Privacy Policy
Per GDPR
Introduction
The protection of your personal data is important to me. This privacy policy informs you under Art. 13 GDPR which data I process when you visit this website, for what purpose, and on which legal basis.
This website is a pure information site. It has no contact form, no comment function, no newsletter, and no user account area for visitors. You can use the site in full without actively providing any data. A separate privacy policy applies to the AgenticCutter product and describes the additional processing that occurs there for purchase and licensing.
Data Controller
- Name
- Bernhard Götzendorfer
- Address
- Rittingergasse 15/11
1210 Wien
Austria
No data protection officer has been appointed, as the conditions of Art. 37 GDPR are not met.
Data Processing on This Website
Hosting and Server Logs (Vercel)
This website is hosted by Vercel Inc. (USA). When a page is requested, Vercel automatically processes the technically necessary connection data: IP address, date and time of the request, URL requested, volume of data transferred, HTTP status code, referrer, and user agent. This processing is technically necessary to deliver the page and additionally serves to defend against attacks and to diagnose faults. The data is not merged with other data sources. Vercel is bound as a processor under Art. 28 GDPR. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and uninterrupted operation of the website).
Cookieless Audience Measurement (Vercel Analytics and Speed Insights)
To improve the website, page views are counted (Vercel Analytics) and technical performance values are recorded (Vercel Speed Insights, known as Core Web Vitals such as load time, responsiveness, and layout stability). The evaluation is aggregated. No cookies are set for this purpose, no identifiers are stored persistently on your device, and no personal profiles of individual visitors are created. Technical details such as IP address and user agent are processed only briefly in order to distinguish requests from one another; no recognition across other websites takes place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in evaluating and improving my own offering).
Error Monitoring (Sentry)
To detect and resolve errors on this website, error stack traces, the requested URL, the user agent, and technical runtime information are transmitted to Sentry. Processing takes place in the provider's EU region (Frankfurt data centre). Personal data such as IP addresses or email addresses is not transmitted: the sendDefaultPii option is disabled, and an additional scrubber removes user details, cookies, and authentication headers from the event data before it is sent. Session replay recording is switched off. In addition, performance data is sampled at a rate of 10 % to monitor site performance. Transmission runs through an endpoint on this domain, so your browser never opens a direct connection to Sentry. Error events are retained for 90 days. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in site stability and quality).
Contact by Email
There is no contact form. If you write to me at the email address provided, I process the data you send (your email address, your name, and the content of your message including any attachments) in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR where your enquiry serves to initiate or perform a contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Email traffic runs through the mailbox provider for the gotzendorfer.at domain.
Appointment Booking via cal.eu (External Link)
For scheduling appointments I link to my profile with the booking service Cal.com on its EU instance cal.eu. No booking widget is embedded in this website. Accordingly, no data is transmitted to the booking service when you open this page. Only when you actively click the link do you leave this website; from that point onward the booking service's privacy terms apply. Booking data such as name, email address, and preferred appointment is entered directly there. Legal basis for a booking initiated by you: Art. 6(1)(b) GDPR (pre-contractual measures).
Web Fonts
Fonts are self-hosted via Next.js font optimization and delivered from this domain. When a page loads, no connections are made to external font servers, in particular not to Google Fonts. No data is transmitted to third parties in this process. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in consistent presentation without third-party connections).
No External Scripts or Embeds
This website includes no tracking pixels, no tag manager, no advertising networks, no social media plugins, and no embedded videos. References to external offerings are plain links only: data is transmitted to the respective provider only once you click the link.
Blog and RSS Feed
Blog posts are delivered as static files. There is neither a comment function nor a newsletter sign-up. Retrieving the RSS or JSON feed requires no registration; only the server logs described above are generated in the process.
Administration Area (Supabase)
The non-public administration area at /admin is used solely by me as the operator, for example to maintain the availability notice on the home page. Sign-in uses a one-time link sent by email. The data processed consists of the email address of the authorised account and the associated session data; data is held with Supabase in the EU (Frankfurt region). No processing takes place in this context for visitors to this website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure operation and maintenance of the website).
Cookies and Storage on Your Device
This website sets no marketing and no analytics cookies. Only functionally necessary entries are used:
- NEXT_LOCALE (cookie): stores the language version you selected or that was detected (de or en) so the site is delivered in the correct language. No personal data and no identifiers for recognition are stored.
- theme (browser local storage): stores your choice between light and dark presentation. The value remains in your browser and is not transmitted to the server.
- Administration area sign-in cookie: set only when I sign in at /admin, and technically required for session management. This cookie does not arise during a normal visit to the website.
All of the entries listed are strictly necessary for the functions you have requested and are therefore exempt from consent. Because no marketing or analytics cookies are set, no cookie-consent prompt is required. You can delete or block cookies at any time in your browser settings; the website remains usable but will lose the stored language and presentation choice.
Your Rights
As a data subject, you have the following rights regarding your personal data:
Right of Access (Art. 15)
You have the right to confirmation whether personal data concerning you is being processed, and access to that data.
Right to Rectification (Art. 16)
You have the right to demand the correction of inaccurate data or the completion of incomplete data.
Right to Erasure (Art. 17)
You may request the deletion of your personal data, provided no legal retention obligation applies.
Right to Restriction of Processing (Art. 18)
Under the conditions of Art. 18 GDPR, you may request a restriction on the processing of your data.
Right to Data Portability (Art. 20)
You have the right to receive the data concerning you in a structured, commonly used, machine-readable format or to have it transmitted to another controller.
Right to Object (Art. 21)
For reasons arising from your particular situation, you have the right to object at any time to the processing of your data. This applies in particular to the processing described above that is based on Art. 6(1)(f) GDPR.
No Automated Decision-Making
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.
Contact for Data Protection Requests
For questions about data protection or to exercise your rights, please contact:
office@gotzendorfer.atRetention Periods
I store personal data only for as long as it is required for the respective purpose or as long as statutory retention obligations apply.
- Email Enquiries
- until the matter is settled, then statutory retention periods
- Error Logs (Sentry)
- 90 days
Server logs are kept by the hosting provider only for the period required for operational security and fault diagnosis, and are deleted automatically thereafter. Audience measurement produces no personal records subject to a retention period; the evaluation is aggregated. I retain email enquiries until your matter has been conclusively handled; if a business relationship results from it, the seven-year tax retention obligation under § 132 BAO (Austrian Federal Fiscal Code) applies to the associated correspondence and records. Session data for the administration area becomes invalid upon sign-out or when the session expires.
Right to Lodge a Complaint
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority:
- Name
- Österreichische Datenschutzbehörde
- Address
- Barichgasse 40-42, 1030 Wien
- Website
- www.dsb.gv.at
Consumers may address data protection complaints directly to the data protection authority named above. The EU Online Dispute Resolution platform (ODR platform) was discontinued by the European Commission on 20 July 2025 and is no longer available.
International Data Transfer
The processing operations on this website are chosen so that data remains primarily within the EU. Error monitoring runs in the EU region (Frankfurt), and data storage for the administration area is likewise in the EU (Frankfurt region). The linked booking service is addressed via its EU instance cal.eu, and this too only after a click by you.
Hosting by Vercel Inc. may involve processing in the USA, for example in the course of support and operations. The same applies where the providers named above, as US companies, access data from a third country in individual cases. Such transfers are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the EU Commission adequacy decision (Data Privacy Framework).