1. Controller
Responsible for the data processing in connection with the MAGSARO platform is:
Adrian Kloc Digital Solutions (AKDS)
Lisztgasse 2/3/23, 2284 Untersiebenbrunn, Österreich
Email: office@akds.at
2. Overview of processing & purposes
We process personal data solely for clearly defined purposes:
- Account & contract data (name, email, login, booked plan) — to provide your access and handle the hosting contract.
- Website content that you create or upload in the generator — to create and operate your website.
- Payment data — to process your monthly payments via our payment service providers.
- Support & ticket data — to handle your requests via our integrated ticket system.
- Usage & log data — for security, stability and error analysis.
3. Legal bases
- Art. 6(1)(b) GDPR (performance of a contract) — account, hosting, payment processing, support.
- Art. 6(1)(f) GDPR (legitimate interest) — operation, security, anonymous reach measurement, SEO analysis.
- Art. 6(1)(a) GDPR (consent) — where required, e.g. when loading external maps or connecting an external calendar.
- Art. 6(1)(c) GDPR (legal obligation) — e.g. tax-law retention of invoices.
4. Hosting & server logs
The platform and all customer websites are hosted with Hetzner Online GmbH in Nuremberg, Germany — so your data does not leave the EU for pure operation. When a page is accessed, technically necessary server logs (including IP address, timestamp, requested resource) are processed to ensure operation and security. These logs are stored only briefly and are not merged with other data.
5. Reach measurement (cookieless)
For anonymous statistics we use Plausible Analytics — self-hosted on servers in the EU. Plausible works without cookies and without personal data: no profiles are created, IP addresses are not stored, and there is no cross-device tracking. That is why no cookie banner is required for this. The legal basis is our legitimate interest in improving our offering (Art. 6(1)(f) GDPR).
6. AI-assisted generation
To generate copy, designs and logos, we transmit your business description and chosen settings to AI services (Anthropic and OpenAI). No sensitive personal data is passed on — only the information needed to generate your content. The providers are located in the USA; the transfer is safeguarded by standard contractual clauses or the EU-US Data Privacy Framework (see section 12). If you use receipt capture, uploaded supplier invoices are also transmitted to the same services for automated reading; they are processed solely for that purpose, are not used for training and are deleted after a short period — the extracted data is stored only with us.
7. SEO & competitor analysis
As part of our SEO service, at your request we analyze competitor websites named by you. In doing so, we evaluate only publicly accessible, search-engine-relevant data (in particular page titles, meta tags, headings and thematic keywords). We respect the robots.txt of the respective website, do not copy content, and do not process personal data of third parties. The evaluation serves solely to improve the visibility of your website.
8. Payment processing
We process payments via external payment service providers (Stripe, PayPal and — depending on your selection — Apple Pay or Google Pay). You enter the payment data (e.g. card details) directly with the respective provider; we do not store full credit card data. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
9. Maps & calendar synchronization
You activate the following functions yourself, thereby integrating third-party services:
- Calendar synchronization: Sync appointments with your own calendar (only after you explicitly connect it) (Provider: Google Calendar, Microsoft Outlook/365, Apple iCloud).
- Location map (Google Maps): Shows the business location on the customer website — loaded only after the visitor clicks/consents (Provider: Google Ireland Ltd.).
Location map (Google Maps): If you embed a map on your website, it is only loaded after your visitors actively consent (two-click solution). Only then is data transmitted to Google. The legal basis is consent (Art. 6(1)(a) GDPR).
Calendar synchronization: If you connect an external calendar (Google, Microsoft/Outlook or Apple), we sync appointments to the extent you have authorized. We store the required access tokens in encrypted form; you can disconnect the connection at any time in the settings. The legal basis is your consent or the performance of the contract (Art. 6(1)(a) or (b) GDPR).
10. Google user data (Google API Services)
This section describes separately which data MAGSARO receives from your Google account through Google APIs, what we use it for, whom we share it with, how we protect it and how long we keep it. It applies in addition to the other statements in this policy. We only receive Google data if you connect a Google account yourself or sign in with Google.
Which Google user data we access: Only the data covered by the scopes you approve on the Google consent screen: (1) the primary email address of your Google account (userinfo.email scope) — so that the settings show which account is connected and so that signing in with Google can be matched to your account; (2) the list of your calendars including name and colour (calendar.readonly scope) — so that you can choose which calendar is synchronized; (3) the events of the selected calendar including title, description, location, start and end time, time zone, attendees, recurrence rule and status (calendar.events scope) — read and write, so that appointments can be synchronized in both directions. If you sign in with Google, we additionally process your name and profile picture (openid and userinfo.profile scopes) to create and display your account. We do not access any other Google services such as Contacts, Drive, Gmail, Photos or advertising accounts.
What we use it for: Solely to provide the features you visibly requested: synchronizing your appointments between MAGSARO and your Google calendar (including bookings made by your customers, so that busy times are not double-booked) and — when signing in with Google — authenticating you to your account. We do not use Google user data for advertising, profiling, credit or scoring purposes, we do not sell it, and we do not use it to train AI models. Calendar data from Google is never passed to our AI providers (Anthropic, OpenAI).
Whom we share it with: No one. We do not sell Google user data, do not transfer it to advertising networks, data brokers, analytics or AI providers, and do not combine it with data from other sources. It is processed exclusively on our own servers at Hetzner Online GmbH in Nuremberg (Germany, EU), which acts as our processor for server operations only and takes no access to the content. Beyond that, we disclose it only if you expressly consent in the individual case, if disclosure is necessary to investigate or prevent a security incident or fraud, or if we are required to do so by law or by a public authority.
How we protect it: We store the access and refresh tokens of your Google connection in encrypted form only (AES-256-GCM); the key is held in the server environment, separately from the database. All transfers use TLS/HTTPS throughout. Each account's data resides in its own isolated database schema, and the database is not reachable from the internet. Administrative access is limited to a small number of named accounts protected by two-factor authentication. We do not read your calendar data — the only exceptions are a support case you explicitly request, the mitigation of a security incident, and legal obligations. Changes and access are logged.
How long we keep it and how you delete it: While the connection exists, we keep the synchronized events for a window from 30 days in the past to 400 days in the future. If you disconnect under “Settings → Calendar”, we delete the stored Google tokens immediately and irreversibly, unsubscribe the change notification channel at Google and remove the links between your events and Google's; any further access to your Google account is thereby ruled out. Events that had already been imported into your MAGSARO calendar remain as your own entries so that your calendar does not silently empty out — you can delete them individually or in bulk in the calendar. Name, email address and profile picture from signing in with Google belong to your user account and are stored for as long as that account exists. If you delete your account (Art. 17 GDPR, informally by email to office@akds.at), we remove your entire data area including all events, sign-in data and tokens; where backups still contain remnants, these are overwritten in the regular rotation cycle. Independently of this, you can revoke access at any time directly at Google under myaccount.google.com/permissions.
Limited Use: MAGSARO's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
11. Data of your website's visitors
When visitors enter data via your website's contact form, newsletter signup, an appointment booking or the live chat, we process this data on your behalf. For this data, you are the controller and we are your processor within the meaning of Art. 28 GDPR. We provide you with a corresponding data processing agreement (DPA). This data is self-hosted on our EU servers and belongs to you — you can export it at any time.
12. Recipients / processors
We use carefully selected service providers with whom — where required — data processing agreements are in place:
| Service | Purpose | Location | Transfer |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting & object storage | Nuremberg, Germany (EU) | No transfer to third countries |
| Anthropic PBC (Claude) | AI generation of texts & SEO analysis | USA | Standard contractual clauses (SCC) / EU-US Data Privacy Framework |
| OpenAI, L.L.C. | AI generation of texts & logos (fallback) | USA | Standard contractual clauses (SCC) / EU-US Data Privacy Framework |
| Stripe Payments Europe, Ltd. | Payment processing (credit card) | Ireland (EU) / USA | Standard contractual clauses (SCC) |
| INWX GmbH & Co. KG | Domain registration & DNS | Berlin, Germany (EU) | No transfer to third countries |
| Plausible Analytics | Cookieless, anonymous analytics (self-hosted, EU) | EU | No transfer to third countries |
13. Third-country transfer
Some service providers (in particular Anthropic, OpenAI and, where applicable, Stripe, Apple and Google) process data in the USA. The transfer is safeguarded by standard contractual clauses (SCC) of the EU Commission and/or a certification under the EU-US Data Privacy Framework. A residual risk of access by US authorities cannot be entirely ruled out; we inform you transparently about this.
14. Storage period
We store personal data only for as long as it is necessary for the respective purposes. We delete account and contract data after the end of the contract, unless statutory retention obligations exist. We keep invoice-relevant data for seven years in accordance with §132 BAO. Server logs are retained only briefly.
15. Your rights
You have the following rights at any time:
- access to the data stored about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing (Art. 21 GDPR)
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
To exercise these rights, an informal message to office@akds.at is sufficient.
16. Right to complain
You have the right to complain to a supervisory authority. The competent authority in Austria is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
17. Currency & changes
We adapt this privacy policy when our processing or the legal situation changes. The current version published here applies in each case.
This is a translation for convenience; in the event of any discrepancy, the German version prevails.