This is a convenience translation. The German version is legally binding.
The protection of your personal data is of particular concern to us. We therefore process your data exclusively on the basis of the statutory provisions (GDPR, Austrian Telecommunications Act — TKG 2021). In this privacy notice, we inform you about the most important aspects of data processing on our website.
Contacting us
If you contact us via the form on the website or by email, the data you provide will be stored by us for six months for the purpose of processing your request and in case of follow-up questions. We will not share this data without your consent.
Data storage
We would like to point out that, for the purpose of simplifying the purchasing process and for subsequent contract processing, we store the IP data of the connection owner in cookies, as well as the buyer's name, address, email address, and credit card number (when paying by credit card). The data you provide is required for the fulfilment of the contract or for carrying out pre-contractual measures. Without this data, we cannot conclude the contract with you.
Data will not be transferred to third parties, with the exception of the transmission of credit card data to the processing banks / payment service providers for the purpose of debiting the purchase price, to the transport/shipping company commissioned by us for the delivery of the goods, and to our appointed accounting office (tax advisor, accountant) for the fulfilment of our tax obligations.
If the purchasing process is cancelled, the data stored by us will be deleted. In the event that a contract is concluded, all data arising from the contractual relationship will generally be stored until the expiry of the tax-law retention period (7 years), and at most until the expiry of the general civil-law limitation period (30 years). Data processing is carried out on the basis of the statutory provisions of § 165 (3) TKG 2021 and Art 6 (1) lit a (consent) and/or lit b (necessary for the fulfilment of the contract) of the GDPR.
Cookies
Cookies are small text files the browser stores on your device. We use them in three clearly separated groups and ask you before any of them goes beyond what is necessary:
- Necessary (no consent needed, § 165 (3) TKG 2021): the login cookie of your session, the cookie holding your language choice ("hg_lang") and the cookie that records your cookie decision itself ("hg_consent", one year). Without them you cannot stay signed in, or we would have to ask you again on every visit.
- Analytics (only with your consent, Art 6 (1) lit a GDPR): cookies of our self-hosted statistics (Matomo, see below) so that a later visit is recognised as a returning visit. Without consent we keep measuring, but without cookies and without recognition.
- Marketing (only with your consent): measuring the ads that brought you here. At present we set no marketing cookies and share nothing with ad platforms; should that change, this group appears as its own choice in the cookie notice.
You make your decision in the cookie notice on your first visit and change it at any time under Cookie settings (in the footer of the website and in the app menu). If you are signed in, we also store the decision on your account so it applies server-side too. Independently of that you can set your browser to reject or delete cookies; signing in is then limited.
Analytics
When you visit our website, personal data is processed automatically by analytics software on the basis of the statutory provisions of § 165 (3) TKG 2021 and Art 6 (1) lit a (consent) and/or lit f (legitimate interest) of the GDPR. The purpose of this data processing, which also reflects our legitimate interests, consists of an improved analysis of user behavior and personal preferences for the targeted distribution of advertising with the aim of avoiding wastage, acquiring new customers to increase our reach, collecting user numbers to document our reach, and improving our services.
We use "Matomo" as our analytics software. We host Matomo ourselves on our own servers in Germany; no analytics data is transmitted to the makers of Matomo or to any other third party.
Matomo runs without cookies unless you allow otherwise. Without your consent no tracking cookies are set and no comparable information is stored on or read from your device; every visit then counts separately. If you agree to "Analytics" in the notice, Matomo may set a cookie so that a later visit is recognised as a returning visit. Your account identifier is never passed to the analytics: the evaluation happens at the level of reach and usage patterns, not as a personal usage profile of individual accounts. We store your decision in a necessary cookie ("hg_consent", one year) and, when you are signed in, on your account; you can change it at any time under Cookie settings. These statements concern Matomo; session recording has its own section below.
This data is collected in databases and stored on servers in Germany (operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany). The data is processed by our own employees and by the following third-party companies, which may also access this data for technical, economic, and/or contractual reasons: the controllers of "Stripe" (Stripe Payments Europe, Ltd., Ireland) (https://stripe.com/at/privacy), the controllers of "auth0.com" (https://www.auth0.com/privacy), the controllers of "Loops" (Loops, Inc., USA) (https://loops.so/privacy).
Session recording
In addition to reach measurement we record usage sessions, so we can see where the app is confusing or breaks. On the public pages (start page, self-test, content previews) this happens only with your consent in the cookie notice (service „Session recording“, Art. 6(1)(a) GDPR), revocable at any time under Cookie settings; without consent nothing is recorded there. We use „OpenReplay“ for this and run it on our own servers in Germany (Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen). Recordings are not passed to any third party, the vendor included.
What is recorded: the structure of the pages shown to you and how it changes, clicks, scrolling and mouse movement, the pages you visit, details about your browser and device, application error messages, and for network requests the address, the status and the duration.
What is not recorded: anything you type into a form — every input field is masked by default, with no exception list. E-mail addresses, numbers and dates in displayed text are masked as well, as is every area that shows content of your own (self-reflections, goals and lists, for example). The bodies of network requests and responses are never transmitted.
Exception for the assistant: your conversation with the assistant (your questions and its answers) is readable in the session recording, so we can see where the assistant fails to help. What you type into the input field stays masked; the conversation becomes visible once it is displayed. Please do not give the assistant names, addresses or health data of other people.
Link to your account: when a session is signed in, the identifier of your login account is attached to it — not your name and not your e-mail address. This creates a pseudonymous link between a recording and an account. Identifiers are also stored in your browser so that the parts of one session can be held together.
Legal basis is Art 6 (1) (f) GDPR. Our legitimate interest is finding usability problems and errors that nobody reports to us — the large majority of affected people do not complain, they leave. We keep the intrusion as small as we can through the masking described above.
Objection and switching it off: if your browser sends the „Do Not Track“ signal, no recording takes place. Independently of that, you can switch recording off for this browser in your account settings. You may also object to the processing at any time under Art 21 GDPR (see contact above).
Retention: recordings are deleted after 30 days at the latest. There is no backup of this data; once the period has passed it cannot be restored.
User account
When you sign in, personal data from your login account is also stored in our own database. This lets us link your account to your usage and to support requests; without that link we could neither show you your own content nor answer a request. The legal basis is Art 6(1)(b) GDPR (performance of the contract). This data is deleted together with your account when you delete it.
Self-test and account: the public self-test is evaluated without reference to you. If you tick “Link my result to my new account” on the result page, we store the three section levels (body, soul, mind) and the mean with your account – not the single answers. This is information about your health; we process it solely on the basis of your explicit consent (Art 9(2)(a) GDPR), to understand which starting points bring people to us and how usage differs afterwards. You withdraw at any time by choosing “Reset data” in your profile or by deleting your account; without the tick nothing is linked.
Payment processing
We use "Stripe" (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland) to process payments. When you make a purchase, the data required for the payment (in particular name, email address, billing data, and payment method data) is transmitted to Stripe and processed there. Payment method data such as credit card numbers is processed exclusively by Stripe and is never stored by us. The legal basis is Art 6 (1) lit b GDPR (performance of the contract). Stripe may also transfer personal data to affiliated companies in the USA; such transfers are based on the European Commission's Standard Contractual Clauses (Art 46 (2) lit c GDPR). For details, please see Stripe's privacy policy: https://stripe.com/at/privacy.
Transfer to the USA (email/newsletter): For sending emails and managing newsletter and contact data we use the service "Loops" (Loops, Inc., USA). In doing so, personal data (in particular email address and name) is transferred to a provider in the USA. The legal basis for the transfer is your consent (Art 6 (1) lit a in conjunction with Art 49 (1) lit a GDPR); in addition, where applicable, we base the transfer on the European Commission's Standard Contractual Clauses (Art 46 (2) lit c GDPR) and a data processing agreement pursuant to Art 28 GDPR. The USA may not offer a level of data protection equivalent to EU law; access by US authorities cannot be entirely ruled out.
The following personal data is processed in this context: for newsletter subscribers, the email address and name; for donors, the donor's contact details (name, address, email, bank account or credit card details); for visitors to our website, internet browsing data and IP addresses, insofar as this data is technically traceable in each case. This data is stored until the expiry of the general statutory limitation periods, unless it is deleted earlier for technical or legal reasons.
Newsletter
You have the option of subscribing to our newsletter via our website. For this, we need your email address and your declaration that you consent to receiving the newsletter. Your name and email address are processed and stored by our email service provider "Loops" (Loops, Inc., USA) (see the note above on the transfer to the USA). You can cancel your newsletter subscription at any time. Please send your cancellation to the following email address: . You can also cancel the newsletter subscription via a dedicated link in the newsletter itself.
If you sign up via the form on our website, our server forwards your address to Loops and itself keeps only a check value of it (SHA-256 hash) together with the time, page and campaign of the signup. The check value serves solely to recognise whether a newsletter signup later becomes an account; the address cannot be recovered from it. Our team is notified internally about every signup – without your address.
Your rights
You are generally entitled to the rights of access, rectification, erasure, restriction, data portability, withdrawal of consent, and objection. If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been infringed, you can lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority (Datenschutzbehörde). You can reach us at the following contact details: Sebastian Starke, Trattfelderstrasse 21/1, 8054 Graz -- .