Privacy
This page is a draft and is not in force. It has not been reviewed or approved by Essential Code GmbH and has not been seen by a lawyer. It is published in the repository so that it can be reviewed, not so that it can be relied on. Do not treat anything below as a binding statement by Essential Code GmbH until this notice is removed.
We are committed to protecting personal data. The use of this website and our business activities generally involve the processing of personal data. To make these data processing activities transparent, we want to inform you here about how we process personal data and what rights you have in this context. If you have any further questions, our contact details are below.
1. Who we are and how you can contact us
The responsible party (controller) within the meaning of the General Data Protection Regulation (GDPR) is:
Essential Code GmbH (brand: staticsites.eu) David Wippel Glücksallee 8 3012 Wolfsgraben Austria Email: hallo@essentialcode.eu
2. Our data processing
2.1 General
We process personal data in compliance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR, Regulation [EU] 2016/679) and the Austrian Data Protection Act (DSG). Processing takes place only on the basis of a legal ground (in particular pursuant to Article 6(1)(a) to (f) GDPR), which is specified below for each data processing. All persons entrusted with the processing are obliged to maintain the confidentiality of your data. We do not carry out automated decision-making.
As a rule, we collect personal data directly from the data subject.
2.2 Operation of this website
Whenever you access this website, your device or browser automatically transmits certain information to enable the visit or operation of the website:
- IP address
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (page or content to be retrieved)
- Access status and HTTP(S) status code
- URL of the previously visited website
- Browser and browser version
- Operating system and its interface
This data is stored in the log files of the system serving the site. It is not stored together with other personal data.
Legal basis and purpose. The legal basis for the processing of this data and its temporary storage in log files is Article 6(1)(f) GDPR. Temporary storage is necessary to deliver the website to your device. Storage in log files serves to ensure the functionality of the website, to optimise it, and to ensure the security of our information technology systems. In these purposes lies our legitimate interest.
Duration of storage. The data is deleted as soon as it is no longer necessary for the purpose for which it was collected. For delivery of the website, that is when the session ends. For log files, that is after at most seven days, unless further processing is required to clarify a suspected attack.
Where it is processed. This website is hosted on the network of BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia. Files are stored in Bunny’s German region. Privacy policy: bunny.net/privacy.
2.3 No analytics and no cookies
This website sets no cookies, runs no analytics, embeds no advertising and loads no third-party fonts or scripts. Nothing on it tracks you. If that changes, this page changes first.
2.4 The waitlist form
The waitlist form is provided by Tally B.V., August Van Lokerenstraat 71, 9050 Gentbrugge, Belgium. When you submit it, the data you enter (in particular your email address, and anything else you choose to tell us) is processed by Tally on our behalf and stored in Europe. Privacy policy: tally.so/help/privacy-policy.
Legal basis and purpose. Article 6(1)(a) GDPR, your consent, given by submitting the form. We use the address for one purpose: to tell you when staticsites.eu opens and what it costs. You can withdraw consent at any time by emailing us, and we will delete the entry.
Duration of storage. Until you ask us to delete it, or until the waitlist has served its purpose and is closed, whichever comes first.
2.5 Contacting us
When you contact us by email, the information you provide (name, contact details, other information) is processed to document, handle and answer your request. The basis is our legitimate interest in properly handling and answering it (Article 6(1)(f) GDPR); where the contact concerns an existing customer relationship or the initiation of one, we rely on Article 6(1)(b) GDPR.
2.6 The staticsites.eu service
This section describes the service itself rather than this website, and applies once you have an account.
To provide the service we use the following processors, each of which is an EU company:
- BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia: hosting, storage, content delivery and the database. Your site’s files and our records are stored in Bunny’s German region.
- BDY PSA, Twarda 18, 00-105 Warszawa, Poland (Buddy): builds. Your source code is checked out and built here.
- Hanko GmbH, Ringstraße 19, 24114 Kiel, Germany: sign-in. Handles your passkey or email code so that no password is stored.
Content delivery is global by design, because that is what makes a site load quickly. What stays in the EU is every company we depend on and every copy of your data we hold.
If you connect a GitHub repository, we read it through a GitHub App with read-only access to repository contents. GitHub is your own choice of code host and is not part of our stack.
2.7 Payment
Nothing is being charged today and this website cannot take a payment. This section describes the processing that will happen once billing is live, and takes effect then.
Payment is processed by Paddle, which acts as the merchant of record for your purchase. We do not receive, see or store your card details at any point, and no payment data is held on our systems.
What reaches Paddle. Your name, email address, billing address, country, VAT number where you provide one, the card or payment-method details you enter directly with them, and the details of your subscription and its transactions. They return to us only what we need to run your account: which plan is active, whether it is paid, and the invoice records we are required to keep.
Legal basis. Article 6(1)(b) GDPR, because the processing is necessary to perform the contract you enter into, and Article 6(1)(c) GDPR for the invoicing and retention obligations that follow from it.
Where. For buyers outside the United States the contracting entity is Paddle.com Market Limited, in the United Kingdom; for buyers in the United States it is Paddle.com Inc. Your invoice names the one that contracted with you.
This means your payment data is transferred out of the EU. The United Kingdom is a third country for the purposes of the GDPR, and the European Commission has adopted an adequacy decision covering transfers to it. The transfer therefore rests on Article 45 GDPR, and no additional safeguards under Article 46, such as Standard Contractual Clauses, are required for it.
What leaves the EU is payment data, and only payment data. Where your site and the rest of your data are stored is set out above, and that stays in the EU.
Paddle’s own privacy policy is at paddle.com/legal/privacy.
Worth saying plainly, because the rest of this page makes a point of European suppliers: a payment provider is not part of the hosting stack, and where the merchant of record is domiciled is a separate question from where your site and your data are stored. Those stay in the EU, as set out above. The payment answer will be stated here precisely rather than glossed.
3. How long we store personal data
Unless otherwise specified above, we store personal data for as long as it is necessary to fulfil the stated purposes or as long as we are legally obliged to do so.
For business letters, contracts and bookings, under § 212(1) UGB and § 132(1) BAO: until the end of the business relationship or until the expiry of the applicable limitation and statutory retention periods, in particular at least 7 years; in addition, until the end of any legal disputes in which the data is required as evidence. For enquiries: up to 3 years after completion, unless a longer retention period is required.
4. Your rights
Provided that the statutory requirements are met, you can exercise the following rights:
- Right of access: you can request confirmation as to whether personal data about you is being processed, and information about it (Article 15 GDPR).
- Right to rectification: if we process incorrect or incomplete data about you (Article 16 GDPR).
- Right to erasure: of your personal data, where the conditions of Article 17 GDPR are met.
- Right to restriction: of the processing of your data (Article 18 GDPR).
- Right to data portability: of the data you provided, where processing is based on consent (Article 6(1)(a)) or on a contract (Article 6(1)(b)) and is carried out by automated means (Article 20 GDPR).
Where processing is based on legitimate interests (Article 6(1)(f) GDPR), you have the right to object under Article 21 GDPR on grounds relating to your particular situation. For direct marketing, that right applies without restriction.
You can withdraw consent at any time by contacting us. The lawfulness of processing carried out on the basis of consent before its withdrawal is not affected.
4.1 Right to lodge a complaint
You have the right to lodge a complaint with the supervisory authority responsible for you. In Austria that is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at. We would ask you to contact us first, so that we have a chance to correct any mistake straight away.