This English text is a courtesy translation. The German privacy policy is authoritative.
1. Controller
Simon Marcel Schlieber
Bienengasse 5, Tür 6, 1060 Vienna, Austria
Phone: +43 (0) 720 347 381
Email: mail@schlieber.net
2. Scope and current operating state
This policy describes the publicly delivered website, communication through mail@schlieber.net, B2B mandates, and the contact, newsletter, payment, and accounting capabilities that are technically prepared but each subject to a separate release.
At the date of this review draft, public contact intake, checkout, and unrestricted newsletter campaigns are disabled. Disabled capabilities do not accept data through their intended browser controls. Public newsletter signup on schlieber.net is active under its narrower, separately approved newsletter privacy notice. That notice governs newsletter registration and delivery until this broader policy is approved.
The current website uses no analytics, advertising, cross-site advertising, or social-media trackers. Carbon graphics and IBM Plex fonts are served from the website’s own files and cause no request to IBM.
3. Website delivery and technical security
The static website is delivered through Cloudflare Workers and Cloudflare’s network. Cloudflare processes technical connection data, particularly the IP address, time, requested resource, and browser or device information, to the extent required for delivery, network security, and attack mitigation.
The application writes no raw IP address to the commercial database or its logs. For public write requests, it creates a cryptographic digest using a secret additional value. The rate limiter sees only this digest and a short-lived counter.
The legal basis is Article 6(1)(f) GDPR: the legitimate interest in a secure, available, and abuse-resistant website. Where delivery is directly necessary for pre-contractual steps requested by an individual, Article 6(1)(b) GDPR may also apply.
Cloudflare D1 is provisioned for commercial data as a database with the European Union jurisdiction. This setting restricts where the D1 database runs and persistently stores data. It does not mean that Cloudflare’s global edge infrastructure processes all connection data only within the EU. Cloudflare may process data outside the EEA under its contractual and privacy terms, relying in particular on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
More information: Cloudflare privacy policy and D1 data location.
4. Local browser preference
If you expressly select light or dark display, the website stores that choice under schlieber-theme in your browser’s local storage. It contains no identifier, name, or contact details. It remains until you change it or clear it in the browser.
Storage is required to provide the display you selected (section 165(3) TKG 2021) and, insofar as personal data is involved, relies on Article 6(1)(f) GDPR.
5. Contact by email and phone
If you contact us by email or phone, the contact details, content, metadata, and any attachments you provide are processed to answer you, assess a possible mandate, or perform an existing contract.
The schlieber.net domain currently uses Microsoft 365 / Exchange Online for incoming email. Microsoft processes addressing, message, and technical-delivery data under the contractual and privacy terms applicable to the tenant. Do not send passwords, private keys, or special-category personal data by email unless specifically requested and protected.
The legal bases are Article 6(1)(b) GDPR for pre-contractual steps or a contract with the individual, and Article 6(1)(f) GDPR for business correspondence with a corporate contact. The legitimate interest is handling and documenting the enquiry.
Correspondence is kept until the matter is resolved and thereafter only for as long as required for follow-up, forming or performing a mandate, statutory records, or establishing, exercising, or defending legal claims. Contract- and accounting-relevant messages may be subject to the statutory periods in section 12.
More information: Microsoft privacy statement.
6. Public contact intake: only after separate activation
If the contact intake capability is activated after its legal, privacy, and provider gates have closed, it processes name, email address, company, language, and message. Cloudflare D1 is then the system of record; durable work is passed through a queue to a separate jobs Worker. A contact enquiry never creates a newsletter subscription.
Enquiries are normally anonymised in the system 24 months after receipt unless a documented retention hold applies for tax, dispute, legal-claim, or fraud reasons. Anonymisation removes name, email address, company, and message while retaining a low-personal-data operational record.
The legal bases are Article 6(1)(b) and (f) GDPR as described in section 5. Required fields are necessary to handle the enquiry.
7. Newsletter and Brevo
Newsletter signup asks for an email address, language, and express consent. It becomes active only after separate confirmation through double opt-in. A confirmation link is valid for up to 48 hours. Cloudflare D1 holds subscription, consent, withdrawal, and suppression status; no Brevo contact list is used as the source of truth.
Brevo (Sendinblue GmbH, Berlin, part of the Brevo group) transports confirmation and lifecycle messages. Newsletter messages are transported only after separate approval. Brevo receives the email address and message and returns technical delivery events such as delivery, deferral, bounce, complaint, block, or unsubscribe.
Brevo open and click tracking is accepted at the provider boundary and may record interactions in Brevo’s systems. schlieber.net does not ingest those open or click events into its own database. The HTML authored by schlieber.net loads no remote content; the provider check concerns the body returned by Brevo and is not a claim to inspect the unchanged raw email in the recipient’s mailbox.
The legal basis for newsletter delivery is consent under Article 6(1)(a) GDPR in conjunction with section 174 TKG 2021. You may withdraw consent at any time through the unsubscribe link or by email.
Unconfirmed addresses are erased no later than 30 days after the request. After unsubscribe or hard suppression, the raw address and stored newsletter bodies are removed. A peppered pseudonym, consent and withdrawal timestamps, and minimal suppression state remain to honour and evidence the withdrawal.
More information: Brevo privacy policy.
8. B2B mandates
The following data may be processed when forming and performing a mandate:
- names, business contact details, role, and authority to represent;
- company, billing address, order, and contract references;
- meeting notes, requirements, decisions, approvals, and project communications;
- supplied system, architecture, security, and governance material;
- performance, time, acceptance, and billing evidence.
The purposes are selecting, forming, planning, delivering, and documenting a mandate, communication, quality assurance, billing, and legal defence. The legal bases are Article 6(1)(b) GDPR for contracts with individuals, Article 6(1)(f) GDPR for corporate contacts and staff, and Article 6(1)(c) GDPR for statutory duties.
The client is responsible for supplying only personal data that is necessary for the mandate and may lawfully be disclosed. If schlieber.net processes personal data on the client’s behalf, an Article 28 GDPR data-processing agreement will be concluded before that processing starts. Special-category data belongs in a mandate only where expressly agreed, lawful, and technically protected.
9. Stripe payment: only after separate activation
If an approved fixed-price engagement is purchased through activated checkout, Stripe runs the hosted payment. Payment-instrument data such as full card numbers is entered directly with Stripe and is not stored by schlieber.net. schlieber.net receives in particular payment status, method, billing and contact details, and provider or transaction identifiers.
Stripe may act as an independent controller for parts of the processing, particularly fraud prevention, payment services, and its own legal duties. schlieber.net relies on Article 6(1)(b), (c), and (f) GDPR. A flagged payment does not lead to a solely automated decision with legal effect within schlieber.net; mismatches are held for manual review.
More information: Stripe Privacy Center.
10. sevdesk accounting: only after separate activation
An integration with sevdesk GmbH, Hauptstraße 115, 77652 Offenburg, Germany, is prepared for invoices, credit notes, and accounting. When activated, sevdesk receives data needed for the contact, invoice, and booking, particularly name, email address, billing address, service lines, amounts, and references.
The legal bases are Article 6(1)(b) GDPR for contract performance and Article 6(1)(c) GDPR for tax and fiscal duties. The integration remains off until the small-business treatment, including invoice characteristics, and the write process have been separately configured, tested, and approved.
More information: sevdesk privacy information.
11. Recipients and international transfers
| Recipient | Function | Location or international aspect |
|---|---|---|
| Cloudflare | Website, D1, queues, rate limiting, operator access | global infrastructure; D1 database with EU jurisdiction; possible US processing |
| Microsoft | Email mailbox and delivery | EU contracting entity with global infrastructure |
| Brevo | Email transport and provider tracking | Germany/France; processing under provider terms |
| Stripe | Hosted payment, fraud prevention, payment evidence | Ireland/EU with possible group and third-country processing |
| sevdesk | Invoicing and accounting | Germany/EU |
Article 28 GDPR agreements are concluded with processors where required. International transfers rely, as applicable, on adequacy decisions, the EU-U.S. Data Privacy Framework, and/or Standard Contractual Clauses with necessary supplementary measures. Data may also be disclosed to authorities, courts, or professional advisers where legally required or necessary for legal claims.
12. Retention
- Email and enquiries: under the criteria in section 5; activated form enquiries normally 24 months, then anonymisation.
- Unconfirmed newsletter request: raw address for no more than 30 days; action link valid for up to 48 hours.
- Confirmed newsletter: until withdrawal or suppression; then only minimal pseudonymous evidence and suppression state.
- Contract, invoice, and accounting documents: generally seven years from the end of the relevant calendar year under section 132 of the Austrian Federal Fiscal Code (BAO); longer where required for a pending procedure or legal claim.
- Project records: for the mandate and thereafter according to warranty, limitation, documentation, and legal-defence needs; mandatory law prevails.
- Technical security data: only for as long as required for operation, abuse prevention, and fault analysis.
A documented retention hold may temporarily prevent erasure. Restriction and legally required retention are recorded as such and are not represented as erasure.
13. Your rights
Subject to statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), and objection (Article 21). You may withdraw consent at any time with future effect under Article 7(3) GDPR.
Email mail@schlieber.net to exercise a right. Appropriate proof of identity may be required to protect the individual concerned.
You may complain to a supervisory authority. In Austria:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
www.dsb.gv.at
14. Required data and automated decisions
Where data is required for an offer, contract, invoice, or payment, the relevant service cannot be provided without it. Newsletter information is voluntary.
schlieber.net makes no solely automated decision within Article 22 GDPR. Providers may perform their own automated security or fraud checks; resulting mismatches are not automatically repaired or decided against the individual in schlieber.net’s own system.
15. Security and confidential material
Access to operational capabilities is restricted, transmissions are encrypted, and sensitive capabilities are not stored in public URLs or logs. No technical system is risk-free. Send highly confidential material only after an appropriate transfer channel and mandate boundary have been agreed.
16. Changes
This policy will be revised when data flows, providers, retention periods, or legal bases change. A substantively changed approved version receives a new stable version identifier and immutable snapshot. Technical preparation alone never activates processing.