Privacy Policy

    Last updated

    Protecting your data matters to us. We therefore process your data solely on the basis of the applicable law (GDPR, Austrian Data Protection Act, Austrian Telecommunications Act 2021). Below we explain the main aspects of data processing on this website.

    1. Controller

    The controller within the meaning of the GDPR is:

    Matthias Sammer Sankt Margarethen 194a 6220 Buch in Tirol Austria

    Email: contact@open-beta.ai VAT identification number: ATU79376738 Member of the Austrian Federal Economic Chamber (WKÖ)

    For any data protection matter, please contact us at contact@open-beta.ai.

    No data protection officer has been appointed. There is no obligation to appoint one under Art 37 GDPR, as neither large-scale regular monitoring of data subjects nor large-scale processing of special categories of data forms part of our core activities.

    2. General

    This policy describes data processing in connection with this website.

    We use no web analytics, tracking or advertising services on this website. No cookies are set. There is no profiling and no automated decision-making within the meaning of Art 22 GDPR.

    One exception concerns an analysis tool embedded on a single sub-page, which is loaded only after your explicit consent. See section 6.

    3. When you visit this website

    When you visit this website, our hosting provider records data about each request to the server (server log files). This is technically necessary in order to deliver the website to your device and to ensure secure, stable operation. The legal basis is our legitimate interest under Art 6(1)(f) GDPR.

    These access data include:

    • name of the page or file requested
    • date and time of the request
    • volume of data transferred and confirmation of successful retrieval
    • browser type and version
    • operating system
    • referrer URL, i.e. the previously visited page
    • IP address
    • requesting provider

    These data are processed exclusively by our hosting provider. We ourselves never learn our visitors' IP addresses — these logs are not made available to the site operator.

    Access logs are stored for less than 30 days. Security-related system logs are retained, under the data processing agreement concluded with our hosting provider, for at most 90 days online and one year offline, and are deleted thereafter. Data whose further retention is required for evidentiary purposes are exempt from deletion until the matter concerned has been finally resolved.

    Hosting

    We host this website with Netlify, Inc., 442 Post Street, Suite 500, San Francisco, CA 94102, USA. Netlify is a content delivery network and ensures that the website is delivered quickly and securely. The legal basis is Art 6(1)(f) GDPR; we have a legitimate interest in reliable and secure delivery.

    A data processing agreement under Art 28 GDPR is in place with Netlify. Netlify processes our visitors' data exclusively on our documented instructions. The sub-processors engaged are listed at netlify.com/legal/subprocessors.

    Transfers to the USA rest primarily on Netlify's certification under the EU-US Data Privacy Framework. Where a transfer is not covered by it, the European Commission's Standard Contractual Clauses apply (Implementing Decision (EU) 2021/914, Module Two — controller to processor). For details see Netlify's privacy policy.

    4. Cookies and local storage

    This website uses no cookies.

    We store a single item of information locally in your browser:

    NamePurposeStorage period
    language-preferenceStores the language you selected (German or English) so that your choice is retained on your next visit.Until you delete it

    This is stored only if you change the language yourself. It is required to provide a service you have expressly requested and is therefore permitted without consent under § 165(3) of the Austrian Telecommunications Act 2021. No personal data is transmitted to us in the process; the information remains in your browser.

    If the language is selected automatically from your browser's language settings, nothing is stored.

    If you disable local storage in your browser, the website remains fully usable; only your language choice will not be remembered.

    5. Fonts and encryption

    The fonts used on this website are served from our own server. There is no connection to Google Fonts or any other external font service. No data is therefore transmitted to third parties when this website is displayed.

    This website uses TLS/SSL encryption throughout. You can recognise encrypted connections by the https:// prefix in your browser's address bar. This prevents the data your browser sends to this website from being read by third parties.

    6. Embedded external content

    On two sub-pages we embed content that is loaded from other servers. When it loads, your IP address is transmitted to the server concerned, because it is technically necessary in order to deliver the content to your browser.

    PageContentOperator
    Data Tale "On the trail of green capital"map tiles for the interactive mapCARTO (CartoDB Inc., USA)
    Data Tale "Climate risk in ICAAP"embedded interactive analysis tooloperated by us

    This content is loaded only after you have expressly requested it by clicking a button. Before that click, no connection is made and no data is transmitted. The legal basis is your consent under Art 6(1)(a) GDPR and § 165(3) of the Austrian Telecommunications Act 2021, given by clicking. You may withdraw this consent at any time by reloading the page without activating the content. The lawfulness of processing carried out up to that point remains unaffected.

    For information on processing by CARTO, see CARTO's privacy policy.

    Reach measurement within the embedded analysis tool

    The embedded analysis tool is operated by us; the controller is the same entity named in section 1. No transfer to another undertaking therefore takes place.

    The tool includes its own self-hosted reach measurement (Umami) and an endpoint for technical error and operations monitoring. Both run on our own infrastructure; no data is passed to an external analytics provider.

    The technical usage data collected include pages viewed, referring source, approximate region of origin, and browser and device type. These data are stored for 12 months and deleted thereafter. The legal basis is your consent under Art 6(1)(a) GDPR, given when you load the tool.

    This measurement takes place exclusively within the embedded tool, i.e. only after your click. No reach measurement takes place on any other page of this website.

    Fonts within the embedded tool

    The embedded tool loads its fonts from Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Your IP address is transmitted to Google in the process, and onward transfer to Google LLC in the USA cannot be ruled out. Google bases such transfers on the European Commission's Standard Contractual Clauses. For details see Google's privacy policy.

    This request likewise occurs only after you consent to load the tool; the legal basis is your consent under Art 6(1)(a) GDPR. The fonts of this website itself, by contrast, are served from our own server (see section 5).

    7. Contacting us

    If you contact us by email, the details you provide will be stored for six months in order to process your enquiry and in case of follow-up questions. The legal basis is our legitimate interest under Art 6(1)(f) GDPR. We do not pass these data on without your consent.

    We do not offer a contact form on this website; contact is made solely via the email address given. Appointments are likewise arranged by email; we use no online booking tool.

    For our email mailbox we use Microsoft 365 (Microsoft Ireland Operations Ltd, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) on the basis of the Microsoft Data Protection Addendum under Art 28 GDPR. Data is stored at rest within the European Union or EFTA.

    8. Your rights

    In relation to the data we process about you, you generally have the rights to access, rectification, erasure, restriction, data portability, withdrawal and objection.

    Where we process data on the basis of consent, you may withdraw that consent at any time. The lawfulness of processing carried out up to the withdrawal remains unaffected.

    To exercise your rights, please contact contact@open-beta.ai.

    If you believe that the processing of your data infringes data protection law, or that your data protection rights have otherwise been violated, you may complain to us or to the supervisory authority. In Austria, the competent authority is:

    Austrian Data Protection Authority (Datenschutzbehörde) Barichgasse 40–42, 1030 Vienna Telephone: +43 1 52 152-0 Email: dsb@dsb.gv.at Web: dsb.gv.at