Privacy Policy.
Privacy policy of medeqon GmbH (hereinafter referred to as "medeqon")
This Privacy Policy explains how medeqon GmbH (hereinafter “medeqon”, “we”) processes your personal data – in the course of our business activities as well as when you visit our website. We process your data exclusively in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Austrian Data Protection Act (Datenschutzgesetz, DSG) as amended.
1. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
medeqon GmbH
Bergstraße 42/5/3, 2102 Hagenbrunn, Austria
Company register number: FN 672926y · VAT ID: ATU83016237
Phone: +43 670 550 5612 · E-mail: office@medeqon.com
Contact for data protection: Georg Scherzer · g.scherzer@medeqon.com · +43 670 550 5612
We have not appointed a data protection officer (see section 10); for all data protection matters, please contact us using the details above.
2. Principles of our data processing
We process personal data in accordance with the principles of Art. 5 GDPR:
- Lawfulness, fairness and transparency – processed lawfully and in a comprehensible manner.
- Purpose limitation – only for specified, explicit and legitimate purposes.
- Data minimisation – limited to what is necessary.
- Accuracy – inaccurate data are corrected or erased.
- Storage limitation – stored only for as long as necessary (see section 7).
- Integrity and confidentiality – protected by technical and organisational measures (see section 9).
- Accountability – we can demonstrate compliance.
3. Individual processing activities
Below we inform you about each individual processing activity – in each case with the purpose, legal basis, recipients, any third-country transfer and the storage period.
3.1 Initiation and performance of contracts (customers, suppliers, business partners)
Data subjects / data: Customers, suppliers and their contact persons: name, company, function, address, VAT and company register number, phone, e-mail, contract, order and payment data.
Purpose: Initiation, conclusion and performance of contracts (planning, consulting, trade in medical devices, safety inspections, consulting), communication and processing.
Legal basis: Art. 6 (1) (b) GDPR (contract / pre-contractual measures). For contact persons of business partners additionally Art. 6 (1) (f) GDPR – legitimate interest in efficient B2B communication.
Recipients: Tax advisor; IT/cloud service providers (see section 5); banks for payment processing; authorities where legally required.
Third country: None.
Storage period: For the duration of the business relationship; thereafter 7 years pursuant to Section 132 BAO / Section 212 UGB; in the event of potential legal claims, until the applicable limitation periods expire.
3.2 Invoicing and retention for tax purposes
Data: Invoice data, name and address of the recipient of services, VAT ID, payment and accounting data.
Purpose: Proper invoicing, accounting and compliance with tax and commercial law obligations.
Legal basis: Art. 6 (1) (c) GDPR (legal obligation, incl. BAO, UGB, UStG).
Recipients: Tax advisor, tax office and other authorities within the scope of legal obligations.
Third country: None.
Storage period: 7 years pursuant to Section 132 BAO (or longer where legally required).
3.3 Contacting us (contact form, e-mail, phone)
Data: Contact details (e-mail address and/or phone number, name) and any further information you provide voluntarily in your enquiry.
Purpose: Handling and responding to your enquiry.
Legal basis: Legitimate interest in responding to your enquiry (Art. 6 (1) (f) GDPR). If your enquiry is aimed at a contract, we process the data on the basis of Art. 6 (1) (b) GDPR (pre-contractual measures).
Recipients: No disclosure to third parties; the hosting provider (see section 3.5) is technically involved as a processor.
Third country: None.
Storage period: Until your enquiry has been dealt with; thereafter erased unless retention obligations apply.
3.4 Provision of the website and server log files
Data: Automatically on each access: IP address, date and time, host name of the accessing device, browser type and version, operating system, referrer URL, file/page requested, volume of data transferred.
Purpose: Delivery of the website, ensuring security, stability and functionality, error analysis, protection against misuse.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a secure, stable web presence); additionally Art. 6 (1) (b) GDPR (provision of the website) and Section 165 (3) TKG 2021 (technical necessity).
Recipients: Hosting provider IONOS SE as processor (see section 3.5).
Third country: None (processing within the EU).
Storage period: The log files are deleted or anonymised after 7 days; subsequent review only takes place where there are concrete indications of unlawful use.
3.5 Hosting and provision of the website (IONOS SE)
Recipient: Our website is operated by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. IONOS processes personal data on our behalf (in particular the server log files referred to in 3.4).
Purpose: Provision and secure operation of the website, system security and stability, error analysis, protection against misuse.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a secure, stable and efficient provision of our online offering).
Processing agreement: A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS SE.
Third country: Processing takes place within the EU. No transfer to a third country occurs.
Further information: Privacy Policy of IONOS SE.
The website is built and published technically via GitHub as a pure build/source environment; no personal data of website visitors is processed in this context. Delivery to visitors takes place via IONOS.
3.6 Cloudflare (security / content delivery)
Recipient: To secure our website and protect against abusive access, we use services of Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany.
Data / purpose: Cloudflare analyses the traffic to our website to detect and block potentially harmful requests; the data processed include IP address, device/browser information, date and time, content accessed and technical connection data. Purpose: security, stability and availability of the website.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in protection and secure operation).
Processing agreement: Cloudflare processes the data as a processor pursuant to Art. 28 GDPR.
Third country: For transfers to the USA: Cloudflare participates in the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR); in addition, Standard Contractual Clauses pursuant to Art. 46 GDPR are in place.
Storage period: Up to 7 days.
3.7 Personnel administration (employees)
Data: Master data, contract, payroll and accounting data, social insurance data.
Purpose: Establishment, performance and termination of the employment relationship, payroll, compliance with labour, social security and tax law obligations.
Legal basis: Art. 6 (1) (b) and (c) GDPR in conjunction with labour, social security and tax law provisions.
Recipients: Tax advisor/payroll, social insurance institution, tax office.
Storage period: For the duration of the employment relationship; thereafter in accordance with statutory retention periods (generally 7 years, under social insurance law up to 30 years).
4. Cookies
Cookies are small text files stored on your device. On our website we use exclusively technically necessary cookies that are required for the operation and secure provision of the website – this also includes technically necessary cookies set by our security service provider Cloudflare (see section 3.6). No consent is required for these pursuant to Section 165 (3) TKG 2021; the legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the technical operation of the website).
We do not use cookies that are not technically necessary (e.g. statistics or marketing); a cookie consent banner is therefore not required. Should a consent-requiring service be added in future, it will only be integrated after your active consent via a cookie banner with an equivalent “reject” option (Art. 6 (1) (a) GDPR), which you may withdraw at any time.
5. Recipients and processors
Data are only disclosed insofar as this is necessary for the stated purposes or a legal obligation exists. We conclude data processing agreements pursuant to Art. 28 GDPR with service providers that process data on our behalf. Recipients or categories of recipients are:
- Tax advisor / payroll service – accounting, bookkeeping, payroll.
- Microsoft (Microsoft 365 / OneDrive) – storage and processing of documents and e-mail; processing on the basis of the Microsoft Data Protection Addendum (Art. 28 GDPR). Processing predominantly within the EU.
- IONOS SE – website hosting (EU, processing agreement in place).
- Cloudflare Germany GmbH – web security/content delivery (processing agreement, see section 3.6).
- Banks – for payment processing.
- Authorities and courts – where legally required.
6. Transfer to third countries
Within the EU/EEA there is a uniform level of data protection. A transfer to a third country (outside the EU/EEA) only takes place where one of the conditions of Art. 44 et seq. GDPR is met:
- an adequacy decision of the EU Commission exists (Art. 45 GDPR) – for the USA this applies to companies certified under the EU-U.S. Data Privacy Framework; or
- appropriate safeguards are in place (Art. 46 GDPR), in particular the Standard Contractual Clauses approved by the EU Commission (SCC); or
- exceptionally, a case under Art. 49 GDPR applies (e.g. your explicit consent, necessity for the performance of a contract or for the establishment of legal claims).
Specific third-country references may result from the services referred to in sections 3 and 5 (in particular Cloudflare and, where applicable, Microsoft). The third country concerned is in each case the USA; the transfer is based on the EU-U.S. Data Privacy Framework (adequacy decision) or on Standard Contractual Clauses.
7. Storage period
We store personal data only for as long as is necessary for the respective purpose or as long as statutory retention obligations exist. The specific periods result from section 3. Invoicing and accounting-related documents are generally retained for 7 years pursuant to Section 132 BAO. After the periods expire, the data are erased or anonymised.
8. Your rights as a data subject
Under the GDPR you have the following rights:
- Access (Art. 15) – whether and which data we process about you.
- Rectification (Art. 16) – correction of inaccurate or incomplete data.
- Erasure (Art. 17), unless a retention obligation applies.
- Restriction of processing (Art. 18).
- Data portability (Art. 20).
- Objection (Art. 21) – to processing based on legitimate interests.
- Withdrawal of consent (Art. 7 (3)) – at any time with effect for the future; the lawfulness of processing carried out up to that point remains unaffected. Withdrawal is as easy as giving consent.
To exercise your rights, an informal notice to the contact details in section 1 is sufficient. We will generally respond to your request within one month.
Right to lodge a complaint with the supervisory authority
If you believe that the processing of your data infringes data protection law or that your data protection rights have otherwise been violated, you may lodge a complaint with the supervisory authority (Art. 77 GDPR). In Austria this is the:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40–42, 1030 Vienna · Phone: +43 1 52 152-0
E-mail: dsb@dsb.gv.at · Web: www.dsb.gv.at
9. Data security and internal organisation
We take appropriate technical and organisational measures (Art. 24, 32 GDPR) to protect your data. These include in particular:
- Data protection by design & by default – only the data required are collected.
- Access protection: our cloud environment is access-protected. Employees are granted access to personal data only upon approval by the management.
- Obligation of employees to maintain confidentiality (data secrecy) – also after termination of the employment relationship.
- Maintenance of a record of processing activities pursuant to Art. 30 GDPR.
10. Data protection officer
We have not appointed a data protection officer, as there is no obligation under Art. 37 GDPR: the processing is not carried out by a public authority or body, our core activity does not require extensive, regular and systematic monitoring of data subjects, and we do not process special categories of personal data (Art. 9 GDPR) on a large scale.
11. Personal data breaches
In the event of a personal data breach, we will notify the Data Protection Authority within 72 hours of becoming aware of it (Art. 33 GDPR), where the breach is likely to result in a risk to the rights and freedoms of natural persons. Where a high risk is likely, we will inform the data subjects concerned without undue delay (Art. 34 GDPR).
12. Automated decision-making and profiling
Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.
13. Necessity of providing data
For the conclusion and performance of contracts and to comply with legal obligations (e.g. invoicing), the provision of certain data is necessary. Without these data we cannot conclude or perform the contract. Otherwise, the provision of data is voluntary.
14. Currency and amendment of this Privacy Policy
This Privacy Policy is dated 6 August 2026. Changes to our activities or the legal situation may make an amendment necessary. The current version is available on our website.