Legal
Privacy Policy
This policy explains what data we process when you use alpinesite.cc, why we process it, and the rights you have under the General Data Protection Regulation (GDPR / DSGVO).
1. Controller
The controller responsible for processing under Art. 4 (7) GDPR is:
anvotic e.U.
Rain 14, 6167 Neustift, Austria
Email: [email protected]
2. What we don't do
This site does not use:
- web analytics (no Google Analytics, Plausible, Matomo, or similar)
- marketing or advertising pixels (no Meta Pixel, LinkedIn Insight, etc.)
- third-party tracking scripts or cookies
- session-recording tools
- cross-site profiling
- webfonts or other assets loaded from third-party CDNs (fonts and icons are self-hosted)
We don't track you across other sites and we don't sell or share personal data with advertisers.
3. Data we process
3.1 Demo request form
When you submit the demo request form, we process the data you enter — name, company, role, email, optional asset count, optional notes, and preferred language — to contact you about your demo request and any subsequent business relationship. We additionally record the IP address from which the request was sent and the submission timestamp to enforce the rate limit and prevent abuse. The IP is logged on the server only; it is not included in the notification email.
If the notification email cannot be delivered — for example because our mail provider is temporarily unavailable — the data you submitted is written to our server log instead, so that your request is not lost. This happens only when delivery fails, does not include your IP address, and the entry is deleted when the log rotates: at the latest after 60 days, and sooner if log volume reaches the rotation limit.
Legal basis: pre-contractual measures at your request (Art. 6 (1) (b) GDPR) and our legitimate interest in responding to inquiries and preventing abuse (Art. 6 (1) (f) GDPR).
Retention: kept for as long as needed to handle the request and any subsequent business relationship, then deleted unless statutory retention obligations apply (max. 12 months).
3.2 Server logs
Our hosting infrastructure records standard technical logs — IP address, request path, user-agent, timestamp, response status — for the purpose of network security, abuse prevention, and operational debugging.
Legal basis: legitimate interest in maintaining a secure, functional service (Art. 6 (1) (f) GDPR).
Retention: 60 days, after which logs are automatically deleted.
3.3 Cookies
We set a single first-party cookie, alpinesite_lang, when you choose a language. It stores only the two-letter language code (en, de, it, fr, es, or ru) so we can serve the same language on your next visit. The cookie is set with the SameSite=Lax and (over HTTPS) Secure attributes, has a lifetime of 12 months, and is not used for tracking, analytics, or profiling.
Legal basis: technically necessary under § 25 (2) No. 2 TTDSG / § 165 (3) Z 2 TKG; otherwise Art. 6 (1) (f) GDPR (legitimate interest in serving the correct language).
Because the site is served through Cloudflare, Cloudflare may set strictly-necessary security cookies (e.g. __cf_bm) for bot and abuse mitigation; these are exempt from consent (§ 25 (2) TTDSG / § 165 (3) TKG) and are not used for tracking. No analytics or advertising cookies are used.
We do not use localStorage, sessionStorage, or any other client-side storage.
4. Service providers
We rely on a small number of carefully chosen processors to operate this site. Each acts as a processor under Art. 28 GDPR or as a separate controller for clearly defined purposes.
- Cloudflare, Inc. (USA) — DNS, reverse-proxy/CDN, security/edge protection for alpinesite.cc, and email forwarding for the
@alpinesite.ccaddresses. In doing so it processes connection data including visitor IP addresses; the US transfer relies on the EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
cloudflare.com/privacypolicy - Hetzner Online GmbH — Server hosting; data center located in Germany.
hetzner.com/legal/privacy-policy - Resend, Inc. (USA) — Transactional email delivery for the demo request form (notification + confirmation); covered by SCCs and the EU-US Data Privacy Framework.
resend.com/legal/privacy-policy - Ledl.net GmbH & Co. KG — Email hosting for the
@anvotic.commailboxes that inquiries are delivered to; servers in Austria/Germany (EU).
ledl.net
5. International transfers
Where a service provider processes data outside the European Economic Area, transfers are protected by the European Commission's Standard Contractual Clauses or an equivalent mechanism under Art. 46 GDPR.
6. Your rights
Under the GDPR you have the right to:
- request access to your personal data (Art. 15)
- request correction (Art. 16) or deletion (Art. 17)
- restrict processing (Art. 18) or object (Art. 21)
- receive your data in a portable format (Art. 20)
- withdraw consent at any time, where processing is based on consent (Art. 7 (3))
- lodge a complaint with a supervisory authority (Art. 77)
To exercise any of these rights, contact [email protected].
7. Changes to this policy
We may update this policy as the service evolves. The "Last updated" date at the top reflects the current version.