Skip to content
Setup FoundrySetup Foundry

Privacy Policy

Controller
Steidl IT GmbH
Hervicusgasse 19/2/15
1120 Vienna, Austria
Email: office@setupfoundry.com

No data protection officer has been appointed; the statutory conditions for appointing one are not met.

This policy covers the websites setupfoundry.com, docs.setupfoundry.com and download.setupfoundry.com. A separate privacy policy applies to the Setup Foundry desktop software; you will find it in the software and at download.

When you visit this website
Each time a page is requested, your browser necessarily transmits data to our server: IP address, date and time, the address requested together with the method and protocol, the status code, the volume of data transferred, the page previously visited (referrer), browser and operating system identifiers, and the response time. Our server records this in access logs in order to keep the service secure and to detect attacks (Art. 6(1)(f) GDPR). The logs are rotated daily; a rotated log is deleted once it is more than 30 days old — that is, at the latest about one month after the visit.

This website uses no analytics and no advertising services, and embeds no third-party content. All content, including fonts, is served from our own server; visiting the site transfers no data to third parties.

Access by invitation
Parts of this website are currently accessible only with an invitation code. When you redeem a code, we set two cookies for that purpose:

  • site_access — a signed token stating only that you may be admitted. It holds no information about you.
  • einladung_ergebnis — a signed token including your invitation code, so that the download page can show you exactly the version and details belonging to your invitation. Through the code, this data is attributable to you.

Both are protected against access by scripts (HttpOnly) and are transmitted only over an encrypted connection (Secure). They are renewed each time you are admitted and expire by themselves if you do not return for a longer period. They are strictly necessary for the access you requested (§ 165 para 3 Austrian Telecommunications Act 2021, Telekommunikationsgesetz 2021, TKG 2021) and therefore require no consent; the associated processing is based on the performance of your participation in the test programme (Art. 6(1)(b) GDPR). This section ceases to apply when the beta ends.

Cookies and local storage
Apart from that, we store only your display and language preferences, all on this domain only:

  • sprache — a cookie holding the language version you have chosen (de or en). It is created only when you switch languages, and makes sure you see the sites in your language on every visit. As long as you do not switch, no cookie is set; which version you see first then follows from your browser's language setting alone. The cookie is strictly necessary for the display you expressly chose (§ 165 para 3 TKG 2021) and requires no consent; the associated processing rests on our legitimate interest in a working multilingual site (Art. 6(1)(f) GDPR).
  • Light/dark display — entries in your browser's local storage (fnd-web-modus, vitepress-theme-appearance, foundry-theme-modus). They record how you want the site displayed, are never transmitted to us and contain no identifier relating to you; they are strictly necessary for the display you requested (§ 165 para 3 TKG 2021).

You can delete all of these at any time in your browser; the sites work without them. No cookies are set for advertising or analytics, and there is no tracking pixel.

When you write to us
We process the details you give us and the content of your message in order to deal with your enquiry (Art. 6(1)(b) GDPR where it concerns an order, otherwise Art. 6(1)(f)). Messages relating to orders are retained for as long as we are required to retain them for tax purposes (seven years, § 132 Austrian Federal Fiscal Code, Bundesabgabenordnung, BAO); all others are deleted once the matter is closed and no further questions are to be expected. Providing your details is voluntary; without them, however, we cannot reply to you.

Who else receives the data

  • Andreas Steidl, sole proprietor, Hervicusgasse 19/2/15, 1120 Vienna, Austria — operation and hosting of these websites on behalf of the company, processor (Art. 28 GDPR). For this he uses server infrastructure of netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany, as a sub-processor, with further sub-processors of the Anexia group in Austria and Germany; the processing takes place at the data centre in Vienna. No processing outside the European Union takes place in this context.
  • Google Cloud EMEA Limited, Dublin, Ireland — email service (Google Workspace), processor. Google may also process data in the United States; the basis for this is the European Commission's adequacy decision on the EU-US Data Privacy Framework, supplemented by standard contractual clauses.

Your rights
You have the right of access (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object (Art. 21). A message to office@setupfoundry.com is sufficient; we will reply within one month.

Right to object (Art. 21(1) GDPR)
Where we process data on the basis of legitimate interests — this concerns the access logs, the language cookie and messages outside an order — you may object at any time on grounds relating to your particular situation.

Right to lodge a complaint
You may lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde): Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.

Changes
Once the customer account at account.setupfoundry.com is available, this policy will be extended to cover the processing that takes place there.