Legal
Privacy Policy
Last updated: August 2026
One item here still needs a real answer before this goes live: the name of the hosting provider in "Hosting and server logs" below, which depends on which of the two paths in DEPLOY.md you pick. Everything else reflects how the site actually works today. Have a lawyer confirm this before launch regardless — it's a solid foundation, not a substitute for legal sign-off.
1. Overview
ORENDA Nachfolge GmbH ("we", "us") operates this website as a static, read-only informational site. There is no contact form, no user accounts, no shopping cart, and — as of today — no analytics or advertising trackers of any kind. This policy explains what little personal data the site does touch, why, and what rights you have over it under the EU General Data Protection Regulation (GDPR) and, where applicable, the Austrian Data Protection Act (DSG).
2. Who is responsible for your data (the "controller")
ORENDA Nachfolge GmbH, Vienna, Austria, is the data controller for this website. Full registered company details are in the Impressum. For anything privacy-related, contact:
thomas@orenda-nachfolge.com
+43 699 12171670
3. What data we process, and why
3.1 Visiting the site — hosting and server logs
Like effectively every website, the server that delivers these pages automatically records a short-lived technical log for each request: your IP address, browser and device type, the page requested, and the date and time. This happens automatically at the infrastructure level — the site itself contains no tracking code, and this data is never linked to any profile of you. It's processed solely to keep the site running securely (detecting abuse, diagnosing errors), on the basis of our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR), and is typically retained for a short, provider-defined period before automatic deletion.
Hosting provider: [name of hosting provider — to be completed once a host is chosen; see DEPLOY.md]. Their own privacy policy governs exactly how long these logs are kept and where their servers are located.
3.2 Cookies and similar technologies
This site does not set cookies, does not use browser local storage for tracking, and does not embed any third-party analytics, advertising, or social-media widgets. Because nothing is stored on or read from your device for tracking purposes, no cookie-consent banner is shown — there is nothing here that would require one under the ePrivacy Directive. If that ever changes (for example, if we add a privacy-first analytics tool), this section will be updated to match, and a consent mechanism will be added first if the tool we choose requires one.
3.3 Booking a conversation (Calendly)
Every "Book a Conversation" button on this site is a plain link that opens Calendly's scheduling page in a new tab — it is not embedded on this site as a script or iframe, and no data is exchanged between this site and Calendly before you click it. If you go on to book a call, the information you enter there (such as your name, email address and any notes) is collected and processed directly by Calendly, Inc., under Calendly's own privacy policy, as an independent controller of that data — not on our behalf. We only see the booking details Calendly's confirmation email chooses to share with us. Calendly is a US-based company; any transfer of your data outside the EEA in this process is governed by Calendly's own safeguards (such as the EU-U.S. Data Privacy Framework or standard contractual clauses), not by us.
3.4 Contacting us directly (email or phone)
If you email or call us directly, we process whatever personal data you choose to share — your name, contact details, and the content of your message — solely to respond to your enquiry. The legal basis is our legitimate interest in handling correspondence (Art. 6(1)(f) GDPR), or the taking of pre-contractual steps at your request (Art. 6(1)(b) GDPR) if your enquiry concerns a potential engagement with us. We keep these messages only as long as needed to handle the conversation and any reasonable follow-up, and delete them once that purpose has passed.
3.5 The one-page PDF download
The downloadable overview PDF linked from this site is a static file. Downloading it does not involve any form, tracking pixel, or data submission on your part.
4. Who we share data with
We do not sell, rent, or trade personal data. The only parties involved in processing data described above are our hosting provider (server logs, as infrastructure necessarily requires) and Calendly (only for those who actively choose to book through it, and as an independent controller of that specific data — see 3.3). We do not use any other data processors, ad networks, or analytics vendors at this time.
5. International data transfers
This website's hosting infrastructure may be located within or outside the European Economic Area, depending on the provider ultimately chosen (see section 3.1). Where personal data is transferred outside the EEA — including via Calendly, a US company, for those who choose to book a call — such transfers rely on recognized safeguards such as the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses, as implemented by the relevant provider.
6. How long we keep data
Server logs are retained only for the short period our hosting provider needs for security and operational purposes, then automatically deleted or anonymized. Emails and other direct correspondence are kept only for as long as reasonably needed to handle your enquiry and any follow-up, and are deleted once that purpose has passed unless a longer retention is legally required (for example, statutory bookkeeping obligations for correspondence tied to an actual engagement).
7. Your rights
Under the GDPR, you have the right to:
- request access to the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure of your data ("right to be forgotten");
- request that we restrict how we process your data;
- object to processing based on our legitimate interest;
- request a portable copy of data you provided to us; and
- lodge a complaint with a data protection supervisory authority.
To exercise any of these rights, contact us at thomas@orenda-nachfolge.com. We'll respond within the timeframes required by law. If you believe we haven't handled your data properly, you can lodge a complaint with the Austrian data protection authority (Österreichische Datenschutzbehörde, dsb.gv.at), or with the supervisory authority in your own EU member state.
8. Children's privacy
This site is directed at business owners and investors, not children, and we do not knowingly collect personal data from anyone under 16.
9. Changes to this policy
We may update this policy as the site or applicable law changes. The version published here always applies; the date at the top of this page reflects the most recent update.