Privacy policy
Status: 14 July 2026
Introduction
This privacy policy informs you, pursuant to Art. 12 et seq. GDPR, about the processing of personal data in connection with visits to this website (www.a-log.at) and the use of the services offered through it. Where supplementary privacy information is required for individual processing operations, it will be provided at the relevant point.
01 Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
A-Log Technology GmbH
Legal form: limited liability company
Commercial register number: FN 681048t
Address: Felbigergasse 39/1, 1140 Vienna, Austria
Email:
Website: https://www.a-log.at
Privacy contact
If you have questions about privacy or the processing of personal data, you can contact us at:
Data protection officer
Our company is not currently under a statutory obligation to appoint a data protection officer. Please direct privacy enquiries to the privacy contact point specified above.
02 General information on data processing
Protecting your personal data is of great importance to us. We process personal data solely in accordance with the provisions of the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and other applicable data protection legislation.
Personal data means any information relating to an identified or identifiable natural person. This includes, for example, names, email addresses, telephone numbers, IP addresses, billing data or online identifiers.
We process personal data solely
• to provide this website
• to handle enquiries
• to take steps prior to entering into a contract
• to fulfil contractual obligations
• to ensure the security of our IT systems
• to fulfil legal obligations
• and, where permitted, to pursue legitimate interests or on the basis of your consent
In doing so, we observe in particular the principles of Art. 5 GDPR:
• lawfulness, fairness and transparency
• purpose limitation
• data minimisation
• accuracy
• storage limitation
• integrity and confidentiality
• accountability
As a rule, no automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place in connection with merely visiting this website, unless expressly stated otherwise in this privacy policy.
03 Legal bases
Depending on the processing operation, personal data is processed on one or more of the following legal bases:
Art. 6(1)(a) GDPR – consent
Where you have given us consent, processing is carried out solely for the purposes described in that consent. Consent may be withdrawn at any time with effect for the future.
Art. 6(1)(b) GDPR – contract or steps prior to entering into a contract
Where processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract.
Art. 6(1)(c) GDPR – legal obligation
Where statutory provisions require us to process personal data.
Art. 6(1)(f) GDPR – legitimate interest
Where processing is necessary for the purposes of our legitimate interests or those of third parties and these are not overridden by the interests or fundamental rights of the data subject. Our legitimate interests may include, in particular:
• ensuring IT and information security
• protection against misuse and cyberattacks
• ensuring the stable operation of this website
• error analysis and system monitoring
• establishment, exercise and defence of legal claims
• improvement of our services
• communication with prospective customers and business partners
• direct marketing to businesses to the extent permitted by law
04 Categories of personal data
Depending on your use of this website and our services, the following categories of personal data in particular may be processed:
Identification data
• surname
• first name
• title
• user identifier
Contact details
• email address
• telephone number
• business address
• postal address
Company data
• company
• VAT identification number
• commercial register number
• role within the company
Contract and billing data
• contract data
• billing data
• payment information
• order history
Communication data
• content of contact enquiries
• support enquiries
• correspondence
Technical data
• IP address
• browser type
• operating system
• device information
• language settings
• referrer URL
• date and time of access
• server log data
Usage data
• pages visited
• click paths
• session information
• consent status
• cookie information
Which of these data are actually processed depends on the functions of this website that you use.
05 Processing when visiting this website
5.1 Provision of the website
When you access this website, our web server automatically processes the information transmitted to our server by your browser. This includes in particular:
• IP address
• date and time of access
• time zone
• URL accessed
• HTTP status code
• browser type and browser version
• operating system
• language settings
• referrer URL
• volume of data transferred
• device information
This processing is carried out for the purposes of providing the website, ensuring system security, analysing errors, defending against attacks, detecting misuse and technical administration. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and economical operation of our online services.
5.2 Server log files
Server log files are created to ensure operational security. In particular, they contain the IP address, timestamp, requested resources, HTTP status, browser information, operating system and error messages. Server log files are processed solely for security, operational and error-analysis purposes. As a rule, they are not combined with other personal data.
Retention period: Server log files are generally stored for 90 days and then deleted automatically, unless longer storage is necessary to investigate security incidents or to establish, exercise or defend legal claims.
Recipients: Hosting providers and IT administrators. Third-country transfers in connection with this processing operation take place to the extent described in section 11.
06 Getting in touch
6.1 Contact form
You can contact us using the contact form provided on this website. Providing your data is voluntary, except for the information marked as mandatory (subject, first and last name, email address and message), which is required to process your enquiry.
Categories of data processed – depending on the nature of your enquiry, we process in particular:
• first and last name
• company (optional)
• email address
• telephone number (optional)
• subject of your enquiry
• content of your message
• date and time of the enquiry
• IP address and technical metadata, where necessary to prevent misuse or ensure IT security
Purposes of processing: Handling and responding to your enquiry, taking steps prior to entering into a contract, communicating with prospective customers, customers or business partners, documenting communications, preventing misuse and spam, and ensuring IT security.
Legal bases: Art. 6(1)(b) GDPR where your enquiry concerns entering into or performing a contract; Art. 6(1)(f) GDPR for handling general enquiries, communicating with business partners and ensuring IT security; Art. 6(1)(a) GDPR where you voluntarily provide us with information whose processing is based on your consent.
Our legitimate interest lies in efficient communication with prospective customers and customers, handling business enquiries, documenting business communications, preventing misuse of our systems and ensuring the secure operation of this website.
Recipients: Where necessary, your data may be disclosed in particular to the following categories of recipients: hosting providers, email service providers, IT service providers, internal departments and support or ticketing systems. Where service providers outside the European Union or European Economic Area are used for this purpose, transfers take place solely in compliance with the requirements of Chapter V GDPR.
Retention period: Contact enquiries are generally stored until their processing has been completed. Where a contractual relationship develops from an enquiry, the retention periods for contractual documents apply. Enquiries with no further business purpose are generally deleted after 12 months, unless statutory retention obligations or legitimate interests require longer storage.
6.2 Communication by email
If you contact us directly by email, we process the personal data you provide solely to handle your enquiry and for subsequent business communications. This may include, in particular, your name, email address, company data, communication content, attachments and the email’s technical metadata. Processing is based on Art. 6(1)(b) or (f) GDPR.
Please note that communication over the internet may be subject to security risks. Although we use appropriate technical and organisational measures to protect your data, complete protection of data transmitted by email cannot be guaranteed. For particularly confidential information, we recommend using an agreed secure transmission method.
07 Newsletter and direct communication
7.1 Newsletter
This website does not currently offer a newsletter subscription form. If we offer a newsletter in future, the following will apply: If you subscribe to our newsletter, we will process your personal data in order to send you regular information about our company, our services, product news, events and other business information.
Categories of data processed: email address, name (if provided), company (optional), language settings, date of subscription, time of confirmation (double opt-in), IP address at the time of subscription and confirmation, and log data documenting consent.
The legal basis is Art. 6(1)(a) GDPR. Registration generally follows a double opt-in process. After registering, you will receive an email in which you must confirm your subscription.
Withdrawal: You may withdraw your consent at any time with effect for the future, for example by using the unsubscribe link in each newsletter or the contact details specified in section 1. This does not affect the lawfulness of processing carried out before withdrawal.
Recipients: Depending on the technical implementation, newsletters may be sent through specialised delivery providers (newsletter providers, hosting providers or IT service providers). Any third-country transfer takes place solely in compliance with the requirements of Chapter V GDPR.
Retention period: Your data will be stored until you withdraw your consent. After you unsubscribe, we may store your email address on a suppression list for a reasonable period to ensure that you do not receive any further newsletters (Art. 6(1)(f) GDPR).
7.2 Business information for businesses
Where we process personal contact details of representatives of existing or potential business customers, processing may also take place for the purposes of business communication and providing information about our services. This applies in particular to representatives of companies, public authorities or other organisations.
The data processed may include, in particular, name, work email address, business telephone number, company, role and communication history. The legal basis is Art. 6(1)(f) GDPR.
Our legitimate interest lies in maintaining existing business relationships, informing prospective customers about our services, marketing our B2B services and establishing and developing customer relationships. You may object to the processing of your personal data for direct marketing purposes at any time with effect for the future.
Retention period: The data will be stored for as long as there is a legitimate interest in business communication or statutory retention obligations prevent deletion. Once the purpose of processing ceases to apply, the data will be deleted or anonymised.
08 Cookies and similar technologies
8.1 Current use
This website uses your browser’s local storage to store technically necessary settings on your device – specifically, access status (if the website is access-protected), your selected language and your design preference (light/dark colour scheme). This information does not leave your device, is not transmitted to us or third parties and serves solely to ensure the functionality and usability of the website. Pursuant to § 165(3) TKG 2021 and Art. 6(1)(f) GDPR, no consent is required for this purely technically necessary storage.
In addition, we use Google Analytics 4 cookies to statistically evaluate the use of this website (see section 10). These cookies are set only if you have first given your express consent through the consent banner displayed on your first visit (see section 9); without your consent, no analytics cookies are set and no data is transmitted to Google.
8.2 Categories of cookies
Depending on their purpose, we generally distinguish between the following categories:
a) Strictly necessary cookies
These cookies would be essential for the operation of the website and could not be disabled. In particular, they would serve to provide the website securely, manage sessions, store cookie preferences, protect against misuse, ensure IT security, balance loads and maintain system stability. The legal basis would be § 165 TKG 2021 (where applicable) and Art. 6(1)(f) GDPR. We do not currently use cookies of this kind (see 8.1).
b) Preference cookies
These cookies would store settings you have selected, such as language settings or other convenience features – on this website, these are currently implemented using local storage rather than cookies (see 8.1).
c) Statistics and analytics cookies
These cookies help us better understand how the website is used and further develop our offering, for example by recording page views, time spent, click paths, browser information, device type and the source of the visit. We use Google Analytics 4 for this purpose (see section 10). The cookies set (\_ga, \_ga\_<Container-ID>) have a lifetime of up to two years. The legal basis is Art. 6(1)(a) GDPR (consent).
d) Marketing cookies
Marketing cookies would enable the success of marketing measures to be measured and, where applicable, interest-based content to be displayed. They would be used solely with your express consent. We do not currently use marketing cookies.
8.3 Withdrawal and browser settings
You may withdraw consent previously given at any time with effect for the future by opening the “Cookie settings” link in the footer of this website and selecting “Reject”. Withdrawal does not affect the lawfulness of processing carried out on the basis of your consent before its withdrawal. Independently of this, you can configure your browser at any time to block all cookies, delete cookies when the browser is closed, notify you before a cookie is stored, or allow or reject individual cookies. Google also provides a browser add-on at tools.google.com/dlpage/gaoptout that allows you to disable collection by Google Analytics across websites.
09 Consent management
On your first visit to this website, you will be shown a consent banner through which you can consent to the use of Google Analytics 4 (“Accept”) or reject it (“Reject”). Without your express consent, no analytics cookies are set and no data is transmitted to Google: using the so-called Google Consent Mode, the consent status is technically preset to “denied” before any analytics scripts are loaded.
Your selection is stored solely in your browser’s local storage – not on our servers – and is automatically taken into account on subsequent visits so that the banner is not displayed again. You can change your selection at any time using the “Cookie settings” link in the footer of this website.
The legal basis for storing your selection is our legitimate interest under Art. 6(1)(f) GDPR in implementing your decision in compliance with data protection law and, where you have given consent, Art. 6(1)(a) GDPR.
10 Analytics, statistics and marketing services
This website uses Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (part of the Google group, whose parent company is Google LLC, USA), to statistically evaluate the use of this website and continuously improve our offering.
It is used solely on the basis of your consent under Art. 6(1)(a) GDPR, which you give through the consent banner and may withdraw at any time with effect for the future using the “Cookie settings” link in the footer (see section 9).
In connection with Google Analytics 4, the following data in particular may be processed: truncated or pseudonymised IP address, browser and device information, operating system, screen resolution, language settings, referrer URL, pages visited, time spent, click behaviour, session information and a pseudonymous client identifier (cookie ID).
Google Analytics 4
Provider
Google Ireland Limited (Google LLC, USA)
Purpose
Reach measurement, statistics, website optimisation
Legal basis
Art. 6(1)(a) GDPR (consent)
Cookies set
\_ga, \_ga\_<Container-ID> · lifetime of up to 2 years
Retention period at Google
Event data deleted after no more than 14 months
Third-country transfer
USA · EU-U.S. Data Privacy Framework
Withdrawal
“Cookie settings” in the footer of this website
Enhanced Measurement
In addition to standard event collection, we have enabled the following “Enhanced Measurement” functions in Google Analytics 4, which automatically collect additional events:
• Page views: A page-view event is recorded whenever a page loads and when the browser history changes on the client side.
• Scrolls: Recorded when you reach the bottom of a page.
• Outbound clicks: Recorded when you click a link that leads away from this website.
• Site search: Search queries are recorded if the URL accessed contains common search parameters; this website does not currently provide its own search function, so in practice this event will generally not be triggered.
• Form interactions: Recorded when you interact with a form on this website, such as the contact form or the carrier verification form.
• Video engagement: Play, progress and completion events are recorded for embedded YouTube videos with the JS API enabled; this website does not currently embed YouTube videos, so in practice this event will generally not be triggered.
• File downloads: Recorded when you click a link to a common document, compressed, application, video or audio file.
Enhanced Measurement cannot be disabled separately for each function, but only in its entirety through your consent to Google Analytics 4 (see above and section 9).
Further information about data processing by Google, including Google’s privacy policy, is available at policies.google.com/privacy. Google also provides a browser add-on at tools.google.com/dlpage/gaoptout that allows you to disable collection by Google Analytics across websites.
Providing personal data for analytics purposes is always voluntary. Refusing or withdrawing your consent has no effect on your use of the technically necessary functions of this website.
11 Hosting and technical infrastructure
11.1 Website hosting
This website is a static website and is provided through GitHub Pages, a service of GitHub, Inc. (a subsidiary of Microsoft Corporation, USA). We use Cloudflare, Inc. for the domain’s name resolution (DNS); Cloudflare solely resolves the domain to the GitHub Pages address and – unlike in a proxied/CDN configuration – is not involved in the actual transmission path of the website content.
In providing the website, GitHub Pages processes in particular technical connection and usage data required for the website’s secure operation, including IP address, date and time of access, browser type and browser version, operating system, referrer URL, pages accessed, device information and server log data. In connection with DNS resolution, Cloudflare processes technical request data (including the requesting IP address) solely to resolve the domain.
Purposes of processing: Providing the website, delivering website content, ensuring system stability, detecting and defending against cyberattacks, analysing and rectifying errors, and ensuring IT and network security.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in operating this website securely, efficiently and economically and in ensuring the availability of our online offering. Where individual processing operations are technically essential, the technologies required for them are additionally used on the basis of the relevant provisions of the Austrian Telecommunications Act (TKG 2021).
Recipients: GitHub, Inc. (including companies affiliated with GitHub or Microsoft and sub-processors engaged by them) and Cloudflare, Inc., to the extent described and limited to DNS resolution.
Third-country transfers: GitHub Pages and Cloudflare are US providers; processing of personal data in the USA therefore cannot be ruled out. Further information is provided in section 13.
Encryption: This website uses state-of-the-art transport encryption (TLS/SSL) to protect personal data against unauthorised access while it is transmitted between your device and our systems.
11.2 Technical infrastructure
To provide, secure and continuously improve this website, we use infrastructure components provided by GitHub Pages and Cloudflare, in particular a content delivery network (CDN), Domain Name System (DNS), TLS/SSL certificate services and protective measures against attacks and misuse. Operation of this infrastructure may involve the processing of, in particular, IP addresses, device and browser information, date and time of access, resources accessed, HTTP status codes, referrer URLs and technical diagnostic and security logs.
Processing is carried out solely to provide the website, ensure availability, detect and defend against cyberattacks, analyse errors, optimise performance, ensure IT security and fulfil statutory evidence and documentation obligations. The legal basis is Art. 6(1)(f) GDPR.
11.3 Information and IT security
Protecting personal data and the security of our information technology systems are high priorities for us. We take appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect personal data against loss, destruction, unauthorised access, unauthorised alteration or unauthorised disclosure. For reasons of information security, we do not publish further technical details of the security measures used where their disclosure could impair the security of our systems.
11.4 Use of processors
To provide our services, we use carefully selected external service providers that process personal data on our behalf (processors within the meaning of Art. 28 GDPR). They act solely on the basis of a data processing agreement pursuant to Art. 28 GDPR and may process personal data only on our documented instructions. Depending on the functions you use, we may use processors in particular from the categories of hosting and CDN infrastructure, IT and system administration, email and communication services, and security and monitoring services.
12 Recipients and categories of recipients of personal data
We disclose personal data only where this is necessary for the purposes stated in this privacy policy, where there is a legal obligation, where you have given consent or where another legal basis under data protection law applies. Data is always disclosed in accordance with the principle of data minimisation.
12.1 Internal recipients
Within our company, personal data is accessible only to those functions that require it to perform their respective tasks, in particular management, sales, customer communications, IT administration, and privacy and compliance functions. Access is based on internal authorisation policies and the need-to-know principle.
12.2 External service providers as processors
We use external service providers that process personal data on our behalf (Art. 28 GDPR). These may include the following categories in particular:
Hosting and CDN providers
Purpose
Provision and operation of the website
Typical data
IP address, log data, technical usage data
DNS providers
Purpose
Domain name resolution
Typical data
Requesting IP address
Email and communication service providers
Purpose
Sending and receiving emails and contact enquiries
Typical data
Name, email address, communication content
Analytics and statistics services (Google Analytics 4)
Purpose
Reach measurement where consent has been given (see section 10)
Typical data
Usage data, device information, cookie identifiers
IT security and monitoring service providers
Purpose
Protection against attacks, error analysis
Typical data
Log data, IP addresses, security events
12.3 GitHub Pages and Cloudflare as hosting and DNS providers
This website is operated through GitHub Pages; Cloudflare provides the domain’s DNS resolution. Further information about the data processed, purposes and legal bases is provided in section 11. Where GitHub or Cloudflare process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.
12.4 Payment, billing and accounting service providers
If paid services are initiated or processed through this website in future, or billing and payment data are processed, personal data may be transmitted to payment service providers, accounting software providers, tax advisers, banks or, where necessary, debt collection service providers. The legal bases are, in particular, Art. 6(1)(b), (c) and (f) GDPR.
12.5 Legal advisers, tax advisers, auditors and public authorities
Personal data may be transmitted to lawyers, tax advisers, auditors, public authorities or courts where this is necessary to fulfil legal obligations, for tax and corporate-law documentation, to examine and enforce legal claims, or to comply with official or court orders. The legal bases are Art. 6(1)(c) and (f) GDPR.
12.6 Communication and marketing service providers
If in future you consent to receiving newsletters or marketing communications, or to analytics and tracking services, personal data may be transmitted to the relevant communication or marketing service providers. Processing takes place only where an appropriate legal basis exists, in particular your consent under Art. 6(1)(a) GDPR.
12.7 Group companies and affiliated companies
If affiliated companies, subsidiaries or companies within a corporate group exist in future, personal data may be shared within the group where this is necessary for internal administrative purposes, contract performance, IT security, compliance or customer communications (Art. 6(1)(f) GDPR).
12.8 No disclosure for third-party advertising purposes
We do not sell personal data to third parties. Personal data is disclosed to third parties for their own advertising purposes only where express consent has been given or another statutory basis exists.
13 Third-country transfers
13.1 Principle
As a rule, we process personal data within the European Union (EU) or the European Economic Area (EEA). Where we use external service providers, it may in individual cases be necessary, or cannot be ruled out, that personal data will be transferred to recipients in countries outside the EU or EEA (so-called third countries) or processed there. Such transfers take place solely in compliance with the requirements of Chapter V GDPR.
13.2 Adequacy decisions and the EU-U.S. Data Privacy Framework
Where the European Commission has adopted an adequacy decision for a third country pursuant to Art. 45 GDPR, transfers take place on that basis. Where personal data is transferred to companies in the United States of America, this is done – where applicable – on the basis of the adequacy decision for the EU-U.S. Data Privacy Framework (DPF); in doing so, we ensure that the relevant recipient is certified under the DPF for the data processing concerned.
13.3 Standard Contractual Clauses (SCCs)
Where no adequacy decision exists for a recipient or it does not cover all processing operations, we base third-country transfers on the Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Art. 46 GDPR, supplemented by additional technical and organisational measures where necessary.
13.4 Service providers used with a third-country connection
The following service providers or categories of service providers currently or potentially have a third-country connection:
GitHub Pages (GitHub, Inc. / Microsoft)
Purpose
Hosting this website
Legal basis
EU-U.S. DPF / Standard Contractual Clauses
Cloudflare, Inc.
Purpose
Domain DNS resolution
Legal basis
EU-U.S. DPF / Standard Contractual Clauses
Google Analytics 4 (where consent has been given)
Purpose
Reach measurement and website optimisation
Legal basis
EU-U.S. Data Privacy Framework
Where Microsoft Azure services, including Azure OpenAI Service, are used for individual functions of our products (not this corporate website), personal data is generally processed within the selected Azure region; according to Microsoft’s contractual assurances, data processed through Azure OpenAI Service is not used by either Microsoft or OpenAI to train the underlying foundation models.
13.5 Information about appropriate safeguards
You may request further information about third-country transfers and a copy of, or reference to, the appropriate safeguards used pursuant to Art. 46 GDPR at any time, unless statutory or contractual confidentiality obligations prevent this. Please use the contact details specified in section 1.
14 Retention, erasure and storage of personal data
We process personal data only for as long as is necessary for the respective processing purposes or statutory retention obligations apply. Once the respective processing purpose ceases to apply, personal data is deleted or – where deletion is not possible because of statutory retention obligations – restricted and processed further solely for the purposes permitted by law.
14.1 Overview of retention periods
Server log files
Retention period
generally 90 days
Contact enquiries
Retention period
until processing is completed, then generally 12 months
Newsletter (if offered in future)
Retention period
until consent is withdrawn
Cookie/consent permissions (if required in future)
Retention period
generally 3 years
The retention periods that actually apply may differ in individual cases where legal obligations or overriding legitimate interests require longer storage.
14.2 Statutory retention obligations and backups
Where tax, corporate, commercial or other statutory provisions require us to retain personal data, processing takes place for the duration of the relevant statutory retention period. Backups are also created regularly as part of our IT security measures; for technical reasons, personal data may therefore remain in encrypted backups for a limited period after its deletion before those backups are automatically overwritten or deleted.
15 Privacy management and organisational safeguards
Protecting personal data is an essential part of our business processes. We have implemented appropriate technical and organisational measures to ensure that personal data is processed in compliance with data protection law throughout its lifecycle, including:
• assigning responsibilities for privacy and information security
• documenting processing activities
• regularly reviewing processes relevant to data protection
• incorporating data protection requirements into new products (privacy by design)
• privacy-friendly default settings where technically and organisationally feasible (privacy by default)
• role-based access policies and the need-to-know principle
All persons with access to personal data are bound to confidentiality. External service providers receive personal data solely on the basis of a contractual agreement and only to the extent necessary to provide the relevant service.
Internal processes are in place to detect, assess and manage personal data breaches. Where required by law, reports are made to the competent data protection supervisory authority and affected persons are notified within the periods prescribed by law.
16 Rights of data subjects
Where we process your personal data, you have the following rights in accordance with the GDPR. To exercise your rights, you may contact us at any time using the contact details specified in section 1. Exercising your rights is generally free of charge.
Right of access (Art. 15 GDPR)
You have the right to request information as to whether we process personal data concerning you and to obtain a copy of that data.
Right to rectification (Art. 16 GDPR)
You have the right to request the rectification of inaccurate personal data without undue delay and the completion of incomplete personal data.
Right to erasure (Art. 17 GDPR)
You have the right to request the erasure of your personal data under the statutory conditions, in particular where the data is no longer necessary, you have withdrawn consent or processing is unlawful. This right may be restricted where statutory retention obligations prevent deletion.
Right to restriction of processing (Art. 18 GDPR)
Under the statutory conditions, you may request that the processing of your personal data be restricted.
Right to data portability (Art. 20 GDPR)
Where processing is based on consent or a contract and is carried out by automated means, you have the right to receive the data you have provided in a structured, commonly used and machine-readable format.
Right to object (Art. 21 GDPR)
Where we process personal data on the basis of our legitimate interest, you have the right to object at any time on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons.
Withdrawal of consent (Art. 7(3) GDPR)
Where processing is based on your consent, you may withdraw it at any time with effect for the future without affecting the lawfulness of processing carried out before its withdrawal.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
If you believe that the processing of your personal data infringes data protection legislation, you have the right to lodge a complaint with a data protection supervisory authority. For controllers established in Austria, the following authority is competent in particular:
Austrian Data Protection Authority
Address
Barichgasse 40–42, 1030 Vienna, Austria
Website
https://www.dsb.gv.at
17 Obligation to provide personal data
As a rule, there is no statutory requirement to provide personal data. Certain data is, however, necessary for us to provide this website, handle enquiries, take steps prior to entering into a contract, or enter into and perform contracts.
Where personal data is not required for entering into or performing a contract or fulfilling legal obligations, it is provided voluntarily – for example, optional information in the contact form. Failure to provide optional information generally has no adverse consequences, but may limit individual convenience features.
If, by contrast, personal data required to enter into or perform a contract is not provided, this may mean that enquiries cannot be handled or contracts cannot be entered into or performed.
18 Automated decisions and profiling
As a rule, no decision based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR takes place in connection with visits to this website. In particular, we do not make decisions that produce legal effects concerning you or similarly significantly affect you.
If in future we use functions involving automated decision-making or profiling within the meaning of Art. 22 GDPR, we will inform you separately before the relevant processing begins and – where necessary – obtain your consent.
19 Information under Art. 14 GDPR
As a rule, we collect personal data directly from you. In certain cases, however, we also receive personal data from other permitted sources, such as your employer or client, business partners, publicly accessible registers or company directories.
Depending on the individual case, the data processed may include, in particular, name, business contact details, company, role or position, and professional communication data – for the purpose of initiating or conducting business relationships, communicating with contact persons and fulfilling contractual and legal obligations (Art. 6(1)(b), (c) and (f) GDPR).
Where personal data is not collected directly from the data subject and we are legally obliged to do so, we provide the information required under Art. 14 GDPR within the periods prescribed by law, unless an exception under Art. 14(5) GDPR applies.
20 Changes to this privacy policy
We reserve the right to amend this privacy policy as necessary to reflect changes in the legal, technical or organisational framework or changes to this website and our services – in particular where new functions are introduced, new service providers are engaged or the technical infrastructure changes.
The current version of this privacy policy is available on this website at all times. Where required by law or where changes materially affect your rights, we will inform you of the relevant changes in an appropriate manner.
This version is the privacy policy of A-Log Technology GmbH for the website www.a-log.at. Version 1.0 · Status: 14 July 2026. Controller: Ehsan Mahmoudzadehvazifeh, A-Log Technology GmbH, Felbigergasse 39/1, 1140 Vienna, Austria ·
