Legal

Privacy Policy

Version 1.0-AT  ·  As of: April 2026  ·  Last updated: April 2026
1 General
Controller

We take data protection seriously and apply the highest standards of data security and care. This privacy policy provides an overview of what personal data is collected when you visit ferdinanz.at, how it is processed and what rights you have as a data subject.

feodos GmbH
Dresdnerstraße 68/1/2b, A-1200 Vienna, Austria
E-mail: office@feodos.at

Purposes of processing

Data processed when you visit this website is used exclusively to provide this online service and to improve usability. Data collected in the course of contacting us is used solely to respond to your enquiry.

Legal bases

The processing of personal data is carried out on the basis of the following legal grounds under the GDPR:

Art. 6(1)(a)
Consent
e.g. when linking bank accounts via finAPI or when setting optional cookies
Art. 6(1)(b)
Contract performance
Processing necessary to take steps prior to entering into a contract or for performance of a contract
Art. 6(1)(f)
Legitimate interests
Operation and management of our online channels, responding to enquiries, ensuring network and data security
Your rights under the GDPR

Under the provisions of the GDPR, you have the following rights:

Art. 15
Right of access
You have the right to obtain free information about which personal data is stored about you and how it is processed.
Art. 16
Right to rectification
You have the right to request the correction of incomplete or inaccurate data.
Art. 17
Right to erasure
You have the right to request the deletion of your data, provided no statutory retention obligations apply.
Art. 20
Right to data portability
You are entitled to receive your data in a structured, commonly used and machine-readable format.
Art. 21
Right to object
You have the right to object to the processing of your personal data.
Art. 22
No automated decision-making
You have the right not to be subject to a decision based solely on automated processing.
Art. 18
Right to restriction of processing
You may request restriction of processing where the accuracy of your data is contested, processing is unlawful, or you require the data for the establishment of legal claims.

If you believe that the processing of your data infringes the GDPR, you may lodge a complaint with the Austrian Data Protection Authority. To exercise your rights, please contact office@feodos.at.

2 Data collection on this website
Hosting & server log files

This website is hosted externally. Personal data is transmitted to the hosting provider's servers on the basis of our legitimate interest in providing a secure, fast and efficient website.

Hetzner Online GmbH
Industriestr. 25, D-91710 Gunzenhausen, Germany

When you visit this website, the web server automatically collects technical data (IP address, browser, operating system, date and time of the page visit) and stores it in log files. Server log files are automatically deleted after two weeks. No merging with other data sources takes place.

Cookies

This website uses cookies. Session cookies are automatically deleted at the end of your visit. Persistent cookies remain on your device until you delete them manually. For optional third-party cookies, we obtain your consent via our cookie banner. A detailed list can be found in our Cookie policy.

TLS encryption

This website uses TLS encryption (recognisable by the "https://" prefix and the padlock symbol in the address bar) to protect the transmission of sensitive data.

3 Bank connection & financial data

To enable automatic bank import, ferdinanz uses the PSD2-compliant bank interface provided by finAPI. Linking your bank accounts is based exclusively on your explicit consent and can be revoked at any time.

finAPI GmbH
Georg-Brauchle-Ring 50/52, 80992 Munich, Germany

The connection is exclusively read-only – ferdinanz cannot trigger payments or modify account data. Transmitted financial data (transactions, account balances) is stored in encrypted form and used solely to provide ferdinanz's features (cash flow analysis, AI categorisation, forecasts). Data is not passed on to third parties. For further information, please refer to the finAPI privacy policy.

4 Data when contacting us

When you contact us by e-mail or via our contact form, the data you provide (name, e-mail address, message) is used solely to process your enquiry. The data is deleted once the matter is resolved, unless statutory retention obligations apply. Data is not passed on to third parties.

5 Google services
Google Fonts
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland

We use Google Fonts for consistent font rendering. When the page loads, your browser connects to Google's servers and transmits your IP address. Legal basis: Art. 6(1)(f) GDPR.

Google Analytics

We use Google Analytics on the basis of our legitimate interest in better understanding how visitors interact with our website. Your IP address is transmitted to Google's servers in anonymised form and is not merged with other Google data. Data is only collected after you have given your consent via the cookie banner.

Google Tag Manager

We use Google Tag Manager to manage the tracking tools used on this website. The Tag Manager itself does not store or process any personal data.

Google reCAPTCHA

To protect our forms against bot submissions, we use Google reCAPTCHA. The service analyses behaviour on the website in the background and transmits data to Google's servers. Legal basis: legitimate interests (Art. 6(1)(f) GDPR). Further information: Google Privacy Policy.

6 Other third-party providers
Cal.eu (appointment booking)
Cal.com, Inc. – European instance
app.cal.eu · Data processed exclusively on European servers

This website integrates an appointment booking widget from cal.eu. When you click the "Book a meeting" button or open the booking form, a connection is established to the servers of app.cal.eu. Your IP address and technical browser information are transmitted in this process. If you complete an actual booking, the contact details you provide (name, e-mail address) are also processed and used for appointment management and communication.

We use exclusively the European instance app.cal.eu – all data is stored and processed on European servers. No transfer to third countries outside the EU takes place. The legal basis for processing is Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in efficient appointment management). Further information: cal.com/privacy.

Complianz (cookie consent)
Really Simple Plugins
Kalmarweg 14-5, 9723JG Groningen, Netherlands

We use the Complianz plugin to manage cookie consent. It allows us to design our cookie banner and store your consents in a GDPR-compliant manner, ensuring that third-party services are only activated after you have given your approval. Further information: Really Simple Plugins privacy policy.