Privacy policy
As of: 23 march 2025
Table of contents
- Responsible
- Overview of processing
- Relevant legal bases
- Safety measures
- Transmission of personal data
- International data transfers
- Rights of the data subjects
- Provision of the online offer and web hosting
- Use of cookies
- Contact and enquiry management
- Web analysis, monitoring and optimisation
- Plug-ins and embedded functions and content
Responsible
allomio – Digital Experiences That Think With You
8020, Graz
Styria, Austria
E-Mail-Adresse: hey@allomio.com
Telefon: +43 677 610 30795
Overview of processing
The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects.
Types of data processed
- Inventory data.
- Contact data.
- Content data.
- Usage data.
- Meta, communication and process data.
- Log data.
Categories of affected persons
- Communication partner.
- Users.
Purposes of the processing
- Communication.
- Security measures.
- Range measurement.
- Organisational and administrative procedures.
- Feedback.
- Profiles with user-related information.
- Provision of our online services and user-friendliness.
- Information technology infrastructure.
Relevant legal bases
Safety measures
We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, safeguarding of availability and its separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data and responses to data threats. Furthermore, we already take the protection of personal data into account during the development and selection of hardware, software and processes in accordance with the principle of data protection, through technology design and data protection-friendly default settings.
Transmission of personal data
As part of our processing of personal data, it may be transmitted to other bodies, companies, legally independent organisational units or persons or disclosed to them. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.
International data transfers
Rights of the data subjects
Provision of the online offer and web hosting
We process users‘ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or end device.
- Processed data types: Usage data (e.g. page views and length of stay, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time data, identification numbers, persons involved). Log data (e.g. log files relating to logins or the retrieval of data or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
- Storage and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’.
- Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Collection of access data and log files: Access to our online offering is logged in the form of so-called ‘server log files’. The server log files may include the address and name of the web pages and files accessed, date and time of access, data volumes transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used for security purposes, e.g. to avoid overloading the servers (especially in the event of abusive attacks, so-called DDoS attacks), and also to ensure server utilisation and stability;
- Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further storage is required for evidentiary purposes is excluded from erasure until the respective incident has been finally clarified.
Use of cookies
The term ‘cookies’ refers to functions that store information on users‘ end devices and read it from them. Cookies can also be used for various purposes, for example to ensure the functionality, security and convenience of online offers and to create analyses of visitor flows. We use cookies in accordance with the statutory provisions. If necessary, we obtain the user’s consent in advance. If consent is not required, we rely on our legitimate interests. This applies if the storage and reading of information is essential in order to be able to provide expressly requested content and functions. This includes, for example, saving settings and ensuring the functionality and security of our online offering. Consent can be revoked at any time. We provide clear information about the scope and which cookies are used.
Information on legal bases under data protection law: Whether we process personal data using cookies depends on consent. If consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage period: With regard to the storage period, a distinction is made between the following types of cookies:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online service and closed their end device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, the log-in status can be saved and favourite content can be displayed directly when the user visits a website again. The user data collected with the help of cookies can also be used to measure reach. If we do not provide users with explicit information on the type and storage duration of cookies (e.g. when obtaining consent), they should assume that they are permanent and that the storage duration can be up to two years.
General information on revocation and objection (opt-out): Users can revoke the consents they have given at any time and also declare an objection to the processing in accordance with the legal requirements, also by means of the privacy settings of their browser.
- Processed data types: Meta, communication and process data (e.g. IP addresses, time data, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
Further information on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: We use a consent management solution in which user consent is obtained for the use of cookies or for the procedures and providers mentioned in the consent management solution. This procedure is used to obtain, log, manage and revoke consent, in particular with regard to the use of cookies and comparable technologies that are used to store, read and process information on users‘ end devices. As part of this procedure, user consent is obtained for the use of cookies and the associated processing of information, including the specific processing and providers mentioned in the consent management procedure. Users also have the option of managing and revoking their consent. The declarations of consent are stored in order to avoid a new request and to be able to provide proof of consent in accordance with the legal requirements. The storage takes place on the server side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies in order to be able to assign the consent to a specific user or their device. If no specific information on the providers of consent management services is available, the following general information applies: Consent is stored for up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, information on the scope of consent (e.g. relevant categories of cookies and/or service providers) and information on the browser, system and end device used;
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
Contact and enquiry management
When contacting us (e.g. by post, contact form, email, telephone or via social media) and in the context of existing user and business relationships, the data of the enquiring persons are processed insofar as this is necessary to answer the contact enquiries and any requested measures.
- Processed data types: inventory data (e.g. full name, residential address, contact information, customer number, etc.); contact information (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and posts as well as the information concerning them, such as information on authorship or time of creation); usage data (e.g. page views and length of stay, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, time information, identification numbers, persons involved).
- Data subjects: communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via online form). Provision of our online services and user-friendliness.
- Storage and erasure: Erasure in accordance with the information in the section ‘General information on data storage and erasure’.
- Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Performance of a contract and prior requests (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Further information on processing, procedures and services:
- Contact form: When you contact us using our contact form, by email or by other means of communication, we process the personal data transmitted to us in order to answer and process your request. This usually includes information such as your name, contact information and, if applicable, other information that you provide to us and that is necessary for us to process your request appropriately. We use this data exclusively for the stated purpose of establishing and maintaining contact and communication.
- Legal basis: Performance of a contract and prior requests (Art. 6 (1) (b) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR)
Web analysis, monitoring and optimisation
The web analysis (also referred to as ‘reach measurement’) is used to evaluate the flow of visitors to our online offering and may include behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, identify the times when our online services or their functions or content are most frequently used, or invite users to reuse them. It also enables us to identify areas that require optimisation.
In addition to web analysis, we may also use test procedures to test and optimise different versions of our online services or their components.
Unless otherwise stated below, profiles, i.e. data summarised for a usage process, can be created and information can be stored in a browser or in a terminal device and then read for these purposes. The information collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data vis-à-vis us or the providers of the services we use, the processing of location data is also possible.
In addition, the IP addresses of users are stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear user data (such as email addresses or names) is stored in the context of web analysis, A/B testing and optimisation, but pseudonyms. This means that we, as well as the providers of the software used, do not know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.
Notes on the legal basis: If we ask users for their consent to use the third-party providers, the legal basis for data processing is that consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this data protection declaration.
- Processed data types: Usage data (e.g. page views and time spent on the page, click paths, frequency and intensity of use, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles). Provision of our online services and user-friendliness.
- Storage and erasure: Erasure in accordance with the information in the ‘General information on data storage and erasure’ section. Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users‘ devices for a period of two years).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing, procedures and services:
- Google Analytics: We use Google Analytics to measure and analyse the use of our online services on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It is used to assign analysis information to a terminal device in order to recognise which content users have accessed within one or more usage processes, which search terms they have used, which they have accessed again or with which they have interacted with our online offering. The time of use and its duration are also stored, as well as the sources of the users who refer to our online offering and technical aspects of their end devices and browsers.
- In doing so, pseudonymous profiles of users are created with information from the use of various devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics does provide broad geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU data traffic, the IP address data is used exclusively for this derivation of geolocalisation data before it is immediately deleted. It is not logged, is not accessible and is not used for any further purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com/intl/en/about/analytics/; Security measures: IP masking (pseudonymisation of the IP address); Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Opt-Out: Opt-out plug-in: https://tools.google.com/dlpage/gaoptout?hl=en, settings for the display of advertising: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and processed data).
Plug-ins and embedded functions and content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as ‘third-party providers’). These may be graphics, videos or city maps (hereinafter uniformly referred to as ‘content’).
The integration always requires that the third-party providers of this content process the IP address of the user, since they would not be able to send the content to the user’s browser without the IP address. The IP address is therefore required for the presentation of this content or these functions. We endeavour to use only content from providers who use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as ‘web beacons’) for statistical or marketing purposes. Pixel tags’ can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, time of visit and other information about the use of our online services, but may also be linked to such information from other sources.
Notes on legal bases: If we ask users for their consent to use third-party providers, the legal basis for data processing is permission. Otherwise, user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this data protection declaration.
- Processed data types: Usage data (e.g. page views and duration of visit, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, time information, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness.
- Storage and erasure: Erasure in accordance with the information in the ‘General information on data storage and erasure’ section. Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users‘ devices for a period of two years).
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing, procedures and services:
- Google Fonts (obtained from Google server): Obtaining fonts (and symbols) for the purpose of a technically secure, maintenance-free and efficient use of fonts and symbols with regard to up-to-dateness and loading times, their uniform presentation and consideration of possible licensing restrictions. The IP address of the user is communicated to the provider of the fonts so that the fonts can be made available in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) are transmitted, which are necessary for the provision of the fonts depending on the devices used and the technical environment. This data may be processed on a server of the font provider in the United States. When you visit our online offering, the user’s browser sends its HTTP request to the Google Fonts web API (i.e. a software interface for retrieving fonts). The Google Fonts web API provides users with the cascading style sheets (CSS) of Google Fonts and then the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the internet, (2) the requested URL on the Google server and (3) the HTTP headers, including the user agent that describes the browser and operating system versions of the website visitors, as well as the reference URL (i.e. the website on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers and they are not analysed. The Google Fonts Web API logs details of HTTP requests (requested URL, user agent and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wishes to load fonts. This data is logged so that Google can determine how often a particular font family is requested. The Google Fonts Web API requires the user agent to customise the font that is generated for each browser type. The user agent is primarily logged for debugging purposes and used to generate aggregated usage statistics that measure the popularity of font families. These aggregated usage statistics are published on the ‘Analytics’ page of Google Fonts. Finally, the reference URL is logged so that the data can be used to maintain production and generate an aggregated report on the top integrations based on the number of font requests. According to Google, it does not use any of the information collected by Google Fonts to create profiles of end users or to display targeted ads; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://fonts.google.com/; Privacy Policy: https://policies.google.com/privacy. More information: https://developers.google.com/fonts/faq/privacy?hl=en.