Privacy Policy

I am committed to protecting personal data. The use of my website and my business activities generally involve the processing of personal data. To make these data processing activities transparent, I want to inform you in my privacy policy about how I process personal data and what rights you have in this context. If you have any further questions, you will find my contact details below.

1. Who I am and how you can contact me

The responsible party within the meaning of the General Data Protection Regulation (GDPR) is:

David Wippel
Glücksallee 8
3012 Wolfsgraben
Email:david@davidwippel.com

2. My data processing

2.1 General

I process personal data in compliance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR, Regulation [EU] 2016/679) and the Austrian Data Protection Act (DSG). Processing takes place only on the basis of a legal ground (in particular pursuant to Article 6(1)(a)-(f) GDPR), which is specified below for each data processing. All employees entrusted with the processing are obliged to maintain the confidentiality of your data (data secrecy). I do not carry out automated decision-making.

As a rule, I collect personal data directly from the data subject. In individual cases, I collect and store personal data (in particular name, contact information) based on correspondence with my customers and business partners or from publicly accessible sources (e.g. telephone book, websites, commercial register) on the basis of Article 6(1)(f) GDPR (and in this case not directly from the data subject) if this is necessary for the provision of my services or for contacting and administration, which is also my legitimate interest.

2.2 Operation of my website

Whenever you access my website, your computer (device) or browser automatically transmits certain information to enable the visit or operation of the website:

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (page/content to be retrieved)
  • Access status/HTTP(S) status code
  • URL of the previously visited website
  • Browser and browser version
  • Operating system and its interface

This data is stored in the log files of my system. This data is not stored together with other personal data of the user.

Legal basis and purpose of data processing: The legal basis for the processing of the data and their temporary storage in log files is Article 6(1)(f) GDPR. The temporary storage of the aforementioned data by the system is necessary to enable the delivery of the website to the user's device. The storage in log files is done to ensure the functionality of the website. In addition, the data serve to optimize the website and to ensure the security of my information technology systems, in particular to ensure the integrity, confidentiality, and availability of the data processed via my website. In these purposes also lies my legitimate interest in data processing according to Article 6(1)(f) GDPR.

Duration of storage: The data will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected. In the case of data collection for the provision of the website, this is the case when the respective session is ended. In the case of storage of the data in log files, this is the case after at most seven days, unless further processing is required to clarify a (suspected) attack. Personal data collected during the operation of the website will only be disclosed by me in the event of a (suspected) data security incident or a criminal offense (e.g., an attack) for the purpose of terminating the attack, investigating, prosecuting, and asserting claims against third parties (in particular experts and competent state authorities).

2.3 Social Media

I use social media to present my work through common communication channels. Each social medium has its own policies on how your personal data is processed when you access its pages. If you have concerns or questions about the use of your personal data, you should carefully read the privacy policies of the social media providers before using these services:

2.4 Provision of services and customer support

I process personal data for the purpose of providing my services, customer support and information, including internal documentation and administration. The legal bases for the processing of the data are the performance of a contract or the implementation of pre-contractual measures (Article 6(1)(b) GDPR), provided that the data subject (natural person) is directly a party to the contract; the fulfillment of legal obligations (Article 6(1)(c) GDPR) and my legitimate interests (Article 6(1)(f) GDPR), in particular interests in asserting or defending my own legal claims as well as internal administration within the company.

For a contract to be concluded, the provision of certain personal data is required by law or contractually, to which the respective data subject is obliged; otherwise, no contract can be concluded (and thus no service can be provided).

2.5 Contact and online appointment scheduling

When contacting me (e.g., via online appointment scheduling or email), the information provided by the requester (name, contact details, other information) will be processed for documentation, handling, and response to the request. I offer an online appointment scheduling option on my website. The data required to answer a request is marked as mandatory fields. The provision of further data is voluntary.

The basis for the processing of this data is my legitimate interest in the proper documentation, handling, and response to the request (Article 6(1)(f) GDPR); in the case of contact in an existing customer relationship or the initiation of a business relationship, I rely on the performance of a contract or the implementation of pre-contractual measures (Article 6(1)(b) GDPR).

If you contact me to fulfill your work or civil law obligations as an employee (service provider) for your employer or other client, I also have a legitimate interest in the proper documentation, handling, and response to the request (Article 6(1)(f) GDPR), which also includes your data as an external contact person; in the case of contact in an existing customer relationship or the initiation of a business relationship, I rely on the performance of a contract or the implementation of pre-contractual measures (Article 6(1)(b) GDPR).

For sending our newsletter, we use the service of Brevo. This service has its own policies regarding the processing of your personal data when you subscribe to the newsletter. If you subscribe to our newsletter, your personal data will be processed by Brevo according to their privacy policy:brevo.com/legal/privacypolicy

For contact purposes, we use the form provided by Tally.so, operated by Tally B.V., August Van Lokerenstraat 71, 9050 Gentbrugge, Belgium. This service has its own policies for processing your personal data. When you use our contact form, your personal data will be processed by Tally.so in accordance with their privacy policy:tally.so/help/privacy-policy

2.6 Cookies and other storage in your browser

This website stores information in your browser. What is stored, and on what legal basis, depends on what it is for. Nothing in this section is used to build a profile of you across other websites, except where the advertising pixel below is described and you have allowed it.

Your consent choice

When you answer the consent banner, your answer is stored in two places in your browser. A first-party cookie namedc15t, valid for 365 days, with path/, SameSite=Lax and, over an encrypted connection, the Secure flag. And an entry in your browser’s local storage under the keyprivacy-consent-storage. Both hold the same thing: the categories you chose, an identifier for that record, and the version of the consent policy you were shown.

This storage is strictly necessary. Without it the site cannot tell that you have already answered, and it would ask you again on every page. The basis is my legitimate interest in honouring the choice you made (Article 6(1)(f) GDPR), and § 165(3) TKG 2021, which exempts storage that is strictly necessary to provide a service you asked for.

Your answer is also recorded on a server I operate, so that I can show later what was consented to and when. That record is stored in the European Union and holds the same information as the cookie. It is kept for as long as the consent is relevant as evidence, and no longer than the retention rules in section 3.

Analytics: Plausible, and why it is not behind the banner

Every page loads Plausible Analytics, a European company whose data infrastructure is in Germany. Plausible is not consent-gated, and that is a deliberate decision rather than an oversight. It stores nothing in your browser and creates no identifier for you, so there is nothing to ask permission for.

According to its own data policy, Plausible uses no cookies, no browser cache and no local storage, and does not store IP addresses. Your IP address and browser user agent are used at the moment of the request to compute a daily changing hash, so that two visits in one day can be counted as one visitor, and the IP itself is then discarded. I have also read the script this site loads: it reads one local storage key and writes none, and that key is a flag I can set on my own devices to keep my own visits out of the numbers. You can read their policy atplausible.io/data-policy.

Advertising: the OpenAI conversion pixel

I advertise on ChatGPT, and I use OpenAI’s conversion measurement pixel to see whether those advertisements lead anywhere. This is the one thing on the site that needs your consent, and it is off unless you turn it on.

You should know exactly how it is loaded, because the honest description is not the simple one. OpenAI’s script is fetched on every page before you have answered the banner, and the first instruction it is given is that it does not have your consent. It is loaded that early because the identifier that connects a visit to an advertisement exists only in the address of the page you first land on, and it is gone by the time a banner has been answered. Until you allow the marketing category, the script sets no advertising identifier, stores nothing on your device for advertising, and reports nothing to OpenAI.

If you do allow it, the script may set cookies on this domain, including one named __oppref holding the advertisement click identifier, and it reports two things to OpenAI: that a page was viewed, and that the button linking to my booking calendar was clicked. That second one is recorded as a scheduled appointment because that is the only name OpenAI’s system has for it. It is a click on a link, not a booking, and no information from the booking calendar itself reaches OpenAI.

The basis is your consent (Article 6(1)(a) GDPR, and § 165(3) TKG 2021). You can withdraw it at any time, as described below. The operator is OpenAI, which processes this data in the United States. Seeopenai.com/policies/privacy-policy.

Forms

The contact form is provided by Tally and appears only on the pages that carry a form. It runs in its own frame, so it is separate from the rest of the page. What Tally processes is described in section 2.5 above.

If you decline

Nothing stops working. Declining the marketing category costs you no content, no page and no function. Every page, the contact form and the booking calendar behave exactly as they would if you had accepted.

Changing your mind

Every page carries a Consent settings link in the footer. It reopens the same dialog you saw the first time, with your current choice shown, and you can change it there and save. Withdrawing consent takes the same number of clicks as giving it, and it applies from the moment you save.

Processing outside the EU

One of the services named on this page processes data outside the European Union: OpenAI, in the United States, and it is only reached if you allow the marketing category. Everything else described here, including the consent record itself, stays in the European Union.

3. How long do I store personal data?

Unless otherwise specified in the respective processing, I generally store personal data for as long as it is necessary to ensure the fulfillment of the stated purposes or as long as I am legally obliged to do so.

This means for business letters, contracts, bookings, etc. according to § 212(1) UGB and § 132(1) BAO: Until the end of the business relationship or until the expiration of the applicable limitation and statutory retention periods (in particular at least 7 years to prove compliance with tax, levy, and corporate law retention obligations); in addition, until the end of any legal disputes in which the data is required as evidence. For services where claims for damages or other titles are asserted, for the necessary duration (between 3 and 30 years). For inquiries (contact): Personal data that you voluntarily provide to us will be stored by me for the purpose of providing the associated processing and record-keeping (up to 3 years after completion or termination), unless a longer retention period is required for the fulfillment of a legal obligation or for the assertion or defense of legal claims.

4. Rights of the data subject

Provided that the respective statutory requirements are met, you can exercise the following data subject rights:

  • Right of access: You can request confirmation as to whether personal data about you is being processed and request information about this data and the information according to Article 15 GDPR.
  • Right to rectification: If I process incorrect or incomplete data about you (Article 16 GDPR).
  • Right to erasure: Of your personal data if the conditions of Article 17 GDPR are met.
  • Right to restriction: Of the processing of your data (Article 18 GDPR).
  • Right to data portability: Of the data you have provided to me, if the processing is based on consent (Article 6(1)(a)) or on a contract (Article 6(1)(b)) and the processing is carried out using automated procedures (Article 20 GDPR).

In the case of processing based on legitimate interests (according to Article 6(1)(f) GDPR), you have the right to object to the processing of your personal data according to Article 21 GDPR, provided that there are reasons for this arising from your particular situation. In the case of processing for direct marketing purposes, this right exists without restrictions.

You can revoke consents given for the processing of personal data at any time, please contact me (see my contact details). The legality of the processing carried out based on the consent until the revocation is not affected by the revocation.

4.1 Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority responsible for you (in Austria: Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna,www.dsb.gv.at) if you believe that the processing of personal data concerning you violates the GDPR or your data subject rights have been violated. I ask you to contact me first in cases where you were not completely satisfied with me so that I can have an opportunity to correct any errors immediately.