Demo access
LegalPrivacy

Privacy Policy

In accordance with Article 13 of the General Data Protection Regulation (EU) 2016/679 (GDPR), the Austrian Data Protection Act (DSG) and Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021), this policy explains which personal data we process when you visit our websites, for which purposes, on which legal basis, to whom we disclose it, how long we keep it and which rights you have.

Last updated
[DD Month 2026]
Language
EnglishDeutsch
Contents
14 ·

Draft — open points are highlighted · 9

01Controller

Rostify GmbH
Tigergasse 17
1080 Vienna
Austria
Email: office@rostify.app
Phone: +43 1 4120052
Company register: FN 522237x, Commercial Court of Vienna

For all data protection matters, contact us at office@rostify.app or at the postal address above. We have not appointed a data protection officer, as the requirements of Article 37 GDPR do not apply to us.

02Scope

This policy applies to

  • the website www.rostify.app (including its English version) and
  • the product documentation at docs.rostify.app.

[OPEN – see change log, item A: add or delete sentence on shop.rostify.app and login.rostify.app.]

03Visiting our websites (server log files)

Purpose:
When you access www.rostify.app or docs.rostify.app, your browser necessarily transmits data to our web server. We process this data to deliver the pages to you, to keep the service stable and to detect and repel attacks on our servers.
Data:
IP address, date and time of access, requested address (URL), previously visited page (referrer), amount of data transferred, HTTP status code, browser type and version, and operating system (user agent).
Legal basis:
Article 6(1)(f) GDPR. Our legitimate interest is the secure and functional provision of our websites.
Retention:
We delete server log files after 30 days. If a specific attack is detected within this period, we keep the affected entries until the investigation is complete.
Provision:
Without this data, the websites cannot technically be accessed.

04Protection against automated attacks

To protect against spam and automated access, www.rostify.app uses a security module that runs on our own server. It sets the cookie icwp-wpsf-notbot, valid for 10 minutes, and evaluates the IP address and access behaviour to distinguish bots from human visitors.

Legal basis: Section 165(3) TKG 2021 (strictly necessary storage) and Article 6(1)(f) GDPR. Our legitimate interest is protecting the website and the contact form against misuse.

05Contacting us by form, email or phone

Purpose:
Answering your enquiry and, where applicable, preparing a contract.
Data:
Name, email address, subject and message (contact form), or the information you give us by email or phone.
Legal basis:
Article 6(1)(b) GDPR where your enquiry concerns the conclusion or performance of a contract; otherwise Article 6(1)(f) GDPR. Our legitimate interest is answering enquiries addressed to us.
Recipients:
Form submissions are sent as an email to our mailbox. Our web server and mailbox are operated for us by Host Europe GmbH, Germany, as processor (see section 9).
Retention:
We delete enquiries that do not lead to a contract [12 months] after the correspondence has ended. If an enquiry leads to a contract, we retain the correspondence as business correspondence for seven years from the end of the calendar year (Section 212 Austrian Commercial Code (UGB), Section 132 Austrian Federal Fiscal Code (BAO)), and beyond that only as long as it is relevant to pending proceedings.
Provision:
Name and email address are mandatory fields; without them we cannot reply. There is no legal or contractual obligation to contact us.

06Product documentation at docs.rostify.app

Purpose:
Providing the Rostify manual to our customers and their staff. Protected areas are accessible only after login.
Data:
Username, [email address, name], password (stored exclusively as an encrypted hash), time of login, and the server log data described in section 3.
Cookie:
For login, docs.rostify.app sets a session cookie (grav-site-…) valid for 30 minutes.
Legal basis:
Article 6(1)(b) GDPR where you are our contractual partner yourself. If you use the documentation as an employee of a customer, the legal basis is Article 6(1)(f) GDPR; our legitimate interest is providing the contractually owed documentation to the persons designated by our customer. For the session cookie: Section 165(3) TKG 2021.
Retention:
We delete access credentials as soon as access is no longer needed, at the latest [3 months] after the end of the contract with the respective customer.

07Cookies and similar technologies

Cookies are small text files that your browser stores on your device. We set strictly necessary cookies without consent on the basis of Section 165(3) TKG 2021. We set all other cookies only after you have actively consented in the cookie banner. Rejecting is as easy as accepting.

Cookie Website Purpose Duration Consent
pll_language www.rostify.app Stores the selected language version 1 year not required
icwp-wpsf-notbot www.rostify.app Protection against automated attacks (section 4) 10 minutes not required
[name of consent cookie] www.rostify.app Stores your choice in the cookie banner [duration] not required
grav-site-… docs.rostify.app Login session (section 6) 30 minutes not required
_ga, _ga_09ZGBH7CHY www.rostify.app Google Analytics (section 8) [up to 2 years] required

Changing or withdrawing consent: The “Cookie settings” link in the footer of every page reopens the cookie banner, where you can change or withdraw your consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal (Article 7(3) GDPR).

09Recipients and processors

We do not sell personal data and do not disclose it for advertising purposes. The following service providers process data solely on our behalf and on our instructions under a contract pursuant to Article 28 GDPR:

Recipient Location Service
Host Europe GmbH Germany Web hosting (www.rostify.app, docs.rostify.app), email
STRATO AG Germany [add service]
Google Ireland Limited (with sub-processor Google LLC, USA) Ireland / USA Google Analytics 4 – only with consent

Beyond this, we disclose data to authorities and courts only where we are legally obliged to do so (Article 6(1)(c) GDPR).

11No automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR.

12Data security

All our websites are accessible exclusively via encrypted HTTPS (TLS). We take technical and organisational measures under Article 32 GDPR to protect your data against loss, manipulation and unauthorised access, and keep them up to date with the state of the art. Please note: unencrypted emails are not protected against access by third parties in transit. Do not send us confidential information by unencrypted email.

13Your rights

You have the following rights regarding personal data concerning you:

  • Access (Article 15 GDPR)
  • Rectification (Article 16 GDPR)
  • Erasure (Article 17 GDPR)
  • Restriction of processing (Article 18 GDPR)
  • Data portability (Article 20 GDPR)
  • Withdrawal of consent at any time with effect for the future (Article 7(3) GDPR)

Send your request to office@rostify.app. We respond within one month; in complex cases this period is extended by at most two further months, and we will inform you of this (Article 12(3) GDPR).

Right to object (Article 21 GDPR)

Where we process your data on the basis of our legitimate interest (Article 6(1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process your data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Send your objection informally to office@rostify.app.

Right to lodge a complaint

If you consider that the processing of your data infringes data protection law, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. In Austria, this is the

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at

14Changes to this policy

We update this policy whenever our processing or the legal situation changes. The version published here applies; the date is shown at the top. This English version is a translation; in case of discrepancies, the German version prevails.

↑ Back to top