1. Controller
The controller for data processing on this website within the meaning of the GDPR is:
- Company
- ADASTRA Solutions und Beteiligungen GmbH, FN 529195 d, Landesgericht für Zivilrechtssachen Graz
- Represented by
- Syrous Abtine, managing director
- Address
- Ragnitztalweg 6e, 8047 Graz, Austria
- office@adastrasolutions.at
No data protection officer has been appointed, and none is required under Art. 37 GDPR.
2. Principles
- One cookie is set, and only when you switch the language. It is called lang, stores “de” or “en” and expires after six months. It holds no identifier and serves no other purpose. Because it is necessary for a function you request, it needs no consent (§ 165(3) TKG 2021). No cookies are set for analytics, and there is no cookie banner.
- No advertising or social media plugins are used, and no cross-site tracking takes place.
- Reach is measured with self-hosted software that stores neither cookies nor IP addresses (section 6).
- Typefaces are served from my own server. No connection is made to Google or any other font service.
- No automated decision-making and no profiling take place.
- Data is never sold or passed on for advertising purposes.
3. Hosting and server log files
This website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. The servers are located in Frankfurt am Main, Germany. Hostinger processes the data arising from your visit solely on my behalf, under a data processing agreement pursuant to Art. 28 GDPR that forms part of its terms of service. Hosting involves no transfer of personal data to a third country.
Each time a page is requested, the web server automatically records data in log files:
- Truncated IP address of the requesting device. The final block is removed before the entry is written, so no full address is ever stored.
- Date and time of access
- Name and URL of the requested file
- Volume of data transferred and access status
- Browser, operating system and, where applicable, the referring page
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in technically faultless operation, delivery of the website, and defence against attacks. This data is not merged with other sources and is not evaluated for marketing purposes.
Retention: log files are deleted after 30 days at the latest, unless they are needed longer to preserve evidence of a security incident.
4. Contact form
The contact form on the home page lets you send me an enquiry. The data you enter is transmitted: name, email address, and optionally company, revenue range, type of enquiry and your message.
Purpose: handling and answering your enquiry, and exploring possible cooperation.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps taken at your request), or Art. 6(1)(f) GDPR where the enquiry has no contractual context. Providing the data is voluntary; without a name and email address, however, I cannot answer your enquiry.
Processing: the form is delivered and processed on the same server as this website. No external form service is involved, and no data is transmitted to a third country. Your enquiry is stored on that server and forwarded to my business email address.
Retention: your enquiry and the related correspondence are deleted once the matter has been conclusively dealt with and no statutory retention obligations apply. If a business relationship arises, the commercial and tax retention period of seven years under §132 of the Austrian Federal Fiscal Code applies.
5. Contact by email
If you write to me directly by email, your details are stored in order to handle the enquiry and in case of follow-up questions. Legal basis and retention correspond to section 4.
Email is operated through Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) on the basis of a data processing agreement under Art. 28 GDPR. Google may process data in third countries; the EU standard contractual clauses apply to such transfers.
Please note: unencrypted email does not offer full confidentiality. For sensitive material, financial data in particular, I am happy to agree a secure channel with you.
6. Reach measurement
To learn how often pages are opened and which sources visitors arrive from, this website uses GoatCounter, open-source analytics software. It runs on the same server as the website itself. No third-party provider is involved and no data leaves that server.
Recorded for each page view: the page opened, the referring page, the browser and operating system in general terms, the approximate screen size, and the country derived from the IP address. The IP address itself is not stored. To recognise repeat views within a single day, a non-reversible hash is formed from the IP address, the browser identifier and a value that changes daily. It is discarded at the end of the day and allows no conclusion about you.
The measurement sets no cookies and stores nothing on your device. It therefore works without consent.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in understanding which content is used and in operating the website economically. Because no personal identifiers are stored, the interference with your rights is minimal.
Retention: the aggregated counts are kept indefinitely and contain no personal data. The daily hash is deleted after 24 hours.
7. External links
This website links to external services, in particular my LinkedIn profile and cfofoundry.io. These are plain text links. No content from those providers is loaded automatically and no data is transmitted to them unless you actively click the link. Once you do, the privacy policy of the respective provider applies.
8. Recipients of the data
Your data is passed on only to the processors named in this policy and, where legally required, to public authorities. In the context of a business relationship, data may additionally be transmitted to my tax adviser to the extent necessary to meet tax obligations.
9. Your rights
You have the following rights in relation to your personal data:
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate or incomplete data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a common format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
An informal message to office@adastrasolutions.at is sufficient to exercise these rights.
10. Right to lodge a complaint
If you believe the processing of your data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority in Austria is:
- Authority
- Österreichische Datenschutzbehörde
- Address
- Barichgasse 40–42, 1030 Vienna, Austria
- Phone
- +43 1 52 152-0
- dsb@dsb.gv.at
- Web
- dsb.gv.at
11. Changes to this policy
This privacy policy will be updated whenever data processing on this website changes, for instance through new features or a change of hosting or form provider. The version published here applies in each case.
Last updated: September 2026