Privacy Policy
Last updated: 16. Dezember 2025
1. Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection provisions is:
2. General Information on Data Processing
We only process your personal data to the extent necessary to provide a functional website and our content and services (SaaS application).
3. Data Collection and Processing
a) Website Visits (Server Log Files)
When you access our website, the browser on your device automatically sends information to our web server. This information is temporarily stored in a log file:
- IP address of the requesting device
- Date and time of access
- Name and URL of the accessed file
- Browser used and, where applicable, operating system
Art. 6(1)(f) GDPR (Legitimate interest in technical stability and system security).
b) Registration and Use of the SaaS Application
When you register for our service, we process the data you provide (e.g. name, email address, password, billing data) to fulfill the user agreement and provide the service to you.
Art. 6(1)(b) GDPR (Performance of a contract or pre-contractual measures).
c) Contact Requests
When you contact us (e.g. via contact form or email), your information is processed to handle and respond to your inquiry.
Art. 6(1)(b) GDPR (Contract) or Art. 6(1)(f) GDPR (Legitimate interest in responding).
4. Disclosure of Data to Third Parties
We do not transfer your personal data to third parties for purposes other than those listed below. We only share your personal data with third parties where this is permitted by law or where we use service providers (data processors).
We use the following categories of service providers:
- Hosting: Hetzner (Location: Germany)
- Email Delivery: Scaleway (Location: France)
- Data Backup: Scaleway (Location: France)
Konvio exclusively uses service providers based in the EU.
5. Cookies and Web Analytics
We only use technically necessary cookies.
-
Technically necessary cookies:
These are required for the operation of the website (e.g. session cookies for login).
Section 165(3) TKG 2021 (exemption from consent requirement) and Art. 6(1)(f) GDPR.
6. Data Retention
We only store personal data for as long as it is necessary for the purposes for which it is processed, or as long as a statutory retention obligation exists (e.g. 7-year retention requirement for tax-relevant documents in Austria under BAO).
7. Your Rights (Data Subject Rights)
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification or erasure (Art. 16 & 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. In Austria, this is the:
Austrian Data Protection Authority
Barichgasse 40-42, 1030 Wien
https://dsb.gv.at/
8. Data Security
We use the widely adopted SSL (Secure Socket Layer) method in conjunction with the highest level of encryption supported by your browser when you visit our website.
9. Changes to This Privacy Policy
We may update this privacy policy as needed to comply with new laws or regulations.