We take the protection of your personal data seriously. The legal framework is, in particular, the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021).
1. Controller and contact
The controller responsible for processing your personal data is:
Neptun Data Processing GmbHFrodlgasse 17j
9020 Klagenfurt am Wörthersee
Austria
Data protection enquiries: privacy@neptun.ai
General contact: mail@neptun.ai
Phone: +43 699 15268671
2. Visiting the website and hosting
Hosting with Amazon Web Services
Our website is hosted by Amazon Web Services (AWS) in the Frankfurt am Main region, Germany. AWS provides the server infrastructure needed to run it and processes personal data in doing so as our processor.
When you visit our website, technical connection data is processed, in particular your IP address, the time of access, the content requested and information about your browser and operating system. This serves to provide the website, to fix errors and to protect against abusive access.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in operating our website securely and reliably.
In the event of specific security incidents, the necessary log data may be kept for longer where this is needed to investigate the incident or to establish, exercise or defend legal claims.
4. Enquiries and demo appointments
When you contact us through the contact form, by email or by phone, we process the information you give us. Depending on the enquiry, this includes your name, your organisation, your contact details, the area of interest you selected and the content of your message.
We use this data to answer your enquiry, arrange an appointment and, where applicable, prepare an offer.
Where your enquiry relates to a contract with you or to pre-contractual steps taken at your request, processing is based on Art. 6(1)(b) GDPR. For other enquiries and for communication with contact persons at companies, we rely on Art. 6(1)(f) GDPR. Our legitimate interest is handling your enquiry and business communication.
Providing your information is voluntary. Without the information needed to handle it, however, we cannot answer your enquiry, or only to a limited extent.
We generally keep enquiries for six months after they have been dealt with. They are kept longer only if the data is needed for a subsequent contractual relationship, statutory retention obligations or the handling of specific legal claims.
An enquiry does not automatically sign you up for our newsletter.
5. Using the HeadlineHunter dashboard
The HeadlineHunter dashboard is also hosted by Amazon Web Services (AWS) in the Frankfurt am Main region, Germany.
When you use the HeadlineHunter dashboard, we process the data you provide and data that arises when we deliver our services. This includes in particular:
- Account data: information for setting up and assigning your user account.
- Usage data: your selection criteria and settings for news monitoring.
- Activity data: data about the use of functions and technical events in the dashboard.
- Billing and payment data: information needed to process paid services.
We use this data to provide your access and the agreed functions, apply your settings, give support and bill for our services.
Where you are yourself a party to the contract, the legal basis is Art. 6(1)(b) GDPR. If you use the dashboard as an employee or agent of a customer, your access is managed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in providing and managing the service the customer has commissioned. Statutory documentation and retention obligations fall under Art. 6(1)(c) GDPR.
The information needed to set up the account and deliver the service is a prerequisite for providing the access. Without it we cannot deliver the services concerned.
Retention
Account data and saved settings are processed for as long as your user account exists. After the account is closed, access data and settings no longer needed for operation are deleted within 90 days at the latest. Technical activity logs are generally deleted after 30 days at the latest. Data is deleted earlier as soon as it is no longer needed for its purpose.
Customer account management is subject to the separate period of no more than one year after all business relationships have ended. Statutory retention obligations and data needed to handle specific legal claims remain unaffected.
Content we process on behalf of our customers
Where we process personal content solely on behalf of and on the instructions of a customer, that customer is the controller for this processing. Our work as a processor is then governed by an agreement under Art. 28 GDPR. This is distinct from our own responsibility for account, contract and billing data.
Information on dashboard cookies is in the Cookies section; details of storage and deletion are in the Retention section.
6. Customer account management and contract handling
To manage our business relationship we process, depending on the contract, the name or company name, business and billing addresses, contact details, company register number and VAT number, details of contact persons and project participants, and order, bank, billing and support data. Purely corporate information with no link to a person does not fall under the GDPR.
We use this information to initiate and carry out contracts, for communication, invoicing, payment processing and handling support requests. We receive the data from you or, if you act as a contact person or user, possibly from your organisation.
The legal bases are Art. 6(1)(b) GDPR for contracts with the data subject, Art. 6(1)(c) GDPR for statutory obligations and Art. 6(1)(f) GDPR for managing business contacts and legitimate claims. Our legitimate interest is organising and carrying out our business relationships. Consent is not the general basis for the necessary customer account management.
Automated decisions
In managing accounts and contracts, we do not make decisions based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you.
7. Audience measurement with Matomo
We use the self-hosted web analytics software Matomo to understand how our website and the HeadlineHunter dashboard are used and how we can improve what we offer.
In particular, we process the pages and functions accessed, the time and duration of access, the previously visited page, and technical information about the browser, device, operating system and screen resolution. IP addresses are shortened and not stored in full. Matomo runs on our own server infrastructure. Analytics data is not transferred to the vendor of the Matomo software.
The analysis works without tracking cookies. For logged-in users of the dashboard, usage can be linked to a pseudonymous internal user ID. Names and email addresses are not transmitted to Matomo.
We also record whether a contact or newsletter form was submitted successfully. The content entered in the forms is not transmitted to Matomo.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in understanding how our website and our dashboard are used, identifying technical and content-related weaknesses, and improving what we offer.
The retention period is described in the section “Retention and deletion”. You may object to the processing on grounds relating to your particular situation.
9. Recipients of your data
Within our company, only those people who need your data for the tasks described have access to it.
Where we use service providers for hosting, IT operations, communication or newsletter delivery, they receive only the data they need for their task. Where service providers process data on our behalf, this is done on the basis of a data processing agreement under Art. 28 GDPR.
Where this is necessary to perform a contract or required by law, the following recipients may also be involved:
- payment service providers, to process payments;
- accounting, tax advisers and auditors, to meet accounting and statutory obligations;
- legal representatives and debt collection agencies, to handle legitimate claims or legal claims;
- courts and competent administrative authorities, to meet statutory obligations or in legal proceedings.
Transfers are limited to the data needed for the purpose concerned. The legal basis depends on that purpose, in particular Art. 6(1)(b), (c) or (f) GDPR.
Processing through Mailchimp may involve a transfer to the USA. The safeguards provided for this are described in the Newsletter section.
10. Links to other websites
Our website and the HeadlineHunter dashboard contain links to external websites. If you follow such a link, the provider concerned processes your data under its own privacy terms.
This note concerns ordinary links. Where external content or services are embedded directly in our website and receive data as soon as a page is opened, they are described separately in this privacy policy.
11. Retention and deletion
We keep personal data only for as long as is necessary for the purpose of the processing. Once that purpose ceases, we delete the data unless statutory retention obligations or other permissible grounds for further storage apply.
User accounts and customer management
Customer account data is kept for the duration of the business relationship and, where needed to wind it up, for no more than one year after all business relationships have ended. If the data is no longer needed earlier, we delete it earlier. Statutory retention obligations and the necessary handling of specific legal claims remain unaffected.
Dashboard access data and saved settings no longer needed are deleted no later than 90 days after the account is closed. Technical activity logs are generally deleted no later than 30 days after they are recorded.
For books, records and receipts that must be kept for tax purposes, the retention period under § 132 of the Austrian Federal Fiscal Code (BAO) is generally seven years from the end of the relevant calendar year. Pending proceedings may require longer retention. This obligation does not apply across the board to all usage or activity data.
Server logs and Matomo
| Data | Maximum retention |
|---|---|
| Personal server logs | 30 days from recording, for error analysis and securing operation. |
| Personal Matomo raw data | Six months from recording, for timely analysis of website use; then deletion or full anonymisation. |
| Fully anonymised usage and operating statistics | 24 months from the reporting period concerned, so that trends and seasonal differences can be compared over two years. |
The periods stated are maximum periods. Data is deleted earlier if it is no longer needed for the purpose concerned.
Retention for 24 months requires the statistics concerned to be fully anonymised so that no conclusions about individuals can be drawn. Merely aggregating data or shortening IP addresses does not automatically ensure this.
Longer retention in justified individual cases
In justified individual cases, such as late payment, disputed claims or security incidents, the server logs and activity data needed for this may be kept beyond the regular periods. This applies only where and for as long as the data is needed to clarify the matter or to establish, exercise or defend legal claims. Access is restricted to the people responsible.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in investigating specific incidents and protecting our legal claims. As soon as the reason for further storage ceases and no statutory retention obligations apply, the data is deleted.
12. Your rights
Subject to the statutory requirements, you have the right to:
- access to information about the processing of your personal data;
- rectification of inaccurate or incomplete data;
- erasure of your data;
- restriction of processing;
- data portability, where the statutory requirements are met;
- withdraw consent with effect for the future.
Right to object
Where we process data on the basis of Art. 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will then no longer process the data concerned unless compelling legitimate grounds prevail or the processing serves to establish, exercise or defend legal claims.
You may object at any time, without giving reasons, to the processing of your personal data for direct marketing. This also applies to related profiling.
To exercise your rights, write to privacy@neptun.ai.
Right to lodge a complaint
You can also lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. In Austria, this is the:
Austrian Data Protection Authority (Datenschutzbehörde)Barichgasse 40–42
1030 Vienna
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
13. Updates to this privacy policy
We update this privacy policy when our data processing or the legal requirements change. The current version is always available on this website.