Privacy Notice

Last updated: 28 August 2026

Good to have you here — and first things first: your visit stays private. This website works without cookie banners and without third-party services. Audience measurement runs anonymously on our own server and works without cookies and without recognising anyone (section 6); what else arises when you open a page is the technical access data recorded by our server (section 2). Fonts and icons are hosted locally on our own server; simply reading these pages sends no data to anyone else.

1. Controller

The controller responsible for data processing on this website is:

FINK Brot Pixel GmbH
Fasangartengasse 1
1130 Vienna, Austria
Email: webform@finkbrot.at

Further details can be found in the legal notice.

2. Server log files

When you visit this website, our server automatically records technical access data:

  • IP address
  • date and time of access
  • requested page or file (URL)
  • previously visited page (referrer)
  • browser type, operating system and device information (user agent)

We need this data to keep the site running, fend off attacks and diagnose technical errors. It is not evaluated on a personal level and not combined with other sources. Log files are rotated daily and deleted after seven days at the latest.

This access data arises with every page request — including when the tools and self-tests on this website do all their calculating on your own device (section 6).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation).

3. Cookies

Simply visiting this website sets no cookies. Only when you use the contact form is one technically necessary session cookie set (protection against form abuse, CSRF protection). It contains no analytics or advertising data and is deleted when you close your browser.

We do not use tracking or analytics cookies: the audience measurement described in section 6 works without cookies and stores nothing on your device. That is why this website does not need a cookie banner.

Legal basis: sec. 165(3) of the Austrian Telecommunications Act (TKG 2021) in conjunction with Art. 6(1)(f) GDPR.

4. Contact form and email

If you contact us via the contact form or by email, we process the details you provide — name, email address, optionally a phone number and the content of your message — solely to handle your enquiry. Your message is delivered as an email over an encrypted connection (TLS) via our own mail server to our mailbox; no third-party form services are involved.

We protect the form against automated abuse without tracking: with an invisible control field, a timing check and a short-term submission limit in which technical identifiers are processed only in a shortened form that we do not attribute to any person.

We keep enquiries for as long as processing them requires or statutory retention periods apply.

Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract) and Art. 6(1)(f) GDPR (answering general enquiries, abuse protection).

5. Hosting

This website runs on the Kirby CMS; the content is stored as files on the server and there is no visitor database. Hosting is provided by rackSPEED GmbH, a hosting provider with servers located in Germany. The host processes the data arising here solely on our instructions, as our processor; a data processing agreement pursuant to Art. 28 GDPR is in place. All processing connected with operating this website takes place within the EU; no data is transferred to third countries.

Legal basis: Art. 6(1)(f) in conjunction with Art. 28 GDPR.

6. Anonymous audience measurement, search and tools

We want to know which content gets read — not who reads it. For that we use Matomo, analytics software that we host on our own server. There is no analytics provider in the background: the data never leaves our infrastructure.

The measurement is deliberately configured so that it works without recognising anyone:

  • No cookies: nothing is stored on or read from your device.
  • Truncated IP address: your IP is shortened before storage and can no longer be traced to a connection by us.
  • No profiles: within one visit of at most 30 minutes we group the pages opened. The link is a short value derived from the truncated IP address and browser type; it changes daily and cannot be reversed. We do not link anything across days and use no user IDs.
  • No device probing: browser feature detection is switched off, removing the usual building block for a digital fingerprint.
  • Do Not Track is respected: if you have enabled that signal in your browser, you are not counted.

What remains is a statistic of how often and how long pages were opened and which pages followed each other within a visit — with no reference to a person. We delete the raw data automatically after 90 days; after that only aggregated totals without any personal reference remain.

No cookie banner is required for this, because nothing is stored on or read from your device — which is precisely what sec. 165(3) TKG 2021 addresses. The legal basis for the anonymous evaluation is our legitimate interest in a clear and useful website (Art. 6(1)(f) GDPR).

This website also has interactive features that process data of their own:

  • Search: your search term is transmitted to our server and evaluated there; suggestions appear from two characters onwards. Frequently requested queries are kept briefly in a server-side cache, and a request limit protects the feature against automated overload. We keep no search history; the query may appear as part of the requested address in the log files described in section 2 and is deleted along with them.
  • Citability check: The domain you enter is transmitted to our server, which fetches the website in question and tests it against fixed criteria. We do not store the domain or the result permanently; a ten-minute cache only prevents duplicate fetches, and a request limit protects against overload. Its shortened technical identifiers are not attributed to any person by us. The domain you check can appear as part of the requested address in the log files described in section 2 and is deleted along with them. Nothing is stored or read on your device.
  • Hands-on AI tools: the prompt workshop and the data traffic light process your input in your browser only. Nothing is transmitted and nothing is stored.
  • Display (light/dark): if you switch the site’s display theme, your browser remembers that choice locally on your device. This storage happens only after your click and is strictly necessary for the display you asked for (sec. 165 para. 3 TKG 2021). You can remove it at any time via your browser's site data. Nothing is transmitted to us.
  • Legal basis: for the search and the citability check it is our legitimate interest in functional, abuse-protected tools (Art. 6(1)(f) GDPR).
  • Self-tests: our questionnaires — such as “Does the law apply to me?” — run entirely in your browser. Your answers stay on your device; we do not transmit, store or collect them.
  • Colour, contrast and text tools: the contrast calculator, the colour matrix check and the metadata workshop process your colour values and text entries in the browser only. Nothing is uploaded and nothing is stored.
  • Image tool: the image diet calculator works without any upload — your file never leaves your device.

What we deliberately do not do: we assign no user IDs, read no browser or device characteristics, do not link your visits across sessions and build no profiles. No automated decision-making takes place.

Because we do not recognise you, there is as a rule nothing about your visit that we could attribute to you — apart from the log files described in section 2, for as long as they have not yet been deleted. If you would like to object to the processing (Art. 21 GDPR) or want to know what is stored in your case, simply write to webform@finkbrot.at.

Beyond that, this website uses no social media plugins, no external font or script servers, no embedded maps or videos, no chat window and no other third-party content. Where we link to external services (such as our LinkedIn profile), you leave our website with that click — from there, the privacy notices of the respective provider apply.

7. Sharing of data

We only share your data if you have consented (Art. 6(1)(a) GDPR; you can revoke consent at any time with effect for the future), if it is necessary to perform a contract (point b), if we are legally obliged to (point c), or to protect legitimate interests (point f). We never sell data or share it for advertising purposes.

8. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Simply write to webform@finkbrot.at.

Right to object (Art. 21 GDPR): You may object at any time to processing based on legitimate interests (Art. 6(1)(f) GDPR), on grounds relating to your particular situation. An informal message to webform@finkbrot.at is sufficient.

You may also lodge a complaint with a supervisory authority — in Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at (opens in a new tab) (Art. 77 GDPR).

9. Changes to this notice

We update this privacy notice when technical processes or legal requirements change. The version published here applies.