1. Data Controller
2. Overview of Data Processing
The following overview summarises the types of data processed, the purposes of processing, and the data subjects concerned.
Types of data processed
- Master data (e.g. names, addresses)
- Contact data (e.g. email, phone numbers)
- Content data (e.g. form inputs)
- Usage data (e.g. pages visited, access time)
- Meta/communication data (e.g. IP addresses)
Categories of data subjects
- Website visitors
- Communication partners
- Customers and prospects
3. Legal Basis
The following is an overview of the legal bases under the GDPR on which I process personal data:
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing.
- Contractual necessity (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract.
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary to protect my legitimate interests.
4. Security Measures
I take appropriate technical and organisational measures in accordance with legal requirements, considering the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include:
- Encryption of data transmission (SSL/TLS)
- Hosting on servers in Germany (EU)
- Regular security updates
- No data transfers to third countries
5. Hosting
This website is hosted by Mittwald CM Service GmbH & Co. KG on servers in Germany. The hosting provider automatically collects and stores information in so-called server log files, which your browser automatically transmits. These include:
- Browser type and version
- Operating system
- Referrer URL
- Time of server request
- IP address (anonymised)
This data is not merged with other data sources. The collection of this data is based on Art. 6(1)(f) GDPR. I have a legitimate interest in the technically error-free presentation and optimisation of my website.
6. Contact
When you contact me (e.g. by email or phone), your information is processed for the purpose of handling the enquiry and its follow-up in accordance with Art. 6(1)(b) GDPR.
The information may be stored in a customer relationship management system (“CRM system”) or similar enquiry management tool. Enquiries are deleted once they are no longer necessary. Necessity is reviewed every two years; statutory archiving obligations remain unaffected.
7. Cookies
This website uses no cookies for analytics or tracking. No data is transmitted to third-party providers such as Google, Facebook, or others.
Should technically necessary cookies be used in the future (e.g. for forms or login areas), you will be informed accordingly.
8. No External Services
This website loads no external resources from third-party providers:
- No Google Fonts – typefaces are hosted locally
- No Google Analytics or similar tracking tools
- No social media plugins
- No external CDNs
This means that visiting this website does not transmit any data to servers outside Austria or the EU.
9. Your Rights
As a data subject, you have the following rights:
- Right of access (Art. 15 GDPR) – You have the right to obtain confirmation as to whether personal data concerning you is being processed.
- Right to rectification (Art. 16 GDPR) – You have the right to request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR) – You have the right to request the deletion of your data.
- Right to restriction (Art. 18 GDPR) – You have the right to request restriction of processing.
- Right to data portability (Art. 20 GDPR) – You have the right to receive your data in a structured, commonly used format.
- Right to object (Art. 21 GDPR) – You have the right to object to processing at any time.
- Right to withdraw consent (Art. 7(3) GDPR) – You have the right to withdraw any given consent at any time.
10. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR.
Austrian Data Protection Authority
(Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: mail@colourspace.com
Website: www.dsb.gv.at
11. Changes to This Privacy Policy
I reserve the right to amend this privacy policy to ensure it always complies with current legal requirements or to reflect changes to my services. The updated privacy policy will apply to your next visit.