itereon GmbH
Privacy Policy
Information pursuant to Art. 13 and 14 GDPR. We take the protection of your personal data seriously and process it exclusively on the basis of the statutory provisions, in particular the GDPR, the Austrian Data Protection Act (DSG) and the Telecommunications Act (TKG 2021). In this privacy policy we inform you about the key aspects of data processing in connection with our website and our business activities.
Effective: June 2026
01
1. Controller
itereon GmbH
Arsenalstraße 11, 1030 Vienna, Austria
Email: office@itereon.eu
Represented by the managing directors Dr. Johannes Weinberger, Christoph Antesner and Ferdinand Stich-Regner.
For questions regarding data protection and the exercise of your rights, you can reach us at the address or email above. The appointment of a data protection officer is not legally required for our company; the point of contact for data protection matters is the management.
02
2. Legal bases for processing
We process personal data only where one of the following legal bases applies:
– your consent (Art. 6 (1) lit. a GDPR);
– for the performance of a contract or to take steps prior to entering into a contract (Art. 6 (1) lit. b GDPR);
– to comply with a legal obligation (Art. 6 (1) lit. c GDPR, e.g. tax and commercial retention obligations);
– to safeguard our legitimate interests (Art. 6 (1) lit. f GDPR, e.g. secure operation of the website, communication with prospects and clients).
03
3. Hosting and server log files
Our website is hosted via Microsoft Azure Static Web Apps. The hosting provider and EU contracting entity is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. The hosting provider processes the data arising via the website on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR; any transfers to third countries are safeguarded by standard contractual clauses.
When you access the website, your browser automatically transmits information to the server, which is temporarily stored in so-called server log files: IP address, date and time of access, page/file requested, volume of data transferred, notification of successful retrieval, browser type and version, operating system and the previously visited page (referrer). This processing serves to ensure a smooth connection, system security and stability (Art. 6 (1) lit. f GDPR). The log files are generally deleted after no more than 7 days, unless security-relevant events require longer storage.
04
4. Cookies and consent management
Strictly necessary storage required for the operation of the website (storing your cookie choice as well as your language and theme preference) is based on our legitimate interest (Art. 6 (1) lit. f GDPR) and § 165 (3) TKG 2021. This information is stored exclusively locally in your browser (localStorage) and is not transmitted to us or third parties.
For consent management we use our own, self-operated consent solution (not a third-party cookie service). Your decision is stored in a data-minimising manner locally in your browser (key “itereon.consent”). We distinguish the categories Necessary, Functional, Analytics and Marketing; all non-necessary categories are disabled by default.
All services that are not strictly necessary (in particular the embedded appointment booking, see point 5) are only loaded after you have given your consent via our consent banner (Art. 6 (1) lit. a GDPR). You can withdraw or adjust your consent at any time with effect for the future via the “Cookies” link in the footer.
05
5. Embedded appointment booking (Calendly)
To schedule appointments we embed the Calendly service (provider: Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA). The Calendly widget is only loaded once you have given your consent to the “Marketing” category via our consent banner; without consent, no connection to Calendly is established. If you click an appointment button without having consented, we first show a short consent notice; Calendly is only loaded after you confirm.
After your consent, personal data (e.g. IP address, name, email address, selected appointment) is transmitted to Calendly when the widget loads and when an appointment is booked, and is processed in the USA. As the USA is regarded as an unsafe third country, the transfer is based on your explicit consent (Art. 49 (1) lit. a GDPR) and additionally on standard contractual clauses. The legal basis for processing is your consent (Art. 6 (1) lit. a GDPR). For details, see Calendly's privacy policy at https://calendly.com/privacy
06
6. Contact (contact form and email)
When you contact us via the contact form or by email, we process the data you provide (in particular your name, email address and the content of your message) to handle your request and any follow-up questions. The legal basis is, depending on the context, the taking of steps prior to entering into a contract or the performance of a contract (Art. 6 (1) lit. b GDPR) or our legitimate interest in responding to enquiries (Art. 6 (1) lit. f GDPR).
We retain this data until your request has been conclusively handled and no further queries are to be expected, as well as beyond that within the scope of statutory retention obligations.
07
7. Fonts
For a consistent appearance, this website uses fonts that are embedded locally on our server (self-hosting). When the website is accessed, no connection to third-party servers (in particular not to Google) is established and no IP address is transmitted to third parties.
08
8. Social media profiles
We maintain our own profiles on social networks (e.g. LinkedIn) and link to them from our website. Only by actively clicking such a link are you redirected to the respective network; we do not use embedded active social media plugins that transmit data as soon as the page is loaded. When you visit our profiles within the respective platform, the privacy provisions of the respective provider apply, over whose processing we have no influence.
09
9. Web analytics with Microsoft Clarity
On the basis of your consent (Art. 6(1)(a) GDPR in conjunction with § 165(3) TKG 2021) we use Microsoft Clarity, a web analytics service provided by Microsoft Corporation (One Microsoft Way, Redmond, WA 98052, USA); the EU contracting party is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Clarity helps us understand how visitors use our website (heatmaps, pseudonymous and aggregated session replays, click and scroll behaviour, detected errors) in order to improve content, usability and load times.
Clarity is only loaded after you have consented to the “Analytics” category via our consent banner; without consent the service is not loaded and no data is transmitted to Microsoft. After your consent, Clarity processes in particular your processed IP address, device and browser information, the referrer URL, interaction data (mouse, clicks, scrolling, page views) and a pseudonymous identifier. Input fields, drop-down menus and sensitive content are masked by default and not transmitted; in addition we have enabled the “Strict” masking mode. We do not intend to identify individual persons; we do not use any feature that links data to a specific person (Identify function).
After your consent, Clarity sets first-party cookies (_clck with a lifetime of up to 13 months, _clsk with a lifetime of about one day). No advertising or third-party cookies are set (the “ad_storage” category is permanently disabled). Recording data is stored at Microsoft for around 30 days, aggregated analytics/heatmap data for up to 13 months.
As Microsoft may also process data in the USA, a transfer to a third country takes place. This is based on your consent (Art. 49(1)(a) GDPR), the European Commission’s adequacy decision under the EU-U.S. Data Privacy Framework (Microsoft is certified) and, additionally, on Standard Contractual Clauses (Art. 46 GDPR). Processing on our behalf is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR (Microsoft Products and Services Data Protection Addendum).
You can withdraw your consent at any time with effect for the future via the “Cookies” link in the footer; upon withdrawal Clarity deletes the cookies it has set and stops session capture. For more information, see the Microsoft privacy statement at https://privacy.microsoft.com/privacystatement
10
10. Retention
We process personal data only for as long as is necessary for the respective purposes and then delete it, unless statutory retention obligations (in particular under the UGB and BAO, generally 7 years) prevent this or the data is required for the establishment, exercise or defence of legal claims.
11
11. Recipients and processors
Your data is disclosed only insofar as this is necessary for the performance of a contract, you have consented or we are legally obliged to do so. Where we use service providers (e.g. hosting, IT service providers) who process data on our behalf, this is done on the basis of data processing agreements pursuant to Art. 28 GDPR.
12
12. Your rights as a data subject
Under the GDPR, you have in particular the following rights:
– the right of access to the data processed about you (Art. 15 GDPR);
– the right to rectification of inaccurate data (Art. 16 GDPR);
– the right to erasure (Art. 17 GDPR);
– the right to restriction of processing (Art. 18 GDPR);
– the right to data portability (Art. 20 GDPR);
– the right to object to processing (Art. 21 GDPR);
– the right to withdraw consent granted with effect for the future (Art. 7 (3) GDPR).
To exercise your rights, a message to the contact details listed under point 1 is sufficient.
13
13. Right to lodge a complaint with the supervisory authority
If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with the supervisory authority. In Austria, this is the:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40–42, 1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at · Web: www.dsb.gv.at
14
14. Data security
For security reasons and to protect the transmission of personal data, this website uses TLS/SSL encryption. We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access.
15
15. Changes to this privacy policy
We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services. The version in force at the time applies to your renewed visit.
Last updated: June 2026