Last updated: September 2026
1. Controller within the meaning of the GDPR
Felix Zoffmann
Vantix Solutions
Jacob-Rauschenfelsgasse 8a/2, 7000 Eisenstadt
Email: office@vantixsolutions.at
2. Overview of data processing
We process personal data only to the extent necessary to provide a functional website as well as our content and services. Processing is based on the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
3. Access data and server log files
When you visit our website, our hosting provider automatically collects technical access data in so-called server log files. These include:
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- Host name of the accessing computer
- Date and time of the server request
- IP address (anonymised where applicable)
The storage period depends on the purpose of technical provision, error analysis and prevention of misuse, as well as on the hosting provider's settings applicable to these purposes. The data is collected on the basis of Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient provision of our website).
4. Contacting us
If you contact us by email or via a contact form on our website, the details you provide (name, email address, message content and, where applicable, telephone number) are stored by us for the purpose of processing your enquiry. To process enquiries, we use the service providers described below, in particular for email communication and delivery.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
Your contact data will be deleted as soon as the purpose of storage no longer applies and no statutory retention obligations prevent deletion.
5. Appointment request
If you request an appointment proposal, we process your email address in order to personally arrange the initial consultation. If you have previously completed the potential analysis, its summarised evaluation is additionally transmitted to us as context when you submit the appointment request. Individual answers are not transmitted.
To deliver appointment and contact requests, we use Resend, a service of Plus Five Five, Inc., USA. According to the provider, data is stored in the USA; for transfers from the EU, the data processing agreement provides for EU Standard Contractual Clauses. Further information can be found in Resend's privacy policy. We use the data exclusively to process and coordinate your request and delete it as soon as the purpose no longer applies and no statutory retention obligations prevent deletion.
Legal basis: Art. 6(1)(b) GDPR (implementation of pre-contractual measures at your request).
6. Potential analysis and local browser storage
The potential analysis is evaluated directly in your browser. Your individual answers are not transmitted to our server. A local draft allows you to continue the analysis after changing pages. The draft and the hand-over of the evaluation to the appointment request are valid for no more than two hours after they were last saved and are discarded on the next access thereafter.
Your cookie selection is also stored locally until you change it or delete the website data in your browser. This storage supports functions you have expressly requested (§ 165(3) TKG 2021); it is not used for advertising purposes.
7. Hosting
Our website is provided via Vercel Inc., USA. Vercel operates a global hosting and delivery infrastructure. Processing exclusively within the EU is therefore not guaranteed. Information on processing and on transfers to third countries can be found in Vercel's privacy notice and in the provider's data processing agreement.
8. Meta Marketing API (Facebook & Instagram Lead Ads)
For our own lead generation, we run advertisements on Facebook and Instagram. If you fill in a lead form (Instant Form) on these platforms, the data you provide there – typically name, email address, telephone number and, where applicable, other information you have released – is transmitted to us via the Meta Marketing API so that we can process your enquiry.
We use the Meta Marketing API exclusively to retrieve the leads received on Meta platforms and to transfer them into our internal processing system. No further profiling, no matching for advertising purposes and no resale takes place.
The controller for processing on the Meta platforms themselves (Facebook, Instagram) is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. Further information: https://www.facebook.com/privacy/policy
Once the lead data has been received by us, we store it exclusively within the scope of contacting us as described in section 4 and handle it according to the same rules.
Legal basis: Art. 6(1)(b) GDPR (implementation of pre-contractual measures at your request) or Art. 6(1)(a) GDPR (your consent when submitting the lead form).
You may request the deletion of the data transmitted to us via Meta at any time. Instructions can be found at /en/data-deletion.
9. Google Workspace (Drive, Sheets, Gmail)
For internal work processes, we use Google Workspace from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In this context, your contact and project data may be processed in Gmail (email communication), Google Drive (document storage) and Google Sheets (e.g. lead lists, project overviews) – exclusively for the purpose of processing your enquiry and providing our services.
A data processing agreement pursuant to Art. 28 GDPR is in place with Google. Data transfers to the USA are safeguarded by the EU Standard Contractual Clauses and the EU-US Data Privacy Framework. Further information: https://policies.google.com/privacy
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in efficient internal organisation).
10. n8n automations
We use the open-source platform n8n to connect incoming leads and customer communication between our systems (e.g. Meta Lead Ads, Gmail, Google Sheets) and to automate routine steps.
Our n8n instance is self-hosted on a server within the European Union. Your data is not transmitted to n8n GmbH or to n8n Cloud. Only data that we receive anyway within the scope of the preceding sections (contact and lead data) is processed.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in efficient internal processes).
11. Slack (internal communication)
For internal communication, we use Slack from Slack Technologies Limited, 4th Floor, One Park Place, Hatch Street Upper, Dublin 2, Ireland. In the course of processing your enquiry, your name and the context of your enquiry may be discussed internally in a Slack channel.
A data processing agreement pursuant to Art. 28 GDPR is in place with Slack. Data transfers to the USA are safeguarded by EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient internal collaboration).
12. Overview of data categories and storage periods
Depending on the occasion, we process the following categories of personal data:
- Master and contact data: name, email address, telephone number, company.
- Communication data: content of your messages and emails.
- Lead data: information from lead forms (Meta Lead Ads, contact form, appointment request).
- Contract and project data: information about your request, agreed services and appointments.
- Technical access data: server log files (see section 3).
We store personal data only for as long as is necessary for the respective purpose. Leads that do not result in a business relationship are deleted after 12 months at the latest. We retain contract and billing data within the scope of the statutory retention obligations (in particular § 132 BAO: 7 years).
14. LinkedIn Insight Tag and Conversions API
If you select “Marketing” in the privacy settings, we use the LinkedIn Insight Tag and the LinkedIn Conversions API to measure the effectiveness of our LinkedIn advertising, attribute conversions and optimise campaigns. Without this consent, the Insight Tag is not loaded and no conversion data is sent to LinkedIn.
The Insight Tag may process technical browser and device information, IP address, timestamp, accessed URL, referrer and information about the interaction with LinkedIn ads. For a successfully submitted appointment request, we send, server-side, the normalised email address exclusively as a SHA-256 hash, a random event value and – where available – the LinkedIn ad click ID. Names, message contents and specific answers from the potential analysis are not transmitted to LinkedIn.
The hashed email address is pseudonymised, not anonymous: LinkedIn can use it to match it with a member account.
The browser and server events use the same event value so that LinkedIn counts the same appointment request only once. The recipient is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. Processing by affiliated companies in third countries cannot be ruled out. Further information can be found in LinkedIn's privacy policy.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and § 165(3) TKG 2021. You can change your selection at any time, with effect for the future, via “Cookie settings” in the page footer.
15. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, our website uses SSL or TLS encryption. You can recognise an encrypted connection by “https://” in your browser's address bar.
16. No further disclosure to third parties
Beyond the recipients expressly named above (hosting provider, Resend, Google, Meta, LinkedIn, PostHog, Cloudflare, Slack), we do not transfer your personal data to third parties unless:
- you have given your express consent (Art. 6(1)(a) GDPR),
- the disclosure is necessary for the performance of a contract (Art. 6(1)(b) GDPR),
- there is a legal obligation (Art. 6(1)(c) GDPR),
- the disclosure is necessary to safeguard legitimate interests and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data (Art. 6(1)(f) GDPR).
17. Your rights as a data subject
Subject to the respective statutory requirements, you have the following rights against us with regard to your personal data:
- Right of access (Art. 15 GDPR): You can request information about your data stored by us.
- Right to rectification (Art. 16 GDPR): You can request the rectification of inaccurate data.
- Right to erasure (Art. 17 GDPR): You can request the erasure of your data, provided that no statutory retention obligations prevent this.
- Restriction of processing (Art. 18 GDPR): You can request the restriction of the processing of your data.
- Data portability (Art. 20 GDPR): You can request to receive your data in a structured, commonly used format.
- Right to object (Art. 21 GDPR): Where processing is based on legitimate interests, you can object on grounds relating to your particular situation. You can object to direct marketing at any time.
- Withdrawal of consent (Art. 7(3) GDPR): You can withdraw any consent you have given at any time with effect for the future.
To exercise your rights, please contact: office@vantixsolutions.at. Step-by-step instructions specifically for the deletion of your data can be found at /en/data-deletion.
19. Changes to this privacy policy
We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services. The new privacy policy will then apply to your next visit.