside the European Union or European Economic Area only where the requirements of Articles 44 et seq. GDPR are met. Depending on the recipient, this may rely on an adequacy decision of the European Commission or appropriate safeguards such as Standard Contractual Clauses, supplemented by additional technical and organisational safeguards where necessary.
10Data security
We implement appropriate technical and organisational measures to protect personal data. Depending on the system, these include encrypted transport (TLS/HTTPS), access restrictions, role-based permissions, secure authentication, system updates, logging, backups and safeguards against abusive access.
No internet-based system can guarantee absolute security. Measures are therefore reviewed and developed in line with the risk and the state of the art.
11Retention and deletion criteria
Personal data is stored only for as long as necessary for the respective processing purpose. It is then deleted or anonymised unless statutory retention obligations, ongoing contracts, unresolved claims or legitimate security/evidentiary interests require longer retention.
12Your GDPR rights
Subject to the statutory requirements, your rights include:
Withdrawal of consent operates for the future and does not affect the lawfulness of processing carried out before withdrawal. To exercise your rights, contact info@mbb-websolutions.com. A reasonable identity check may be required to prevent unauthorised disclosure.
13Objection to legitimate-interest processing
Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will then stop processing unless compelling legitimate grounds override your interests, rights and freedoms, or processing is required for the establishment, exercise or defence of legal claims.
14Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. In Austria, the competent authority is the Austrian Data Protection Authority.
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
dsb.gv.at
15Automated decisions and profiling
No solely automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR is carried out in connection with ordinary use of the public website or normal contact enquiries. The public website currently does not use marketing profiling.
16Sources of data
Most data is obtained directly from you, for example through the contact form, email or a business relationship. Technical usage data is generated when systems are accessed. Where data from other sources is processed and Article 14 GDPR requires notice, the relevant information will be provided in the specific case.
17Changes to this privacy policy
We update this policy when website functions, processing activities, service providers or legal requirements change. The version published on this website is the current version.
