Privacy policy
Last updated: 27 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (“GDPR”) is:
Agentic KMU GesbR
Matthäus Konradsheim and Felix Dräxler
Krugerstraße 13
1010 Vienna
Austria
Email: kontakt@agentic-kmu.at
Telephone: +43 681 81300132
Agentic KMU is responsible for this website.
2. General information on data processing
We process personal data only to the extent necessary to provide this website, handle enquiries, initiate or perform a contract, improve our services or comply with legal obligations.
Depending on the processing activity, we rely in particular on the following legal bases:
- your consent pursuant to Art. 6(1)(a) GDPR;
- pre-contractual measures or performance of a contract pursuant to Art. 6(1)(b) GDPR;
- legal obligations pursuant to Art. 6(1)(c) GDPR;
- legitimate interests pursuant to Art. 6(1)(f) GDPR.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
3. Provision and hosting
This website is provided using services from Cloudflare. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When the website is accessed, Cloudflare processes technically necessary connection and log data, in particular the IP address, time, URL, referrer, browser, device, security and error data.
Processing is necessary to deliver the website and ensure its stability and security. The legal basis is Art. 6(1)(f) GDPR. Cloudflare processes data on the basis of a contract pursuant to Art. 28 GDPR. Where applicable, transfers to the USA are based on the EU–US Data Privacy Framework or Standard Contractual Clauses.
Further information: Cloudflare Privacy Policy .
4. Contact form and contacting us
We process the following data through the contact form:
- name and email address;
- company and a free-text message, where provided;
- page URL and time of submission;
- technical campaign, referrer and browser data, where available;
- a technical event ID and, following marketing consent, Meta identifiers.
We use this data to handle your enquiry, contact you, take pre-contractual measures and prevent misuse. Depending on the content of the enquiry, the legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR.
4.1 Transmission via Google Apps Script
We use Google Apps Script (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to receive form submissions. Google processes the data as a processor pursuant to Art. 28 GDPR. Where data is processed in the USA, the transfer is based on the EU–US Data Privacy Framework or Standard Contractual Clauses.
Further information: Google Privacy Policy .
4.2 Lead management and communication
We use Google Sheets and Gmail or Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to store and process enquiries and send notifications. Google processes data as a processor. Where data is processed in the USA, the transfer is based on the EU–US Data Privacy Framework or Standard Contractual Clauses.
Further information: Google Privacy Policy .
4.3 Retention period for enquiries
If no contractual relationship is established, we generally delete the enquiry no later than three years after the last substantive contact, unless statutory obligations or legal claims justify longer retention. We retain contract-related data in accordance with statutory retention periods.
5. Audience measurement and product analytics with PostHog
We measure page views and basic usage events with PostHog (PostHog, Inc., USA; EU Cloud), including without consent in cookieless mode. No cookies are set, and no information is stored on or read from your device. The visitor identifier is recreated server-side each day and does not permit recognition beyond that day. The legal basis is Art. 6(1)(f) GDPR. A Global Privacy Control signal is treated as an objection.
If you consent to the “Analytics” category, we additionally use PostHog with persistence and masked session recordings. Data collected may include pages, interactions, navigation paths, technical errors, timestamps and browser, device, campaign and pseudonymous session data. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 165(3) TKG 2021.
Contact form entries are technically masked in session recordings. Name, email, company and message are not transferred to PostHog as analytics properties. Session recordings are deleted after no more than 30 days.
Further information: PostHog Privacy Policy .
6. Marketing measurement with Meta
Following your consent to the “Marketing” category, we use the Meta Pixel and, where applicable, the Meta Conversions API to measure advertising effectiveness and conversions. The provider for users in the EEA is generally Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland.
Data processed may include page and lead events, browser and device information, campaign and
referrer data, cookie identifiers such as _fbp and _fbc, event ID,
IP address, user agent and contact data hashed server-side. Browser and server events use the
same event ID to prevent duplicate counting.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 165(3) TKG 2021. Further information: Meta Privacy Policy .
7. Cookies and similar technologies
We store your selection in the consent management system. Optional analytics and marketing technologies are activated only after you have given the relevant consent. Without analytics consent, only the cookieless measurement described in Section 5 takes place. You can change your selection at any time via “Cookie settings” in the footer.
8. Recipients and international transfers
Recipients may include hosting and security service providers, Google (Apps Script and Workspace), PostHog and, following consent, Meta, as well as advisers, courts and authorities. We enter into contracts with processors pursuant to Art. 28 GDPR.
International transfers take place only under the conditions of Art. 44 et seq. GDPR, in particular on the basis of an adequacy decision or Standard Contractual Clauses.
9. Data security
We take appropriate technical and organisational measures to protect personal data. Data transmitted between your browser and the website is encrypted using HTTPS.
10. Your rights
Subject to the applicable statutory requirements, you have in particular the rights of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent already given. To exercise these rights, contact kontakt@agentic-kmu.at.
You may also lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
11. Changes to this privacy policy
We update this policy when legal requirements, the services used or data processing activities change. The current version is available on this website.