PRIVACY POLICY
On this page, we inform you about the processing of personal data in connection with the use of our website and our services.
Processing is carried out exclusively in accordance with the General Data Protection Regulation (GDPR) and the applicable national data protection provisions.
Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
onestephost GmbH
Wissenspark Salzburg, Urstein S 17/Top D1.1
5412 Urstein
Austria
Email: support@onestephost.com
Hosting & Technical Data Processing
When you access our website, information that is necessary for the operation, security, and stability of the website is automatically processed. This data is stored in what are known as server log files.
In particular, the following data may be processed:
- IP address
- Browser type and version
- Operating system
- Referrer URL
- Pages accessed
- Date and time of access
- Internet service provider
Hosting by Webflow
Our website is operated using the Webflow service. The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA. Webflow processes the data required to provide the website on our behalf, in particular the server log files mentioned above.
In the course of using Webflow, personal data may be transferred to third countries, in particular the USA. Any such transfer takes place exclusively in compliance with the legal requirements of the GDPR and on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g. standard contractual clauses or the EU–US Data Privacy Framework). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
Purpose of Processing
This data is processed for the purpose of:
- Ensuring stable and error-free operation of the website
- Guaranteeing technical functionality
- Improving stability and security
- Detecting and analysing attacks
- Technical administration and maintenance
Legal Basis
Processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in the secure and technically error-free provision of our website.
Storage Period
The data is stored only for as long as is necessary for the stated purposes. Longer storage only takes place where this is required to investigate security-related incidents.
Cookies
This website uses cookies and similar technologies.
Cookies are small text files that are stored on your device and may contain information that allows your browser to be recognised.
a) Strictly Necessary Cookies
These cookies are required for the operation of the website and enable basic functions such as security, stability, and navigation. Processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.
b) Analytics Cookies
These cookies are used to analyse user behaviour on our website and to improve the website.
Processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR.
c) Marketing Cookies
These cookies are used to tailor content and advertising to your interests and to measure the effectiveness of campaigns.
These cookies are also only set with your consent pursuant to Art. 6(1)(a) GDPR.
Depending on their purpose, cookies are stored for different lengths of time and are then automatically deleted, or they can be removed by the user at any time. An overview of the cookies used and their storage periods can be found in the settings of our cookie banner.
d) Consent Management
On your first visit to our website, you can use a cookie banner to select which categories you wish to accept. Processing is carried out exclusively on the basis of your consent, which can be withdrawn at any time with effect for the future.
Your consent is managed via the consent management function provided by Cookiebot.
Services & Tracking Tools Used
Below, we inform you about the individual services we use for analytics, marketing, and the management of our communications. Unless otherwise stated, processing via these services is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR, which you provide via our cookie banner and may withdraw at any time with effect for the future.
HubSpot
We use HubSpot as our central CRM, communications, and marketing system. The provider is HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA. HubSpot may use cookies and comparable technologies to evaluate user behaviour on our website, track interactions, and analyse and optimise marketing activities.
In the course of using HubSpot, personal data may be transferred to third countries, in particular the USA. Any such transfer takes place exclusively in compliance with the legal requirements of the GDPR and on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g. standard contractual clauses or the EU–US Data Privacy Framework).
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is a tool that allows us to centrally manage and integrate tracking and analytics tags on our website. Google Tag Manager itself does not set any cookies and does not collect any personal data; it serves solely to manage and trigger the services integrated through it. The services triggered via Tag Manager are only activated after you have given your consent.
Google Ads & Conversion Tracking
We use Google Ads and the associated conversion tracking. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. These services allow us to measure the effectiveness of our advertisements and to display interest-based advertising to users based on their behaviour. In doing so, cookies may be set and personal data may be processed.
In the course of using these services, personal data may be transferred to third countries, in particular the USA. Any such transfer takes place on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.
Meta Pixel (Facebook & Instagram)
We use the Meta Pixel to measure and optimise our advertising campaigns on Facebook and Instagram. The provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The Meta Pixel allows us to track the behaviour of users after they have been directed to our website by clicking on a Meta advertisement, and to display targeted advertising. In doing so, cookies may be set and personal data may be processed.
In the course of using the Meta Pixel, personal data may be transferred to third countries, in particular the USA. Any such transfer takes place on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.
LinkedIn Insight Tag
We use the LinkedIn Insight Tag. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The LinkedIn Insight Tag allows us to evaluate campaigns and display targeted advertising on the LinkedIn platform. In doing so, cookies may be set and personal data may be processed.
In the course of using the LinkedIn Insight Tag, personal data may be transferred to third countries, in particular the USA. Any such transfer takes place on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.
Newsletter & Marketing Emails
We send a newsletter with which we regularly inform you about our company, our services, and current updates.
a) Newsletter Sign-Up
To receive our newsletter, you are required to provide an email address. Additional data may optionally be provided, where this is used to personalise the newsletter.
Sign-up takes place using the so-called double opt-in procedure. After signing up, you will receive a confirmation email in which you must confirm your registration once more. Your registration only becomes effective upon this confirmation.
To document the registration, the email address, the time of registration, and the IP address are stored.
The legal basis for processing is your consent pursuant to Art. 6(1)(a) GDPR.
b) Sending the Newsletter & Marketing Emails
We use HubSpot to send and manage our newsletter.
When sending the newsletter and marketing emails, information on usage behaviour may be processed, in particular open rates, click behaviour, time of access, and interactions with the content contained in the newsletter.
Processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR.
In the course of using HubSpot, personal data may be transferred to third countries, in particular the USA. Any such transfer takes place exclusively in compliance with the legal requirements of the GDPR and on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.
c) Withdrawal and Unsubscribing
You can withdraw your consent to receive the newsletter at any time with effect for the future. You will find a corresponding unsubscribe link in every newsletter, or you can contact us directly. Following withdrawal, your data will be removed from the newsletter distribution list, unless statutory retention obligations apply.
Contacting Us
Due to legal requirements, our website contains information that enables quick electronic contact with our company as well as direct communication with us. This includes, in particular, the provision of an email address and, where applicable, further means of contact.
If you contact us by email, contact form, or other means of communication, the personal data you provide will be processed for the purpose of handling your enquiry.
This relates in particular to:
- Name
- Email address
- Phone number (if provided)
- Content of the enquiry
- Other information voluntarily provided
This data is processed exclusively for the purpose of handling your enquiry and the associated technical administration. The legal basis is Art. 6(1)(b) GDPR as well as our legitimate interest pursuant to Art. 6(1)(f) GDPR in the efficient handling of enquiries.
We use HubSpot as our CRM, communications, and marketing system to manage and process enquiries and to organise our customer communications.
In doing so, personal data may also be transferred to the USA. Any such transfer takes place on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g. standard contractual clauses or the EU–US Data Privacy Framework).
Rights of Data Subjects
Within the framework of the statutory provisions, you have the right to obtain information at any time about the personal data stored about you. In addition, you have the right to rectification of inaccurate data, erasure of your personal data, restriction of processing, and data portability.
You also have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data, where such processing is based on a legitimate interest.
Where processing is based on your consent, you can withdraw this consent at any time with effect for the future.
To exercise your rights, you can contact us at any time.
Right to Lodge a Complaint with the Supervisory Authority
You also have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority.
The competent data protection authority in Austria is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Austria
Website: https://www.dsb.gv.at
Legal Basis for Processing
The processing of personal data is carried out in accordance with the General Data Protection Regulation (GDPR). Depending on the type of processing, we rely on the following legal bases:
- Art. 6(1)(a) GDPR – Consent of the data subject (e.g. newsletter sign-up, cookies, tracking, marketing)
- Art. 6(1)(b) GDPR – Performance of a contract or implementation of pre-contractual measures (e.g. handling enquiries or providing our services)
- Art. 6(1)(c) GDPR – Compliance with legal obligations (e.g. statutory retention obligations)
- Art. 6(1)(f) GDPR – Legitimate interest (e.g. technical security, stability, and operation of the website as well as protection against misuse, CRM / communications)
Where processing is based on consent, this can be withdrawn at any time with effect for the future.
Storage Period of Personal Data
Personal data is stored only for as long as is necessary for the respective purposes or due to statutory retention obligations.
Data processed on the basis of consent is stored until consent is withdrawn.
Status & Updates to this Privacy Policy
We reserve the right to update this privacy policy so that it always complies with the current legal requirements or to implement changes to our services. The version applicable at the time of your renewed visit will then apply.
Last updated: June 2026