Privacy policy
Last updated: 13 September 2026
Throughout this page, “I” means PalmChrom e.U., the one person company I run in Vienna.
What this page is about, and who is responsible
This page explains what happens to your data when you visit palmchrom.com, write to me, or work with me. Which data I collect, why I need it, how long I keep it, and what you can ask me to do with it. If something here is not clear, write to me and I will explain it.
The responsible party is PalmChrom e.U., David Jaime Cocovi Solberg, Brigittagasse 5/2/49, 1200 Vienna, Austria. You can reach me at david [at] palmchrom [dot] com. Full company details are in the Imprint.
Under the GDPR I am the controller of the data described here. That means I decide what is collected and why, and I am the person you complain to if you are not happy about it.
The short version
There are three situations in which I handle data about you.
You visit this website. My server logs the request: your IP address, the time, the page you asked for, your browser and operating system. I need this to send you the page at all, and to see whether the server is being attacked. These logs are deleted after 30 days. Separately, if you allow it, I use Google Analytics to see which pages people read and Google Ads to see which advertisements brought them here. You decide that with the cookie banner, and you can change your mind whenever you wish.
You get in touch. Through the contact form, by email, or by telephone. I keep your name, your address, and whatever you wrote to me, for as long as it takes to answer you and to handle whatever comes out of it.
You become a customer, a supplier, or a partner. Then I also handle the things a business has to handle: the contract, the invoices, the bank details, the correspondence. Austrian tax law requires me to keep most of that for seven years.
What I do not do. There is no shop and no user account on this site, so I never see your card details here. I do not sell or rent your data to anyone. I do not use it to make automated decisions about you. Nobody receives your data except the service providers I need in order to run the business, and they are named further down.
Why I am allowed to process your data
The GDPR does not permit me to process your data simply because it is convenient. Everything described on this page rests on one of four grounds. Here is what each of them means in practice.
Because you agreed to it. You ticked a box or clicked a button, and I can demonstrate that you did. This covers the analytics and advertising cookies, and nothing else on this site. You may withdraw your agreement whenever you wish, and withdrawing it is as straightforward as giving it was. Art. 6(1)(a) GDPR.
Because we have a contract, or are working toward one. If you request a quotation, order an instrument, or send me a specification to review, I need your data in order to do what you have asked of me. This also covers everything that happens before a contract exists. Art. 6(1)(b) GDPR.
Because the law requires it. Austrian tax and commercial law determines which documents I must keep and for how long, and leaves me no discretion in the matter. Art. 6(1)(c) GDPR.
Because I have a legitimate interest. I may process data where I have a genuine interest in doing so, but only after weighing that interest against your rights, and only where it does not override them. I rely on this ground for three things: keeping the server running and protected, replying to people who write to me, and maintaining a presence on social media. You may object to any of it, and if you do, I must stop unless I can demonstrate compelling grounds that outweigh your objection. Art. 6(1)(f) GDPR.
Austrian law applies alongside the GDPR, since I am based in Vienna. The relevant statute is the Datenschutzgesetz (DSG), which adds specific provisions on access, correction, erasure, sensitive categories of data, and automated decisions. Where a national rule and the GDPR differ, I follow whichever affords you greater protection.
When you visit this website
Some things happen automatically, before you have clicked on anything. They are the price of the page reaching you at all. When your browser asks my server for a page, the request itself contains your IP address, and my server records it along with the time, the page you asked for, how much data was sent, whether it worked, your browser and its version, your operating system, and the address of the page you came from, if you arrived by a link. This is a server log, and every website on the internet keeps one.
I need your IP address for the same reason the postal service needs an address: without it there is nowhere to send the page. The rest I keep for a short period because it is what tells me whether the server is being attacked, overloaded, or quietly failing. I do not use it to work out who you are, and I do not connect it to anything else I hold. Logs are deleted or anonymized after 30 days, the exception being a log connected to a specific security incident, which I keep until the matter is settled. The legal basis is my legitimate interest in delivering this site and keeping it running (Art. 6(1)(f) GDPR).
The site is hosted in Germany, on rented server space with ALL-INKL.COM, Neue Medien Münnich GmbH [FULL ADDRESS FROM CONTRACT]. They also handle the email for palmchrom.com. That means my hosting provider technically has access to what passes through their servers, including the content of emails. They act on my instructions under a data processing agreement, and they are bound by the GDPR as I am. The legal basis is my legitimate interest in running this site on rented infrastructure rather than my own (Art. 6(1)(f) GDPR).
Cookies, and what you agree to
A cookie is a small file that a website stores on your device and reads back later. Some are unavoidable, most are not, and the difference matters.
One cookie you cannot refuse. It remembers what you decided about all the others. Without it, the banner would ask you the same question on every page you open. It holds your answer, the date you gave it, and a random number that means nothing outside this site, and it is the only cookie this site sets on its own. It lasts twelve months, and then you are asked again. The legal basis is my legitimate interest in the site functioning as you expect it to (Art. 6(1)(f) GDPR).
I also keep a record of each decision on my server, because the law expects me to be able to show that consent was given. The record holds the same random number, the date and time, and what you chose. Nothing else: no IP address, no browser details, nothing that tells me who you are. It stays on the same server as the site, and no third party is involved. The legal basis is my obligation to be able to demonstrate consent (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR).
Everything else waits for you. Until you press accept, nothing is loaded, nothing is sent, and no third party learns that you were here. If you press reject, the site works exactly as it does otherwise, and you are not asked again.
Google Analytics is the first of the two services that appear if you accept. It tells me which pages are read, how long people stay, and what they came looking for. I use it to work out which parts of this site are worth expanding and which nobody opens. It identifies you by a number, not a name, and my settings shorten your IP address before it is stored. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, and their privacy policy is at policies.google.com/privacy.
Google Ads is the second. It tells me whether the advertisements I place actually lead anywhere, by recording that a visit followed a click on one of them. I see totals, not individuals. Same provider and same privacy policy as above. The legal basis for both is your consent (Art. 6(1)(a) GDPR). Analytics cookies last up to two years, advertising cookies vary, and the banner tells you the exact duration for each one.
You can change your mind at any time. There is a link at the bottom of every page that reopens the banner. Whatever you decided, you can decide differently, and it takes effect immediately. You can also delete cookies from your browser settings, which clears the record of your decision along with everything else.
When you get in touch
However you reach me, through the form on the contact page, by email, by telephone, or through a message on one of the social media accounts below, the principle is the same: I use what you tell me to answer you, and for nothing else.
The form asks for three things: your name, your email address, and your message. That is all it asks for, and all three are needed for the obvious reason that I cannot reply otherwise. Anything further you choose to include is up to you.
What you send arrives in two places, my inbox and a store on my own server, so that nothing is lost if an email goes astray. That store is hosted with the same provider as the site itself and no third party is involved in carrying your message. The form is protected against automated spam by a hidden field that only machines fill in, which means no data leaves my server for that purpose either. Submissions are cleared from the server store after twelve months, and what remains is whatever has become part of an ongoing working relationship.
Then I read it and I reply, usually myself and usually within a few days. If your inquiry turns into a quotation, an order, or a collaboration, your data moves into the next section and is kept for as long as that relationship and the law require. If it does not, there is no reason for me to keep your message and I do not.
The legal basis depends on why you wrote. If you are asking about buying or commissioning something, it is the steps taken before a contract at your request (Art. 6(1)(b) GDPR). If you are writing for any other reason, it is my legitimate interest in being reachable and in answering the people who take the trouble to contact me (Art. 6(1)(f) GDPR).
When we do business
If you order an instrument, commission a piece of development work, or supply me with something, the relationship generates data that I am obliged to handle properly and, in part, obliged to keep.
What I hold is your name and, if applicable, your organization. Your address, email, and telephone number. What we agreed, when, for how much, and under what terms. Invoices, payment records, and bank details. The correspondence between us, including whatever technical material you send me in the course of the work. When I need something specific from you, I ask for it and I say why. Nothing on that list is collected quietly.
What I do with it is the work itself, invoicing you for it, handling warranty questions and anything that goes wrong, and keeping the accounts that Austrian law requires me to keep. I also use it to run the business sensibly: knowing who my customers are, what I have promised them, and what I still owe them.
Who else sees it is only those who need to, and only as much as they need. In practice that means my accountant, my bank, and where physical delivery is involved, the carrier. If a specific project requires bringing in a manufacturing partner or a subcontractor, I tell you before it happens. I do not pass your data to anyone for marketing, mine or theirs.
The legal basis is the performance of our contract and the steps leading up to it (Art. 6(1)(b) GDPR), the legal obligations that come with running a business in Austria (Art. 6(1)(c) GDPR), and my legitimate interest in orderly administration, in defending myself if a dispute arises, and in keeping my systems secure (Art. 6(1)(f) GDPR).
Sometimes I see data that is not yours either. Development and analytical work can mean I handle information belonging to your clients, your staff, or your measurements. Where that happens, I handle it under the terms we agree for that project, I use it only for the work in question, and I return or delete it when the work is done.
Social media
I post about PalmChrom on LinkedIn, Instagram, and Facebook. If you follow me there, comment, or send me a message, the platform handles your data under its own rules, not mine, and I have no control over that. All of these companies use what you do on their platforms to build advertising profiles, and all of them may process your data outside the European Union.
What I do with it is narrow. I read what you write to me and I reply. If a message turns into a real conversation about the instrument, it ends up in my email and is covered by the contact section above. The legal basis is my legitimate interest in being reachable and in talking about what I build (Art. 6(1)(f) GDPR).
LinkedIn is operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Their privacy policy is at linkedin.com/legal/privacy-policy and transfers outside the EU are based on the Data Privacy Framework.
Facebook is operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Their privacy policy is at facebook.com/privacy/policy and transfers outside the EU are based on the Data Privacy Framework.
Instagram is operated by the same company as Facebook, and its privacy policy is at privacycenter.instagram.com/policy. My account there is a professional one, which means Meta gives me aggregated statistics about who sees my posts. I never see individual names or profiles in those statistics, only counts. For the collection of that data, Meta and I may be considered jointly responsible.
If you want your data deleted, or want to know what any of these platforms holds on you, ask them directly. They hold it, not me, and they are the only ones who can act on it. If you get stuck, write to me and I will help as far as I can.
Where your data goes
Everything I control directly stays in the European Union. The site is hosted in Germany, the form submissions sit on that same server, and my email is with the same provider.
Some of the services described above are another matter. Google and Meta are both incorporated in Ireland, and their European operations are what I deal with, but both are subsidiaries of American parent companies and both may transfer data to the United States or elsewhere.
This is worth being straightforward about. Data protection outside the European Union is not equivalent to data protection inside it, and that is not a formality. In the United States in particular, public authorities have powers of access to data held by American companies that go beyond what European law permits, and the practical routes for challenging that are narrower than the ones available to you here. The legal mechanism that permits these transfers is the adequacy decision adopted by the European Commission in July 2023, known as the EU-US Data Privacy Framework, together with the standard contractual clauses the providers have in place. The companies named in this policy are certified under that framework.
What this means in practice is that if you decline the analytics and advertising cookies, no data about your visit leaves the European Union, because the services that would send it never load. Your dealings with me by email, by telephone, or through the contact form do not leave the European Union at all. The one exception is the social media accounts, where your data reaches those platforms because you are using them, and that is between you and them regardless of anything I do.
How long I keep your data
The general rule is that I delete data once the reason I had for holding it no longer applies. The exception is that some data I am obliged to keep even after that point, and Austrian law is quite specific about which.
Server logs: 30 days. Then deleted or anonymized, unless a particular incident is still being investigated.
Contact inquiries that lead nowhere: until the conversation is over. If you write to me and we conclude the matter, I have no reason to keep your message and I do not.
Form submissions: twelve months. Everything you send me through the contact form is stored on my server as well as arriving in my inbox. Each submission is deleted from that store automatically once it is twelve months old. What has become part of an ongoing working relationship lives on in my email, under the rules below.
Consent records: three years. The record of what you chose in the cookie banner is kept for three years from each decision, which is the limitation period under §1489 ABGB, so that I can demonstrate your consent if it is ever questioned. Then it is deleted automatically.
Email: reviewed periodically. Correspondence that has tax or commercial relevance falls under the seven year rule below. The rest I review from time to time and delete what no longer serves any purpose. I would rather tell you that honestly than commit to a schedule I would not keep.
Anything with tax relevance: seven years. Invoices, accounting records, annual statements, business correspondence, and the documents behind them. This is required by §132 BAO and §§190 to 212 UGB. I have no discretion here, and neither does any other Austrian business.
Contract data where a claim could still arise: three years. This is the limitation period under §1489 ABGB for warranty and damage claims. If a longer statutory obligation applies to the same document, the longer one wins.
Cookies: up to two years, unless the cookie banner tells you otherwise for a specific one.
Two practical details about how these periods are counted. A period that does not start on a named date begins at the end of the calendar year in which the triggering event occurred, so an invoice issued in March 2026 starts its seven years on 31 December 2026. And where a contractual relationship is ongoing, the triggering event is the day it ends, not the day it began.
If several periods apply to the same piece of data, I keep it for the longest of them, and I use it only for the reason that justified keeping it. Once a document survives solely because the tax office requires it, that is the only thing it is used for.
How your data is protected
I take appropriate technical and organizational measures to protect your data, proportionate to the risk involved. Since I would rather be specific than reassuring, here is what that consists of.
This site is served exclusively over HTTPS, using TLS encryption. Everything you send me through the contact form, and everything the site sends back to you, is encrypted between your browser and my server. You can recognize this by the padlock in your address bar.
Access to the server and to the site’s administration is protected by unique passwords and two factor authentication, and backups are encrypted and stored separately from the server itself. The site’s software is kept up to date, since outdated software is the most common way websites are compromised.
I keep the number of third parties involved to the minimum I can manage. Fonts are served from my own server rather than from Google’s. I do not install components that collect data I have no use for, and where I have a choice of provider, I prefer one whose servers are in the European Union. Data that is no longer needed is deleted rather than archived indefinitely.
One thing I cannot protect is email. It is not encrypted end to end. It is normally encrypted while traveling between servers, but it sits unencrypted on the servers it passes through, mine included. If you need to send me something genuinely confidential, tell me and we will find another way.
Your rights
All of the following are yours by law, they cost you nothing, and you do not need to explain why you want them. Write to david [at] palmchrom [dot] com and I will answer within a month. If your request turns out to be complicated, the law allows me two further months, and in that case I will tell you so within the first one.
Ask me what I have. You can request confirmation of whether I hold data about you, and if I do, a copy of it, together with what I use it for, where it came from, and who else has seen it.
Have it corrected. If something I hold about you is wrong or incomplete, tell me and I will put it right.
Have it deleted. You can ask me to erase your data. I will, unless I am legally obliged to keep it, in which case I will tell you which obligation and for how long.
Have it frozen instead. If deletion is not what you want, or is not possible, you can ask me to restrict processing. The data stays where it is but I stop using it.
Take it with you. Data you have provided to me, I will give you in a structured, machine readable format, or send directly to whoever you nominate.
Withdraw your agreement. Wherever I rely on your consent, you can take it back, and it is as easy to take back as it was to give. Withdrawing does not make what came before it unlawful, it simply stops things from that point on.
Object. Where I process your data on the basis of my legitimate interest, you can object on grounds arising from your particular situation, and I must stop unless I can demonstrate compelling grounds that override your objection. Where the processing is for direct marketing, there is no balancing exercise at all: you object, I stop, without exception.
Complain about me. If you think I am handling your data unlawfully, you can complain to a supervisory authority, either where you live, where you work, or where you believe the problem occurred. For Austria that is the Österreichische Datenschutzbehörde, Barichgasse 40 to 42, 1030 Vienna, dsb@dsb.gv.at. You do not need to raise it with me first, though I would appreciate the chance to fix it.
Changes to this page
This policy describes what I do now. When what I do changes, the policy changes with it, and the date at the top tells you when that last happened.
Most changes will be small, and you will not hear about them. If a change requires something of you, such as agreeing to something new, or if it materially alters what happens to data I already hold about you, I will tell you rather than expecting you to notice.
The addresses and links in this policy belong to other companies and may go out of date. If one of them does not work, tell me and I will fix it.