Legal
Privacy Policy
How we process personal data — under the GDPR and the Austrian TKG 2021.
Controller
Sprachzentrum Dialog e.U., owner: Mag. Mladen Nenadic
Franz-Fritsch-Straße 11, 4600 Wels
Warwitzstraße 9, 5023 Salzburg
Email: info@sprachzentrum-dialog.at
Phone: 0676 / 45 00 380
Purposes and legal bases of processing
- Contact enquiries (contact form, email, phone): Art 6(1)(b) and (f) GDPR — to handle your enquiry, or on the basis of our legitimate interest in responding to it.
- Course and exam bookings: Art 6(1)(b) GDPR — to perform or enter into the contract. When you register, we ask for your gender in addition to your name, contact details and address (for a company registration, for each participant). We need this information to register you for exams, because the examination bodies (ÖSD, ÖIF) require it. The options follow the official Austrian form; you can always choose “Not applicable: not specified”.
- Customer account (optional): Art 6(1)(b) GDPR — sign-in with a link sent to your email address or, if you set one up, with a passkey (e.g. Face ID, Touch ID, Windows Hello). With a passkey, the private key and any biometric check stay on your device; we only store the public key, a technical identifier and the device name you chose. You can remove passkeys in your account at any time.
- Invoicing and bookkeeping: Art 6(1)(c) GDPR together with the statutory 7-year retention requirement under §132 BAO (Austrian Federal Fiscal Code).
- Newsletter: only with your explicit consent, Art 6(1)(a) GDPR together with §174 TKG 2021 (Austrian Telecommunications Act). We currently do not send a newsletter.
- Operation and security of the website: Art 6(1)(f) GDPR — see the sections “Hosting of the website and server logs”, “Form protection” and “Security log and abuse prevention”.
- Anonymous visitor statistics by country: Art 6(1)(f) GDPR — see the section “Visitor statistics by country (anonymous)”.
We need the details marked as required in our forms to handle your enquiry or registration or to conclude the contract; without them this is not possible. There is no statutory obligation to provide this data to us. No automated decision-making, including profiling, within the meaning of Art 22 GDPR takes place.
Recipients of data
We only share data where necessary to perform a contract or operate this website, and only with processors under a data processing agreement pursuant to Art 28 GDPR:
- Hetzner Online GmbH, Germany — operation of the server, database and backups of this website and of our mailboxes.
- Brevo (Sendinblue SAS), France — sending our emails, e.g. registration confirmations, invoices and sign-in links.
- Cloudflare, Inc., USA — protecting our forms against automated submissions (Cloudflare Turnstile, see below).
Hosting of the website and server logs
When you visit this website, your browser necessarily transmits data to our server, in particular your IP address, the date and time, the address requested, the browser identifier (user agent) and the previously visited page (referrer). Without this data the page cannot be delivered. The web server writes this information to log files (server logs), which we only analyse when there is a specific reason — to troubleshoot errors or to fend off attacks. The log files are limited in size and are continuously overwritten automatically. Server and database run on servers of Hetzner Online GmbH in data centres in Germany. The legal basis is our legitimate interest in a secure and functioning website (Art 6(1)(f) GDPR).
Form protection (Cloudflare Turnstile)
We protect our forms (registration, contact, company registration and enquiries) against spam and automated submissions with Cloudflare Turnstile. Cloudflare processes technical data of your request — in particular your IP address and browser and device information — to determine whether the submission comes from a human. The Cloudflare script is only loaded on pages or in dialogs containing such a form. No advertising or tracking cookies are set. The legal basis is our legitimate interest in protecting the website and our customers against abuse (Art 6(1)(f) GDPR).
Security log and abuse prevention
For forms, bookings and sign-in to the administration area, we count requests per IP address (for sign-in to the administration area, additionally per email address used). If too many attempts are made in a short time, we block the address concerned for a limited period (rate limiting). For this counting we store the IP address or the email address used for sign-in, together with the count and time; we delete this data automatically 30 days after the last request. An active block remains in place until it expires.
In addition, we log security-relevant events — such as a triggered block, a failed sign-in attempt in the administration area, an automatically filled, invisible form field (a “honeypot”), a failed automated bot check, or access to known vulnerability paths (e.g. WordPress or .env files, which do not exist on our site). We store the IP address (for IPv6 only the leading network part), the time, the type of event, the affected form or the type of path accessed, and — for a failed sign-in attempt in the administration area — a shortened, redacted email address (e.g. “iv***@gmail.com”); in this log we never store the full email address.
We derive the country of origin from the IP address. For this we use a country database stored locally on our own server; your IP address is never transmitted to an external provider for this — the lookup runs exclusively on our own server.
The purpose of this logging is to protect our website and our customers against abuse (spam, automated sign-in attempts, security scans). The legal basis is our legitimate interest in the security and integrity of our website, Art 6(1)(f) GDPR. We automatically delete the events after 30 days. An active block itself remains in place, independently of this, until it expires on its own.
You have a right to object to this processing under Art 21 GDPR (see the “Your rights” section above).
Country-of-origin lookup: IP geolocation by DB-IP (License: CC BY 4.0).
Visitor statistics by country (anonymous)
To know from which countries our website is visited, we count visits to the public pages by country of origin. Only pages actually visited are counted — not the administration area, no images, scripts or other files, and no pages preloaded in the background. We filter out obviously automated requests (bots, search engines) based on the browser identifier; the browser identifier is only read for this purpose and is not stored.
Your IP address is only held briefly in the working memory of our web server (at most about 30 seconds until the next batched hand-over; during that time only so that too many requests from the same address are not counted). Only a shortened address (for IPv4 without the last block, for IPv6 only the first three blocks) is then passed to our own database on the same server at Hetzner. There it is used solely to determine the country via the locally stored country database (DB-IP, see above) and is discarded immediately afterwards — neither the full nor the shortened address is stored, logged or passed on to third parties. If your browser sends a “Do Not Track” or “Global Privacy Control” signal, we do not count your visits at all.
Only anonymous totals are stored: per day and country the number of page views (kept for 13 months, so that a month can be compared with the same month of the previous year) and per hour and country the number of page views (kept for 48 hours, for the view of the last 24 hours). For these statistics we set no cookies, store nothing in your browser, assign no visitor ID, create no device “fingerprint” and do not recognise you on a later visit. No external providers are involved.
The purpose is an overview of the website's reach and of where its visitors come from, as well as a general security overview. The legal basis is our legitimate interest in anonymous audience measurement (Art 6(1)(f) GDPR); the IP address is processed for only a few seconds and immediately reduced to the country. You have the right to object to this processing under Art 21 GDPR (see “Your rights”). Because we do not recognise you and no data relating to you exists after a few seconds, there is as a rule no longer any data whose processing we could stop in response to an objection.
Transfers to third countries
Hetzner (Germany) and Brevo (France) process data within the EU. Cloudflare, Inc. is based in the USA; the transfer takes place on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework and, additionally, the EU Standard Contractual Clauses.
Storage periods
We delete enquiry data once it is no longer needed to handle your request. Invoicing and bookkeeping records are retained for 7 years pursuant to §132 BAO. Security-relevant events and the abuse-prevention counters (see the “Security log and abuse prevention” section above) are automatically deleted after 30 days. The anonymous totals of the visitor statistics are kept for 13 months (daily values) or 48 hours (hourly values); no IP address is stored for them. We store the data of your customer account until you request its erasure (see the “Erasure and statutory retention” section).
Your rights
Under the GDPR you have the following rights:
- Access to your stored data
- Rectification of inaccurate data
- Erasure of your data
- Restriction of processing
- Data portability
- Objection to processing
- Withdrawal of consent already given, with effect for the future
To exercise these rights, contact us at info@sprachzentrum-dialog.at.
Erasure and statutory retention (Art 17(3)(b) GDPR)
This section is a draft based on the researched legal framework and on how erasure is actually implemented; it has not yet been reviewed by a lawyer or tax advisor. That review is still pending.
Under Art 17 GDPR you generally have the right to request the erasure of your personal data. That right does not, however, extend to data we are required to retain in order to comply with a legal obligation (Art 17(3)(b) GDPR).
As an Austrian business we are legally required to retain invoices and bookkeeping records for seven years (§132 BAO, the Austrian Federal Fiscal Code; §11 UStG for the mandatory content of an invoice; the retention duties of the Austrian Commercial Code, UGB). Invoice data — including the name and address shown on the invoice, which are a legally required part of it — can therefore only be deleted once that retention period has expired.
If you request the erasure of your data, we proceed as follows:
- We anonymise your “live” personal data — name, contact details and address in your customer record, participant details, free-text notes, and documents you uploaded — and we block your account access, so that no further sign-in is possible.
- The invoice records covered by the statutory retention duty (the issued invoices and the archived invoice PDFs) are kept unchanged until the seven-year retention period expires. During that time we process this data solely to meet our statutory retention and evidentiary obligations, and for no other purpose.
- Once the statutory period has expired, those records are deleted or anonymised as well.
Technically, erasure is therefore implemented as anonymisation: your personal data is neutralised, while the accounting records required by law remain intact. The name and address frozen onto an invoice that has already been issued are legally mandated invoice content, not active account data.
How to exercise your right to erasure: if you have a customer account, you can submit the request yourself at any time under My Account → Privacy. Alternatively, an informal message to the controller (see the “Controller” section above) is sufficient — info@sprachzentrum-dialog.at. For security reasons the anonymisation is not triggered automatically: we review your request, then carry it out, and inform you of the outcome.
The controller for this processing is Sprachzentrum Dialog e.U.; addresses and contact details as above. VAT ID (ATU): to be added. There is currently no separate data protection contact address — please use the contact details given above.
Right to lodge a complaint
You have the right to lodge a complaint with the Austrian data protection authority:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40–42, 1030 Vienna, Austria
www.dsb.gv.at
Cookies
This website only uses cookies and comparable browser storage (localStorage, sessionStorage) that are strictly necessary to provide a service you have explicitly requested (§165(3) TKG 2021, Austrian Telecommunications Act). No consent is required for this. We do not use tracking, analytics or advertising cookies; the anonymous visitor statistics (see above) work without cookies and without storing anything in your browser.
| Name | Purpose | Duration | When |
|---|---|---|---|
sb-…-auth-token (may be split into parts) | Sign-in: keeps your session in the customer account or the administration area | until you sign out, at most 400 days; without “Stay signed in” until you close the browser | only after signing in |
sb-…-auth-token-code-verifier | Security value that binds the sign-in to your browser | until the sign-in is completed | during a sign-in |
konto-remember | remembers that you did not choose “Stay signed in” | until you close the browser | only with that choice |
__Host-dialog-geraet | marks a trusted device of our staff (protection against lock-out) | 400 days or until revoked | staff in the administration area only |
dg_kunden_anonym | view setting of the customer list in the administration area | 1 year | staff in the administration area only |
dg-cookie-notice-dismissed (localStorage) | remembers that you closed this cookie notice | until you clear the site data in your browser | after clicking “OK” |
dialog.kontakt.entwurf (sessionStorage) | draft of your contact message, so it is not lost if an error occurs | at most 30 minutes; deleted after successful sending or when you close the tab | when submitting the contact form |
On pages with a form, Cloudflare Turnstile additionally loads a script from Cloudflare (see the “Form protection” section). Fonts are self-hosted — there is no Google Fonts or other external font CDN embedded, so loading this page does not transmit your IP address to such providers.
If you add this website to your smartphone or computer as a web app (“Add to Home Screen”), your device only stores a shortcut with the website's name and icon. We receive no additional data as a result; no further cookies are set and no content is stored for offline use.
Last updated: 27 September 2026