Skip to content
Wogenfels Consulting

Privacy notice

Controller

The controller for the processing of personal data on this website is Wogenfels Consulting GmbH, Pribelsdorf 87, 9125 Eberndorf, Austria.

Telephone: +43 660 2719741. Email: office@wogenfels.com.

Companies register number: 550483i. Companies register court: Landesgericht Klagenfurt. VAT identification number: ATU76609528.

Managing director: Ing. Dominik Stefan Pototschnig, MSc. Supervisory authority: Bezirkshauptmannschaft Völkermarkt. Chamber membership: Wirtschaftskammer Kärnten.

Please address any data protection questions to office@wogenfels.com or to the postal address given above.

Overview and principles

You can read this website without telling us anything about yourself. You only provide personal data if you use the contact form or book an appointment.

The processing on this website falls into three groups. First, what is needed to operate the site and therefore always runs. Second, what is loaded only when you actively ask for it, such as the appointment calendar. Third, analytics and marketing, which take place only after you have consented.

For the third group the rule is simple: without consent, no request is sent to the provider concerned. These services are not preloaded in the background, and they are not replaced by workarounds such as noscript pixels.

The sections below describe each of these processing activities separately: which data arise, what they are used for, on which legal basis, and who receives them.

Data processed when you open the website

This website consists of static files served by a web server (Nginx) on a rented server. When you open a page, your browser connects to that server and transmits the details needed for the connection, in particular your IP address. This is technically necessary for the page to reach you.

The server is operated at Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, and stands in their data centre in Nuremberg. Hetzner processes the data solely on our behalf. Hosting at Hetzner therefore involves no processing outside the European Union. Besides the operator of the server, the provider of the server administration named in the section “Recipients and processors” has administrative access; that provider is likewise established in the European Union.

For the delivery of pages the web server keeps no access log: logging of ordinary page views is switched off. Only an error log is written, and only when a request actually fails. Such an entry may contain the IP address of the request concerned and serves solely to analyse the fault.

Requests to our interface — that means submitting the contact form, not simply reading a page — produce a log entry with the request method, the path requested, the status code of the response and the processing time. The IP address, query parameters and request content are not logged, which means in particular no form entries. The technical availability check of the server produces no such entry.

For those interface requests we derive a key from the connection in order to limit the number of requests per sender (rate limiting). The derivation uses only a fixed, configured number of trusted proxy hops, so that no arbitrary browser-supplied value counts as the sender address. The counter runs in a window of one minute; a tighter limit applies to the contact form on top of that.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the stable and secure operation of the website and the protection of the form and the interface against overload and automated abuse.

Typeface and embedded files

The Epilogue typeface used here is served from our own server. Your browser does not connect to Google Fonts or any other external font network for it.

External providers are involved only in the cases described explicitly in the following sections: bot protection on the contact page, the delivery and keeping of an enquiry sent through the contact form, the appointment calendar after a click, and the consent-based analytics and marketing services.

Consent and the cookie banner

The first time you visit, you see a consent banner. It uses the vanilla-cookieconsent software, which is served from our own server. There you can decide, per category, which services may be loaded. A category is only offered as long as a service is set up for it at all; at present that is the statistics category alone.

Your choice is stored in a cookie named “cc_cookie” in your browser so that the website can respect it on later visits. The cookie expires after 182 days. No user account is created, and the choice is not transmitted to an external consent service.

You can change your choice or withdraw consent at any time. Once you have made a first choice the banner is no longer shown; you then open the dialogue through the “Cookie settings” button in the footer of every page. A withdrawal takes effect going forward. Third-party code that was already loaded on the basis of an earlier consent is not retroactively removed from your browser by the withdrawal.

If the services used or the recipients change materially, we raise the revision of the consent configuration and ask again. An older stored consent then no longer applies.

The legal basis for storing and evaluating the choice itself is Article 6(1)(c) and (f) GDPR: without that record we could neither respect nor demonstrate your decision. For the storing of and access to information on your terminal equipment, Section 165(3) of the Austrian Telecommunications Act (Telekommunikationsgesetz 2021, TKG 2021) applies in addition; the cookie holding your choice is strictly necessary for the operation of the website, and every other storage operation takes place only with your consent.

Contact form

You can send us an enquiry through the contact form. We collect your name, your email address and your message and, if you wish, your telephone number and company. Telephone number and company are optional. Name, email address and message are required so that we can match your enquiry to you and answer it; without those details we cannot deal with the enquiry.

In addition, you confirm by ticking a box that your details may be processed in order to deal with your enquiry. Without that confirmation the form is not submitted.

The form is delivered as an email through the service provider Resend (Resend, Inc.) to a fixed recipient address that is set on the server. The recipient cannot be changed through the form. Your email address is entered as the reply address of the message; which language version of the website you wrote from is also included.

Your details are not stored in a database of this website and are not transferred into a CRM system. Resend delivers the message; after that it sits in our mailbox and is handled like any other piece of correspondence. We run that mailbox through Google Workspace. The provider is Google Ireland Limited, where applicable involving Google LLC; Google processes the messages held there on our behalf.

The legal basis is Article 6(1)(b) GDPR where your enquiry concerns a contract, otherwise Article 6(1)(f) GDPR with the interest of answering enquiries addressed to us. The confirmation in the form sits alongside this and does not change that basis.

To protect against automated submissions the form contains a field that is invisible to you and that humans do not fill in, and the number of submissions is limited. If a submission is identified as automated, you receive the same response as on success, but no processing and no delivery take place.

Bot protection with Cloudflare Turnstile

On the contact page we use Cloudflare Turnstile to detect automated submissions. The provider is Cloudflare, Inc.

Turnstile is loaded as soon as the contact page is opened, not only on submission. In doing so, technical characteristics of your device and browser as well as your IP address are transmitted to Cloudflare. According to the provider, Turnstile sets no advertising cookies, and we do not use it for audience measurement.

On submission we verify the token issued by Turnstile on our server, including the expected action and the permitted host. If the check fails or the token is missing, the request is not processed. A spent token is renewed for a new attempt.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to protect the form against automated submissions; without that protection an open contact form could not be operated.

The bot protection is only rendered if a key is configured for it. If none is configured, the check does not appear and no request reaches Cloudflare. Turnstile is not loaded on any other page of this website.

Booking an appointment

On the appointment page you can book a slot in an online calendar. The calendar is not embedded from the outset: it loads only when you click the button to load it. Before that, no request is made to any external provider.

The calendar frame is loaded via the address www.mediapool.video. That address is operated by mediapool mvp GmbH, a company in the same group. Your browser loads the embedding script needed for it directly from HubSpot. The provider of the calendar is HubSpot Ireland Limited, where applicable involving HubSpot, Inc.

With your click, your IP address and technical characteristics of your device and browser are transmitted to mediapool and to HubSpot. Which cookies or comparable storage techniques HubSpot uses, and for how long they apply, is determined by HubSpot; we ourselves set no cookies through this embed.

If you book an appointment, you enter the details required for it directly in HubSpot's calendar. We process those details in order to arrange and hold the appointment.

The legal basis for loading the calendar is your consent under Article 6(1)(a) GDPR, which you give with the explicit click. For arranging and holding the appointment the legal basis is Article 6(1)(b) or (f) GDPR.

Without that click, none of these transmissions takes place. If you would rather not load the calendar, you can reach us on the telephone number and email address given on the same page.

Analytics after consent

We use Google Analytics 4 for the statistics category. The provider is Google Ireland Limited, where applicable involving Google LLC.

We use Google Consent Mode in its basic form. As long as there is no consent for the statistics category, neither the loader nor a configuration nor an event is sent. In that case no request reaches Google at all.

If your consent is in place, Google processes usage data: which pages you open, when and for how long, technical characteristics of your device and browser, and your IP address. The purpose is to measure reach and to improve the content of this website.

The legal basis is Article 6(1)(a) GDPR. You can withdraw your consent at any time through the “Cookie settings” button in the footer of every page; from that point on, no further events are sent.

The service is switched on for this website, which is why the statistics category is offered in the consent banner. Google Analytics 4 is currently the only service in that category. If a further analytics service is switched on, we review and extend this list.

Marketing after consent

Three services are configured for the marketing category: Google Ads conversion measurement (Google Ireland Limited, where applicable involving Google LLC), the Meta Pixel (Meta Platforms Ireland Limited) and the LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company). None of these three services is switched on at present; they are prepared and will be put into operation individually.

As soon as one of these services is switched on, the marketing category in the banner controls them together. Without the matching consent, no request would be sent to the provider concerned, no script would be loaded and no event would be transmitted. There are no noscript pixels as a substitute.

Were your consent in place, the providers would receive event and usage data, including your IP address, technical characteristics of your device and browser, and information about which page you opened and which action you took, for example submitting an enquiry. The purpose is to measure whether an advertisement led to an enquiry and to evaluate advertising activity.

The legal basis is Article 6(1)(a) GDPR. You can withdraw your consent at any time through the “Cookie settings” button in the footer of every page, with effect going forward.

As long as none of these services is switched on, the marketing category is not offered in the consent banner at all, and no request reaches any of the providers named. If a marketing service is switched on, we review this list, the consent configuration and the consent revision together: a choice made earlier did not yet know the category and therefore does not release the new service.

Server-side conversion interfaces

Alongside the browser scripts, server-side interfaces to Google Analytics 4, Meta and LinkedIn are prepared. They would send event data directly from our server to the provider, for example the information that an enquiry has been submitted.

At present none of these interfaces is connected to any processing on this website: no data is transmitted to Google, Meta or LinkedIn by this route. We describe them here because they are prepared in the source code and can be put into operation individually.

If one is put into operation, the following applies. The transmission is not exempt from consent. Before every call the server checks whether consent for the matching category is in place — statistics for Google Analytics 4, marketing for Meta and LinkedIn. If it is not, nothing is transmitted. Whether a stored choice still matches the current revision of the consent configuration is checked by the browser before it reports a consent as given at all; a choice made under an earlier revision does not count. A cookie or a stored state alone does not release a later transmission.

What would be transmitted is event data together with identifiers for matching. To Meta, the email address, telephone number and parts of the name would go solely as a SHA-256 hash, whereas the IP address, the browser identifier and the Meta cookie values fbc and fbp would go in plain text. To LinkedIn, the email address would go as a SHA-256 hash, but first name, last name and a company name in plain text, because the provider's interface requires it that way. To Google Analytics 4, event data would go without any contact identifiers. Before putting an interface into operation we review this list again and extend it if anything changes.

If an interface is in operation and you withdraw your consent, no further transmission takes place from that point on. Events already transmitted are not undone by the withdrawal. To have such data deleted, please contact us or the provider concerned directly.

Links to external offerings

On the home page, two buttons lead to the order processing for two books at CopeCart. These are links, not embeds: as long as you do not click, no request is made to CopeCart. With the click you leave this website; the processing of your data there is the responsibility of CopeCart or of the provider operating there, and their privacy notice applies.

In the blog and in the footer of every page we link to providers we work with, among them monday.com, Notion, PandaDoc, Recruitee and Perspective. For some of these links we receive a commission; they are marked as paid links for that reason. The badges in the footer are image files held on our own server. A customer video on the home page is likewise only a link, to Vimeo. In all of these cases the same applies: without a click no request reaches the provider concerned, and nothing is embedded.

The map on the contact page is likewise only a link to Google Maps and not an embed. Without a click, no map material is loaded and no request is sent to Google.

The operators of third-party websites we link to are responsible for their content. We have no influence over their processing.

Artificial intelligence

No artificial intelligence system that processes your data is used when you visit this website. There is no chatbot, no speech or writing assistant and no AI-supported evaluation of your entries. What you write in the contact form is not handed by this website to any AI system; it goes to our mailbox as an email through the delivery provider named in the “Contact form” section. Individual images on this website were created with generative AI; no personal data is processed in doing so.

Nor does any automated decision-making, including profiling within the meaning of Article 22 GDPR, take place here. The check for automated submissions in the contact form serves solely to prevent abuse; it makes no decision about you and has no legal effect concerning you.

The position is different for our consulting and implementation work, which is not delivered through this website. There it can happen that software and AI systems are used and that personal data from a client's business is processed in the course of that work.

Which systems those are in an individual case, which data may reach them, where they process it and who has access is settled with the client before implementation and recorded in the respective engagement. The client decides on the purposes and means of that processing. This notice does not cover it; it describes this website only.

Recipients and processors

Always involved is Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, as the operator of the server this website sits on. It processes the data solely on our behalf.

Also always involved is the administration of that server. We administer it through Ploi, Amperestraat 16J, 3861 NC Nijkerk, Netherlands, which according to the provider is a product of WebBuilds B.V. (commercial register number KvK 94117233). Server administration entails administrative access to the server and therefore to the data processed on it. Ploi acts on our behalf in doing so; the provider is established in the European Union.

On the contact page, Cloudflare, Inc. is added for the bot protection. If an enquiry is sent through the contact form, Resend, Inc. is additionally involved as the delivery provider. The delivered message then sits in our mailbox, which we run through Google Workspace; for that part Google Ireland Limited, where applicable involving Google LLC, is involved on our behalf.

Only if you load the calendar: mediapool mvp GmbH and HubSpot Ireland Limited, where applicable involving HubSpot, Inc.

Only after your consent: Google Ireland Limited, where applicable involving Google LLC, for Google Analytics 4. The same applies to the marketing services — Google Ads conversion measurement, the Meta Pixel of Meta Platforms Ireland Limited and the Insight Tag of LinkedIn Ireland Unlimited Company — as soon as one of them is switched on; none is in operation at present.

Beyond that, we disclose data where we are legally obliged to do so or where it is necessary to establish or defend legal claims. In such a case our tax or legal advisers may also be recipients.

Transfers to third countries

The server this website sits on stands in Germany; the hosting itself therefore involves no transfer to a third country. The provider of the server administration is established in the Netherlands; we have no further information on where its administrative access is carried out.

With Cloudflare, Google, Meta, LinkedIn, HubSpot and Resend, by contrast, processing in the United States is possible. Whether and to what extent this happens in an individual case is determined by the provider concerned. Three of these providers are involved without your consent: Cloudflare when the contact page is opened, and Resend and Google when the contact form is submitted — Resend delivers the message, and Google then processes it as the provider of our mailbox. All other processing by these providers, including Google Analytics 4, is added only after your consent or after an explicit click by you; the marketing services are not switched on at present.

Possible bases for such a transfer are the European Commission's standard contractual clauses under Article 46(2)(c) GDPR and the adequacy decision on the EU-US Data Privacy Framework.

We do not give any assurance that a particular provider is certified under the EU-US Data Privacy Framework. Before we take on any further provider, we clarify what a transfer would be based on. On request to office@wogenfels.com we will tell you what a transfer to a particular provider is based on and provide you with a copy of the standard contractual clauses where those form the basis; their wording is also published in the Official Journal of the European Union.

In third countries the level of protection may differ from the European one. In particular, access by authorities there is not excluded in the same way and legal remedies are not secured in the same way. If you consent to analytics or marketing, you consent in the knowledge of that.

Retention periods

The delivery of pages produces no access log that could be retained. The web server's error log arises only when something goes wrong, serves solely to analyse the fault and is deleted once it is no longer needed for that. The log entries for interface requests contain neither IP address nor request content. The counter for rate limiting runs in a window of one minute.

Enquiries sent through the contact form sit as email in our mailbox, which we run through Google Workspace. We keep them for as long as it takes to deal with your enquiry, and beyond that for as long as statutory retention duties or the establishment and defence of legal claims require. After that we delete them.

Your choice in the consent banner stays in your browser. The cookie expires after 182 days; you can delete it yourself at any time or change your choice through the “Cookie settings” button in the footer of every page.

With Cloudflare, Google, Meta, LinkedIn, HubSpot and Resend, the retention period follows the rules set by the provider concerned. It is described in that provider's privacy information; we have no influence over it. How long a delivered enquiry stays in our mailbox, by contrast, is for us to decide; the second paragraph of this section applies to that.

Your rights

You have the right to obtain information about which data we process about you (Article 15 GDPR), to have inaccurate data corrected (Article 16 GDPR) and to have data erased (Article 17 GDPR).

You can also request that processing be restricted (Article 18 GDPR) and receive the data you provided to us in a common format, or have it transferred to another controller (Article 20 GDPR).

To exercise these rights, write to office@wogenfels.com or to the postal address given above. We reply within one month; for complex requests that period may be extended under Article 12(3) GDPR, and we will tell you if it is.

So that we do not disclose information to the wrong person, we may ask for further details that allow us to match your request to our records.

Objection and withdrawal

Where we process data on the basis of a legitimate interest — this covers the logging of faults and interface requests, the rate limiting, the bot protection and the handling of your enquiry — you may object under Article 21 GDPR. We then examine whether our grounds outweigh your interests in the individual case.

You can withdraw a consent you have given at any time (Article 7(3) GDPR). For analytics and marketing this is done through the “Cookie settings” button in the footer of every page, which opens the same dialogue as the banner on your first visit. For anything else, a message to office@wogenfels.com is enough.

A withdrawal takes effect going forward. The lawfulness of processing carried out up to that point is unaffected, and events already transmitted to a provider are not undone by the withdrawal.

Complaint to the data protection authority

Regardless of the above, you can lodge a complaint with a supervisory authority at any time. The authority responsible for us is the Austrian data protection authority.

Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria. Telephone: +43 1 52 152-0. Email: dsb@dsb.gv.at. Website: www.dsb.gv.at.

Changes to this notice

We update this notice when the services used, the recipients or the legal situation change. The current version is always available on this page.

If recipients or processing activities change materially, we review the consent configuration together with this notice and raise the consent revision so that you are asked again.

Version of this notice: 10 September 2026.