Legal

Privacy Policy

This is a translation for your convenience. The German version is the legally binding one: Datenschutzerklärung.

Last updated: 4 July 2026

1. Controller

Mag. Martin Posarnig – mpdigital
Gerbergasse 1
9500 Villach, Austria
Email: martinposarnig@mpdigital.at

If you have any questions about data protection, you can reach me at the address given above.

2. Principles of data processing

I process personal data exclusively in accordance with the European General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (Datenschutzgesetz, DSG). Personal data is collected only where this is necessary to provide my website and my services.

3. Access to the website (server log files)

Each time my website is accessed, the hosting provider automatically records information that your browser transmits in server log files:

  • IP address of the requesting device
  • Date and time of access
  • Name and URL of the page accessed
  • Browser and operating system used
  • Referrer URL (the page you visited before)

This data is evaluated solely to ensure the smooth operation of the website. It does not allow any conclusions to be drawn about you as a person.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical provision and security of the website).

4. Contact and appointment booking

If you book an appointment via my website, you are redirected to the booking service Microsoft Outlook Bookings. The data entered there (name, email address and, where applicable, phone number and message) is used solely to handle your enquiry and coordinate the appointment.

If you contact me directly by email or phone, I likewise process the data you provide solely to handle your enquiry.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures or contract initiation).

Your data is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations apply.

5. Processing of contact data for business development (CRM)

Purpose of processing

As part of my consulting work, I manage the contact data of managing directors, senior executives and other decision-makers in mid-sized companies in Austria, Germany and Switzerland (DACH region) in my own customer relationship management system (CRM). The purpose of processing is to initiate, conduct and maintain business relationships and to document the related communication.

No data protection officer has been appointed, as the statutory conditions requiring one do not apply.

Legal basis

  • Art. 6(1)(f) GDPR (legitimate interest) for processing the contact data of potential business partners in a B2B context. My legitimate interest lies in initiating and maintaining business relationships with decision-makers in mid-sized companies in the DACH region. The interests of the data subjects have been weighed against this; since only professional data is involved and the context is B2B, my legitimate interest prevails.
  • Art. 6(1)(b) GDPR (contract initiation and performance) for clients and for persons who actively initiate a business relationship with mpdigital.

Data categories

Only professional data is processed:

  • First name and surname
  • Current position and company
  • Business email address, business phone number
  • Public LinkedIn profile (URL, headline, current position)
  • Business location
  • Communication history (date, channel, content category) and internal notes on the business relationship
  • Status within the sales process (e.g. "First contact", "In dialogue")

Special categories of personal data under Art. 9 GDPR are not processed.

Data sources

The data comes from the following sources:

  • Publicly accessible LinkedIn profiles that I viewed while approaching a specific business contact
  • Personal recommendations from my network
  • Events at which business cards or contact details were exchanged
  • Direct contact by the data subject (e.g. by email or phone)

Recipients and processors

The following processors are used for the technical provision of the CRM system:

  • Supabase Inc., 970 Toa Payoh North, #07-04, Singapore: database and authentication. Data is stored in the eu-central-1 region (Frankfurt am Main). A data processing agreement under Art. 28 GDPR including EU standard contractual clauses is in place with Supabase.
  • Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA: hosting of the web application. The contractual relationship includes a Data Processing Addendum with EU standard contractual clauses.

Beyond these processors, data is not passed on to third parties. The only exceptions are statutory obligations to disclose data (e.g. to tax authorities in connection with client engagements).

Transfers to third countries

Both Supabase and Vercel are US companies. Supabase stores the data in the EU (Frankfurt). Nevertheless, a transfer to the USA does take place as part of the processors' administrative activities. This transfer is safeguarded by EU standard contractual clauses (Module 2). Transfer impact assessments from the providers are on file.

Retention period

  • Active business contacts are stored for the duration of the business relationship or its initiation.
  • Contacts with no further interest ("Lost") are deleted automatically 24 months after the status change.
  • Contacts kept for longer-term observation ("Watch") are reviewed after 36 months without interaction.
  • In the event of an objection under Art. 21 GDPR, deletion takes place in the next monthly deletion run and within 30 days at the latest.
  • Data relating to completed client engagements is retained for up to seven years in line with statutory retention obligations (in particular Section 132 of the Austrian Federal Fiscal Code (BAO) and Section 212 of the Austrian Commercial Code (UGB)) and deleted thereafter.

6. Newsletter "Der Produktivitäts-Pilot"

On my website you can subscribe to my weekly newsletter "Der Produktivitäts-Pilot" (in German). When you subscribe, I collect your email address, the time of subscription and your IP address. The IP address is collected as proof of your consent under the GDPR.

I use the double opt-in procedure: after entering your email address, you receive a confirmation email with which you verify your subscription. Your address is added to the mailing list only after confirmation.

Legal basis: Art. 6(1)(a) GDPR (consent).

You can unsubscribe from the newsletter at any time via the unsubscribe link at the end of every newsletter email, or withdraw your consent by email to martinposarnig@mpdigital.at. The lawfulness of processing carried out before the withdrawal remains unaffected.

Processor MailerLite: I use the service MailerLite (UAB MailerLite, Paupio g. 28, LT-11341 Vilnius, Lithuania) to send the newsletter. MailerLite is a GDPR-compliant email marketing provider based in the European Union. Data is processed on servers within the EU. A data processing agreement under Art. 28 GDPR is in place with MailerLite.

MailerLite processes the following data: email address, time of subscription, IP address, time of sending, status (e.g. delivered, opened, unsubscribed) as well as click and open statistics to optimise newsletter delivery.

Further information on data processing by MailerLite can be found in MailerLite's privacy policy: https://www.mailerlite.com/legal/privacy-policy.

7. AI phone assistant Anna

Through my website you can reach my AI-based phone assistant Anna on +43 720 986 331. Anna is a voice-based AI assistant that takes your enquiry and forwards it. When you call, the usual connection data (phone number, time, duration) is processed. The content of the conversation may be captured for the purpose of handling your enquiry. No fully automated decision about you is made.

Processor: The service is provided via Fonio.ai; processing takes place on servers in Germany (Nuremberg). A data processing agreement under Art. 28 GDPR is in place with the provider (part of the terms of use).

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in handling enquiries).

8. AI-supported service delivery

mpdigital delivers consulting services with AI support. Analyses, evaluations and work results are produced with the help of AI tools and are always reviewed by a qualified person. No fully automated decisions about individuals are made in the process (human oversight).

Where personal data is processed in this context, this is done in a data-minimising and, where possible, pseudonymised form. Only providers are used that contractually exclude training on the data entered and with which a data processing agreement is in place:

  • OpenAI: AI-supported text and analysis work; business plan with no training on business data.
  • Anthropic: AI-supported analysis and concept work; training on the data entered is disabled.

These providers may transfer personal data to the USA; the transfer is safeguarded by EU standard contractual clauses. The use of AI is disclosed in accordance with Art. 50 of Regulation (EU) 2024/1689 (AI Act). I will provide my internal AI policy on request.

Legal basis: Art. 6(1)(b) GDPR (contract initiation and performance) or Art. 6(1)(f) GDPR (legitimate interest in efficient service delivery).

9. Cookies

My website uses only technically necessary cookies that are required for the proper operation of the site. These cookies enable basic functions and are set automatically. No consent is required for this.

No analytics, tracking or marketing cookies are used.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical functionality of the website).

You can generally restrict or block the setting of cookies in your browser settings. You can delete cookies that have already been set at any time. Please note that disabling cookies may limit the functionality of the website.

10. Fonts

The font used on this website (Space Grotesk, SIL Open Font License) is served from my own server. When the page is loaded, no connection is made to Google's servers or those of other font providers. As a result, no personal data is transmitted to third parties.

11. Data transfers to third countries

The use of Microsoft Outlook Bookings may involve a transfer of personal data to the USA. Microsoft has committed to maintaining an adequate level of data protection under the EU-US Data Privacy Framework.

12. Retention period

Personal data is stored only for as long as necessary for the respective purpose of processing. It is then deleted, unless statutory retention obligations (e.g. periods under tax or commercial law of up to seven years) prevent deletion.

13. Your rights

As a data subject, you have the following rights under the GDPR:

  • Right of access to the data stored about you (Art. 15 GDPR)
  • Right to rectification of inaccurate data (Art. 16 GDPR)
  • Right to erasure of your data (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)

To exercise your rights, please contact: martinposarnig@mpdigital.at.

14. Right to lodge a complaint with the supervisory authority

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority:

Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at

15. Changes to this privacy policy

I reserve the right to amend this privacy policy to reflect changes in the legal situation or in my services. The version currently published on this page applies.

← Back to the home page