Privacy Policy

Data Protection Information

1. Controller (Data Protection Officer)

DI Samuel Ziegler, BSc
Email: office [at] vetosec [dot] at
Website: https://vetosec.at
Address: Steinhofstraße 16, 2560 Berndorf, Austria

2. Data We Collect

We collect the following types of personal data:

  • Contact Information: Name, email address, company name, phone number, collected when you submit contact forms or inquire about our services
  • Technical Data: IP address, browser type, operating system, access times, pages visited, referrer information, collected via server logs
  • Cookie Data: For analytics and website functionality (only with your explicit consent)
  • Form Submission Data: Information you voluntarily provide in contact forms or service requests

3. Purpose of Data Processing

We process your personal data for the following purposes:

  • Responding to your inquiries and service requests
  • Providing cybersecurity consulting services and support
  • Improving our website functionality and user experience
  • Website analytics and performance optimization (with your consent)
  • Compliance with legal and regulatory obligations (Austrian and EU law)
  • Legitimate business interests in understanding user behavior and service effectiveness

4. Legal Basis for Data Processing

We process your personal data based on the following legal grounds under GDPR:

  • Article 6(1)(a) GDPR: Your explicit consent (e.g., Google Analytics, marketing communications)
  • Article 6(1)(b) GDPR: Contract performance (service delivery, consulting)
  • Article 6(1)(c) GDPR: Legal obligations (tax law, Austrian Corporate Code)
  • Article 6(1)(f) GDPR: Legitimate interests (security, website optimization, fraud prevention)

5. Data Retention Periods

We retain your personal data only as long as necessary for the stated purpose:

  • Contact Form Submissions: Retained for 3 years or until legal obligations are fulfilled
  • Server Logs: Retained for 30 days (IP addresses, access logs)
  • Analytics Data: Retained according to Google Analytics retention settings
  • Customer Service Data: Retained for 7 years (Austrian tax and business law requirements)

You may request deletion of your data at any time, subject to legal and contractual obligations.

6. Cookies and Web Analytics

Cloudflare Turnstile: The contact form is protected against automated submissions by Cloudflare Turnstile, operated by Cloudflare, Inc. Turnstile examines technical characteristics of the request in order to tell humans apart from programs. Your IP address and technical details of your browser are transmitted to Cloudflare in the process. Turnstile sets no advertising cookies and builds no profile across websites. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in protecting the form from abuse.

Google Tag Manager: We use Google Tag Manager (container GTM-TXLNB9NS), operated by Google Ireland Limited. The tag manager governs the services listed below and decides which of them is loaded. The tag manager itself stores no cookies and collects no personal data for analytics or advertising purposes. Loading the script does transmit your IP address to Google for technical reasons.

Google Consent Mode v2: Google Tag Manager is loaded after you consent to analytics or marketing. Before that, this website does not load Google measurement tags. Your choices for analytics and advertising are passed to Google separately. You can change or withdraw them through the cookie settings.

Legal bases for the Google services: We rely on your consent under Article 6(1)(a) GDPR for analytics and advertising measurement. You can withdraw your consent through the cookie settings. Withdrawal does not affect processing carried out before withdrawal.

Google Analytics: We use Google Analytics 4 to analyze website usage. Cookies and any recognition of you are used only with your explicit consent via our cookie banner (analytics category). Google Analytics may transfer data to the United States under the EU-US Data Privacy Framework.

Google Ads: We use Google Ads to measure whether a visit originated from an advert and whether it led to an enquiry (conversion measurement). Advertising identifiers are processed only with your explicit consent via our cookie banner (marketing category). Without marketing consent, the consent signals ad_storage, ad_user_data and ad_personalization remain denied. The controller is Google Ireland Limited.

  • Tracking ID (if enabled): Google Analytics
  • Data Controller: Google Ireland Limited
  • Processing Purpose: Website analytics and user behavior analysis
  • Cookies Set: _ga, _ga_[measurement-id]
  • Retention: according to the configured Google Analytics retention period
  • Manage your Google data

Images and stock photos: We use stock photos from Unsplash. All images are stored on our own servers and delivered from there. Loading our website establishes no connection to Unsplash or any other image service. No data is transmitted to third parties in this process. The credits are listed in our imprint.

External content (Cal.com): The Cal.com booking calendar (cal.eu) is embedded on the contact page and sets its own cookies once loaded. It is loaded only with your explicit consent, either through the external content category in the cookie banner or through the button shown at the calendar itself. Without consent the calendar stays closed and no connection to Cal.com is made. The legal basis is Article 6(1)(a) GDPR.

Essential Cookies: We may set essential cookies for website functionality without consent (e.g., CSRF tokens, session identifiers).

You can withdraw your consent at any time by adjusting your cookie preferences via our cookie settings or your browser settings.

7. External Resources and Third-Party Services

Our website uses the following third-party services, which may process your data:

  • Google Analytics: Tracks website usage and visitor behavior (with consent)
    Google Analytics Privacy Policy
  • Cal.com (cal.eu): Embedded appointment-booking calendar, loaded only after your explicit consent. When the calendar is opened, Cal.com may set cookies and process connection data (IP address, browser type, interactions with the booking widget) to operate the booking flow.
    • Data Controller: Cal.com, Inc. (United States)
    • Servers used by the embed: cal.eu (European Union)
    • Processing Purpose: scheduling and booking of online meetings
    • Cookies set by Cal.com when the booking widget is loaded
    • Legal basis: Art. 6(1)(a) GDPR (consent)
    • Cal.com Privacy Policy
  • Stripe (payments): The external security analysis can be booked and paid for directly on the page. The Stripe payment field is loaded only when you press the booking button, that is, only when you actually want to pay. Stripe.js then sets the cookies __stripe_mid and __stripe_sid for fraud prevention and processes connection data.
    • Data Controller: Stripe Payments Europe, Ltd. (Ireland), Stripe, Inc. (United States)
    • Processing Purpose: processing the payment and preventing payment fraud
    • Data processed: amount, payment details entered at Stripe, IP address, browser and device characteristics
    • Cookies: __stripe_mid and __stripe_sid, set by Stripe once the payment field is loaded
    • Legal basis: Art. 6(1)(b) GDPR (performance of a contract you requested) and Art. 6(1)(f) GDPR for fraud prevention. No consent banner applies because the payment field loads only on your own request and is technically necessary for it.
    • We never see or store your card details. Payment data is entered directly at Stripe.
    • Stripe Privacy Policy
  • Email Service: Contact form submissions may be processed via secure email (office [at] vetosec [dot] at)

8. Your Rights Under GDPR

You have the following rights regarding your personal data under GDPR and Austrian Data Protection Law:

  • Right of Access (Art. 15 GDPR): Obtain confirmation of whether your data is processed and receive a copy
  • Right to Rectification (Art. 16 GDPR): Correct inaccurate or incomplete personal data
  • Right to Erasure/Right to be Forgotten (Art. 17 GDPR): Request deletion of your data (subject to legal obligations)
  • Right to Restrict Processing (Art. 18 GDPR): Limit how we use your data
  • Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format
  • Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests or direct marketing
  • Right to Lodge a Complaint: File a complaint with the Austrian Data Protection Authority (Datenschutzbehörde)
  • Right to Withdraw Consent: Withdraw consent at any time (without affecting the lawfulness of prior processing)

9. Data Security and Protection Measures

We implement comprehensive technical and organizational security measures:

  • All data transmission encrypted using TLS 1.2+ (HTTPS)
  • Secure server infrastructure with access controls
  • Regular security updates and patches
  • Limited access to personal data (need-to-know basis)
  • Monitoring for unauthorized access attempts
  • Secure disposal of data when no longer needed

10. Automated Decision-Making and Profiling

We do not use your personal data for automated decision-making or automated profiling that produces legal or similarly significant effects.

11. Data Transfers and International Transfers

Personal data may be transferred to the United States for Google Analytics processing. These transfers are safeguarded under the EU-US Data Privacy Framework and Standard Contractual Clauses. You have the right to obtain information about safeguards applied to such transfers. Web fonts are served locally and do not result in international transfers.

12. Changes to This Privacy Policy

We may update this Privacy Policy to reflect legal changes, new technologies, or improvements to our services. We will notify you of material changes via email or a prominent notice on our website.

13. Contact and Data Subject Rights Requests

To exercise any of your rights or for privacy-related inquiries, please contact us:

DI Samuel Ziegler, BSc
Email: office [at] vetosec [dot] at
Website: https://vetosec.at

Austrian Data Protection Authority (Datenschutzbehörde):
If you wish to lodge a complaint: www.dsb.gv.at

Last updated: May 2026

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.