Legal
Privacy policy
Version: August 2026
Controller
SAVVATA IT Services e.U.
Kohlagasse 43, 9020 Klagenfurt am Wörthersee, Austria
DI Alexander Steinwender, MBA
Alexander.Steinwender@savvata.com
savvata.com
Website access and hosting
Technically necessary connection data is processed when you access this website. This may include the IP address, date and time, requested address, amount of data transferred, referrer, browser and operating system. Processing is necessary to provide the website securely and reliably and to defend against attacks. It is based on legitimate interests under Article 6(1)(f) GDPR. Access and error logs are retained for seven days and then deleted. The website, database and form API are hosted by Infomaniak Network SA in Switzerland. The European Commission has adopted an adequacy decision for Switzerland.
Language selection
Your selected language is stored only in your browser's local storage under the key savvata_language. On your first visit, the browser language may be read to select the appropriate language version. This information is not transmitted to Savvata and can be removed through your browser's website data settings.
Contact form
When you use the contact form, Savvata processes your name, email address, subject, message, language, delivery status and necessary timestamps. The request is stored in a MariaDB/MySQL database and forwarded through an authenticated SMTP service to a recipient address configured exclusively on the server. Processing is based on Article 6(1)(b) GDPR where the request relates to contractual or pre-contractual matters, and otherwise on the legitimate interest in communication under Article 6(1)(f) GDPR. Providing the data is voluntary but necessary for a response.
Contact by email
When you contact Savvata directly by email, your email address, name, message content, any attachments you provide and the technical metadata required for delivery are processed. Processing is carried out to handle and respond to your enquiry. It is based on Article 6(1)(b) GDPR where the enquiry relates to contractual or pre-contractual matters, and otherwise on the legitimate interest in reliable business communication under Article 6(1)(f) GDPR. Recipients are limited to authorised persons and Infomaniak Network SA as the email service provider. Providing the data is voluntary; however, a response by email is not possible without a reachable sender address.
Abuse prevention
The form is protected by an invisible honeypot field, a self-hosted ALTCHA CAPTCHA and rate limiting. For rate limiting, the IP address is processed only temporarily and converted together with the endpoint into a non-reversible HMAC key. Only this key, a counter and the time window are stored for no more than one hour. A hash of an already used CAPTCHA solution is stored for no more than 15 minutes to prevent reuse. Processing is based on the legitimate interest in website security and abuse prevention under Article 6(1)(f) GDPR.
Recipients and processors
Access is limited to authorised persons and Infomaniak Network SA as the processor required for hosting, database operation and SMTP delivery, and only to the extent necessary. Form data is not sold or used for advertising or profiling.
Retention
The additional database copy of a contact-form enquiry that has been successfully forwarded by email is deleted after 30 days. Form enquiries that cannot be delivered successfully are deleted no later than 30 days after receipt. Direct emails and subsequent email correspondence relating to an enquiry are retained for 30 days after the communication has ended and are then deleted, unless statutory retention obligations or the establishment, exercise or defence of legal claims require longer retention. Backups at Infomaniak are retained for seven days and then overwritten or deleted. Expired rate-limit and CAPTCHA records are removed regularly.
Cookies, tracking and automated decisions
The website uses no analytics, advertising or tracking services and no cookies for such purposes. No profiling or solely automated decision-making producing legal or similarly significant effects takes place.
Your rights
Subject to the GDPR, you have rights including information, access, correction, deletion, restriction, portability and objection. To exercise your rights, contact the email address stated above. You also have the right to complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, at dsb.gv.at.
