Privacy policy
Information pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR) on the processing of personal data in connection with visiting and using this website.
1. Controller
LEMCON.TECH · Ingenieurbüro Lemmerer e.U.Ing. Dipl.-Wirtsch.-Ing. (FH)
Jörg Lemmerer
B.A., EUR ING
Kreuzplatz 7, 4820 Bad Ischl
Austria
Email: office@lemcon.tech
Phone: +43 677 6343 7472
2. General principles
We process personal data exclusively in accordance with the GDPR, the Austrian Data Protection Act (DSG) and other applicable data protection provisions. Personal data means any information relating to an identified or identifiable natural person.
As a general rule, you can visit this website without providing any personal data. Where personal data is processed, this is done on the basis of one of the legal bases set out below.
3. Hosting and server log files
This website is hosted by World4You Internet Services AG, Hafenstraße 35, 4020 Linz, Austria. The hosting provider automatically collects data about every access to the server (so-called server log files):
- IP address of the requesting computer
- Date and time of the request
- URL accessed and amount of data transferred
- Referrer URL (page of origin)
- User agent (browser and operating system identifier)
Purpose: Ensuring a
trouble-free connection setup; detecting and fending off attempted
attacks.
Legal basis: Art. 6(1)(f)
GDPR (legitimate interest in secure operation).
Retention period: 14 days,
after which the data is deleted automatically.
4. Contact form
If you send us a message via the contact form on this website, we process the information you submit (name, email, phone, company, topic, message) exclusively for the purpose of handling your enquiry.
Legal basis: Art. 6(1)(b)
GDPR (pre-contractual measures) or Art. 6(1)(a) GDPR (consent given by
submitting the form together with the GDPR notice).
Retention period: until your
enquiry has been dealt with conclusively; in the event of follow-up
contact or the initiation of a contract, beyond that in accordance with
the statutory retention periods (§132 of the Austrian Federal Fiscal
Code (BAO): 7 years).
4.1 Spam protection for the contact form (Cloudflare Turnstile)
To protect the contact form against automated submissions, we use Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Purpose of processing: Turnstile checks whether a submission of the contact form comes from a human or from an automated program. Without this check, the form could be misused for mass submissions and would be practically unusable as a means of contact.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in preventing misuse of the contact form and in ensuring that we can be reached via this form.
Data processed: When you open the contact page, the Turnstile widget is loaded from a Cloudflare server. In the process, your IP address and information about your browser and device are transmitted to Cloudflare and processed there, in particular browser type and version, operating system, language setting, screen properties, the address accessed and information about your behaviour on the page, such as mouse and keyboard input. From this information, Cloudflare forms an assessment and issues a single-use verification token. When the form is submitted, we verify this token server-side with Cloudflare. In doing so, we transmit exclusively the token itself and expressly not your IP address.
Cookies: In the configuration
we use, Turnstile does not set any cookies for advertising or tracking
purposes. The check is carried out without recognising you across
websites.
Transfer to third countries: The
processing also takes place in the USA. It is based on the standard
data protection clauses adopted by the European Commission, which we
have agreed with Cloudflare. In addition, Cloudflare has committed
itself to its own technical and organisational safeguards.
Retention period: The retention
period at Cloudflare is determined by Cloudflare as the controller of
its own security infrastructure. We ourselves do not store any
verification token or any of the information collected by Cloudflare.
Further information:
cloudflare.com/privacypolicy
4.2 Limiting submissions (hashed IP address)
To prevent the contact form from being misused for mass submissions, we limit the number of messages delivered from any one internet connection within 24 hours to three.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in preventing misuse and in the proper operation of the contact form.
Data processed: We do not store your IP address. On our server, a non-reversible check value is calculated from the IP address (HMAC-SHA256 with a secret key that exists only on the server). Only this check value and the time of delivery are stored. Without the secret key, it is not possible to infer the IP address; matching against other data sets is therefore ruled out.
Retention period: Entries older
than 24 hours are deleted automatically on the next submission.
Logging: Rejected and
delivered submissions are recorded in a log file on the server in
order to detect misuse and to trace technical faults. There, too, the
IP address is not recorded in plain text, but only as a truncated
check value. In addition, the time, the reason for any rejection and
the selected subject of the enquiry are logged. The log file cannot be
accessed via the internet; it is protected by the server configuration
and by file permissions. It is overwritten once it reaches one
megabyte.
Recipients: This data does not
leave our server and is not disclosed to third parties.
4.3 Delivery of your message (sending by email)
Your form message is delivered to our mailbox as an email. It is submitted via an authenticated, STARTTLS-encrypted connection to the mailbox service of Google Ireland Limited, which we use for our business email. The email contains the information you provided as well as the time and the hashed check value from section 4.2, but not your IP address.
Legal basis: Art. 6(1)(b)
GDPR (pre-contractual measures) or Art. 6(1)(a) GDPR (consent); the
use of an email service is a necessary consequence of your choice to
contact us via the form.
Processing on our behalf: A data
processing agreement pursuant to Art. 28 GDPR is in place with Google.
It forms part of the Google Workspace contract as the
Cloud Data Processing Addendum.
Transfer to third countries:
Processing in the United States cannot be ruled out in this context.
For this, Google relies on the EU-U.S. Data Privacy Framework
(adequacy decision of the European Commission pursuant to Art. 45
GDPR) and additionally on the standard contractual clauses pursuant to
Art. 46(2)(c) GDPR.
Retention period: as described
in section 4; the email remains in the mailbox until your enquiry has
been concluded and the statutory retention periods have expired.
4.4 Are you obliged to provide this data?
No. Providing the data is neither a statutory nor a contractual requirement. However, in order to be able to respond to an enquiry at all, we need your name, an email address, a description of your request and your consent to the processing; without this information, the form will not accept the message. Company and phone number are optional. Alternatively, you can reach us informally by email or phone at any time.
5. Newsletter (LEMCON.TECH Monatsbrief)
You can subscribe to the “LEMCON.TECH Monatsbrief” (monthly letter). It is published once a month and summarises what has appeared on the blog of this website. You can subscribe via the forms on this website and via the subscription page at news.lemcon.tech. Both lead to the same subscriber management system, which we operate ourselves at news.lemcon.tech: your entries are transmitted directly there, even if you fill in the form on this website.
Subscription via double opt-in: After you subscribe, we send you an email with a confirmation link. The subscription only takes effect once you open this link. If you do not confirm, we will not send you the monthly letter.
Data processed: Your email address and, if you provide it, your name. As proof of consent, we additionally store the time of confirmation and the IP address from which the confirmation was made. This record is necessary in order to be able to demonstrate consent in the event of a dispute (§ 174 of the Austrian Telecommunications Act 2021 (TKG 2021), Art. 7(1) GDPR).
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 174 TKG 2021. Consent is voluntary and can be withdrawn at any time.
Where the data is stored: The subscriber list is stored on a server that we operate ourselves. It is not outsourced to a newsletter service provider. The server is located in the data centre of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, which provides us exclusively with the operation of the machine (processing on our behalf pursuant to Art. 28 GDPR). This server is not the same one on which this website is hosted (see section 3).
Processor for sending: To deliver the emails, we use the email delivery service Mailjet GmbH, Alt-Moabit 2, 10557 Berlin, Germany (a company of the Sinch group). Mailjet processes the data exclusively for the purpose of delivery and in accordance with our instructions. According to the provider, processing takes place in data centres within the European Union (Frankfurt am Main and Saint-Ghislain, Belgium). A data processing agreement pursuant to Art. 28 GDPR is in place with Mailjet GmbH. Where data is transferred to third countries within the group of companies or by sub-processors, such transfer is based on the standard contractual clauses of the European Commission (Commission Implementing Decision (EU) 2021/914). Mailjet only ever receives the individual message being delivered, not the subscriber list. This also applies to the confirmation email for the subscription.
No performance tracking: We do not measure whether or when you open an email, and we do not count clicks. The links in the monthly letter lead unaltered to where they purport to lead; they are not routed via an intermediate server. No invisible tracking pixel is included. Tracking is both switched off in our mailing software and suppressed vis-à-vis the delivery service for every single message.
Unsubscribing: Every monthly
letter contains an unsubscribe link at the end, which takes effect
immediately and requires no reason to be given. You can also contact
office@lemcon.tech
at any time.
Retention period: Your email
address is stored for the duration of the subscription and removed
from the mailing list when you unsubscribe. We then retain the proof
of consent (time and IP address of the confirmation) for a further
three years and delete it
afterwards. This period corresponds to the general limitation period
under § 1489 of the Austrian Civil Code (ABGB). Its sole purpose is to
be able to demonstrate the lawfulness of the mailing in the event of a
dispute; the proof is not used for any other purpose.
6. Online appointment booking
For the online booking of first calls, we refer, on the contact page, to a booking calendar provided by Google Ireland Limited (Google Calendar appointment booking). The calendar is not embedded in the page: it only opens in a new window when you click the button for choosing an available appointment slot. As long as you do not click, no data is transmitted to Google. Once you click, you leave this website; data is transmitted to Google servers (predominantly within the EEA, in certain cases to the USA), and Google’s privacy policy applies.
Legal basis: Art. 6(1)(b)
GDPR (pre-contractual measures) and consent pursuant to Art. 6(1)(a)
GDPR, insofar as you actively use the booking calendar.
Further information:
policies.google.com/privacy
7. Web analytics (Plausible Analytics)
This website uses Plausible Analytics, operated by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible is a privacy-friendly web analytics solution that works without cookies and without personal tracking mechanisms. No unique identifiers are generated, IP addresses are not stored permanently and no data is passed on to third parties. All data is processed exclusively within the EU.
The following is recorded in aggregated form: pages visited, country of origin (determined from the IP address, which is not stored), referrer, browser and operating system used, and device type.
In addition, the following interaction events are counted anonymously and in aggregated form in order to assess the usefulness of the content:
- Outbound clicks: Clicks on links that lead to external websites (e.g. to authority websites or source references). The target URL is recorded, but not which person clicked.
- File downloads: Clicks on downloadable files (e.g. PDF attachments in blog posts). The file URL is recorded.
- Form submissions: The successful submission of a form on this website (e.g. the contact form). Only the fact that a form was submitted is recorded, not the content of the input fields.
Legal basis: Art. 6(1)(f)
GDPR (legitimate interest in measuring reach without
cookies/identifiers).
Further information:
plausible.io/data-policy
8. Map display (OpenStreetMap)
The contact page includes an embedded map provided by the OpenStreetMap Foundation (St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom). When the map is loaded, a connection is established to the OpenStreetMap servers, in the course of which your IP address may be transmitted to OpenStreetMap.
Legal basis: Art. 6(1)(f)
GDPR (legitimate interest in a low-data location display as opposed to
commercial map services).
Further information:
osmfoundation.org/wiki/Privacy_Policy
9. WhatsApp contact link
On the contact page, we provide a link to WhatsApp (Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). The link is only loaded when you actively click on it; without a click, no data is transmitted to WhatsApp. As soon as you use the link, Meta’s privacy policy applies.
Further information: whatsapp.com/legal/privacy-policy-eea
10. Fonts
This website uses exclusively locally hosted fonts (Inter, Source Serif Pro). No connection is made to Google Fonts or any other external font services.
11. Editorial area (content manager)
The interface we use to maintain the content of this website is
located at /admin/. It is of no use to visitors, but it
is technically accessible. Anyone who opens this address loads a
software library via a
content delivery network (unpkg.com); the IP address
is transmitted to its operator.
The subsequent login concerns
exclusively us as the operator.
Visitors to this website do not log in anywhere and are not affected
by it. Editorial access takes place via an account with
GitHub, Inc., 88 Colin P. Kelly Jr. Street,
San Francisco, CA 94107, USA. In the process, a short-lived technical
cookie (oauth_state) is set, which serves exclusively to
secure the login process and is deleted again afterwards. GitHub
processes the login data in the United States. Without a login, no
further data is processed.
Legal basis: Art. 6(1)(f)
GDPR. Our legitimate interest lies in being able to maintain the
content of this website without running our own server software.
Retention period: The cookie of
the login process is deleted once that process has been completed.
Beyond that, we do not store anything in this context.
12. Cookies and access to your terminal equipment
This website does not set any cookies when you visit it. Nor does it store anything in your browser’s local data storage (Local Storage, Session Storage). A consent banner is therefore not required — there is nothing for which we would need to ask your permission. Tracking or marketing cookies are not set; the reach measurement described in section 7 works without them.
Access to your terminal equipment within the meaning of § 165(3) TKG 2021 therefore does not take place. The sole exception is the technical cookie of the login process in the editorial area described in section 11, which is strictly necessary for the service expressly requested by the person logging in. Services that you only access by clicking — the booking calendar described in section 6 and the WhatsApp link described in section 9 — may set cookies on their own pages; their privacy policies apply there.
13. Your rights
You have the following rights vis-à-vis us with regard to the personal data concerning you:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to data portability (Art. 20 GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal. You can send your requests to office@lemcon.tech .
14. Automated decision-making
Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place. We do not create profiles, we do not evaluate anyone by automated means, and we do not take decisions about persons that would be made solely by a machine.
For the sake of completeness: the contact form automatically checks incoming submissions for characteristics of unsolicited bulk mail. The result of this check merely flags a message — it does not decide whether we read it; we read every message that is delivered. If the spam protection rejects a submission, you immediately receive a notice with our phone number, so that this means of contact remains open to you.
15. Complaint to the supervisory authority
You have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde) if you believe that the processing of your personal data infringes the GDPR.
Austrian Data Protection Authority (Datenschutzbehörde Österreich)Barichgasse 40–42
1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Web: dsb.gv.at
Last updated: September 2026