01 — ResponsibilityController within the meaning of the GDPR
- Controller
- VORALYN Technologies GmbH i.G.
- Address
- Jodok-Stuelz-Weg 17
6850 Dornbirn
Vorarlberg, Austria - hello@voralyn.tech
- Represented by
- Stefan Ebenhoch, Manuel Henny
- Data protection officer
- Not appointed — the statutory conditions under Article 37 GDPR are not met. Please address enquiries to the contact above.
Further company details are set out in the legal notice.
This is a courtesy translation. The German version of this page is the legally binding one; in case of any discrepancy the German text prevails.
02 — OverviewWhat this is about
This website consists of static pages. It has a contact form, but no login, no shopping basket and no comment function. All fonts, scripts and graphics sit on our own server — no content is loaded from third parties, captchas included.
- Opening the page creates technical server log files.
- No cookies are set and no data is stored in your browser — not for the contact form either.
- Beyond that we process only what you write to us yourself.
- There is no audience measurement, no analytics and no advertising.
We process personal data only where this is technically necessary to run the website or where you write to us of your own accord.
03 — AccessServer log files
Each time a page is opened your browser transmits data for technical reasons, which our web server records in log files:
- IP address of the requesting device
- date and time of access
- name and URL of the file retrieved
- volume of data transferred and HTTP status code
- browser and operating system used (user agent)
- where applicable, the previously visited page (referrer)
Purpose and legal basis
The processing serves technically sound operation, delivery of the content and defence against attacks. The legal basis is our legitimate interest in a secure and functioning web presence under Article 6(1)(f) GDPR.
Retention
Log files are deleted automatically after 14 days at the latest. They are kept longer only where a specific security incident requires analysis; the entries concerned are then deleted once the investigation is complete.
This data is not merged with other sources and is not analysed for marketing purposes.
04 — OperationHosting and processing on our behalf
The website runs on servers of Hetzner Online GmbH, Industriestrasse 25, 91710 Gunzenhausen, Germany. The servers are located within the European Union.
Hetzner processes the connection data above solely on our behalf and on our instructions. A data processing agreement under Article 28 GDPR is in place.
Transport encryption
The connection to this website is encrypted throughout with TLS (visible as https:// in the address bar). Requests over unencrypted HTTP are redirected to HTTPS automatically. Content you send us cannot readily be read by third parties in transit.
06 — EnquiriesContact form and email
When you write to us we process the data you provide solely in order to deal with your enquiry.
Which fields the form collects
- Required: name, email address, topic and your message
- Optional: company and telephone number
- technically in addition: the time of sending
The details are not stored in a database but delivered to us as an email. We use a service provider for delivery; which one and on what terms is set out in section 07.
Protection against automated submissions
To limit how many enquiries originate from one sender we keep a counter for 24 hours. Your IP address is not stored in plain text for this, only as a one-way check value. The legal basis is our legitimate interest in a functioning contact channel (Article 6(1)(f) GDPR).
Legal basis
- Article 6(1)(b) GDPR where your enquiry is aimed at concluding or performing a contract
- Article 6(1)(f) GDPR in all other cases — our legitimate interest lies in being able to answer enquiries
Retention
We delete your message six months after it has been dealt with, unless a statutory retention obligation applies. If the contact leads to a contract, the commercial and tax retention periods of up to seven years apply (§ 212 UGB, § 132 BAO).
Please note: unencrypted email is not a secure channel. If you wish to send us confidential information, talk to us first — we will then agree an encrypted route.
07 — DisclosureRecipients and transfers to third countries
Your data is passed on only where this is necessary for the purposes stated. The recipients are:
- our hosting provider (see section 04)
- Sinch Germany GmbH (Mailgun), Trakehner Strasse 7–9, 60487 Frankfurt am Main, Germany — for delivering the form messages. We expressly use the EU region of the service; processing takes place on servers within the European Union. A data processing agreement under Article 28 GDPR is in place.
- our email provider for receiving and sending messages
- authorities and courts, where we are legally obliged to provide information
No transfer takes place to countries outside the EU or the EEA. Should that change in future we will say so here and name the safeguards under Article 44 et seq. GDPR.
Your data is not sold, not rented out and not used for third-party advertising.
08 — PeriodsRetention at a glance
- Server log files
- maximum 14 days
- Email correspondence
- 6 months after the matter is closed
- Contract documents
- 7 years (statutory retention)
- Form enquiries
- as for email correspondence
- Anti-spam counter
- 24 hours, as a check value only
- Cookies
- not applicable — none are set
Once the relevant period expires the data is deleted or, where deletion is not technically possible, its processing is restricted.
09 — Data subject rightsYour rights
You have the following rights towards us:
- Access (Article 15 GDPR) — whether and what data we process about you
- Rectification (Article 16 GDPR) — correction of inaccurate data
- Erasure (Article 17 GDPR) — where no retention obligation applies
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR) — release in a common format
- Objection (Article 21 GDPR) — to processing we base on a legitimate interest
- Withdrawal of consent (Article 7(3) GDPR) — with effect for the future
An informal message to hello@voralyn.tech is enough. Exercising these rights is free of charge. We reply within one month; if a request exceptionally needs more time, we will tell you.
To prevent misuse we must be able to establish your identity beyond doubt. Where there is reasonable doubt we will ask for additional details.
10 — SupervisionComplaint to the supervisory authority
If you consider that the processing of your data infringes the GDPR, you may complain to a supervisory authority without prejudice to other remedies. In Austria this is:
- Authority
- Austrian Data Protection Authority
- Address
- Barichgasse 40–42
1030 Vienna, Austria - Web
- dsb.gv.at
We would be glad if you came to us first — a great deal can be sorted out directly.
11 — AI and profilingAutomated decisions
No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place. Your data is not used to evaluate or predict your behaviour.
We build AI systems for our clients. Data that reaches us through this website is not used to train models — neither our own nor those of third parties.
12 — CurrencyChanges to this policy
We update this privacy policy when the legal situation or our processing activities change. The version published here applies to each new visit.
Last updated: September 2026