Privacy Policy

This policy explains what personal data we process, why, on what legal basis, who receives it and how long we keep it. It is based on the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021).

This is a translation of our German Datenschutzerklärung. If the two differ, the German version applies. To have data deleted, see our data deletion instructions.

1. Controller

Adrian Hutterer, Hut Ab Agency (sole proprietorship)
Margaretenstraße 71-73/1/24b
1050 Vienna, Austria
Email: office@hut-ab-agency.com
Phone: +43 664 144 7315
VAT ID: ATU80655239

We are not legally required to appoint a data protection officer and have not appointed one. For any privacy matter, write to office@hut-ab-agency.com.

2. Scope

  • visits to this website and all forms on it (sections 3 to 12),
  • data we obtain through Meta's APIs (Facebook, Instagram) when we manage ad accounts (section 13),
  • work we do on behalf of clients (section 14),
  • business contacts we did not collect from you directly (section 15).

3. Hosting and server logs

The website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. For every request Vercel processes technically necessary access data: IP address, date and time, requested URL, amount of data transferred, status code, browser and operating system, and the referring page. If your browser reports a violation of our Content Security Policy, we log the affected URL and the blocked source, without your IP address.

Purpose: delivering the website, stability, troubleshooting, defence against attacks.
Legal basis: Art. 6(1)(f) GDPR. Our interest is a secure and working website.

Recipient: Vercel as processor (Art. 28 GDPR).

Third country: Transfer to the USA based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) are in place as a fallback.

Retention: log data for no more than 30 days, or until a security incident is resolved.

4. Cookieless audience measurement (Vercel Analytics)

We count page views with Vercel Analytics. It sets no cookies and stores nothing on your device. Vercel derives a hash from the request (including IP address and user agent) and discards it after 24 hours at most. IP addresses are not stored. No profiles are built across days or websites. We only see aggregated figures: pages, referrers, country, device type.

Purpose: understanding which pages are used.
Legal basis: Art. 6(1)(f) GDPR. Our interest is statistical analysis without recognising individuals.

Recipient: Vercel as processor.

Third country: Transfer to the USA based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) are in place as a fallback.

Objection: at any time by writing to office@hut-ab-agency.com (Art. 21 GDPR).

5. Forms

The website has five forms. Depending on the form we process:

  • Contact form: name, email address, message (required), company and phone number (optional).
  • Enquiry check ("Anfragen-Check"): your answers to the questions (region, capacity, current enquiries, state of your website, ad budget), name, company, email address and phone number (required), website URL (optional). You then receive an automatic confirmation email. The estimate shown is a simple calculation from your answers.
  • Visibility check and video analysis: domain and email address. We prepare the report by hand and email it to you.
  • Conversion checklist: email address (required), name (optional).

With every submission we also process your IP address (abuse protection, limited to a few requests per hour) and, where available, which campaign brought you to us (section 9). We need the required fields to handle your enquiry. There is no legal obligation to provide them. Every enquiry is stored as a contact in our CRM and sent to us by email (section 7). We only contact you about your enquiry. There is no newsletter, and we do not sell your data.

Purpose: answering your enquiry, preparing the requested analysis, preparing a contract.
Legal basis: Art. 6(1)(b) GDPR (steps taken at your request before a contract). For abuse protection Art. 6(1)(f) GDPR.

Recipients: HighLevel (CRM) and Resend (email delivery) as processors, see section 7. With your marketing consent also Meta, see section 9.

Retention: if no contract follows, we delete no later than three years after the last contact. If one does, statutory retention periods apply (seven years under § 132 BAO).

6. Appointment booking

The booking page and the result screen of the enquiry check embed a calendar by LeadConnector (HighLevel Inc., 400 N Saint Paul St #920, Dallas, TX 75201, USA). It loads when you open the booking page or complete the enquiry check. HighLevel then receives your IP address and browser data. When you book, HighLevel processes your name, email address, phone number and chosen time slot on our behalf and sends you a confirmation and reminders.

Our Meta Pixel is embedded in the calendar. When you complete a booking, the calendar reports the event "Schedule" to Meta Platforms Ireland Limited and sends your name, email address and phone number as SHA-256 hashes together with your IP address and browser data. Meta matches these values against its own accounts. This happens inside the calendar itself and independently of your choice in this website's cookie banner. If you do not want this, please arrange the appointment by email to office@hut-ab-agency.com. For Meta see also section 9.

Purpose: arranging and holding the call. For the Meta Pixel in the calendar: measuring which ads lead to booked appointments.
Legal basis: Art. 6(1)(b) GDPR. Loading the calendar is strictly necessary for the booking you requested (section 165(3) TKG 2021). For the report to Meta Art. 6(1)(f) GDPR (measuring the success of our advertising). You can object at any time.

Recipients: HighLevel as processor; Meta for the report of booked appointments.

Third country: Transfer to the USA based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) are in place as a fallback.

Retention: as for forms (section 5).

7. CRM and email delivery

CRM: we manage enquiries, bookings and follow-up in HighLevel (address in section 6). Stored are your form entries, call notes and the origin of your enquiry. The data is held on servers in the USA. A data processing agreement is in place.

Email: notifications about new enquiries and the confirmation after the enquiry check are sent through Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). Resend processes the email address and message content on servers in the USA. A data processing agreement is in place.

Legal basis: Art. 6(1)(b) GDPR; for the choice of providers Art. 6(1)(f) GDPR (reliable handling of enquiries).
Third country: Transfer to the USA based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) are in place as a fallback.

8. Spam protection (reCAPTCHA)

Our forms are protected by Google reCAPTCHA v3 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The script loads only when you click into a form field or submit a form, not when you merely visit a page. reCAPTCHA uses your IP address, browser data and behaviour on the page to assess whether a human or a program is filling in the form, and sets the cookie _GRECAPTCHA. On submission our server verifies the result with Google. We also use a hidden honeypot field and a per-IP request limit. Since 2 April 2026 Google acts solely as our processor and uses the data only to operate and secure reCAPTCHA.

Purpose: protecting forms against automated abuse.
Legal basis: Art. 6(1)(f) GDPR. Spam protection is part of the form you expressly use (section 165(3) TKG 2021).

Recipient: Google as processor, with sub-processing in the USA.

Third country: Transfer to the USA based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) are in place as a fallback.

Alternative: if you prefer not to use it, email us directly at office@hut-ab-agency.com.

9. Services that run only with your consent

The following services start only after you agree in the cookie banner. If you decline or make no choice, they are not loaded, no related cookies are set, and our server sends nothing about you to third parties either. The only exception is the report of booked appointments by the booking calendar (section 6). You can change or withdraw your choice at any time via "Cookie-Einstellungen" (cookie settings) in the footer. Withdrawal takes effect from that moment.

Category "Analytics": Microsoft Clarity

Clarity (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA) shows us how the website is used: heatmaps (clicks, scroll depth) and recordings of individual sessions (mouse movements, clicks, scrolling). Form inputs are masked. It processes IP address, device and browser data and your behaviour on the page, and sets the cookies _clck and _clsk. Microsoft also uses the data for its own purposes, such as improving its services. See the Microsoft Privacy Statement.

Category "Marketing": Meta Pixel and Conversions API

The provider is Meta Platforms Ireland Limited, Block J, Serpentine Avenue, Dublin 4, Ireland. We use these tools to measure which ads on Facebook and Instagram lead to enquiries and to show ads to people who visited our website. Third parties including Meta use pixels, cookies and similar technologies to collect information from our website and use it for measurement and for targeting and delivering ads.

  • Meta Pixel (in the browser): reports page views, the start of the enquiry check and submitted forms to Meta. Sets the cookies _fbp and _fbc. Booked appointments are reported by the booking calendar itself, see section 6.
  • Conversions API (from our server): reports the same events server-side so they are not counted twice or missed. It sends IP address, user agent, page URL, the identifiers from _fbp and _fbc and an event ID. For a submitted form it also sends email address, phone number and name, each as a SHA-256 hash and never in plain text. Meta matches these values against its own accounts.
  • Origin of your visit (our own cookie hutab-attr): if you arrive through an ad or a link with campaign parameters, we store campaign, ad, click ID (fbclid, gclid, msclkid), landing page and referring website for 90 days on your first visit. If you submit a form, we save this with your enquiry in the CRM. Without consent we store none of this on your device. If the campaign is still in the URL of the page you submit the form from, we take only those campaign parameters, without any click ID.

For collecting the data on our website and transmitting it to Meta, we and Meta are joint controllers (Art. 26 GDPR). The arrangement is set out in Meta's Controller Addendum. We inform you and obtain your consent. Meta alone is responsible for what it does with the data afterwards. You can exercise your rights directly with Meta, see Meta's Privacy Policy. For matching, measurement and analytics Meta acts as our processor (Data Processing Terms).

Independently of our website you can opt out of personalised advertising in the ad settings of your Facebook or Instagram account and via youronlinechoices.eu and aboutads.info/choices.

Legal basis: your consent (Art. 6(1)(a) GDPR, section 165(3) TKG 2021).
Third country: Microsoft and Meta also transfer data to the USA. Both are certified under the EU-US Data Privacy Framework, and Standard Contractual Clauses apply in addition. Access by US authorities cannot be ruled out entirely.

Retention: _clck 12 months, _clsk 1 day, _fbp and _fbc 90 days, hutab-attr 90 days. If you withdraw consent, the banner deletes these cookies.

Google Analytics, Google Ads and Google Tag Manager are currently not in use on this website.

10. Cookies and local storage

  • cc_cookie (necessary, 6 months): stores your choice in the cookie banner.
  • _GRECAPTCHA (Google, 6 months): only when you use a form, see section 8.
  • _clck, _clsk (Microsoft Clarity): only with "Analytics" consent.
  • _fbp, _fbc (Meta) and hutab-attr (ours): only with "Marketing" consent.
  • Session storage in your browser: two flags with no personal reference that disappear when you close the tab. One notes that you arrived through a campaign link so the page shows the matching header. The other prevents a booking from being counted twice on reload.

11. Embedded content: YouTube and Google Maps

Videos are served by YouTube (Google Ireland Limited) in privacy enhanced mode (youtube-nocookie.com). Preview images are hosted on our own server. Only when you click a video does the player load and Google receive your IP address and browser data, including in the USA. The map on the contact page (Google Maps) loads only after you click "Karte laden" (load map).

Legal basis: your consent given by the click (Art. 6(1)(a) GDPR, section 165(3) TKG 2021), valid for that page view.
Third country: Transfer to the USA based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) are in place as a fallback.

More: Google Privacy Policy

12. Fonts

All fonts are hosted on our own server. Nothing is requested from Google Fonts.

13. Data obtained through Meta's APIs (Platform Data)

We manage ad accounts on Facebook and Instagram, our own and those of our clients. For reporting we obtain data through Meta's official interfaces (Marketing API, Graph API, Meta Ads connector), most recently through our internal app "Hut Ab - Ads". The app has no public users. Only we have access, and only to accounts whose owner has granted us access in Meta Business Manager.

What data we obtain

  • ad account ID and name, currency, status,
  • names, settings and status of campaigns, ad sets and ads,
  • aggregated performance figures: spend, impressions, reach, frequency, clicks, results and cost per result,
  • ad texts, images and videos,
  • publicly visible ads of other advertisers from the Meta Ad Library,
  • access tokens for the API.

We do not obtain profile data of Facebook or Instagram users, lead form data, messages or comments through these interfaces. We never ask for login credentials to Meta accounts.

How and why we process it

We retrieve the data at most once a day, store it separately per client and use it to produce reports and recommendations for that specific ad account. An AI assistant (Claude by Anthropic PBC, San Francisco, USA) supports the analysis. We do not use the data to build or augment profiles of individuals, for retargeting, or for other clients, and we do not sell or license it.

Legal basis: Art. 6(1)(b) GDPR (contract with the client); for our own ad account Art. 6(1)(f) GDPR. Where client data is personal data, we act as processor (section 14).
Sharing: only with the respective client, with technical service providers we use for analysis and storage (Anthropic for analysis, GitHub for version control and backup of reports in a private repository), or where the law requires it. Anthropic only receives campaign and performance data, no data about individual people.

Retention: raw API data for 13 months. Reports for the duration of the engagement. After it ends we delete all of the client's data within 30 days unless the law requires us to keep it. Access tokens are deleted immediately.

Security: encrypted transmission, encrypted storage, access by the owner only, tokens kept separate from code and never included in reports or chats.

Requesting deletion: clients and any other person concerned can request deletion of this data at any time. See our data deletion instructions. We confirm receipt within three business days and delete within 30 days. The account owner can also revoke our access at any time in Meta Business Manager under "Partners".

We comply with the Meta Platform Terms and the Developer Policies. This policy does not modify or supersede them. What Meta itself does with data is governed by Meta's Privacy Policy.

14. Work on behalf of clients

When we manage ad accounts, landing pages, CRM access or enquiries from prospects for our clients, we process that data as a processor under Art. 28 GDPR on the client's instructions. The client remains the controller. For access or deletion, please contact the company you enquired with. If such a request reaches us, we pass it on.

15. Business contacts from public sources

For our market overview we keep a list of businesses in Vienna, Lower Austria and Burgenland, mainly in photovoltaics and the trades. The information comes from publicly accessible sources: business listings on Google Maps and the businesses' own websites (legal notice). We collected it in April and September 2026.

Data: company name, address, industry, website, general phone number and email address of the business, category, number and average of Google reviews. For sole proprietors this can be personal data.
Purpose: market overview and selecting businesses for business contact. Promotional calls and emails happen only with prior consent (section 174 TKG 2021).

Legal basis: Art. 6(1)(f) GDPR. Our interest is initiating business relationships with companies based on information they published themselves.

Recipients: not shared with third parties.

Retention: until you object, otherwise two years after collection.

Objection: at any time by writing to office@hut-ab-agency.com. We then delete the entry and only note that you must not be added again.

16. Recipients at a glance

  • Vercel Inc., USA: hosting, audience measurement
  • HighLevel Inc., USA: CRM, appointment booking
  • Plus Five Five, Inc. (Resend), USA: email delivery
  • Google Ireland Limited, Ireland: reCAPTCHA; after a click YouTube and Google Maps
  • Microsoft Corporation, USA: Clarity, only with consent
  • Meta Platforms Ireland Limited, Ireland: Pixel and Conversions API, only with consent
  • Anthropic PBC, USA: analysis of ad account data (section 13)
  • GitHub, Inc., USA: backup of reports in a private repository (section 13)
  • tax adviser, bank and authorities where the law requires it

All US providers named state that they are certified under the EU-US Data Privacy Framework. You can obtain a copy of the Standard Contractual Clauses by writing to office@hut-ab-agency.com.

17. Your rights

  • access to your data (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on legitimate interests (Art. 21 GDPR)
  • withdrawal of consent with effect for the future (Art. 7(3) GDPR)

An informal message to office@hut-ab-agency.com is enough. We reply within one month. The steps for deletion are in our data deletion instructions.

18. Complaints

Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40-42, 1030 Vienna, Austria
dsb.gv.at

19. Automated decisions

There is no automated decision-making with legal or similarly significant effect (Art. 22 GDPR). The estimate in the enquiry check is a simple calculation from your answers and has no consequences for you.

20. Security

The website is available over HTTPS only. Forms are protected against spam and abuse, and data from client work is kept on encrypted storage. If you find a security vulnerability, please write to office@hut-ab-agency.com.

21. Changes

We update this policy when the law or our services change. The version on this page applies.

Last updated: 18 September 2026.