Privacy policy
Controller
OROZ Solutions e.U.
Owner: Valentin Oroz
Illekgasse 7/4
1150 Vienna, Austria
Email: office@oroz-solutions.at
Phone: +43 680 2336129
Website access and server log files
This website is operated using Infomaniak's Web Bundle product. When you access the website, the hosting service processes in particular the IP address of the requesting device, the date and time of access, the requested address, the HTTP status and, where transmitted by the browser, browser information and the previously visited page. These data are technically necessary to deliver the website.
Processing serves to provide the website securely and reliably, diagnose errors and protect it against abusive or harmful access. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and technically functional operation of our website.
The application log used by this project contains only technical information such as the time, a random request ID, route, HTTP status, event category, approximate processing time and release identifier. Names, contact details, messages, full IP addresses and CAPTCHA values are not intended to be included. Because the same request ID is included in the internal contact email, it may in individual cases be associated with an enquiry.
Current details about the access and error logs maintained by Infomaniak, their availability and technical safeguards are available in Infomaniak's web log documentation and data confidentiality policy. Infomaniak updates this information to reflect the current technical and contractual status of its services.
Contact form and email delivery
When you contact us through the form, we process your name, email address and message, as well as your optional phone number and selected project type. These details are stored solely to process and answer your enquiry and clarify related follow-up questions. They are not disclosed to other third parties for their own purposes without your consent. Infomaniak, the processor identified in this policy, is used exclusively for technical transmission and storage.
The legal basis is Article 6(1)(b) GDPR where your enquiry concerns pre-contractual measures or a contractual relationship. Other enquiries are processed under Article 6(1)(f) GDPR on the basis of our legitimate interest in handling business enquiries in an orderly and efficient manner.
Your name, email address and message are required so that we can assign, process and answer your enquiry. Without these details, the form cannot be submitted and the enquiry cannot be processed. The phone number and project type are optional.
The enquiry is sent over an encrypted SMTP connection to our Infomaniak business mailbox. The internal message contains the form details and a randomly generated request ID. A confirmation of receipt is sent to the email address provided. The application does not additionally store the enquiry in a project database or CRM. File uploads are not available.
Enquiries made by direct email or phone are likewise processed for the purpose of handling the respective enquiry on the legal bases stated above.
We use A1 Telekom Austria AG for telephony. Calls generate connection data, in particular telephone numbers and the time and duration of the connection. A1 processes connection data under its own data protection responsibility to provide and bill for the telecommunications service. We do not record calls. Further information is available in the A1 privacy information.
Abuse prevention and rate limiting
To protect the contact form against automated abuse and excessive requests, the server processes the IP address supplied by the hosting proxy and the normalised email address. Pseudonymous check values are generated from this information using a secret key. The raw values are not written to the rate-limit store.
The provisional IP check value is retained for no more than 15 minutes. After a valid enquiry, the IP and email check values are retained in the running application process's memory for no more than 60 minutes. Restarting the process deletes these values. The purpose is to protect the form's availability and security. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is protection against spam, overload and misuse.
Hosting and email by Infomaniak
We use Infomaniak's Web Bundle product for hosting and kSuite for our business mailbox. The provider is Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Geneva, Switzerland. Infomaniak processes the resulting data on our behalf under a data processing agreement pursuant to Article 28 GDPR.
Infomaniak states that it stores and processes data from the services used exclusively in its own data centres in Switzerland. Under the data processing agreement, access is restricted to authorised persons bound to confidentiality, and subprocessors may be used only to the extent necessary to provide the service. Switzerland is a third country outside the EU and EEA for which the European Commission has adopted an adequacy decision under Article 45 GDPR.
Further information is available in Infomaniak's data confidentiality policy and data processing agreement.
Storage period for contact enquiries
Enquiry data is retained only for as long as it is needed to process the enquiry and any related follow-up. Statutory retention obligations and retention needed to establish, exercise or defend legal claims remain unaffected.
Recipients and disclosure
Within OROZ Solutions, access to personal data is limited to persons who need it to process an enquiry or administer the technology. As a processor, Infomaniak receives access to the extent required for hosting, email transmission, storage, backup, maintenance or support. Plausible Insights OÜ receives the data described in the section “Analytics with Plausible” as a processor. A1 Telekom Austria AG is involved as the telecommunications provider when you contact us by phone.
Data is not disclosed for third parties' own advertising purposes. Further disclosure takes place only where required by law, necessary to perform a contract, needed to establish or defend legal claims, or based on your prior valid consent.
Cookies, browser storage and fonts
The current application sets no cookies and does not use localStorage, sessionStorage or IndexedDB to recognise visitors.
Fonts and images are served locally through this website. Loading these resources does not establish an additional connection to a font or image provider.
According to the provider, the Plausible web analytics service used by us likewise sets no cookies and uses neither browser cache nor localStorage to recognise visitors.
The technical review of the current application code and intended production configuration found no additional cookies, storage access, external scripts or network connections not described in this privacy policy.
Analytics with Plausible
We use Plausible Analytics on this website. The provider is Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible acts as a processor under a contract pursuant to Article 28 GDPR.
Web analytics helps us understand use of the website in aggregate and improve its content, navigation and technical quality. Plausible processes page views, the hostname and path of the requested page, referring website, browser, operating system, device type and an approximate location derived from the IP address. Plausible generally discards URL query parameters, except that campaign parameters such as ref or utm parameters may be processed.
In addition, the application code provides only predefined events: clicks on primary calls to action, email and phone links, starting the contact form, its successful submission or a technical error category, selection of a service area, opening a frequently asked question, switching language and opening an external project. Only the respective event name is sent to Plausible. Custom event properties, free text, form content, names, email addresses, phone numbers, CAPTCHA data and raw error messages are not transmitted to Plausible.
Plausible uses no cookies and creates no persistent identifier. The IP address and user agent are technically transmitted when a page is requested and used to create a daily changing identifier. According to Plausible, the raw data is not stored; the secret daily value used for this purpose is replaced and deleted every 24 hours. Recognition across multiple days, websites or devices is therefore not intended. Analytics results are aggregated and are not used for advertising, profiling or the sale of data.
Plausible loads automatically when the technical configuration is complete. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to understand use of the website solely in aggregate and improve its content, navigation and technical quality. No cookies or comparable persistent identifiers are used. If Do Not Track or Global Privacy Control is enabled, the application code does not load the Plausible script and therefore prevents transmission.
In balancing the interests involved, we considered in particular that measurement is performed without cookies, persistent identifiers or cross-site recognition, that only limited usage data is processed and that results are used solely to improve this website. These interests are weighed against visitors' interests and fundamental rights. In view of the data minimisation, aggregated analysis and absence of profiling, we consider our legitimate interests to prevail. Your right to object remains unaffected.
Plausible states that website visitor data is processed exclusively in the European Union. It identifies Hetzner in Germany, Bunny in Slovenia and UpCloud in Finland as subprocessors for visitor data. Under the Starter plan used, aggregated analytics data is retained for up to three years under the current plan terms. If the site or account is deleted earlier, Plausible states that the data is permanently deleted without undue delay.
Further information is available in Plausible's data policy, privacy policy and data processing agreement.
Your rights
Subject to the applicable legal conditions, you have in particular the rights of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
Where processing is based on Article 6(1)(f) GDPR, you may object to it on grounds relating to your particular situation. To exercise your rights, contact office@oroz-solutions.at.
You also have the right to lodge a complaint with a data protection supervisory authority. In Austria, this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, email: dsb@dsb.gv.at, website: www.dsb.gv.at.
Automated decisions and profiling
No solely automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place. Technical abuse checks may temporarily limit the acceptance of further form enquiries, but they do not evaluate personal characteristics or make a decision with legal or similarly significant effects.
Changes to this policy
This privacy policy is updated when the website, services used or legal requirements change. The version published on this page is authoritative.