Privacy Policy

Privacy Policy

Last updated: 8 September 2026

1. Controller

The controller responsible for the processing of personal data on this website is:

Tamas Hegedus

trading as cliix

Laxenburger Straße 151/D

Vienna, Austria

Email: info@cliix.org

Phone: +43 677 6147 8869

2. General information

We process personal data only where necessary to operate this website, respond to enquiries, provide our services, comply with legal obligations, or protect our legitimate interests.

Depending on the circumstances, processing may be based on:

  • Article 6(1)(b) GDPR, where processing is necessary to take steps at your request before entering into a contract or to perform a contract;
  • Article 6(1)(c) GDPR, where processing is required by law;
  • Article 6(1)(f) GDPR, where processing is necessary for our legitimate interests and those interests are not overridden by your rights and freedoms; or
  • Article 6(1)(a) GDPR, where you have given consent.

3. Website hosting and server logs

This website is hosted on a virtual private server provided by DigitalOcean. The server hosting the website is located in Amsterdam, the Netherlands.

When you access this website, the server may automatically process technical information such as:

  • your IP address;
  • date and time of access;
  • requested page or resource;
  • referrer URL;
  • browser type and version;
  • operating system;
  • HTTP status information; and
  • other technical information required to establish and secure the connection.

This data is processed to deliver the website, ensure its technical operation, maintain security, identify technical problems and detect or investigate abuse or attacks.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure and reliable operation of the website.

Server logs are retained only for as long as reasonably necessary for these purposes, unless longer retention is required in connection with a security incident or legal obligation.

DigitalOcean processes data on our behalf as an infrastructure provider. DigitalOcean is headquartered in the United States, although the server hosting this website is located in the Netherlands. Where international transfers occur, appropriate safeguards are used where required by applicable data-protection law.

4. Contact form and enquiries

If you contact us using the contact form, by email or by telephone, we process the information you provide to us.

This may include:

  • your name;
  • email address;
  • telephone number;
  • company name;
  • the contents of your message; and
  • any other information you voluntarily provide.

We process this information in order to respond to your enquiry, communicate with you and, where applicable, prepare or provide requested services.

Where an enquiry relates to a possible or existing contractual relationship, processing is based on Article 6(1)(b) GDPR.

For other business enquiries, processing may be based on Article 6(1)(f) GDPR. Our legitimate interest is responding to communications addressed to our business and maintaining business relationships.

Contact-form submissions are transmitted to us by email.

Correspondence is retained for as long as reasonably necessary to process the enquiry and any resulting business relationship. Information may be retained for longer where required by law or where necessary for the establishment, exercise or defence of legal claims.

5. Email communication via Microsoft 365

We use Microsoft 365 for business email.

When you contact us by email, or when a contact-form submission is delivered to us by email, your message and related information are processed using Microsoft services.

This may include:

  • sender and recipient addresses;
  • message contents;
  • attachments;
  • timestamps;
  • routing information; and
  • technical and security metadata.

Processing is based on the legal basis applicable to the relevant communication, generally Article 6(1)(b) or Article 6(1)(f) GDPR.

Microsoft acts as a processor for Microsoft 365 services under its applicable data-protection terms. Depending on the service and processing involved, data may be processed outside the European Economic Area. Where required, appropriate safeguards are used for such transfers.

6. Google Fonts

This website currently uses Google Fonts.

When fonts are loaded directly from Google servers, your browser establishes a connection to Google in order to download the required font files. In doing so, technical information, including your IP address, may be transmitted to Google.

Google Fonts are used for the consistent and visually appropriate presentation of the website.

If the fonts are later hosted locally on this website, this section will be updated accordingly.

7. Cookies and similar technologies

This website does not currently use analytics, advertising or marketing cookies.

Technically necessary cookies or similar technologies may be used where required for the operation, security or administration of the website.

No optional tracking technologies are currently used.

8. Recipients of personal data

Where necessary, personal data may be processed by service providers assisting us with the operation of our website and business communications.

These currently include:

  • DigitalOcean, for website hosting; and
  • Microsoft, for business email and Microsoft 365 services.

We do not sell personal data.

9. International data transfers

Some service providers we use are headquartered outside the European Economic Area.

Where personal data is transferred outside the EEA, such transfers are carried out using an appropriate legal mechanism where required, such as an adequacy decision, participation in the EU-US Data Privacy Framework, Standard Contractual Clauses, or another legally recognised safeguard.

10. Data retention

Personal data is retained only for as long as necessary for the purposes for which it was collected.

Longer retention may apply where required by statutory retention obligations or where necessary for the establishment, exercise or defence of legal claims.

When data is no longer required and no legal or legitimate reason for continued retention exists, it is deleted or anonymised.

11. Your rights

Subject to the requirements of the GDPR, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of your data;
  • request restriction of processing;
  • receive certain personal data in a portable format;
  • object to processing based on legitimate interests; and
  • withdraw consent where processing is based on consent.

You may exercise these rights by contacting us using the details listed at the beginning of this Privacy Policy.

12. Right to lodge a complaint

You have the right to lodge a complaint with a competent supervisory authority.

In Austria, this is the:

Österreichische Datenschutzbehörde

Austrian Data Protection Authority

13. Automated decision-making

We do not use personal data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects.

14. Changes to this Privacy Policy

We may update this Privacy Policy if the website, the services we use or applicable legal requirements change.

The current version will be published on this website together with the date of the most recent update.