Privacy Policy

Data Protection Information

1. Controller (Data Protection Officer)

Samuel Ziegler, BSc
Email: office@vetosec.at
Website: https://vetosec.at
Address: Steinhofstraße 16, 2560 Berndorf, Austria

2. Data We Collect

We collect the following types of personal data:

  • Contact Information: Name, email address, company name, phone number, collected when you submit contact forms or inquire about our services
  • Technical Data: IP address, browser type, operating system, access times, pages visited, referrer information, collected via server logs
  • Cookie Data: For analytics and website functionality (only with your explicit consent)
  • Form Submission Data: Information you voluntarily provide in contact forms or service requests

3. Purpose of Data Processing

We process your personal data for the following purposes:

  • Responding to your inquiries and service requests
  • Providing cybersecurity consulting services and support
  • Improving our website functionality and user experience
  • Website analytics and performance optimization (with your consent)
  • Compliance with legal and regulatory obligations (Austrian and EU law)
  • Legitimate business interests in understanding user behavior and service effectiveness

4. Legal Basis for Data Processing

We process your personal data based on the following legal grounds under GDPR:

  • Article 6(1)(a) GDPR: Your explicit consent (e.g., Google Analytics, marketing communications)
  • Article 6(1)(b) GDPR: Contract performance (service delivery, consulting)
  • Article 6(1)(c) GDPR: Legal obligations (tax law, Austrian Corporate Code)
  • Article 6(1)(f) GDPR: Legitimate interests (security, website optimization, fraud prevention)

5. Data Retention Periods

We retain your personal data only as long as necessary for the stated purpose:

  • Contact Form Submissions: Retained for 3 years or until legal obligations are fulfilled
  • Server Logs: Retained for 30 days (IP addresses, access logs)
  • Analytics Data: Retained according to Google Analytics retention settings (26 months by default)
  • Customer Service Data: Retained for 7 years (Austrian tax and business law requirements)

You may request deletion of your data at any time, subject to legal and contractual obligations.

6. Cookies and Web Analytics

Cloudflare Turnstile: The contact form is protected against automated submissions by Cloudflare Turnstile, operated by Cloudflare, Inc. Turnstile examines technical characteristics of the request in order to tell humans apart from programs. Your IP address and technical details of your browser are transmitted to Cloudflare in the process. Turnstile sets no advertising cookies and builds no profile across websites. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in protecting the form from abuse.

Google Tag Manager: We use Google Tag Manager (container GTM-TXLNB9NS), operated by Google Ireland Limited. The tag manager governs the services listed below and decides which of them is loaded. The tag manager itself stores no cookies and collects no personal data for analytics or advertising purposes. Loading the script does transmit your IP address to Google for technical reasons.

Google Consent Mode v2 (advanced mode): Before you make a choice, every consent signal for analytics and advertising is set to denied. In that state the Google services set no cookies, store nothing on your device and process no advertising identifiers. The Google tags are, however, already loaded and in that state transmit cookieless signals to Google. What is transmitted includes your IP address, the time of the visit, the page called up, the referrer, general device and browser details, and the fact that no consent is present. These signals contain no identifier by which you could be recognised or followed across websites. Google evaluates them only in aggregate, to build statistical models of unmeasured visits. In addition, ads_data_redaction is active for as long as there is no marketing consent, which removes advertising identifiers such as the click ID (gclid) from the signals. Only once you agree in the cookie banner is the signal set to granted, cookies are set and the services run in full. You can withdraw your choice at any time in the banner.

Legal bases for the Google services: For the cookieless signals sent before your decision we rely on Article 6(1)(f) GDPR. Our legitimate interest lies in measuring reach statistically and in judging whether our advertising works. Set against this, there is no access to your device and no cross site recognition. You may object to this processing at any time (Article 21 GDPR), for example by a message to office@vetosec.at. For the setting of cookies and the processing of advertising identifiers we rely on Article 6(1)(a) GDPR, that is on your consent. That processing does not take place without your agreement.

Google Analytics: We use Google Analytics 4 to analyze website usage. Cookies and any recognition of you are used only with your explicit consent via our cookie banner (analytics category). Without your consent, only cookieless signals are transmitted, as described under consent mode, and they are evaluated in aggregate only. Google Analytics may transfer data to the United States under the EU-US Data Privacy Framework.

Google Ads: We use Google Ads to measure whether a visit originated from an advert and whether it led to an enquiry (conversion measurement). Advertising identifiers are processed only with your explicit consent via our cookie banner (marketing category). Without your consent the signals ad_storage, ad_user_data and ad_personalization remain denied, no advertising identifiers are stored, and the click ID is removed from the cookieless signals. In that case Google estimates conversions in aggregate, by modelling. No attribution to you personally takes place. The controller is Google Ireland Limited.

  • Tracking ID (if enabled): Google Analytics
  • Data Controller: Google Ireland Limited
  • Processing Purpose: Website analytics and user behavior analysis
  • Cookies Set: _ga, _ga_[measurement-id], _gid
  • Retention: 26 months (configurable)
  • Manage your Google data

Images and stock photos: We use stock photos from Unsplash. All images are stored on our own servers and delivered from there. Loading our website establishes no connection to Unsplash or any other image service. No data is transmitted to third parties in this process. The credits are listed in our imprint.

External content (Cal.com): The Cal.com booking calendar (cal.eu) is embedded on the contact page and sets its own cookies once loaded. It is loaded only with your explicit consent, either through the external content category in the cookie banner or through the button shown at the calendar itself. Without consent the calendar stays closed and no connection to Cal.com is made. The legal basis is Article 6(1)(a) GDPR.

Essential Cookies: We may set essential cookies for website functionality without consent (e.g., CSRF tokens, session identifiers).

You can withdraw your consent at any time by adjusting your cookie preferences via our cookie settings or your browser settings.

7. External Resources and Third-Party Services

Our website uses the following third-party services, which may process your data:

  • Google Analytics: Tracks website usage and visitor behavior (with consent)
    Google Analytics Privacy Policy
  • Cal.com (cal.eu): Embedded appointment-booking calendar, loaded only after your explicit consent. When the calendar is opened, Cal.com may set cookies and process connection data (IP address, browser type, interactions with the booking widget) to operate the booking flow.
    • Data Controller: Cal.com, Inc. (United States)
    • Servers used by the embed: cal.eu (European Union)
    • Processing Purpose: scheduling and booking of online meetings
    • Cookies set by Cal.com when the booking widget is loaded
    • Legal basis: Art. 6(1)(a) GDPR (consent)
    • Cal.com Privacy Policy
  • Email Service: Contact form submissions may be processed via secure email (office@vetosec.at)

8. Your Rights Under GDPR

You have the following rights regarding your personal data under GDPR and Austrian Data Protection Law:

  • Right of Access (Art. 15 GDPR): Obtain confirmation of whether your data is processed and receive a copy
  • Right to Rectification (Art. 16 GDPR): Correct inaccurate or incomplete personal data
  • Right to Erasure/Right to be Forgotten (Art. 17 GDPR): Request deletion of your data (subject to legal obligations)
  • Right to Restrict Processing (Art. 18 GDPR): Limit how we use your data
  • Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format
  • Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests or direct marketing
  • Right to Lodge a Complaint: File a complaint with the Austrian Data Protection Authority (Datenschutzbehörde)
  • Right to Withdraw Consent: Withdraw consent at any time (without affecting the lawfulness of prior processing)

9. Data Security and Protection Measures

We implement comprehensive technical and organizational security measures:

  • All data transmission encrypted using TLS 1.2+ (HTTPS)
  • Secure server infrastructure with access controls
  • Regular security updates and patches
  • Limited access to personal data (need-to-know basis)
  • Monitoring for unauthorized access attempts
  • Secure disposal of data when no longer needed

10. Automated Decision-Making and Profiling

We do not use your personal data for automated decision-making or automated profiling that produces legal or similarly significant effects.

11. Data Transfers and International Transfers

Personal data may be transferred to the United States for Google Analytics processing. These transfers are safeguarded under the EU-US Data Privacy Framework and Standard Contractual Clauses. You have the right to obtain information about safeguards applied to such transfers. Web fonts are served locally and do not result in international transfers.

12. Changes to This Privacy Policy

We may update this Privacy Policy to reflect legal changes, new technologies, or improvements to our services. We will notify you of material changes via email or a prominent notice on our website.

13. Contact and Data Subject Rights Requests

To exercise any of your rights or for privacy-related inquiries, please contact us:

Samuel Ziegler, BSc
Email: office@vetosec.at
Website: https://vetosec.at

Austrian Data Protection Authority (Datenschutzbehörde):
If you wish to lodge a complaint: www.dsb.gv.at

Last updated: May 2026

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.