MBB Websolutions e.U./Privacy Policy

LEGAL CENTER · AUSTRIA / EUROPEAN UNION

Privacy Policy

Transparent GDPR information on how personal data is processed across MBB Websolutions e.U. web services.

EU legal framework Privacy & GDPRLast updated: September 2026
Privacy & GDPRLast updated: September 2026
Controller

MBB Websolutions e.U.

Johann-Weitzer-Weg 24/6
8041 Graz, Austria

Privacy contact

Direct contact

info@mbb-websolutions.com
Open contact form

In briefWe process only data required to operate the website securely, handle enquiries, take pre-contractual steps, perform contracts or comply with legal obligations. The public website is currently designed without marketing or profiling tracking.

01Controller and scope

The controller within the meaning of Article 4(7) GDPR is MBB Websolutions e.U., Johann-Weitzer-Weg 24/6, 8041 Graz, Austria. MBB Websolutions e.U. is an Austrian registered sole proprietorship (company register no. FN 687006d; company register court: Regional Court for Civil Matters Graz). This privacy policy applies to the company’s publicly accessible web services, in particular the corporate website and its contact and information functions.

GDPRRegulation (EU) 2016/679
Austrian DSGAustrian Data Protection Act
TKG 2021Where cookies/device access are relevant
Article 13 GDPRInformation when data is collected directly

02Processing principles

Personal data is processed in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. Data is not reused for purposes incompatible with the original purpose.

03Technical delivery and server logs

When the website is accessed, technically necessary connection and log data may be processed, including IP address, date and time, requested URL, referrer, browser/user agent, hostname, HTTP status and technical error information.

PurposeSecure and stable operation, troubleshooting and protection against abuse or attacks
Legal basisArticle 6(1)(f) GDPR – legitimate interest in IT security and service stability
RetentionOnly as long as required for operations, security and evidence relating to specific security incidents
RecipientsTechnical administrators and hosting/infrastructure service providers

04Contact form and project enquiries

When you use the contact form, we process the information you enter. The form currently provides for name, email address, company, phone number, service area, optional budget range and your message. For abuse prevention and technical traceability, the IP address and browser/user agent are also processed.

Required fieldsName, email address and message
Optional fieldsCompany, phone, service area and budget range
Legal basisArticle 6(1)(b) GDPR for pre-contract/contract; Article 6(1)(f) GDPR for abuse prevention
If not providedWithout the required information we cannot process the specific enquiry

Enquiry data is retained for as long as necessary to handle the request, establish a business relationship, document communication or pursue/defend possible legal claims. If a contract is formed, statutory business, tax and accounting retention duties may also apply.

05Email communication

If you contact us by email, we process the sender and recipient addresses, subject, message content, technical message information and any attachments you voluntarily provide. Processing is carried out to handle the communication, take pre-contractual steps or perform a contract, and where necessary document business communications.

06Customer, contract, support and billing data

If an enquiry develops into a customer or contractual relationship, we may process master data, contact data, contract and service data, support information, payment and invoice data. Legal bases include Article 6(1)(b) GDPR (contract performance/pre-contractual steps), Article 6(1)(c) GDPR (legal obligations) and Article 6(1)(f) GDPR (documentation, IT security and legal claims).

07Cookies, local storage and tracking

The public website is currently designed so that marketing, profiling or behavioural tracking cookies are not required for normal presentation. Technically necessary storage mechanisms may be used where required for a function expressly requested by the user.

If non-essential analytics, marketing, social-media, video or other third-party technologies are introduced in the future, they will only be activated after consent where legally required. This policy and any consent interface will then be updated accordingly.

No implied consentWhere consent is required, it is not inferred from pre-ticked boxes or merely continuing to browse. Consent must be voluntary, informed and capable of being withdrawn.

08Hosting, infrastructure and processors

Specialist service providers may be used for hosting, email, backups, infrastructure, maintenance and technical communications. Where such providers process personal data on our behalf, this takes place under a data-processing agreement in accordance with Article 28 GDPR and on documented instructions.

Recipient categories may include hosting/data-centre providers, email/communications providers, IT maintenance, backup/security providers and, where legally required, public authorities, courts or tax/legal advisers.

09Transfers outside the EU/EEA

Personal data is transferred to countries outside the European Union or European Economic Area only where the requirements of Articles 44 et seq. GDPR are met. Depending on the recipient, this may rely on an adequacy decision of the European Commission or appropriate safeguards such as Standard Contractual Clauses, supplemented by additional technical and organisational safeguards where necessary.

10Data security

We implement appropriate technical and organisational measures to protect personal data. Depending on the system, these include encrypted transport (TLS/HTTPS), access restrictions, role-based permissions, secure authentication, system updates, logging, backups and safeguards against abusive access.

No internet-based system can guarantee absolute security. Measures are therefore reviewed and developed in line with the risk and the state of the art.

11Retention and deletion criteria

Personal data is stored only for as long as necessary for the respective processing purpose. It is then deleted or anonymised unless statutory retention obligations, ongoing contracts, unresolved claims or legitimate security/evidentiary interests require longer retention.

12Your GDPR rights

Subject to the statutory requirements, your rights include:

Access · Art. 15Rectification · Art. 16Erasure · Art. 17Restriction · Art. 18Portability · Art. 20Objection · Art. 21Withdrawal of consentComplaint · Art. 77

Withdrawal of consent operates for the future and does not affect the lawfulness of processing carried out before withdrawal. To exercise your rights, contact info@mbb-websolutions.com. A reasonable identity check may be required to prevent unauthorised disclosure.

13Objection to legitimate-interest processing

Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will then stop processing unless compelling legitimate grounds override your interests, rights and freedoms, or processing is required for the establishment, exercise or defence of legal claims.

14Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. In Austria, the competent authority is the Austrian Data Protection Authority.

DSB

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
dsb.gv.at

15Automated decisions and profiling

No solely automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR is carried out in connection with ordinary use of the public website or normal contact enquiries. The public website currently does not use marketing profiling.

16Sources of data

Most data is obtained directly from you, for example through the contact form, email or a business relationship. Technical usage data is generated when systems are accessed. Where data from other sources is processed and Article 14 GDPR requires notice, the relevant information will be provided in the specific case.

17Changes to this privacy policy

We update this policy when website functions, processing activities, service providers or legal requirements change. The version published on this website is the current version.

Transparency is part of our security architecture.

When the website, services or technologies change, we update the legal information accordingly.