Privacy Policy
Last updated: April 2026
1. Controller
The controller responsible for data processing within the meaning of the GDPR is:
- Company
- Webagentur Hochmeir e.U. (Jonathan Hochmeir)
- Address
- Moorweg 7, 4845 Rutzenmoos, Austria
- hello@webhoch.com
- Phone
- +43 680 2208354
2. General information on processing
We process personal data in accordance with the General Data Protection Regulation (GDPR) and Austrian data protection law. Personal data is any information relating to an identified or identifiable natural person.
3. Processing when visiting this website
3.1 Server log files
When the website is accessed, technically necessary data is processed automatically: IP address, date and time of the request, requested URLs, browser and operating-system information and the host name. This serves website delivery, security, error analysis and abuse detection. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
3.2 Hosting
The website and our services run on external hosting / infrastructure providers that process data on our behalf under data-processing agreements.
4. Contacting us
If you contact us (e.g. by form, email or phone) we process the data you provide — such as name, email, phone number, company details, message content and project information — to handle your request. Legal bases: Art. 6(1)(b) GDPR (pre-contractual measures / performance of a contract) and (f) GDPR (effective communication).
5. Contract handling with clients
To provide our services we process master and contact data, invoicing and payment data, access credentials and project/service data — e.g. for quotations, project execution, billing and legal compliance. Legal basis: Art. 6(1)(b) GDPR.
6. Use of our SaaS products and online services
When using our software-as-a-service products (e.g. Cuckoo) we process registration, login, usage, device, content, support and payment data — to deliver the service, for security, billing, further development and abuse prevention. Legal bases: Art. 6(1)(b), (f) and — where required — (a) GDPR (consent).
7. Payment processing
To process payments, name, billing address, email and transaction data are transmitted to external payment service providers. Legal basis: Art. 6(1)(b) GDPR.
8. Third-party services, APIs and subprocessors
We use third parties (hosting, email, payments, authentication, analytics, AI/LLM, automation, CDN, support). Where personal data is processed on our behalf, this is done under data-processing agreements pursuant to Art. 28 GDPR.
9. Cookies and similar technologies
9.1 Strictly necessary cookies
Required for operation and security of the website. Legal basis: Art. 6(1)(f) GDPR.
9.2 Analytics / marketing cookies
Only with your consent where legally required. Legal basis: Art. 6(1)(a) GDPR.
9.3 Withdrawal
You can withdraw a given consent at any time via the consent tool.
10. Google Ads / conversion tracking
Where used, we process advertising and conversion data within legal limits. Legal bases: Art. 6(1)(a) (consent) or (f) GDPR.
11. Analytics and reach measurement
To improve the website, usage data (page views, interactions, device, time on page) may be analysed. Consent is obtained where legally required.
12. Spam protection / bot detection
To prevent spam and abuse we use behavioural and technical detection. Legal basis: Art. 6(1)(f) GDPR.
13. AI / LLM services
When using AI/LLM features, inputs, prompts and metadata may be transmitted to service providers. We ensure a privacy-appropriate configuration and recommend not entering sensitive data unless explicitly safeguarded.
14. Storage period
We store data only as long as necessary for the respective purposes or as required by statutory retention obligations or legitimate interests. Data is then deleted or anonymised.
15. Recipients / categories of recipients
Recipients may be: staff, hosting providers, payment service providers, communication and support services, analytics and security providers, subprocessors and authorities (where legally obliged).
16. Transfers to third countries
Transfers to third countries take place only on the basis of adequacy decisions, standard contractual clauses or other safeguards permitted under the GDPR.
17. Technical and organisational measures
We take appropriate technical and organisational measures to protect data against loss, unauthorised access and alteration, and update them continuously in line with the state of the art.
18. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of a given consent. To exercise these, simply email hello@webhoch.com.
19. Right to complain
You have the right to lodge a complaint with a data protection supervisory authority if you believe the processing violates the GDPR (in Austria: Austrian Data Protection Authority, dsb.gv.at).
20. No automated decision-making
No automated decision-making within the meaning of Art. 22 GDPR with legal effect or similarly significant impact takes place unless expressly stated otherwise.
21. Changes to this privacy policy
We reserve the right to amend this privacy policy to reflect changed legal or technical circumstances. The version published on this website applies at any given time.