START

[ LEGAL ] - privacy

Privacy Policy

This policy explains which personal data is processed when you visit this website or use its features.

This English version is provided for convenience. If the versions differ, the German Privacy Policy prevails.

1. General information and legal basis

Protecting your personal data is important to us. We process data only within the applicable legal framework, in particular Regulation (EU) 2016/679 (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act 2021 (TKG 2021).

This policy covers the public website, contact form, language selection, protected content-management access, and the optional online payment feature when it is enabled.

2. Controller

Sven Avmedoski - AVM FORGE

Kadettengasse 29, 8041 Graz, Austria

Email: [email protected] - any language · Phone: +43 676 5714 322 - English

Based on the current circumstances, the controller is not legally required to appoint a data protection officer.

3. Website delivery, hosting, security, and server logs

The website runs on a server operated by Hetzner Online GmbH within the EU. Hetzner processes the data required to operate the server as a processor. More information: Hetzner privacy policy .

We use Cloudflare, Inc. for DNS, edge delivery, and protection against abusive traffic. Cloudflare processes the IP address, time, requested address, and technical request information for these purposes. More information: Cloudflare Privacy Policy .

The origin server records technical access data. Full IP addresses are not written to the access logs: IPv4 addresses are reduced to /24 networks and IPv6 addresses to /48 networks. Cookie and authorization headers are removed, while OAuth codes and state or payment identifiers in query parameters are redacted. Logs are deleted after 14 days.

This processing is technically necessary for secure and reliable operation and is based on our legitimate interests under Article 6(1)(f) GDPR. All connections to the website are encrypted using TLS (HTTPS).

4. Contact inquiries, email delivery, and abuse prevention

If you contact us through the form or by email, we process your name, email address and/or phone number, package and add-on context, and your message. We use this information to respond to the inquiry and any follow-up questions. The legal bases are steps requested before entering into a contract under Article 6(1)(b) GDPR and our legitimate interest in responding under Article 6(1)(f) GDPR.

We use Resend (Plus Five Five, Inc., United States) to deliver form emails. The message is delivered to our Google Workspace mailbox. Published data-protection terms are available in the Resend Data Processing Addendum and Google data transfer frameworks .

To protect the form against abuse, the IP address confirmed by the trusted proxy is used only in process memory to limit submissions to five attempts within ten minutes. This rate-limit state is not stored permanently.

Inquiries that do not lead to a contract are deleted after 6 months. If a contract is formed, the applicable contractual and statutory retention periods apply.

5. Web analytics with self-hosted Umami

When audience measurement is enabled in the published website, we use a self-hosted Umami installation on our Hetzner infrastructure. We do not use Umami Cloud.

Umami records page views, referrers, approximate country, browser, operating-system and device categories, and explicitly configured event names. It does not set analytics cookies, store full IP addresses, or create profiles across websites. More information: Umami documentation .

The processing provides aggregate usage information and is based on our legitimate interest in improving the website and its content under Article 6(1)(f) GDPR. You may object by contacting the email address above.

6. Language selection and cookies

When you open the language-neutral homepage, the website evaluates the language preference sent by your browser once. It does not store that information permanently for this purpose.

When you use the language switcher, the website sets the functional first-party cookie avm_locale. It stores only de or en for twelve months. The cookie applies to the whole website, is HttpOnly, is also Secure over HTTPS, and uses SameSite=Lax. It is not used for tracking or profiling.

The cookie is technically necessary to provide the language version you explicitly selected. It does not require consent or a cookie banner.

7. Protected content management with Decap CMS and GitHub

The /admin area is intended only for authorised editors. Its locally served Decap CMS interface uses GitHub OAuth to verify authorised access to the private content repository. Ordinary website visitors are not redirected to GitHub.

During sign-in, GitHub processes account, authorisation, and technical access data. The website protects the OAuth flow with an HttpOnly, Secure, SameSite=Lax cookie named decap_oauth_state, which expires after no more than ten minutes. OAuth codes and state values are redacted from server logs.

The legal basis is our legitimate interest in secure content administration under Article 6(1)(f) GDPR. More information: GitHub Privacy Statement .

8. Optional payment processing with Stripe Checkout

Online payments are offered only when the Stripe feature has been explicitly enabled. If checkout is not offered or started, this website does not send payment data to Stripe.

If you start an available checkout, you are redirected to a Stripe-hosted page. Stripe processes information including your name, email address, billing address, and payment-method details. We receive the payment status, amount, currency, and related booking information, but not complete card details.

Stripe Payments Europe, Ltd. (Ireland) and affiliated Stripe companies act as processors or independent controllers depending on the processing activity. The processing we initiate is based on steps requested before entering into a contract or performance of a contract under Article 6(1)(b) GDPR. More information: Stripe privacy policy .

For an electronic withdrawal request, we process the customer name, email address, booking reference, and optional message. Resend delivers the request to our Google Workspace mailbox and sends an acknowledgment. This processing supports contractual and legal obligations under Article 6(1)(b) and (c) GDPR.

9. Recipients and international transfers

Personal data is disclosed only to the provider needed for the relevant purpose: Hetzner for EU hosting, Cloudflare for delivery and security, Resend and Google Workspace for email communication, GitHub for authorised content-management access, and Stripe only when an available checkout is used.

Where data is transferred to the United States or another country outside the European Economic Area, transfers to certified US recipients rely on the EU-US Data Privacy Framework; otherwise, they rely on Standard Contractual Clauses or other appropriate safeguards under Articles 44 et seq. GDPR. You may request a copy of the applicable safeguards by emailing [email protected] .

10. Your rights

Subject to the conditions in Articles 15–21 GDPR, you have rights including access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you may withdraw that consent at any time for the future. To exercise your rights, contact [email protected] .

If you believe that the processing of your data infringes data-protection law, you may complain to the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, Austria, phone +43 1 52 152-0, [email protected] . Current contact details: dsb.gv.at/kontakt .

11. Retention periods

Masked server logs are retained for 14 days. The form limiter counts only requests made during the preceding ten minutes; its bounded in-memory key map is not persisted and is discarded no later than the next application-process restart. The OAuth state cookie lasts no more than ten minutes, and the language cookie no more than twelve months.

Inquiries that do not result in a contract are deleted after 6 months. Contract and invoice data is kept for the statutory retention period, generally seven years under section 132 of the Austrian Federal Fiscal Code (BAO).

Aggregate Umami statistics remain in the self-hosted database until they are no longer needed and are manually deleted; they do not contain full IP addresses. Data that a provider processes as an independent controller is also subject to that provider’s published retention rules and legal obligations.

12. Last updated, changes, and controlling language

Last updated: 29 July 2026. We update this policy when the services, processing activities, or applicable law change. The version published here at the relevant time applies.

This English version is a translation provided for convenience. If there is any conflict or difference in interpretation, the German version prevails.