Privacy Notice

1. Controller

The controller responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Raffael Himmelsbach Consulting e.U.
Proprietor: Dr Raffael Himmelsbach
Lilienbrunngasse 18
1020 Vienna
Austria

Email: info@himmelsbach-consult.at
Telephone: +43 681 10895604

2. General information

We process personal data only where this is necessary to operate this website, respond to enquiries, provide requested services, comply with legal obligations or protect our legitimate interests.

Personal data means any information relating to an identified or identifiable natural person.

3. Website hosting and technical access data

This website is created and hosted using services provided by:

Framer B.V.
Rozengracht 207B
1016 LZ Amsterdam
The Netherlands

When you access this website, technical information required to deliver and secure the website is processed automatically. Depending on the request, this may include:

  • IP address

  • Date and time of access

  • Requested page or file

  • Browser type and version

  • Operating system

  • Referring page

  • Device and connection information

  • Information concerning successful or unsuccessful delivery of the requested content

This processing is necessary to display the website, maintain its stability and security, diagnose technical problems and prevent misuse.

Legal basis: Article 6(1)(f) GDPR
Legitimate interests: Reliable, secure and efficient provision of this website.

Technical data are retained only for as long as necessary for website delivery, security, troubleshooting and compliance with applicable legal obligations. Framer processes relevant data on our behalf under its Data Processing Addendum.

Further information is available in Framer’s Privacy Statement.

4. Framer Analytics

We use only Framer’s built-in analytics functionality to obtain aggregated information about the use of this website. We do not use Google Analytics or other third-party analytics or advertising trackers.

Framer Analytics may provide us with aggregated statistics such as:

  • Daily unique visitors and page views

  • Frequently visited, entry and exit pages

  • Approximate session duration and bounce rate

  • Referral sources and UTM parameters

  • Approximate country

  • Device type, browser and operating system

To calculate daily unique visitors, Framer combines the visitor’s IP address and user-agent information with a secret value that changes daily. This produces a short-lived anonymous identifier. The secret is reset and deleted each day, and no persistent identifier is created.

Framer states that the resulting analytics information is anonymised and cannot be traced back to an individual visitor. We receive only aggregated statistics and cannot identify individual visitors through Framer Analytics.

Framer Analytics:

  • Does not place analytics cookies

  • Does not use persistent identifiers

  • Does not track visitors across different days or websites

  • Does not provide us with individual visitor profiles

To the extent that the initial, short-lived technical processing of the IP address and user-agent information constitutes processing of personal data, it is based on Article 6(1)(f) GDPR.

Purpose: Understanding the general use and performance of the website and improving its content, structure and technical operation.
Legitimate interest: Operating and improving an informative, accessible and technically reliable website.

The daily secret used to calculate unique visitors is reset and deleted each day. Aggregated, anonymous analytics statistics may remain available in the Framer dashboard for the period supported by our Framer plan.

Further details are available in Framer’s information on GDPR and cookies and Framer Analytics.

5. Contacting us

If you contact us by email, telephone or through a contact form, we process the information you provide to handle and respond to your enquiry.

This may include:

  • Your name

  • Your email address

  • Your telephone number, if provided

  • The content of your message

  • The date and time of your enquiry

  • Other information you choose to provide

If you use a contact form provided through Framer, Framer processes the submitted information on our behalf for its transmission to us.

Where your enquiry relates to a possible or existing contractual relationship, processing is based on Article 6(1)(b) GDPR. For other enquiries, processing is based on Article 6(1)(f) GDPR and our legitimate interest in responding to communications addressed to us.

Where necessary, information may subsequently be retained under Article 6(1)(c) GDPR to comply with statutory record-keeping obligations or under Article 6(1)(f) GDPR to establish, exercise or defend legal claims.

Enquiries are otherwise deleted when they have been conclusively resolved and no contractual, statutory or legitimate reason for continued retention remains.

6. Cookies and similar technologies

As currently configured, this website does not use non-essential analytics or marketing cookies.

Framer Analytics operates without cookies or comparable persistent identifiers. We therefore do not request consent for analytics cookies.

If additional services, embedded content or technologies requiring consent are introduced in the future, this notice will be updated and an appropriate consent mechanism will be provided before those technologies are activated.

7. Recipients and international data transfers

Personal data may be made available to service providers where this is necessary to operate the website or respond to communications. These recipients may include:

  • Framer B.V. as website-hosting and infrastructure provider

  • Framer’s authorised subprocessors

  • Providers supporting email and electronic communications

  • Professional advisers or public authorities where disclosure is required by law or necessary to protect legal rights

Service providers acting on our behalf receive access only to the information required for their respective tasks and are contractually required to process it appropriately.

Framer may use subprocessors or infrastructure located outside the European Economic Area. According to Framer’s Data Processing Addendum, transfers to third countries are based on a valid mechanism under Chapter V GDPR, such as an adequacy decision—including the EU–US Data Privacy Framework where applicable—or the European Commission’s Standard Contractual Clauses.

An up-to-date list of Framer’s subprocessors and relevant safeguards is available through Framer’s Trust Centre.

8. Your rights

Subject to the applicable legal requirements, you have the right to:

  • Obtain information about your personal data and receive a copy under Article 15 GDPR

  • Have inaccurate or incomplete data corrected under Article 16 GDPR

  • Request erasure under Article 17 GDPR

  • Request restriction of processing under Article 18 GDPR

  • Receive data you provided in a portable format where Article 20 GDPR applies

  • Object to processing based on legitimate interests under Article 21 GDPR

  • Withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal

  • Lodge a complaint with a competent data-protection authority under Article 77 GDPR

Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary for legal claims.

Requests concerning your rights may be sent to info@himmelsbach-consult.at.

The Austrian supervisory authority is:

Austrian Data Protection Authority
(Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Austria

Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: dsb.gv.at

9. Data security

This website uses TLS encryption to protect information transmitted between your browser and the website. An encrypted connection is normally indicated by “https” and the lock symbol displayed by your browser.

We also take appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure or access.

10. Automated decision-making

We do not use personal data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects.

11. Provision of personal data

You are not legally or contractually required to provide personal data merely to visit this website.

If you contact us, certain information—particularly a means of contacting you and the content of your enquiry—may be necessary for us to respond. Without this information, we may be unable to process your request.

12. Changes to this Privacy Notice

We may update this Privacy Notice if our website, services, processing activities or applicable legal requirements change. The version published on this website at the time of your visit applies.

Last updated: 2 September 2026

Let's talk about what you're facing.

Tell me a little about where you work and what issues you face. I read every message myself.

Let's talk about what you're facing.

Tell me a little about where you work and what issues you face. I read every message myself.