Imprint (Impressum)

CozyCode GmbH
Brandhofgasse 7, Tür 1
8010 Graz
Austria

Email: hello@cozycode.eu

Company register number: FN 670742k
Company court: Landesgericht für Zivilrechtssachen Graz
GLN: 9110038498661

Licensed activities:

  • IT services (Dienstleistungen in der automatischen Datenverarbeitung und Informationstechnik) — GISA 39280039
  • Language services (Sprachdienstleistungen) — GISA 39280176

Responsible for licensed activities (Gewerberechtliche Geschäftsführung): Kumi Mitterer
Supervisory authority: Magistrat Graz
Applicable regulations: Gewerbeordnung 1994 (GewO) — ris.bka.gv.at


Privacy Policy

Last updated: 2026-07-04

Controller

CozyCode GmbH
Brandhofgasse 7, Tür 1
8010 Graz
Austria
Email: hello@cozycode.eu

We have not appointed a Data Protection Officer. For privacy questions, contact us at hello@cozycode.eu.

Scope

This policy explains how we process personal data when you:

  • visit our website at cozycode.eu,
  • contact us (e.g. by email), or
  • discuss or enter into a contract with us.

What data we process and why

1. Visiting our website (server logs)

  • Data: IP address, date/time, URLs visited, referrer, user-agent, HTTP status codes.
  • Purpose: deliver pages, ensure security and reliability, detect abuse.
  • Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure and reliable operation.

2. Cookies

  • We do not set non-essential cookies.
  • If our hosting or CDN sets strictly necessary cookies (e.g. for security or load balancing), these are covered by Art. 6(1)(f) GDPR.

3. Analytics

No invasive tracking, no marketing cookies. If we ever enable privacy-friendly aggregated analytics, we will update this policy and show a notice if consent is required.

4. Contacting us (e.g. by email)

  • Data: your contact details, message content, metadata (time, sender, recipients), attachments.
  • Purpose: respond to enquiries, pre-contractual steps, record-keeping, contract performance.
  • Legal basis: Art. 6(1)(b) GDPR (contract or pre-contract steps), Art. 6(1)(f) GDPR (legitimate interest in efficient communication), Art. 6(1)(c) GDPR (legal obligations, e.g. tax law).

5. Clients and prospective clients

  • Data: business contact details, contract data, billing data, project communications.
  • Purpose: provide services, project management, invoicing, compliance.
  • Legal basis: Art. 6(1)(b) GDPR (contract), Art. 6(1)(c) GDPR (legal obligations), Art. 6(1)(f) GDPR (legitimate business interests).

We do not intentionally process special categories of data (Art. 9 GDPR). Please avoid including sensitive information in emails unless necessary.

Recipients and processors

We use carefully selected processors:

  • Hosting and CDN for serving the website.
  • Email provider for sending and receiving email.

These providers are located in the EU/EEA or in countries with an adequacy decision, or we use EU Standard Contractual Clauses (SCCs). We require all processors to implement appropriate technical and organisational measures.

International transfers

Where data is transferred outside the EU/EEA, we rely on an adequacy decision (Art. 45 GDPR) or Standard Contractual Clauses (Art. 46 GDPR) with supplementary safeguards where appropriate.

Retention

  • Email enquiries: up to 6 months after last interaction, unless longer retention is required (e.g. to establish or defend legal claims).
  • Client, project, and billing data: statutory periods under Austrian commercial and tax law (typically 7 years).
  • Server logs: up to 30 days, unless needed longer for incident investigation.

Your rights

Under GDPR you have the right to:

  • access your personal data (Art. 15),
  • rectification (Art. 16),
  • erasure (Art. 17),
  • restriction of processing (Art. 18),
  • data portability (Art. 20),
  • object to processing based on legitimate interests (Art. 21),
  • withdraw consent at any time (Art. 7(3)), where processing is consent-based.

To exercise your rights, write to hello@cozycode.eu. You also have the right to lodge a complaint with a supervisory authority. In Austria:

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Wien
dsb.gv.at

Security

We apply appropriate technical and organisational measures: least-privilege access, encryption in transit, regular updates, and restricted administrative access.

Children

Our services are aimed at businesses and adults. We do not knowingly process children's personal data.

Changes

We may update this policy when our practices or legal requirements change. The "Last updated" date reflects the latest revision.