Privacy policy
Short, because little happens: this website measures no reach. It sets one cookie for your language choice and – only if you arrive through one of our ads – one that remembers the ad until you send a request. What is processed is what you send us through the request form. The fonts are served from our own address; nothing is loaded from third parties.
- CONTROLLER
- Geffen Schwarz FlexCo
- ADDRESS
- Siebensterngasse 19, 1070 Vienna, Austria
- sam@geffenschwarz.com
This English version is provided for convenience. The German version is the legally binding one.
1. Visiting the website
When you open this website, our hosting provider (section 3) processes your IP address, the time, the address requested and the browser identification for technical reasons, to deliver the page and secure the connection. These access data sit briefly in the provider's logs and are then deleted; we do not evaluate them or combine them with other data. We log error and security events without personal data. The legal basis is our legitimate interest in the secure operation of the website (Art. 6(1)(f) GDPR).
If you switch the language of the site, a cookie named “lang” remembers your choice for one year. It contains nothing but the two-letter language code and is strictly necessary for the function you asked for (§ 165(3) TKG 2021); it is not used for anything else.
If you scan the QR code on one of our business cards, you open a short address of the form geffenschwarz.com/c/… which forwards you to that person’s contact page. We count that visit: we store the time, which person and which trade fair the card belongs to, the language your browser asked for, whether the visit came from a mobile device, and the browser identification. Your IP address is neither stored nor evaluated in the process, and no cookie is set. The purpose is to see which card and which fair led to a contact; the legal basis is our legitimate interest in measuring the success of our own trade-fair appearances (Art. 6(1)(f) GDPR). We delete this count twelve months after the fair in question.
If you arrive at this website through one of our ads, the ad network appends an identifier to the address („gclid“ from Google or „li_fat_id“ from LinkedIn, for example). We keep that identifier, the name of the campaign and the page you first opened in a cookie called „gs_ref“, so that a request sent through the form can be matched to the ad that led to it. It is created only on such a visit, contains no name and no e-mail address, cannot be read by scripts in the browser, ends with your browser session and is deleted when the form is sent. The legal basis is our legitimate interest in measuring the success of our own ads (Art. 6(1)(f) GDPR); if you do not reach the site through an ad, it is never created.
2. Request form
When you request an offer via /en/request, we process name, company, e-mail address, budget band and your description of the project. The purpose is to answer your request and prepare an offer; the legal basis is the performance of pre-contractual steps (Art. 6(1)(b) GDPR). The details are required for an offer; without them we cannot prepare one. No automated decision-making takes place.
You receive a confirmation at the address you gave, carrying the reference of your request; it does not repeat your description of the project. If your request came through an ad, we additionally process the identifier from section 1 in order to match the request to the campaign.
The request is delivered by e-mail to our mailbox at Google Workspace. The website's log keeps only an identifier with time and budget band, not your details; if delivery fails, the request remains in the log until we have taken it over by hand, for 14 days at most. We keep the request for as long as processing requires, in the case of a contract for the duration of the business relationship and the statutory retention periods (seven years under § 132 BAO), otherwise for twelve months at most.
3. Recipients, processors and third parties
We do not pass your data on. For operation we use the following processors:
The website runs on Vercel for the time being. The move to our own server with Hetzner Online GmbH in Germany is prepared; after it, the transfer to the USA ends and this policy will be updated.
- E-MAIL DELIVERY
- Brevo (Sendinblue SAS), 106 boulevard Haussmann, 75008 Paris, France – processing in the EU (source, opens in a new tab)
- REACH MEASUREMENT
- none
- THIRD-COUNTRY TRANSFER
- USA, through hosting with Vercel Inc. and the mailbox at Google (Google LLC as sub-processor): on the basis of the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses (Art. 46(2)(c) GDPR). E-mail delivery through Brevo and the fonts stay in the EU.
4. LinkedIn
We run a company page on LinkedIn. When you visit it or interact with it – follow it, comment on or share posts – LinkedIn processes your data as a controller in its own right under its privacy policy. For the page statistics („Page Analytics“) that LinkedIn provides to us in aggregated form only, we are joint controllers with LinkedIn (Art. 26 GDPR). LinkedIn has published the agreement on this; under it, LinkedIn is your first point of contact if you want to exercise your rights in this context. You can also contact us. The legal basis is our legitimate interest in presenting our company where our customers look for information (Art. 6(1)(f) GDPR).
We run ads on LinkedIn. We decide whom an ad reaches by criteria such as industry, company size, job function and region; which members match those criteria is determined by LinkedIn from its own data, as a controller in its own right. We receive aggregated reports, such as how often an ad was shown and clicked, but no list of the people who saw it. We only receive names if you send a request form yourself (next paragraph).
Some of our ads contain a request form that opens inside LinkedIn. LinkedIn pre-fills it with details from your profile; you can change them before sending. If you send it, we receive your first name, last name, e-mail address, company, job title and your answers to the questions on topic and budget range. The purpose is to answer your request and prepare an offer; the legal basis is the performance of pre-contractual steps (Art. 6(1)(b) GDPR). We keep the details in the same way as requests sent through our website form (section 2). LinkedIn processes the submission as an independent controller and keeps the details available for retrieval for up to 90 days; after that, LinkedIn deletes them.
If you arrive at this website through a LinkedIn ad, LinkedIn appends an identifier („li_fat_id“) and the name of the campaign to the address. As described in section 1, we keep both in the „gs_ref“ cookie so that a request sent through the form can be attributed to the ad. No further data is passed to LinkedIn in the process.
This website does not embed the LinkedIn Insight Tag or any other LinkedIn script, pixel or plug-in. LinkedIn does not learn from this website which pages you visit. Links to LinkedIn profiles, for example on the team page, are plain links: data only goes to LinkedIn if you follow one.
You can limit which ads LinkedIn shows you and which data it uses for them in your LinkedIn settings under „Advertising data“.
- PROVIDER
- LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (source, opens in a new tab)
- JOINT CONTROLLERSHIP
- Page Insights Joint Controller Addendum (source, opens in a new tab)
- THIRD-COUNTRY TRANSFER
- USA (LinkedIn Corporation) according to LinkedIn, on the basis of the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses (Art. 46(2)(c) GDPR)
5. Cookies and reach measurement
Apart from the two cookies described in section 1, this website sets no cookies and uses no reach measurement. Should that change, this page will say which tool is used – the only thing planned is cookie-free, self-hosted measurement without any evaluation of personal data.
6. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). To exercise them, contact sam@geffenschwarz.com.
If you believe that the processing of your data violates data protection law, you can lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
7. Security
The connection to this website is encrypted (TLS, HSTS); every response carries a Content Security Policy as well as frame and MIME protection. The website is currently delivered through Vercel (section 3); its server functions run in Frankfurt am Main.