Privacy Policy
1. Privacy at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. For detailed information on data protection, please refer to the privacy policy set out below this text.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the operator. You can find their contact details in the “Information on the responsible party” section of this privacy policy.
How do we collect your data?
On the one hand, your data is collected when you provide it to us. This may, for example, be data you enter into a contact form. Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time the page was accessed). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure the website is provided without errors. Other data may be used to analyse user behaviour.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time with effect for the future. Furthermore, under certain circumstances you have the right to request the restriction of the processing of your personal data. In addition, you have the right to lodge a complaint with the competent supervisory authority.
2. Hosting and Content Delivery Networks (CDN)
Cloudflare (CDN, DNS & web application firewall)
Cloudflare is used for DNS, security and delivery of this website – including the subdomain analytics.stermole.at. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).
Cloudflare handles DNS resolution, acts as an upstream protective shield (web application firewall and DDoS protection) and speeds up delivery as a content delivery network. The technical transfer of information between your browser and this website is routed via the Cloudflare network; in doing so Cloudflare processes connection data (including your IP address) and may set technically necessary security cookies (e.g. “__cf_bm” for bot detection). These serve solely security and operational purposes; no cross-site profiling for advertising purposes takes place.
The use of Cloudflare is based on the legitimate interest in providing our web offering in a secure, attack-protected and as error-free manner as possible (Art. 6 (1) (f) GDPR).
As Cloudflare is a US company, connection data may be processed in the USA. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, Standard Contractual Clauses and a data processing agreement serve as the basis for the transfer (Art. 44 et seq. GDPR).
Google Cloud
This website, including server-side processing of the contact form, is operated via Firebase App Hosting on Google Cloud. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”). When the website is accessed and the form is submitted, the hosting infrastructure processes technical connection and log data, in particular the IP address, time, requested URL, and browser information. The form details pass through the server-side application on this infrastructure; this website does not store the form content in Firestore or any other Firebase database.
Google Cloud is used for the secure and reliable operation of the website on the basis of Art. 6 (1) (f) GDPR. Where the infrastructure processes an inquiry submitted through the form, the legal bases stated in the contact-form section also apply.
3. General information and mandatory information
Information on the responsible party
The party responsible for data processing on this website is:
Thomas Stermole
Digitalisierungsberatung & KI-Architektur
Österreich / Remote (DACH)
The responsible party is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses or similar).
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with the operator until the purpose of the data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless there are other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion will take place once these reasons no longer apply.
4. Data collection on this website
Contact form
When you submit an inquiry through the contact form, we process your name, email address, optional company, selected topic, message, and confirmation that you have acknowledged this Privacy Policy. The details are received by the server application operated on Google Cloud/Firebase App Hosting and sent via Brevo SMTP as an email to the controller’s mailbox. Google and Brevo process the data as technical service providers; disclosure for their own advertising purposes is not intended.
Processing is based on Art. 6 (1) (b) GDPR where your inquiry concerns pre-contractual measures or the performance of a contract. In all other cases, it is based on the legitimate interest in securely and effectively handling incoming inquiries (Art. 6 (1) (f) GDPR). The required checkbox documents acknowledgement of this Privacy Policy and does not constitute separate consent to additional purposes that are unnecessary for handling the inquiry.
5. Plugins and tools
Matomo (self-hosted)
This website uses the open-source web analytics service Matomo. Matomo is operated self-hosted at analytics.stermole.at on a server of DomainFactory GmbH (c/o WeWork, Neuturmstraße 5, 80331 Munich; server location Germany), with which a data processing agreement is in place. When the contact form is submitted, only an event containing the selected topic category and the result “successful” or “error” is recorded. Name, email address, company, and message are not transferred to Matomo. Analytics data is stored on this server in Germany and is not disclosed for third parties’ own purposes. Retrieval of the subdomain is – like the entire website – technically delivered via Cloudflare (see the “Cloudflare” section).
By default, Matomo operates on this website without cookies (“cookieless”). IP addresses are shortened (anonymised) before storage, so that a direct attribution to individual persons is not possible. Your browser’s “Do Not Track” setting is respected. This cookieless, anonymised reach measurement is based on Art. 6 (1) (f) GDPR; the legitimate interest lies in the statistical analysis of visitor flows in order to optimise the web offering.
Only if you select “Accept all” in the cookie banner does Matomo additionally set first-party statistics cookies (including _pk_id, _pk_ses) in order to recognise returning visits more accurately. This processing is carried out exclusively on the basis of your consent (Art. 6 (1) (a) GDPR in conjunction with Section 165 (3) of the Austrian Telecommunications Act, TKG 2021). You can revoke your consent at any time with effect for the future by reopening the privacy settings via the shield icon in the bottom left corner and selecting “Essential only”; statistics cookies that have already been set will then be deleted.
The raw data stored as part of the web analysis is automatically deleted after twelve months at the latest; beyond that, only aggregated statistics without personal reference are retained.
Your right to object (opt-out)
Checking status …
Firebase App Hosting
Firebase App Hosting, a Google Cloud service, is used to deliver and execute this Next.js website on the server. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Firebase App Hosting processes the connection data required for delivery and server operation and executes the contact form’s Server Action. The form content is not separately stored in Firebase databases. Further information on purposes and legal bases is provided in the “Google Cloud” and “Contact form” sections.
Google reCAPTCHA Enterprise
Google reCAPTCHA Enterprise is used to protect the contact form against automated abuse. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Under the Google Cloud contractual terms, Google processes Customer Data generated by reCAPTCHA Enterprise as a processor.
The reCAPTCHA script is loaded from Google on the contact page and analyses, in particular, the IP address, device and browser information, and interaction and usage signals for risk detection. On submission, the browser generates an assessment token; the server application sends this token together with the expected action and site key to the reCAPTCHA Enterprise API and receives a risk assessment. This application does not include the actual form fields in the reCAPTCHA assessment.
Processing is based on Art. 6 (1) (f) GDPR. The legitimate interest lies in protecting the form and connected systems against spam and automated abuse. According to Google, device and application data processed for reCAPTCHA Enterprise is not used for personalised advertising.
6. Sending of emails
Brevo SMTP (formerly Sendinblue)
Brevo SMTP is used to send contact inquiries. The provider is Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany.
On submission, the name, email address, optional company, selected topic, and message are sent as the content of a transactional email through Brevo’s SMTP relay. Brevo processes technical transactional logs for this purpose. Transactional logs are automatically deleted after one month. Email previews are not stored for new transactional emails.
Processing follows the legal bases stated in the contact-form section. The use of Brevo as a delivery service is additionally based on the legitimate interest in securely and reliably delivering the inquiry (Art. 6 (1) (f) GDPR).