Privacy Policy

Last updated: 15.9.2026

Protecting your personal data is important to us. This privacy policy explains which personal data we process in connection with your visit to and use of our website www.alpsix.at (“Website”), for what purposes, and what rights you have in this regard.

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

BIK Breitbandinitiative Kärnten GmbH
GF Peter Schark
Herrengasse 9/ 2.OG
9020 Klagenfurt am Wörthersee
T +43 463/50 46 00
E office@breitbandinfrastruktur.at
(hereinafter “we”, “us” or “ALPSiX”)

Data Protection Officer / Privacy Contact

For any questions regarding data protection or to exercise your rights as a data subject, please contact:

Gernot Schiffermayer, MLS
G&S Schiffermayer Consulting GmbH
Schönfeldweg 32
9061 Klagenfurt-Wölfnitz, Österreich
Tel.: +43 660 65 106 77
E-Mail: office@schiffermayer.eu

General Information on Data Processing

We only process personal data where this is necessary to provide a functioning website and our content and services, or where a legal basis or your consent exists. The applicable legal basis is stated separately in each section below. Where processing is based on your consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out prior to the withdrawal.

Hosting

This Website is operated by the following hosting provider:

netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany (“netcup”).

On our behalf, netcup processes, as our processor under Art. 28 GDPR, the data generated in the course of operating the Website (in particular server log files, see Section 5) on servers located within the European Union. A data processing agreement under Art. 28 GDPR is in place with netcup. As long as processing takes place exclusively in data centres within the EU, no transfer to third countries occurs.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable, secure and performant provision of our Website).

Server Log Files

Each time you access our Website, our hosting provider automatically collects information in so-called server log files, which your browser automatically transmits. These include in particular:

  • browser type and version
  • operating system used
  • referrer URL (previously visited page)
  • hostname / IP address of the accessing device
  • date and time of the server request
  • amount of data transferred and status code of the request

This data is not combined with other data sources and is used exclusively for the technically error-free provision of the Website and to ensure IT security (e.g. to investigate misuse). Legal basis: Art. 6(1)(f) GDPR. Log files are automatically deleted after [insert hosting provider’s retention period, e.g. 7 days], unless security-related reasons require longer storage.

Cookies and Consent Management (Borlabs Cookie)

Our Website uses cookies, i.e. small text files stored on your device, as well as comparable technologies. Some of these cookies are technically necessary to provide the Website (see Section 7 on language settings); others serve functional, statistical or marketing purposes and are only set with your consent.

To manage your consent, we use the consent management tool “Borlabs Cookie”. It stores your selection (which categories of cookies/external services you have consented to) locally in your browser, including a randomly generated identifier and information on the version, validity period, domain and path of your consent. This data is stored exclusively on our own server and/or in your browser and is not transmitted to the maker of Borlabs Cookie.

Storing the consent decision itself is based on Art. 6(1)(c) GDPR, as we are legally required to be able to demonstrate consent obtained (Art. 7(1) GDPR). The dependent, consent-based cookies and services (see in particular Sections 10 and 11) are only loaded after you actively consent; the legal basis for this is Art. 6(1)(a) GDPR in conjunction with Section 165(3) of the Austrian Telecommunications Act (TKG 2021). You can change or withdraw your consent at any time, with effect for the future, via the settings of the cookie banner.

Language Setting (Polylang)

Our Website is provided in multiple languages (German/English) using the Polylang plugin. To store your selected or detected language setting, Polylang sets the technically necessary cookie “pll_language”. This cookie contains only the code of the selected language, no further personal data, and is used to display the most recently selected language version on a repeat visit.

Legal basis: Art. 6(1)(f) GDPR, or, to the extent the cookie qualifies as strictly necessary within the meaning of Section 165(3) TKG 2021, the corresponding statutory exemption from the consent requirement. The “Connect Polylang to Elementor” plugin (see Section 8) is technically related to this processing but does not itself process any additional personal data.

Connect Polylang to Elementor

This plugin links Polylang’s multilingual functionality with the Elementor page builder and serves solely as internal editorial display logic for translated content. It does not process any personal data of website visitors and does not require any legal basis beyond that stated in Section 7.

Elementor and Elementor Pro

This Website was built using the Elementor and Elementor Pro plugins. These tools are used for the technical design and display of our Website. As such, they do not process personal data of visitors, provided they are used solely for client-side design. To the extent that individual Elementor / Elementor Pro features load external content, the dedicated sections of this privacy policy apply (in particular Section 10 on Google Fonts and Section 11 on video embeds). The peering and colocation inquiry form described in Section 15 is not an Elementor feature but an application developed individually for us.

Google Fonts

To display fonts consistently, our Website embeds fonts (Google Fonts) that are loaded, when a page is accessed, from servers operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). In doing so, your IP address is transmitted to Google. We are not aware of the extent to which Google processes this data further.

This embedding takes place solely on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021, which you give via our consent management tool (Borlabs Cookie, see Section 6) and may withdraw at any time with effect for the future. Without your consent, fonts are not loaded from Google’s servers; the Website falls back to a system default font. Further information on Google’s data processing can be found in Google’s privacy policy at https://policies.google.com/privacy.

Video Embeds (YouTube / Vimeo)

Our Website may embed videos from YouTube (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) and/or Vimeo (provider: Vimeo.com, Inc., 555 West 18th Street, New York, NY 10011, USA). When you play an embedded video, a connection is established to the respective provider’s servers, transmitting, among other things, your IP address and information about your device and browser. The providers may also process and store this data for their own purposes, including to build usage profiles.

Video embeds are only loaded after you actively consent; until then, only a placeholder is displayed. Legal basis: Art. 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021. A transfer of data to the USA as a third country cannot be ruled out; to our knowledge, the providers named rely on Standard Contractual Clauses under Art. 46 GDPR for this purpose. Further information is available in the providers’ privacy policies (https://policies.google.com/privacy and https://vimeo.com/privacy).

Google Analytics

Where you have given your consent, we use the web analytics service “Google Analytics” (Version 4), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), on our Website. Google Analytics uses cookies or comparable technologies that enable an analysis of your use of our Website (including pages visited, time spent, referral source, and device used). In the configuration we use, IP addresses are not permanently stored or evaluated on a personal basis by Google Analytics.

Processing takes place solely on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021, which you give via our consent management tool (Borlabs Cookie, see Section 6), category “Statistics”, and may withdraw at any time with effect for the future. Without your consent, Google Analytics is not loaded.

Data collected via Google Analytics is automatically deleted once the retention period configured in our Google Analytics account has elapsed (currently set to [insert retention period, e.g. 14 months]). A transfer of data to the USA as a third country cannot be ruled out; to our knowledge, Google relies on Standard Contractual Clauses under Art. 46 GDPR for this purpose. A data processing agreement (Data Processing Terms) under Art. 28 GDPR is in place with Google. Further information on Google’s data processing can be found at https://policies.google.com/privacy.

Feedzy RSS Feeds Lite

We use the “Feedzy RSS Feeds Lite” plugin to display the news feed of our own corporate website (https://breitbandinfrastruktur.at/aktuelles/) on our Website. As this is a source operated by us, this integration does not, as a rule, involve any transfer of data to outside third parties. The feed content is retrieved server-side by our Website. Legal basis for this embedding: Art. 6(1)(f) GDPR (legitimate interest in providing up-to-date company news).

Yoast Duplicate Post

The “Yoast Duplicate Post” plugin is an internal editorial tool available only to logged-in editors within the protected WordPress backend (for duplicating posts/pages). It has no effect on the public-facing part of the Website and does not process any personal data of website visitors.

Rank Math SEO

We use the “Rank Math SEO” plugin to optimise our Website for search engines (including meta tags, XML sitemap, and structured data). In our basic configuration, the plugin operates exclusively server-side, sets no cookies, and does not process any personal data of website visitors. Should we activate additional features in the future, such as the Rank Math Analytics module with a connection to Google Analytics or Google Search Console, we will update this privacy policy accordingly.

Google Search Console

We use the free Google Search Console, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to monitor and improve our Website’s visibility in Google Search (including search queries, click counts, impressions, and indexing status). The data shown is collected by Google exclusively in connection with Google Search itself; no cookies are set on our Website through this, and no personal data of website visitors is processed or transmitted to Google as a result. Legal basis for this use: Art. 6(1)(f) GDPR (legitimate interest in analysing and optimising our Website’s discoverability).

WP Rocket

To speed up page loading, we use the caching plugin “WP Rocket”. In our basic configuration, WP Rocket exclusively creates static caches of our website content on our own server; no personal data of website visitors is processed and no data is transferred to third parties. Should we activate optional add-on features of WP Rocket in the future (e.g. a connection to a content delivery network such as RocketCDN or Cloudflare), we will update this privacy policy accordingly.

General Contact (Email, Phone)

If you contact us by email or phone outside of the inquiry form described in Section “Peering and Colocation Requests” below, we process the data you provide (including name, contact details, and content of your message) to handle and respond to your inquiry. Legal basis, depending on the inquiry, is Art. 6(1)(b) GDPR (pre-contractual or contractual inquiry) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries). For the retention period, see Section”Retention Period”.

Peering and Colocation Requests

If you submit a peering or colocation request via our inquiry form – an application developed individually for us – regarding the ALPSiX node in Villach or Klagenfurt, we process the company, contact, network, location, hardware and installation data you provide.

This may in particular include the following categories of personal data:

  • name and contact details of the technical contact person
  • contact details of the 24/7 NOC
  • name and contact details of the billing contact person
  • information about the represented company
  • technical information, to the extent it can be attributed to a natural person
  • content and timing of the request

This processing takes place for the purpose of reviewing and handling your request, contacting you, technical and commercial coordination, preparing an offer, and planning a possible installation and activation.

Legal basis is Art. 6(1)(b) GDPR, insofar as processing is necessary to carry out pre-contractual measures taken at your request. Where the request is submitted on behalf of a company and there is no direct contractual relationship with the named contact person, processing is based on our legitimate interest in handling business inquiries and communicating with the relevant contact persons pursuant to Art. 6(1)(f) GDPR.

Within our company, the data is made accessible only to those persons who require it for technical, commercial or organisational processing. In addition, hosting and IT service providers engaged by us may gain access to the data in the course of providing their services. These service providers are engaged as processors where required. Notification and confirmation emails relating to your request are sent directly via our WordPress installation; no separate external email or SMTP service provider is used for this purpose.

The submitted information is stored in our WordPress database and in the email mailboxes used for processing. We store the data only for as long as is necessary to process the request and to carry out pre-contractual measures. If no contractual relationship is established, the data is deleted no later than 6 months after processing of the request and any related pre-contractual measures has been completed, unless statutory retention obligations or legitimate documentation interests on our part apply. If a contractual relationship is established, the necessary data is transferred into the relevant customer and contract records and stored for the periods applicable thereto.

To protect the form against automated or abusive submissions, a pseudonymised check value is briefly derived from the IP address. This is used exclusively to limit repeated submissions and is automatically deleted after approximately ten minutes. The full IP address is not permanently stored by our form tool.

Providing the information marked as mandatory fields is required in order to process the request. Without this information, we may not be able to process the request.

No decision is made based exclusively on automated processing, and no profiling takes place.

Recipients and Processors

Within our company, access to your data is limited to those persons who require it to fulfil the purposes stated in this privacy policy. In addition, we engage the following categories of service providers, who act as processors under Art. 28 GDPR on our behalf to the extent they gain access to personal data in the course of providing their services:

  • hosting provider (netcup GmbH, see Section 4)
  • IT service providers who maintain and support the Website

Emails relating to our Website (including contact and form inquiries) are sent directly via our WordPress installation and thus via our hosting provider’s infrastructure; no separate external email or SMTP service provider is used for this purpose.

A data processing agreement under Art. 28 GDPR is in place with all providers named above, where required. Your data is transferred to other third parties only where expressly described in this privacy policy, where legally required, or where you have consented.

Transfers to Third Countries

A transfer of personal data to countries outside the European Union / European Economic Area (“third countries”) occurs only in connection with the consent-based services described in Section 11 (video embeds). In these cases, to our knowledge, the respective providers rely on appropriate safeguards within the meaning of Art. 46 GDPR, in particular the European Commission’s Standard Contractual Clauses. Otherwise, data processing takes place exclusively within the European Union.

Retention Period

As a general rule, we store personal data only for as long as necessary for the respective processing purpose, or as long as required by statutory retention obligations (e.g. under the Austrian Commercial Code or the Federal Fiscal Code). Unless a different period is stated in an individual section of this privacy policy, we generally store personal data for a period of 6 months. Deviating, more specific retention periods (e.g. for server log files or Google Analytics) are stated in the relevant sections of this privacy policy and take precedence over this general period.

Your Rights as a Data Subject

Subject to the applicable legal requirements, you have in particular the following rights:

  • right of access to the personal data we process about you (Art. 15 GDPR)
  • right to rectification of inaccurate data (Art. 16 GDPR)
  • right to erasure (“right to be forgotten”, Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to data portability (Art. 20 GDPR)
  • right to object to processing (Art. 21 GDPR)
  • right to withdraw consent given, with effect for the future (Art. 7(3) GDPR)

To exercise these rights, you may contact the party/parties named in Sections 1 and 2 at any time, without any particular form being required.

Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR. In Austria, this is the:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde),
Barichgasse 40–42, 1030 Vienna, Austria,
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at

Automated Decision-Making and Profiling

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.

Data Security

We take appropriate technical and organisational measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorised persons. Our security measures are continuously improved in line with technological developments.

Currency and Amendment of this Privacy Policy

This privacy policy was last updated on [insert date]. Due to the further development of our Website and offerings, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version of this privacy policy is always available on this Website.