Privacy · GDPR
Privacy Policy
Under Regulation (EU) 2016/679 (GDPR) and the Austrian Data Protection Act (DSG) · Last updated: July 2026. The German version (Datenschutzerklärung) is authoritative.
1. Controller
Controller within the meaning of the GDPR
Vladimir TosovicVillefortgasse 11
8010 Graz, Austria
Email: [email protected]
2. The short version
This is a static, deliberately data-minimal website:
- No analytics or advertising services, no marketing or tracking cookies, no profiling.
- One strictly necessary security cookie set by the hosting provider (
__cf_bmby Cloudflare, see section 3), the only cookie on this website. - No third-party content in the browser: system fonts only; no external scripts, fonts, or media are loaded.
- Personal data arises only through hosting (section 3) and if you voluntarily sign up via the form (section 4).
3. Hosting and server logs (DigitalOcean)
The website is served as a static site via the App Platform of DigitalOcean (DigitalOcean, LLC, 105 Edgeview Drive, Broomfield, CO 80021, USA). When you visit, the host necessarily processes connection data: IP address, date and time of access, requested URL, user agent (browser/operating system), and referrer.
Purpose: delivering the website, operational security, detecting and mitigating attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation). Retention: server and platform logs are kept by the host for a limited time according to its own policies; we keep no access logs of our own. Processing may also take place in the USA; DigitalOcean relies primarily on its certification under the EU-US Data Privacy Framework, with standard contractual clauses (Art. 46 GDPR) agreed as a fallback should that certification lapse. Details: DigitalOcean Privacy Policy.
Security cookie (Cloudflare): To protect its platform,
DigitalOcean uses Cloudflare, Inc. (101 Townsend Street,
San Francisco, CA 94107, USA) as a subprocessor. Cloudflare sets the cookie
__cf_bm when you visit the website. It serves solely to detect and
mitigate automated access (bot protection), processes technical connection
characteristics (including the IP address) for that purpose, and expires after
about 30 minutes of inactivity. This cookie is strictly
necessary for the secure operation of the service you request (§ 165(3) of the
Austrian Telecommunications Act 2021) and is not used for marketing, analytics,
or cross-site tracking. Legal basis of the associated processing:
Art. 6(1)(f) GDPR. Cloudflare may process data in the USA (safeguards as above:
Data Privacy Framework or standard contractual clauses). Details:
Cloudflare cookie documentation.
4. Kit waitlist (signup form)
Via the form you can voluntarily sign up for the kit waitlist. We process your email address, your language preference (German/English), optional free-text input (e.g. your intended use case; please do not enter personal or confidential information), and, for accountability, the version of the consent text and the form through which you signed up.
Double opt-in: After submitting the form you receive an email with a confirmation link. Your signup only takes effect once you click that link; without confirmation you receive no further emails and the details are deleted regularly, at the latest after 30 days. To document your consent (Art. 7(1) GDPR), our email service provider logs the times of signup and confirmation and technical data of the confirmation click (including the IP address used).
Purpose: notifying you about kit availability and launch, plus directly related project updates, no general newsletter, no sharing with third parties for advertising. We do not analyse open or click behaviour at the individual level: opens and clicks are recorded at most in aggregate, without being linked to your email or IP address. For security reasons, Brevo routes links in the emails via its own servers.
Processor: To manage signups, run the double opt-in process, and send emails, we use Brevo (Sendinblue SAS, 106 Boulevard Haussmann, 75008 Paris, France). Contact data is stored on servers within the European Union. For certain support, maintenance, and operational services, subprocessors engaged by Brevo may access data from third countries (e.g. the USA and India); standard contractual clauses under Art. 46 GDPR are in place for this. Brevo publishes its current subprocessor list in its privacy documentation; you can request a copy of the safeguards via the contact address below. A data processing agreement under Art. 28 GDPR is in place with Brevo. Your browser never connects to Brevo directly; the form submits to our own endpoint, which passes the data on to Brevo. Details: Brevo Privacy Policy.
Legal basis: your consent (Art. 6(1)(a) GDPR, §174 of the Austrian Telecommunications Act 2021); the double opt-in logging is based on our duty to demonstrate consent (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR). Retention: until you withdraw consent or the purpose is fulfilled. Withdrawal: at any time via the unsubscribe link in every email or informally by email to [email protected]; processing carried out before withdrawal remains lawful.
5. Contact by email
If you contact us by email, the transmitted data (email address, content) is processed to handle your request (Art. 6(1)(b) or (f) GDPR) and deleted once no longer needed for that purpose.
6. External links
The website links to external services (e.g. GitHub). Data is transferred to the respective provider only when you click such a link; their privacy policies apply.
7. No automated decision-making
No automated decision-making, including profiling (Art. 22 GDPR), takes place. This website also does not operate an AI system within the meaning of Regulation (EU) 2024/1689 (AI Act).
8. Your rights
You have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR)
An informal email to [email protected] suffices. If you believe the processing of your data violates data protection law, you can lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at, email: [email protected].
9. Changes
This policy will be updated as the website changes (e.g. new services, a shop). The version published here applies.