This English text is a courtesy translation. The German privacy policy is authoritative.
1. Controller
Simon Marcel Schlieber
Bienengasse 5, Tür 6, 1060 Vienna, Austria
Phone: +43 (0) 720 347 381
Email: mail@schlieber.net
2. Scope
This policy describes the website, communication through mail@schlieber.net and by phone, B2B mandates, and the newsletter. The newsletter privacy notice explains the newsletter process in a shorter, focused form.
The current website uses no analytics, advertising, cross-site advertising, or social-media trackers. Carbon graphics and IBM Plex fonts are served from the website’s own files and cause no request to IBM.
3. Website delivery and technical security
The static website is delivered through Cloudflare Workers and Cloudflare’s network. Cloudflare processes technical connection data, particularly the IP address, time, requested resource, and browser or device information, to the extent required for delivery, network security, and attack mitigation.
The application writes no raw IP address to the commercial database or its logs. For public write requests, it creates a cryptographic digest using a secret additional value. The rate limiter sees only this digest and a short-lived counter.
The legal basis is Article 6(1)(f) GDPR: the legitimate interest in a secure, available, and abuse-resistant website. Where delivery is directly necessary for pre-contractual steps requested by an individual, Article 6(1)(b) GDPR may also apply.
Cloudflare D1 is provisioned for commercial data as a database with the European Union jurisdiction. This setting restricts where the D1 database runs and persistently stores data. It does not mean that Cloudflare’s global edge infrastructure processes all connection data only within the EU. Cloudflare may process data outside the EEA under its contractual and privacy terms, relying in particular on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
More information: Cloudflare privacy policy and D1 data location.
4. Local browser preference
If you expressly select light or dark display, the website stores that choice under schlieber-theme in your browser’s local storage. It contains no identifier, name, or contact details. It remains until you change it or clear it in the browser.
Storage is required to provide the display you selected (section 165(3) TKG 2021) and, insofar as personal data is involved, relies on Article 6(1)(f) GDPR.
5. Contact by email and phone
If you contact us by email or phone, the contact details, content, metadata, and any attachments you provide are processed to answer you, assess a possible mandate, or perform an existing contract.
The schlieber.net domain currently uses Microsoft 365 / Exchange Online for incoming email. Microsoft processes addressing, message, and technical-delivery data under the contractual and privacy terms applicable to the tenant. Do not send passwords, private keys, or special-category personal data by email unless specifically requested and protected.
The legal bases are Article 6(1)(b) GDPR for pre-contractual steps or a contract with the individual, and Article 6(1)(f) GDPR for business correspondence with a corporate contact. The legitimate interest is handling and documenting the enquiry.
Correspondence is kept until the matter is resolved and thereafter only for as long as required for follow-up, forming or performing a mandate, statutory records, or establishing, exercising, or defending legal claims. Contract- and accounting-relevant messages may be subject to the statutory periods in section 9.
More information: Microsoft privacy statement.
6. Newsletter and Brevo
Newsletter signup asks for an email address, language, and express consent. It becomes active only after separate confirmation through double opt-in. A confirmation link is valid for up to 48 hours. Cloudflare D1 holds subscription, consent, withdrawal, and suppression status; Brevo does not hold the authoritative subscriber list.
Brevo (Sendinblue GmbH, Berlin, part of the Brevo group) transports confirmation, newsletter, and lifecycle messages. Brevo receives the email address and message and returns technical delivery events such as delivery, deferral, bounce, complaint, block, or unsubscribe.
Brevo open and click tracking is enabled and may record interactions in Brevo’s systems. schlieber.net does not import those open or click events into its own database. Messages include HTML and plain-text versions. The HTML prepared by schlieber.net loads no remote content; Brevo may route links through its tracking domains.
The legal basis for newsletter delivery is consent under Article 6(1)(a) GDPR in conjunction with section 174 TKG 2021. You may withdraw consent at any time through the unsubscribe link or by email.
Unconfirmed addresses are erased no later than 30 days after the request. After unsubscribe or hard suppression, the raw address and stored newsletter bodies are removed. A peppered pseudonym, consent and withdrawal timestamps, and minimal suppression state remain to honour and evidence the withdrawal.
More information: Brevo privacy policy.
7. B2B mandates
The following data may be processed when forming and performing a mandate:
- names, business contact details, role, and authority to represent;
- company, billing address, order, and contract references;
- meeting notes, requirements, decisions, approvals, and project communications;
- supplied system, architecture, security, and governance material;
- performance, time, acceptance, and billing evidence.
The purposes are selecting, forming, planning, delivering, and documenting a mandate, communication, quality assurance, billing, and legal defence. The legal bases are Article 6(1)(b) GDPR for contracts with individuals, Article 6(1)(f) GDPR for corporate contacts and staff, and Article 6(1)(c) GDPR for statutory duties.
The client is responsible for supplying only personal data that is necessary for the mandate and may lawfully be disclosed. If schlieber.net processes personal data on the client’s behalf, an Article 28 GDPR data-processing agreement will be concluded before that processing starts. Special-category data belongs in a mandate only where expressly agreed, lawful, and technically protected.
8. Recipients and international transfers
| Recipient | Function | Location or international aspect |
|---|---|---|
| Cloudflare | Website delivery, D1, queues, and rate limiting | global infrastructure; D1 database with EU jurisdiction; possible US processing |
| Microsoft | Email mailbox and delivery | EU contracting entity with global infrastructure |
| Brevo | Email transport and provider tracking | Germany/France; processing under provider terms |
Article 28 GDPR agreements are concluded with processors where required. International transfers rely, as applicable, on adequacy decisions, the EU-U.S. Data Privacy Framework, and/or Standard Contractual Clauses with necessary supplementary measures. Data may also be disclosed to authorities, courts, or professional advisers where legally required or necessary for legal claims.
9. Retention
- Email and phone enquiries: under the criteria in section 5.
- Unconfirmed newsletter request: raw address for no more than 30 days; action link valid for up to 48 hours.
- Confirmed newsletter: until withdrawal or suppression; then only minimal pseudonymous evidence and suppression state.
- Contract, invoice, and accounting documents: generally seven years from the end of the relevant calendar year under section 132 of the Austrian Federal Fiscal Code (BAO); longer where required for a pending procedure or legal claim.
- Project records: for the mandate and thereafter according to warranty, limitation, documentation, and legal-defence needs; mandatory law prevails.
- Technical security data: only for as long as required for operation, abuse prevention, and fault analysis.
A documented retention hold may temporarily prevent erasure. Restriction and legally required retention are recorded as such and are not represented as erasure.
10. Your rights
Subject to statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), and objection (Article 21). You may withdraw consent at any time with future effect under Article 7(3) GDPR.
Email mail@schlieber.net to exercise a right. Appropriate proof of identity may be required to protect the individual concerned.
You may complain to a supervisory authority. In Austria:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
www.dsb.gv.at
11. Required data and automated decisions
Where data is required for an offer, contract, or invoice, the relevant service cannot be provided without it. Newsletter information is voluntary.
schlieber.net makes no solely automated decision within Article 22 GDPR. Providers may perform their own automated security checks.
12. Security and confidential material
Access is restricted, transmissions are encrypted, and confidential values are not placed in public URLs or logs. No technical system is risk-free. Send highly confidential material only after an appropriate transfer channel and mandate boundary have been agreed.
13. Changes
This policy is updated when data flows, providers, retention periods, or legal bases change. The version and effective date shown on this page identify the applicable text.