Privacy Notice
Privacy Policy
In the following privacy policy, we inform you about the most important aspects of data processing within the scope of our website. We collect and process personal data exclusively on the basis of the applicable legal provisions (General Data Protection Regulation – GDPR, Telecommunications Act 2021).
Whenever you access or visit our website, your IP address as well as the beginning and end of your session are recorded. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the secure and reliable operation of the website and in preventing abusive access. We do not store this connection data ourselves.
Whenever you access or visit our website, your IP address as well as the beginning and end of your session are recorded. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the secure and reliable operation of the website and in preventing abusive access. We do not store this connection data ourselves.
Contacting us
If you contact us via the contact form on our website or by email, the data you provide is stored in our email mailbox for the purpose of processing your request and in case of follow-up questions. This data is not stored on the web server — the message is only delivered. We delete the data as soon as it is no longer required for that purpose, at the latest three years after the correspondence ends. That period follows from our legitimate interest in being able to trace an enquiry and to defend ourselves against claims within the three-year limitation period; longer statutory retention obligations take precedence, in particular seven years for accounting records under § 132 of the Austrian Federal Fiscal Code (BAO).
Our email mailbox is operated by Migadu-Mail GmbH (Switzerland) as a processor. An adequacy decision of the European Commission under Article 45 GDPR is in place for Switzerland; the transfer is therefore treated like a transfer within the EU.
Beyond the processors named in this policy, we do not share your data. It is neither sold nor used for advertising purposes.
Our email mailbox is operated by Migadu-Mail GmbH (Switzerland) as a processor. An adequacy decision of the European Commission under Article 45 GDPR is in place for Switzerland; the transfer is therefore treated like a transfer within the EU.
Beyond the processors named in this policy, we do not share your data. It is neither sold nor used for advertising purposes.
Cookies and local storage
This website sets no cookies for analytics, marketing or tracking purposes and creates no usage profiles. A cookie banner is therefore not required.
For audience measurement we use Cloudflare Web Analytics: the page requested, the referring page, country of origin, browser and device type, and loading times. The service works without cookies and without an identifier in your browser and does not recognise you again; because nothing is stored on or read from your device, no consent under § 165 TKG 2021 is required. Your IP address is processed for counting but is not stored and is not shown to us; we see aggregated figures only. The legal basis is our legitimate interest in data-minimising audience measurement under Art. 6(1)(f) GDPR; the processor is Cloudflare, Inc. (USA), on the basis of the standard contractual clauses. We keep no copies ourselves.
To operate the contact form, your browser temporarily keeps your entries in session storage so they are not lost when you move between pages. This data stays on your device only and is deleted as soon as you close the browser tab. It is transmitted to us only when you submit the form.
The spam protection Cloudflare Turnstile may store technically necessary information in your browser for the duration of the security check. According to the provider, no cookies for cross-site recognition are set in the process.
Both of these — the temporary storage of your form entries and the information Turnstile keeps for the check — are strictly necessary for the function you requested; no consent is required for them under § 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021).
You can prevent this storage at any time in your browser settings; the contact form may then not work fully.
For audience measurement we use Cloudflare Web Analytics: the page requested, the referring page, country of origin, browser and device type, and loading times. The service works without cookies and without an identifier in your browser and does not recognise you again; because nothing is stored on or read from your device, no consent under § 165 TKG 2021 is required. Your IP address is processed for counting but is not stored and is not shown to us; we see aggregated figures only. The legal basis is our legitimate interest in data-minimising audience measurement under Art. 6(1)(f) GDPR; the processor is Cloudflare, Inc. (USA), on the basis of the standard contractual clauses. We keep no copies ourselves.
To operate the contact form, your browser temporarily keeps your entries in session storage so they are not lost when you move between pages. This data stays on your device only and is deleted as soon as you close the browser tab. It is transmitted to us only when you submit the form.
The spam protection Cloudflare Turnstile may store technically necessary information in your browser for the duration of the security check. According to the provider, no cookies for cross-site recognition are set in the process.
Both of these — the temporary storage of your form entries and the information Turnstile keeps for the check — are strictly necessary for the function you requested; no consent is required for them under § 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021).
You can prevent this storage at any time in your browser settings; the contact form may then not work fully.
NIS2 coverage check
The NIS2 coverage check offered at /en/nis2-check runs entirely in your browser. Your answers, the company figures you enter and any organisation name you add are neither transmitted to us nor to any third party, are not logged and are not stored — not in cookies and not in your browser’s local storage. They never leave your device. Closing or reloading the page discards them; you save the resulting document yourself, using your browser’s print or PDF function. No processing of personal data takes place in this. The statements on hosting and fonts below apply regardless, because the page itself is delivered like any other page on this website.
Fonts
This website uses the typeface "Poppins". The font files are served exclusively from our own server and are not loaded from an external provider. Visiting the website therefore establishes no connection to Google Fonts or any other third party, and no data is transmitted to Google.
Hosting
This website is operated on Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you visit the website, Cloudflare processes technically necessary connection data, in particular your IP address, the date and time of access and the page requested. The legal basis is our legitimate interest in the secure and reliable operation of the website pursuant to Article 6(1)(f) GDPR. Cloudflare acts as a processor; Cloudflare relies on the European Commission’s Standard Contractual Clauses for transfers to third countries.
Cloudflare privacy policy:
https://www.cloudflare.com/privacypolicy/
Cloudflare privacy policy:
https://www.cloudflare.com/privacypolicy/
Cloudflare Turnstile
To protect our contact form against automated requests we use "Cloudflare Turnstile", a service provided by Cloudflare, Inc. When you open a page containing the contact form, a script is loaded from challenges.cloudflare.com. Turnstile uses technical characteristics of your browser to assess whether the request originates from a human; this involves processing your IP address and information about your browser and device, among other data. According to the provider, Turnstile sets no cookies for this check and does not use the data for advertising purposes. The legal basis is our legitimate interest in preventing spam and abuse pursuant to Article 6(1)(f) GDPR.
Further information:
https://www.cloudflare.com/privacypolicy/
Further information:
https://www.cloudflare.com/privacypolicy/
Delivery of contact requests
The message submitted via the contact form is forwarded to us by email. We use the service "Resend" (Resend, Inc., USA) for delivery. The data you enter — name, email address, company and message — is processed in the course of this. The data is not stored on our server; only the email is delivered. Delivery runs through Resend’s EU region (Ireland); the data does not leave the European Economic Area in the process. Resend, Inc. is a US company acting as a processor; the European Commission’s Standard Contractual Clauses cover any third-country access.
We send an automatic acknowledgement to the address you provide. It does not quote your message back.
To prevent bulk submissions, your IP address is counted in memory when you submit. It is neither stored permanently nor logged, and is not linked to the message.
The legal basis is Article 6(1)(b) and (f) GDPR.
We send an automatic acknowledgement to the address you provide. It does not quote your message back.
To prevent bulk submissions, your IP address is counted in memory when you submit. It is neither stored permanently nor logged, and is not linked to the message.
The legal basis is Article 6(1)(b) and (f) GDPR.
Your Rights
As a data subject, you have the following rights with regard to your personal data stored by us:
• Right of access
• Right to erasure
• Right to rectification
• Right to data portability
• Right to withdraw consent and object to data processing
• Right to restriction of processing
If you believe that violations of data protection law have occurred in the course of processing your personal data, you have the opportunity to lodge a complaint with us (office@tg-advisory.at) or with the Austrian Data Protection Authority (Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at).
Right to object: where we rely on a legitimate interest (Article 6(1)(f) GDPR), you may object to the processing at any time on grounds relating to your particular situation. An informal message to office@tg-advisory.at is sufficient.
A copy of the Standard Contractual Clauses on which the transfers named above rely is available from us on request.
• Right of access
• Right to erasure
• Right to rectification
• Right to data portability
• Right to withdraw consent and object to data processing
• Right to restriction of processing
If you believe that violations of data protection law have occurred in the course of processing your personal data, you have the opportunity to lodge a complaint with us (office@tg-advisory.at) or with the Austrian Data Protection Authority (Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at).
Right to object: where we rely on a legitimate interest (Article 6(1)(f) GDPR), you may object to the processing at any time on grounds relating to your particular situation. An informal message to office@tg-advisory.at is sufficient.
A copy of the Standard Contractual Clauses on which the transfers named above rely is available from us on request.
You can reach us using the following contact details:
Controller within the meaning of the GDPR: Tobias Gösslbauer – IT & Security Consulting
Email: office@tg-advisory.at
Address: Fasangasse 36, 1030 Vienna - Austria
Email: office@tg-advisory.at
Address: Fasangasse 36, 1030 Vienna - Austria