Privacy Policy
Protecting your personal data is important to us. This website processes personal data only in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and Austrian data protection law.
This website is operated with the intention of offering commercial services in the future.
1. Data Controller
Roman Kofler-Popp
Davidsstrasse 30/7
5400 Hallein
Austria
Email: cupitoo2026@proton.me
This website represents a pre-launch project. A formal company has not yet been established.
2. Collection of Personal Data
We collect and process personal data only when you voluntarily subscribe to our newsletter.
The personal data processed includes:
- your email address
- the date and time of your subscription
- confirmation of your subscription through the double opt-in procedure
- IP address and timestamp of subscription and confirmation (for legal verification)
3. Purpose of Processing
Your email address is processed solely for the purpose of sending you our newsletter.
The newsletter constitutes direct marketing within the meaning of Article 21 GDPR.
We do not use your data for:
- profiling
- marketing beyond the newsletter
- tracking newsletter opens
- tracking clicks in newsletters
4. Legal Basis for Processing
The legal basis for processing your personal data is your consent pursuant to Article 6(1)(a) GDPR.
You provide your consent by:
- entering your email address
- confirming your subscription through the double opt-in email
You may withdraw your consent at any time with future effect.
5. Storage and Processing of Data
Your email address is stored and processed using the following service providers:
- Supabase (database hosting, Ireland)
- Resend (email delivery service, USA)
Resend processes data on our behalf in accordance with Article 28 GDPR.
Data transfer to the USA is based on standard contractual clauses (SCCs) pursuant to Article 46 GDPR. It cannot be excluded that US authorities may access personal data.
All third-party providers act as data processors in accordance with Article 28 GDPR.
6. Hosting
This website uses Cloudflare, Inc. (USA) as a content delivery network (CDN) and security provider.
Cloudflare may process technical connection data, including:
- IP address
- browser type
- operating system
- date and time of access
Data transfer to the USA is based on standard contractual clauses (SCCs). It cannot be excluded that US authorities may access personal data.
The legal basis is Article 6(1)(f) GDPR (legitimate interest in secure and stable website operation).
7. Bot Protection (Cloudflare Turnstile)
To protect this website from automated abuse and spam, we use Cloudflare Turnstile, a service provided by Cloudflare, Inc. (USA).
Turnstile is used to distinguish whether input is made by a human or an automated program. For this purpose, technical data such as IP address, browser information, and interaction data may be processed.
Data processing may involve the transfer of personal data to the United States. This transfer is based on standard contractual clauses (SCCs). It cannot be excluded that US authorities may access personal data.
The use of Turnstile is based on our legitimate interest in protecting our website from misuse and ensuring its secure operation (Article 6(1)(f) GDPR).
8. Data Retention
Newsletter data is stored until you unsubscribe from the newsletter.
After unsubscribing, your data will be deleted unless legal retention obligations apply.
9. No Cookies or Tracking
We do not use analytics or marketing tracking tools.
Technical data may be processed in server logs for security and operational purposes.
No visitor profiles are created.
10. Your Rights
Under the GDPR, you have the right to:
- access your personal data
- rectify inaccurate data
- erase your data
- restrict processing
- data portability
- object to processing
- withdraw consent at any time
You also have the right to object at any time to the processing of your personal data for direct marketing purposes ( Article 21 GDPR).
11. Automated Decision-Making
No automated decision-making or profiling within the meaning of Article 22 GDPR takes place.
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority.
Austrian Data Protection Authority (Datenschutzbehörde, Austria)
13. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy when necessary.