Controller
The controller responsible for the processing of personal data on this website under the General Data Protection Regulation (GDPR) is:
- Christina Tschernitz
- Gabelsbergerstraße 9, 9020 Klagenfurt, Austria
- christina.tschernitz@gmx.at
Overview
This website is deliberately built to minimise data. No analytics or tracking services are used, no advertising or statistics cookies are set, and no profiling takes place. That is also why this site has no cookie banner: nothing is stored that would require consent.
All typefaces are served entirely from our own server. Visiting the site therefore establishes no connection to Google Fonts or any other font provider.
A single cookie named “NEXT_LOCALE” is set. It records only whether you chose the German or the English version, so that the site shows you the same language next time. It contains no identifier by which you could be recognised. As this cookie is strictly necessary to provide the service you requested, no consent is required for it (§ 165 (3) of the Austrian Telecommunications Act 2021). Beyond that, no data is stored in your browser.
Hosting and server log files
This website is hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA. The provider processes the data arising when the site is accessed on our behalf, under a data processing agreement pursuant to Art. 28 GDPR.
Netlify, Inc. is established outside the European Union. Even though the site is delivered from European server locations, this means personal data is transferred to a third country. The transfer is based on the European Commission’s Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. Despite these safeguards, access by authorities of that third country cannot be ruled out.
When a page is requested, technically necessary access data is recorded in server log files. This processing is strictly required in order to deliver the website, ensure its stability and defend against attacks.
- IP address of the requesting device
- Date and time of access
- Name and URL of the file retrieved
- Amount of data transferred and status code
- Browser and operating system used
- Previously visited page (referrer), where transmitted
Legal basis and retention of log files
The legal basis is Art. 6 (1) (f) GDPR. The legitimate interest lies in the secure, stable and functional operation of the website. Log files are not combined with other data sources and are not used to identify individuals. They are deleted as soon as they are no longer required for that purpose — as a rule after no more than 30 days.
Contact form
When you use the contact form, only the details you enter yourself are processed: your name, email address, subject (optional), your message, the language version selected and the time of receipt.
Three measures protect against automated submissions: a hidden field that humans do not fill in; a check that a plausible amount of time passed between opening the form and submitting it; and a limit of five submissions per connection per hour. No external anti-spam service is involved and your behaviour on the site is not analysed.
This limit requires your IP address. It is not stored, however: a non-reversible check value is derived from it using a secret key, and only that value is kept — for one hour at most, after which the entry is deleted. Without the key your address cannot be recovered from it. The legal basis is the legitimate interest in the security and availability of the service under Art. 6 (1) (f) GDPR read with Recital 49.
The legal basis is your consent under Art. 6 (1) (a) GDPR, which you give expressly before submitting. Where your enquiry concerns the initiation of a contract — a teaching or engagement request, for example — Art. 6 (1) (b) GDPR also applies. You may withdraw your consent at any time with future effect; an informal email is sufficient.
Your message is deleted once your enquiry has been dealt with conclusively, and in any case no later than six months after receipt. This deletion happens automatically and without exception; it is implemented in the database itself and does not depend on anyone acting manually.
If your enquiry leads to a contractual relationship, the resulting records are subject to the seven-year retention periods under tax and commercial law. Those records are kept outside this website — the original message in the contact form is still deleted after six months.
Processors
The following service providers are used to operate this website.
Supabase — database and file storage. Messages from the contact form and the contents of this website are stored there. The server location is in the European Union (Frankfurt, Germany). Access is secured by row-level security; messages received through the website can only be read after signing in to the protected administration area.
Resend (Resend, Inc., 2261 Market Street, San Francisco, CA 94114, USA) — sends a notification email when a new enquiry arrives. Your name, email address, subject and message are transmitted in the process. As this provider is based in the USA, a transfer to a third country takes place. It is based on the European Commission’s Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. Despite these safeguards, access by US authorities cannot be ruled out.
Videos (YouTube)
The video page embeds recordings hosted on YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). These videos do not load automatically. Initially only a preview image is shown, served from our own server — as long as you do not click it, no connection to Google is established and no data is transmitted.
Only when you actively start a video is it loaded via the domain youtube-nocookie.com. In this enhanced privacy mode, YouTube states that it sets no cookies for analysing usage behaviour before a video is played. Your IP address and technical details about your device are transmitted to Google; transfer to the USA cannot be ruled out.
The legal basis is your consent under Art. 6 (1) (a) GDPR, which you give by deliberately clicking the video. Further information is available in Google’s privacy policy at policies.google.com/privacy.
Your rights
You have the following rights in respect of personal data concerning you:
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent given (Art. 7 (3) GDPR)
Right to lodge a complaint
To exercise your rights, an informal message to the email address above is sufficient. Irrespective of this, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your data infringes the GDPR. The competent authority in Austria is:
- Austrian Data Protection Authority
- Barichgasse 40–42, 1030 Vienna, Austria
- dsb@dsb.gv.at
- +43 1 52 152-0
- www.dsb.gv.at
Changes to this statement
This privacy statement is updated whenever the underlying processing or the legal situation changes. The version published on this page applies.
08
Social media
This website contains references to Instagram. These are ordinary links only, not embedded content or provider buttons. No scripts from the network are loaded, no cookies are set and no data is transmitted as long as you do not click the link. The privacy policy of the respective network applies only once you have clicked.