Last updated: August 2026
The protection of your personal data is a high priority for us. In the following, we inform you in accordance with Articles 13 and 14 GDPR about which data we process when you visit costvise.com, for what purposes and on what legal basis this takes place, and what rights you have in this regard.
This English version is provided for your convenience. In the event of any discrepancy, the German version of this Privacy Policy prevails.
1. Controller
2. General Information on Data Processing
3. Webflow (Website Hosting)
4. Cookies and Consent Management
5. Web Analytics (Google & Microsoft)
6. Google Fonts
7. Contact by Email
8. Cal.com (Appointment Booking)
9. HubSpot (CRM)
10. Recipients and Processors
11. Automated Decision-Making
12. Your Rights
13. Right to Lodge a Complaint
14. Data Security
15. Changes to This Privacy Policy
Costvise GmbH
Birkengasse 53
3100 St. Pölten
Austria
Email: office@costvise.com
A data protection officer has not been appointed, as the legal requirements under Article 37 GDPR do not apply. For all data protection matters, please contact the email address above.
We process personal data only insofar as this is necessary to provide a functional website as well as our content and services, or where you have given your consent. Personal data means any information relating to an identified or identifiable natural person.
The legal basis for each processing activity is set out in the individual sections below.
Our website is hosted by Webflow.
Provider: Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA
When you access our website, Webflow, acting as our processor, automatically collects information transmitted by your browser (server log files):
This data is technically necessary to deliver the website to you, to ensure system security, and to detect malfunctions.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable, and efficient provision of our online offering.
Retention period: Log files are deleted or anonymized after 30 days at the latest.
Transfer to the USA: Processing may involve a transfer to the USA. A data processing agreement under Article 28 GDPR is in place with Webflow. The transfer is carried out on the basis of the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) or, where the provider is certified, on the basis of the EU-US Data Privacy Framework (adequacy decision under Article 45 GDPR).
Further information: https://webflow.com/legal/privacy
Our website uses cookies and comparable technologies. Cookies are small text files stored on your device.
We distinguish between:
Technically necessary cookies: These are required for the operation of the website, for example to store your cookie choice or for security functions. They are set without your consent.
Legal basis: Article 6(1)(f) GDPR in conjunction with Section 165(3) of the Austrian Telecommunications Act (TKG 2021).
Consent-based cookies and services: All cookies and scripts beyond this, in particular for analytics and statistical purposes, are only set after you have actively consented in the cookie banner.
Legal basis: Article 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021.
To manage your consent, we use a consent management solution based on Finsweet Cookie Consent in opt-in mode. Your choice is stored locally in your browser so that the prompt does not reappear on every page load. Supplementary script components are loaded via the jsDelivr content delivery network, whereby your IP address is transmitted to the CDN operator.
You can withdraw your consent at any time with effect for the future by opening the cookie settings on our website again or by deleting the cookies in your browser.
We use Google Tag Manager (container ID: GTM-5RQ993NL), a tool for managing website tags. The Tag Manager itself does not create user profiles and does not store cookies; it serves solely to integrate and control other services. However, your IP address is transmitted to Google when the Tag Manager loads.
We use Google Analytics 4 (measurement ID: G-5P1FE3TRHJ), a web analytics service for evaluating the use of our website.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Google Analytics uses cookies and similar technologies to collect information about your use of the website, in particular:
We have activated IP anonymization, so that your IP address is truncated within the EU or EEA before it is transmitted.
Purpose: analysis and statistical evaluation of website usage in order to improve our offering as needed.
Legal basis: Article 6(1)(a) GDPR. Processing takes place exclusively after your consent in the cookie banner. You can withdraw this at any time with effect for the future.
Retention period: Data collected at user and event level is automatically deleted after 14 months.
Transfer to the USA: A transfer to Google LLC in the USA cannot be excluded. Google LLC is certified under the EU-US Data Privacy Framework, so the transfer is based on an adequacy decision under Article 45 GDPR. Standard Contractual Clauses additionally apply.
A data processing agreement is in place with Google.
Further information: https://policies.google.com/privacy
Browser add-on to opt out: https://tools.google.com/dlpage/gaoptout
We use Microsoft Clarity, a tool for analyzing user behavior on our website.
Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Clarity uses cookies and similar technologies to record and evaluate your interactions with our website. In particular, the following is collected:
Entries in form fields and content identified as sensitive are masked by default by Clarity and are not transmitted in plain text. The recordings are reproductions of your interactions, not video or screen captures of your device.
Microsoft may combine the collected data with other data obtained from the use of other Microsoft services and use it for its own purposes, including personalized advertising. In this respect, Microsoft is not acting solely as a processor but as an independent controller.
Purpose: understanding the actual use of our website, identifying usability problems, and improving user guidance.
Legal basis: Article 6(1)(a) GDPR. Processing takes place exclusively after your consent in the cookie banner. You can withdraw this at any time with effect for the future.
Retention period: The data collected is deleted after 13 months at the latest.
Transfer to third countries: A transfer to Microsoft Corporation in the USA cannot be excluded. Microsoft Corporation is certified under the EU-US Data Privacy Framework. Standard Contractual Clauses additionally apply.
Further information: https://privacy.microsoft.com/en-us/privacystatement
To display fonts consistently, our website embeds the Rethink Sans font via Google Fonts.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
When you access a page, your browser loads the required font files from a Google server. In doing so, your IP address is transmitted to Google. Google thereby becomes aware that our website has been accessed via your IP address.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the consistent and appealing presentation of our online offering.
Further information: https://developers.google.com/fonts/faq and https://policies.google.com/privacy
If you contact us by email, we process the data you provide, in particular your email address, your name, and the content of your message, solely to handle your request.
Legal basis: Article 6(1)(b) GDPR where your request is aimed at concluding or performing a contract, otherwise Article 6(1)(f) GDPR based on our legitimate interest in responding to inquiries.
Retention period: We delete your inquiry once it has been conclusively dealt with and no statutory retention obligations apply. Business-related correspondence is subject to a retention obligation of seven years under Section 132 of the Austrian Federal Fiscal Code (BAO) and Section 212 of the Austrian Commercial Code (UGB).
We point out that the transmission of data by unencrypted email may have security vulnerabilities.
For scheduling demo appointments, we offer online appointment booking.
Provider: Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA
We use the European instance of the service (cal.eu) with hosting in the European Union (Frankfurt region).
When you book an appointment, we process the data you enter, in particular your name, email address, requested appointment, and any voluntary additional information. This data is used solely to organize and conduct the appointment.
Legal basis: Article 6(1)(b) GDPR, as the processing is necessary to carry out pre-contractual measures at your request.
Data storage: Due to the European instance we have selected, appointment data is stored and processed within the EU or EEA. Storage or transfer outside the EU or EEA does not take place unless required by law. Access from third countries may be necessary in individual cases for maintenance, to remedy malfunctions, or to maintain operations, and is then safeguarded by the European Commission's Standard Contractual Clauses.
A data processing agreement under Article 28 GDPR is in place with Cal.com.
The appointment is conducted via Microsoft Teams.
Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Connection data as well as the content of the communication are processed. A recording only takes place if we inform you separately in advance and obtain your consent.
Transfer to third countries via Microsoft Teams: A transfer to Microsoft Corporation in the USA cannot be excluded. Microsoft Corporation is certified under the EU-US Data Privacy Framework. Standard Contractual Clauses additionally apply. A data processing agreement is in place with Microsoft.
Retention period: Appointment data is deleted once it is no longer required for the purposes, but at the latest after the expiry of statutory retention periods.
Further information: https://cal.com/privacy and https://privacy.microsoft.com/en-us/privacystatement
We use a customer relationship management system to manage business contacts.
Provider: HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland
Data is not automatically transferred from our website or the appointment booking to the CRM. We enter contact data there exclusively manually and only where a specific business interest arises from a conversation. In doing so, we process name, business contact details, organization, role, and notes on the status of the business development.
Purpose: initiation, documentation, and handling of business relationships.
Legal basis: Article 6(1)(b) GDPR for processing in the context of pre-contractual measures or a contractual relationship, otherwise Article 6(1)(f) GDPR based on our legitimate interest in the orderly management of our business contacts.
Retention period: We delete the data once the purpose no longer applies, in particular where there is no longer a business interest, and no statutory retention obligations apply.
Transfer to third countries: A transfer to HubSpot, Inc. in the USA cannot be excluded. This is based on the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework. A data processing agreement is in place with HubSpot.
Further information: https://legal.hubspot.com/privacy-policy
Your data is only transferred to third parties where this is legally permitted. Recipients are in particular the service providers named in this policy, who act as our processors under Article 28 GDPR, as well as authorities and courts where there is a legal obligation.
We do not sell your personal data.
Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place on this website.
You have the following rights regarding the personal data concerning you:
To exercise your rights, a message to office@costvise.com is sufficient.
Without prejudice to any other legal remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your data infringes the GDPR.
The supervisory authority responsible for us is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Web: https://www.dsb.gv.at
We implement technical and organizational measures in line with the state of the art to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access. Our website uses TLS encryption, recognizable by the address bar of your browser.
We reserve the right to amend this Privacy Policy so that it always complies with current legal requirements or to implement changes to our services. The version then current applies to your next visit.