Privacy Policy

We value transparency and accountability. Reach out to us for any inquiries or concerns.

1. Controller

Thomas Muehlbacher
Alte Poststraße 102, 8020 Graz, Austria
E‑mail: imprint-d91d@tagtile.io

2. Contact for Data Protection

For any privacy‑related enquiries please e‑mail imprint-d91d@tagtile.io.

3. Individual Processing Activities

No.ActivityDataPurposeLegal BasisRetention
3.1Server log files (Vercel Inc.)Truncated IP, UA, referrer, timestamp, pathOperation & securityArt. 6 (1) (f) GDPR30 days
3.3Newsletter (Brevo – double opt‑in)E‑mail, name, tester checkboxNews & beta invitesArt. 6 (1) (a) GDPR; §107 TKGUntil withdrawal
3.4E‑mail enquiriesE‑mail, content, metaAnswer enquiriesArt. 6 (1) (b) GDPR12 months
3.5Feedback form (Plutio Ltd.), external (my.savory.at/...)Form entries, technical data required to process the requestService improvementArt. 6 (1) (a) GDPR12 months

Scroll horizontally to see the full table on mobile devices.

IP addresses are stored only in truncated form (e.g. 192.168.xxx.xxx).

*Our legitimate interest lies in operating a secure, reliable website; a balancing test is available upon request.

The site cannot be rendered correctly without map tiles.

4. Cookies & Consent Management

This site currently runs no web analytics and sets no tracking cookies. A single strictly-necessary cookie, cc_cookie (1 year), stores the choice you make in the cookie banner so it is not shown again. The banner's analytics category is kept for a possible later analytics setup; nothing is loaded when you enable it today.

5. Recipients & Processors

ServiceCompany / LocationTransfer Safeguard
Hosting / CDNVercel Inc., USASCC, EU–US DPF, EU hosting
NewsletterSendinblue SAS (Brevo), FranceEU hosting, DPA v9
Feedback formPlutio Ltd., United KingdomUK adequacy decision, DPA

6. International Data Transfers

Data with Vercel may be processed in the USA under the EU–US Data Privacy Framework and SCC. Brevo stores data solely within the EU. Plutio operates in the UK under the adequacy decision.

7. Security Measures

We use TLS/HTTPS for all traffic and restrict server access to authorised personnel only, in line with Art. 32 GDPR.

8. Automated Decision‑Making

We do not engage in automated decision‑making or profiling within the meaning of Art. 22 GDPR.

9. Your Rights

Under the GDPR you have the right to access, rectify, erase, restrict or object to processing, to data portability and to withdraw any consent at any time with future effect. Providing data is voluntary; without it certain features (e.g. newsletter) may be unavailable. After withdrawal your data are deleted within 30 days from operational systems.

10. Supervisory Authority & Complaints

You may lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40‑42, 1030 Vienna, Austria – dsb@dsb.gv.at – if you believe that the processing of your personal data infringes applicable law. If you have any questions or concerns regarding this policy, please do not hesitate to contact us at directly and informally at imprint-d91d@tagtile.io. We are open to feedback and will do our best to address your concerns.

11. External Links

External websites are beyond our control; we accept no liability for their content or privacy practices.

12. Copyright

All texts, images and graphics are protected by copyright. Any use outside statutory exceptions requires prior written permission.

13. Changes to this Policy

We may amend this policy to reflect legal or service changes. The latest version is always available here.