Skip to content
Legal

Privacy policy.

Version 2.0 · Last updated: June 2026

1. Data controller (Art. 4(7) GDPR)

PureSurf FlexCo, Sandgasse 36/IV, 8010 Graz, Austria
Phone: +43 664 4788120
Email: office@puresurf.eu

2. Data Protection Officer

Given the size and nature of our processing activities, we are not legally required to appoint a Data Protection Officer (Art. 37 GDPR). Please direct all privacy enquiries to office@puresurf.eu.

3. Data processed and sources

We only process personal data that you actively provide to us yourself. We do not collect personal data from third-party sources within the meaning of Art. 14 GDPR.

  • Contact and form data: Name, company, role, email address, phone number, area of application and interest, message, attachments where provided.
  • Technical server logs: IP address (truncated where technically possible), browser type and version, operating system, referrer URL, time of access.
  • Consent data: Your cookie preferences, timestamp and version of consent (stored locally in your browser).

4. Purposes and legal bases (Art. 6 GDPR)

  • Handling your enquiry / sample request: Art. 6(1)(b) GDPR (pre-contractual measures).
  • Operating and securing the website: Art. 6(1)(f) GDPR (legitimate interest in providing a secure and functional website).
  • Sending confirmation emails: Art. 6(1)(b) GDPR.
  • Optional cookies / analytics: Art. 6(1)(a) GDPR in conjunction with § 165(3) TKG 2021 (Austrian Telecommunications Act): consent.
  • Statutory retention obligations: Art. 6(1)(c) GDPR (e.g. Austrian Commercial Code, Federal Fiscal Code).

5. Recipients and processors (Art. 28 GDPR)

We only share your data with the following carefully selected processors, bound by Art. 28 GDPR data processing agreements:

  • Supabase (EU): Database hosting, storage of form data and edge functions, EU region (Frankfurt).
  • Brevo (EU): Sending of transactional emails (confirmations, replies). Operator: Sendinblue SAS, Paris, France.
  • Lovable / Cloudflare: Hosting, content delivery network and DDoS protection. Data is transmitted in encrypted form via the EU network.

6. Transfers to third countries

Your data is primarily processed within the European Union. If, in individual cases (e.g. support or CDN routing), a transfer to a third country becomes necessary, it will only occur on the basis of appropriate safeguards within the meaning of Art. 46 GDPR (in particular EU Standard Contractual Clauses, SCCs) or a valid adequacy decision (e.g. EU-US Data Privacy Framework).

7. Retention periods

  • Enquiries / sample requests: maximum of 24 months after the last contact.
  • Business correspondence with tax / commercial relevance: 7 years (§ 132 BAO, § 212 UGB).
  • Server logs: 7 to 30 days.
  • Cookie consent: 12 months from the date given.

8. Your rights as a data subject

You have the right at any time to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and to withdraw any given consent at any time with effect for the future (Art. 7(3) GDPR).

Please send your requests to office@puresurf.eu.

9. Automated decision-making / profiling

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.

10. Cookies and similar technologies

By default we only set strictly necessary cookies. Optional cookies (analytics, preferences, marketing) are only set after your explicit, granular consent given via our cookie banner (§ 165(3) TKG 2021 in conjunction with Art. 6(1)(a) GDPR). You can give, change or withdraw consent at any time.

11. Right to lodge a complaint with the supervisory authority

Without prejudice to any other remedies, you have the right to lodge a complaint with the Austrian Data Protection Authority (Art. 77 GDPR):

Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at

12. Security (Art. 32 GDPR)

We implement appropriate technical and organisational measures to protect your data, in particular TLS encryption of all data transmission (HTTPS), strict access controls and regular security updates.

13. Changes to this privacy policy

We reserve the right to amend this privacy policy in order to adapt it to changes in the legal situation or in our services. The current version is always available on this page.

Supported by

  • Supported by European Innovation Council
  • Supported by European Research Council
  • aws Austria Wirtschaftsservice
  • Research partner University of Graz
  • Research partner University of Groningen
  • Research partner TU Graz
  • Research partner Medical University of Graz
  • Supported by Creative Destruction Lab
  • Supported by chemstars.nrw
  • Supported by IECT Hermann Hauser
  • Supported by Startup-uni.at
  • Supported by BMK, Austrian Federal Ministry for Climate Action
  • Supported by Science Park Graz
Supported by European Innovation Councilaws Austria Wirtschaftsservice

Spin-off from an EIC Transition (grant agreement #101058142). Views and opinions expressed are those of the author(s) only and do not necessarily reflect those of the European Union or the European Innovation Council. The PureSurf FlexCo has received aws PreSeed funding from BMIMI.