Austria
Privacy Policy
What this site collects, why, who else touches it, how long it is kept and what you can require us to do about it. It describes the site as it is actually built: two forms, a payment page, a captcha, a rate limit, and two analytics tools that load only if you accept them.
Last updated: 17 September 2026.
Who is responsible for your data
The controller, in the sense of Article 4(7) of the General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR), is:
Goldblum, the firm behind this site.
The address for anything to do with data protection, including any request under the rights section further down, is [email protected]. It is the only address we publish, and it reaches the person who deals with these requests. The registered name and address of the controller are not published on this site yet. We are not going to invent them here: they are stated in writing to anyone who asks at the address above, and they appear on every invoice.
It operates this website and decides why and how the personal data described below is processed. For anything on this page, including a request under the rights section, write to [email protected] or use the contact form. Put "data protection" in the first line so the message is routed correctly.
No data protection officer has been appointed. Nothing described on this page is large scale systematic monitoring of people, and no special category of data under Article 9 is processed here, which are the conditions in Article 37(1) that would make an appointment compulsory.
This page covers this website and the enquiries that come through it. Where it and the terms of service both touch on data, this page governs. Cookies and anything else stored on your device have their own document, the cookie policy, which lists every item by name.
What is collected, why, and on what legal basis
| Where it comes from | What is collected | Why | Legal basis | Kept for |
|---|---|---|---|---|
The contact form at /contact/ | Name, email address, your message, and the shelf company reference carried in ref if you arrived from a listing, and the service name carried in service if you arrived from a service page. The hidden site, page and utm_ fields record which page and which campaign the form was sent from | To read and answer the enquiry | Article 6(1)(b), steps taken at your request before entering a contract | While the enquiry is open, and 24 months after the last message if nothing follows |
The questionnaire at /onboarding/ | Contact details, the company you plan, its activity, shareholders and directors, the services you want, your timeline, your acknowledgement about the origin of funds, and any free text you add | To prepare a quotation and, if you accept it, the engagement | Article 6(1)(b) | As above, and for the life of the engagement file if an engagement follows |
| The standby copy of an onboarding submission | The submitted fields, written to the ONBOARD_KV store under the key lead:<ts> | So a questionnaire you spent time on is not lost if the email delivery fails | Article 6(1)(f), our interest in not losing an enquiry that was actually sent | 30 days, after which the record expires by itself |
The payment page at /pay/ | Invoice number, payer name, email address, the amount and currency you enter, and which method you chose | To route the payment to the processor and match it to the invoice it belongs to | Article 6(1)(b) | With the accounting record of the payment, see the retention section |
| The anti abuse layer on every form | Your IP address, used as the key of a counter; the result the Turnstile widget returns; whether the hidden honeypot field was filled in | To keep the forms usable and free of automated submissions | Article 6(1)(f), our interest in a working contact channel | The rate limit counter expires after 10 minutes. Nothing else is stored |
| Cloudflare's delivery and security layer | IP address, time of the request, the URL, the user agent string, the response code | Serving the site and defending it | Article 6(1)(f), our interest in a site that stays up | Cloudflare's own log retention. We do not download these logs and build no profile from them |
| Google Analytics 4, before you answer the banner | A page view with no cookie and no identifier, approximate location derived from a truncated IP address, device and browser type, referrer. Nothing is written to your device and nothing is read from it | Aggregate audience measurement | Article 6(1)(f), our interest in knowing what is read. § 165 Abs. 3 TKG 2021 has nothing to attach to, because it governs storing something on a device or reading something from it and neither happens in this state | 14 months for event data at property level |
| Google Analytics 4, after you accept | As above, plus a randomly generated identifier in a first party cookie, which is what lets a return visit be recognised as the same visit | Aggregate audience measurement across sessions | Article 6(1)(a), your consent, and § 165 Abs. 3 TKG 2021 for the storage on your device | 14 months for event data at property level |
| Microsoft Clarity | A first party identifier, page views, clicks, scrolling, and a replay of the session with text input masked | Seeing where a page confuses people, mostly on the forms | Article 6(1)(a), your consent, and § 165 Abs. 3 TKG 2021 | Microsoft sets the retention for Clarity data and we do not extend it |
| Ahrefs Web Analytics | Page request data with no cookie, no device identifier and nothing stored on your device | Aggregate traffic measurement | Article 6(1)(f), our interest in knowing what is read. There is nothing to consent to under § 165 Abs. 3 TKG 2021 because nothing is stored on or read from your device | Aggregated, not held against an individual |
| Email you send us directly | Everything in the message and its attachments | To answer it | Article 6(1)(b) or 6(1)(f), depending on why you wrote | As for a form enquiry |
Two of these periods are decisions rather than obligations, and are written here so they can be held against us. 24 months for an unconverted enquiry is chosen because a founder who asks about a GmbH in March often comes back in the following tax year, and a shorter period would mean asking them everything again. 30 days for the standby copy of a questionnaire is the time it takes to notice that an email never arrived.
Every processing operation on this site, with the legal basis under the GDPR and the period the record is kept. Microsoft Clarity loads nothing at all until the banner is accepted; Google Analytics loads in a state that stores nothing, and only stores once you accept.
What happens when you send a form
Both forms on this site follow the same path, and nothing on it is a third party form service. The site is static; the only code that sees your submission is our own function running on Cloudflare's network.
The page checks you are a person.
A hidden field, invisible and skipped by screen readers, catches simple bots. A Cloudflare Turnstile widget catches the rest. Turnstile returns a pass or fail to our function; in the configuration this site uses it stores nothing on your device.
A counter limits how often one address can submit.
The counter lives in the FORM_KV store, keyed on your IP address, and allows 3 submissions in 10 minutes. The counter holds a number, not your message, and it deletes itself after 10 minutes.
The submission is validated and turned into an email.
A Cloudflare Pages Function checks the field types and lengths, then sends the content through Resend as a message from and to [email protected], with your address as the reply to.
The message is forwarded to the people who answer it.
Cloudflare Email Routing forwards [email protected] to a mailbox we control. That mailbox address is not published, here or anywhere else on the site.
You land on a confirmation page.
The browser is redirected to /thanks/, which sets nothing and asks for nothing. We do not state how quickly we reply, because any number would be invented.
No file upload exists on this site. Where identity documents are needed for a client file, they are requested after the first exchange, over a route agreed with you, and never through a form on a static page.
Paying an invoice
/pay/ takes an invoice number, your name, an email address, an amount and a currency, then hands you to a payment processor. Card payments run through Stripe Checkout, which is hosted on Stripe's own domain: card numbers are entered there, never on this site, and never reach any system of ours. Cryptocurrency payments run through NOWPayments in the same way, on a page of theirs.
What comes back to us is the invoice reference, the amount, the currency, the payment status and the email address you used. We store no card number, no wallet address and no private key, because we never receive them. The record of a completed payment is part of the accounting record of the invoice, and is kept for as long as that record is.
The two outcome pages, /pay/success/ and /pay/cancel/, carry no personal data of yours in the page. /pay/success/ records that a payment completed, without the amount, because the amount belongs to the invoice and not to this website.
Analytics, and the consent gate
Nothing is stored on your device, or read from it, before you allow it. That is the promise, and it is a narrower and more honest one than "nothing runs".
On first paint, Google Consent Mode v2 is set to denied before anything else executes, and Google Analytics is loaded in that state. Denied means what it says: no cookie is written, no identifier is generated, and a page view may be counted without anything on your device being touched. This is why the basis for that state is Article 6(1)(f) and not your consent, and why § 165 Abs. 3 TKG 2021, which is about storage and access, does not arrive until you accept.
Microsoft Clarity is handled differently, because it has no equivalent state. It writes its identifier the moment it loads, so it is not fetched at all until you accept, and if you reject it is never fetched.
/js/consent.js shows a banner offering accept, reject and a settings view. If you accept, the consent signal is updated to granted, Google Analytics begins using the cookie described above, and Clarity is loaded. If you reject or ignore the banner, Clarity never loads and Google Analytics stays as it started. Your choice is stored on your own device, and you can change it at any time from the footer.
Clarity records a replay of the session: which pages, which clicks, how far the page was scrolled. It is configured to mask text input, so what you type into a field is not recorded. The replay is a tool for finding a form field that nobody can fill in, not for identifying who was filling it in.
Ahrefs Web Analytics is the exception, and it is fair to say why. It writes no cookie, reads nothing from your device and sets no cross site identifier, so § 165 Abs. 3 TKG 2021 has nothing to attach to and it loads whatever you chose on the banner. What it does process is the request data, which rests on Article 6(1)(f), and you can object to that under the rights section below.
A full list of what is stored on your device, item by item, with its lifetime, is in the cookie policy.
Who else handles your data
Each of these acts as a processor on our instructions, under a contract that meets Article 28, except where the table says otherwise.
| Who | What they do for this site | What they receive | Where it is processed |
|---|---|---|---|
| Cloudflare | Hosting, the network in front of it, the Turnstile captcha, the FORM_KV and ONBOARD_KV stores, the function that handles the forms, and email routing for the domain | Everything that reaches the site, including form submissions in transit | A global network, including servers outside the EEA |
| Resend | Sends the form email | The content of the submission and your email address | The United States |
| Google (Analytics 4) | Aggregate audience measurement, after consent | The analytics identifier and event data described above | The European Union and the United States |
| Microsoft (Clarity) | Session replay and behaviour metrics, after consent | The Clarity identifier and the masked replay | The United States |
| Ahrefs | Cookieless traffic measurement | Request data, with no device identifier | Outside the EEA |
| Stripe | Card payment, on Stripe's own pages | The invoice reference, the amount, the currency, the email address, and the card details you give directly to Stripe. Stripe is a controller in its own right for the payment it processes | The European Union and the United States |
| NOWPayments | Cryptocurrency payment, on their own pages | The invoice reference as the order id, the amount and the currency. They are a controller in their own right for the payment | Outside the EEA |
Besides these, data may go to the notary, the register court, the tax office, a bank or another authority where you have instructed us to act and the filing requires it. That is the service, not a disclosure to a third party, and what goes where is agreed with you before it is filed. We also disclose where a law or a court order requires it, and no further.
Every third party that touches data from this site, what it receives and where it processes. Nothing on this site is sold, rented or passed to an advertising network.
Transfers outside the EEA
Several of the providers above are established outside the European Economic Area, or process on infrastructure that is. Where personal data leaves the EEA, the transfer rests either on an adequacy decision of the European Commission under Article 45, or on the Commission's standard contractual clauses under Article 46 together with the technical measures in the provider's own terms. You can ask which mechanism is relied on for any named provider, and get a copy of it, by writing to [email protected].
There is no transfer beyond what the table above describes. This site runs no advertising, so nothing is shared with an ad network, a data broker or a social platform.
How long things are kept
- An enquiry that goes nowhere: 24 months from the last message, then deleted.
- The standby copy of a questionnaire: 30 days, expiring automatically in the key value store.
- The rate limit counter: 10 minutes, then it expires by itself.
- An engagement: for as long as the engagement runs, and then for as long as record keeping law requires. For an Austrian company that is seven years for books, records and the vouchers behind them, counted from the end of the calendar year the entry belongs to (§ 132 Abs. 1 BAO, in force since 13 January 1999). Tax and accounting law overrides every shorter period on this page, which is why an erasure request cannot always be granted in full.
- Analytics: 14 months for Google Analytics 4 event data. Microsoft sets the retention for Clarity and we do not extend it. Ahrefs data is aggregated and is not held against an individual.
- Anything covering a dispute: kept until the dispute and any limitation period are finished, then deleted.
Your rights, and how to use them
Under the GDPR you can require us to do the following, and none of it costs anything.
Access (Article 15). A copy of the personal data we hold about you and the information on this page, applied to your own record.
Rectification (Article 16). Correction of anything wrong, and completion of anything missing.
Erasure (Article 17). Deletion, except where we still need the data for a contract we are performing, or where a retention obligation applies. Where we cannot delete, we say which obligation stops us.
Restriction (Article 18). Processing paused while a correction or an objection is being worked out.
Portability (Article 20). What you gave us, in a structured, commonly used, machine readable form, for the data processed on consent or for a contract.
Objection (Article 21). Against anything resting on legitimate interest, which on this site means the security layer, the server logs and Ahrefs. Say why it affects you and we stop unless there are compelling grounds that override it.
Withdrawal of consent (Article 7(3)). For analytics, at any time, from the banner's settings link in the footer. Withdrawing does not make what was already collected unlawful, and it stops any further collection at once.
Complaint (Article 77). To the Austrian data protection authority, the Datenschutzbehörde in Vienna, or to the supervisory authority where you live or work. You do not have to ask us first.
To use any of them, write to [email protected] or send the contact form. We may ask one question to confirm who you are, and only enough to be sure. The GDPR gives us one month to answer, extendable by two further months for a request that is genuinely complex, and Article 12(3) requires us to tell you inside the first month if that happens.
Automated decisions and profiling
There is no automated decision making that produces a legal effect on you or similarly significantly affects you, in the sense of Article 22. The one automated judgement on this site is the captcha and rate limit on the forms, which can refuse a submission. If that happens to you, email [email protected] instead and a person will read it.
No profile is built from your reading of the site, and nothing here is used for advertising, scoring or prediction.
Security
The site is served only over HTTPS. Form submissions travel to a function on Cloudflare's network and are sent onward through Resend over an authenticated connection. Keys for Resend, Turnstile, Stripe and NOWPayments exist only as environment variables in the Cloudflare project; none is in the page source, the repository or any document that leaves us. The two key value stores expire their contents automatically rather than relying on anyone remembering to clear them.
No security claim beyond that is made here. Card data is not held because it is never received; the honest version of that statement is that Stripe holds it, on Stripe's own pages, under Stripe's own certification.
Children
This site is aimed at people forming and running companies, and nothing on it is directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has sent us something, write to [email protected] and it will be deleted.
Changes to this policy
This page changes when the site changes. If a processor is added, removed or replaced, or a retention period moves, the change appears here at the same time, and the date at the top is rewritten. Material changes to how consent works are announced through the banner itself, because a changed policy nobody sees is not a change at all.
Questions about anything above: [email protected], or the contact form.