Skip to content

Legal notices

privacy policy

How we process personal data on spiesconsult.at — in accordance with the GDPR and the Austrian Data Protection Act (DSG).

1Controller for the data processing

The controller within the meaning of the GDPR and supplementary data protection provisions is Spies Consult GmbH, Kaplangasse 26, 2630 Ternitz, Austria. Telephone +43 664 53 74 961, email office@spiesconsult.at.

A data protection officer does not have to be appointed under Art. 37 GDPR. If you have questions about the processing of your data, please contact office@spiesconsult.at directly.

2Server log data

Each time the website is accessed, our hosting provider automatically logs technically necessary data:

  • IP address
  • Timestamp of the request
  • URL accessed
  • HTTP status code
  • Volume of data transferred
  • Referrer URL (previous page)
  • User agent (browser identifier)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest — operation, security and stability of the website). Retention period: three months, after which the logs are deleted on rotation.

3Cookies

The website uses only technically necessary cookies (a session cookie for the admin area /admin). These are permissible without consent under Art. 6(1)(f) GDPR.

No tracking cookies, marketing cookies or third-party cookies are set. Should analytics- or marketing-related cookies be used in future, we will obtain your consent in advance via a cookie banner.

4Getting in touch and the contact form

If you write to us at office@spiesconsult.at or use the contact form, we store your details in order to process your enquiry and clarify any follow-up questions. The form collects first name, surname, email address and your message, with company, position, telephone number and subject optional. The form sends these details as an email via our own mail server to office@spiesconsult.at. They are not stored on the website itself.

To protect against automated requests, your browser solves a small computational task when the form is submitted (ALTCHA). No cookies are set and no data is transmitted to third parties in the process. To limit misuse, the server counts requests per IP address. This count is held in memory only and expires after ten minutes.

Legal basis: Art. 6(1)(b) GDPR for enquiries concerning a possible engagement, Art. 6(1)(f) GDPR for other enquiries and for protection against misuse, and your consent under Art. 6(1)(a) GDPR, given by ticking the box in the form and revocable at any time. Retention period: until the correspondence is concluded, thereafter in accordance with the retention periods under commercial and tax law (generally seven years).

5Hosting and data processing on our behalf

The website is hosted by a processor within the meaning of Art. 28 GDPR. Hosting location: EU. A data processing agreement (DPA) under Art. 28 GDPR is in place with the hosting provider.

6Disclosure of data to third parties

Your data is disclosed only to processors (hosting provider, where applicable email provider). No transfer to third countries without an adequate level of protection within the meaning of Art. 44 et seq. GDPR. No commercial disclosure.

7Your rights as a data subject

Within the scope of the statutory provisions, you have the right at any time to:

  • Access to your stored personal data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data where the requirements are met (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw consent given, with effect for the future (Art. 7(3) GDPR)

To exercise these rights, simply email office@spiesconsult.at.

8Right to lodge a complaint with the supervisory authority

Under Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Austria is the Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at.

9Security of processing

We employ technical and organisational measures to protect your data against manipulation, loss or unauthorised access: TLS encryption of the entire transmission, an access and authorisation concept for admin areas, regular security updates, audit logging.

10Changes to this privacy policy

We reserve the right to amend this policy as processing activities or the legal framework change. The version published on this page at any given time is authoritative. Last updated: 19 May 2026.