Privacy Notice
1. Controller
The controller responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Raffael Himmelsbach Consulting e.U.
Proprietor: Dr Raffael Himmelsbach
Lilienbrunngasse 18
1020 Vienna
Austria
Email: info@himmelsbach-consult.at
Telephone: +43 681 10895604
2. General information
We process personal data only where this is necessary to operate this website, respond to enquiries, provide requested services, comply with legal obligations or protect our legitimate interests.
Personal data means any information relating to an identified or identifiable natural person.
3. Website hosting and technical access data
This website is created and hosted using services provided by:
Framer B.V.
Rozengracht 207B
1016 LZ Amsterdam
The Netherlands
When you access this website, technical information required to deliver and secure the website is processed automatically. Depending on the request, this may include:
IP address
Date and time of access
Requested page or file
Browser type and version
Operating system
Referring page
Device and connection information
Information concerning successful or unsuccessful delivery of the requested content
This processing is necessary to display the website, maintain its stability and security, diagnose technical problems and prevent misuse.
Legal basis: Article 6(1)(f) GDPR
Legitimate interests: Reliable, secure and efficient provision of this website.
Technical data are retained only for as long as necessary for website delivery, security, troubleshooting and compliance with applicable legal obligations. Framer processes relevant data on our behalf under its Data Processing Addendum.
Further information is available in Framer’s Privacy Statement.
4. Framer Analytics
We use only Framer’s built-in analytics functionality to obtain aggregated information about the use of this website. We do not use Google Analytics or other third-party analytics or advertising trackers.
Framer Analytics may provide us with aggregated statistics such as:
Daily unique visitors and page views
Frequently visited, entry and exit pages
Approximate session duration and bounce rate
Referral sources and UTM parameters
Approximate country
Device type, browser and operating system
To calculate daily unique visitors, Framer combines the visitor’s IP address and user-agent information with a secret value that changes daily. This produces a short-lived anonymous identifier. The secret is reset and deleted each day, and no persistent identifier is created.
Framer states that the resulting analytics information is anonymised and cannot be traced back to an individual visitor. We receive only aggregated statistics and cannot identify individual visitors through Framer Analytics.
Framer Analytics:
Does not place analytics cookies
Does not use persistent identifiers
Does not track visitors across different days or websites
Does not provide us with individual visitor profiles
To the extent that the initial, short-lived technical processing of the IP address and user-agent information constitutes processing of personal data, it is based on Article 6(1)(f) GDPR.
Purpose: Understanding the general use and performance of the website and improving its content, structure and technical operation.
Legitimate interest: Operating and improving an informative, accessible and technically reliable website.
The daily secret used to calculate unique visitors is reset and deleted each day. Aggregated, anonymous analytics statistics may remain available in the Framer dashboard for the period supported by our Framer plan.
Further details are available in Framer’s information on GDPR and cookies and Framer Analytics.
5. Contacting us
If you contact us by email, telephone or through a contact form, we process the information you provide to handle and respond to your enquiry.
This may include:
Your name
Your email address
Your telephone number, if provided
The content of your message
The date and time of your enquiry
Other information you choose to provide
If you use a contact form provided through Framer, Framer processes the submitted information on our behalf for its transmission to us.
Where your enquiry relates to a possible or existing contractual relationship, processing is based on Article 6(1)(b) GDPR. For other enquiries, processing is based on Article 6(1)(f) GDPR and our legitimate interest in responding to communications addressed to us.
Where necessary, information may subsequently be retained under Article 6(1)(c) GDPR to comply with statutory record-keeping obligations or under Article 6(1)(f) GDPR to establish, exercise or defend legal claims.
Enquiries are otherwise deleted when they have been conclusively resolved and no contractual, statutory or legitimate reason for continued retention remains.
6. Cookies and similar technologies
As currently configured, this website does not use non-essential analytics or marketing cookies.
Framer Analytics operates without cookies or comparable persistent identifiers. We therefore do not request consent for analytics cookies.
If additional services, embedded content or technologies requiring consent are introduced in the future, this notice will be updated and an appropriate consent mechanism will be provided before those technologies are activated.
7. Recipients and international data transfers
Personal data may be made available to service providers where this is necessary to operate the website or respond to communications. These recipients may include:
Framer B.V. as website-hosting and infrastructure provider
Framer’s authorised subprocessors
Providers supporting email and electronic communications
Professional advisers or public authorities where disclosure is required by law or necessary to protect legal rights
Service providers acting on our behalf receive access only to the information required for their respective tasks and are contractually required to process it appropriately.
Framer may use subprocessors or infrastructure located outside the European Economic Area. According to Framer’s Data Processing Addendum, transfers to third countries are based on a valid mechanism under Chapter V GDPR, such as an adequacy decision—including the EU–US Data Privacy Framework where applicable—or the European Commission’s Standard Contractual Clauses.
An up-to-date list of Framer’s subprocessors and relevant safeguards is available through Framer’s Trust Centre.
8. Your rights
Subject to the applicable legal requirements, you have the right to:
Obtain information about your personal data and receive a copy under Article 15 GDPR
Have inaccurate or incomplete data corrected under Article 16 GDPR
Request erasure under Article 17 GDPR
Request restriction of processing under Article 18 GDPR
Receive data you provided in a portable format where Article 20 GDPR applies
Object to processing based on legitimate interests under Article 21 GDPR
Withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal
Lodge a complaint with a competent data-protection authority under Article 77 GDPR
Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary for legal claims.
Requests concerning your rights may be sent to info@himmelsbach-consult.at.
The Austrian supervisory authority is:
Austrian Data Protection Authority
(Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Austria
Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: dsb.gv.at
9. Data security
This website uses TLS encryption to protect information transmitted between your browser and the website. An encrypted connection is normally indicated by “https” and the lock symbol displayed by your browser.
We also take appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure or access.
10. Automated decision-making
We do not use personal data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects.
11. Provision of personal data
You are not legally or contractually required to provide personal data merely to visit this website.
If you contact us, certain information—particularly a means of contacting you and the content of your enquiry—may be necessary for us to respond. Without this information, we may be unable to process your request.
12. Changes to this Privacy Notice
We may update this Privacy Notice if our website, services, processing activities or applicable legal requirements change. The version published on this website at the time of your visit applies.
Last updated: 2 September 2026