PRIVACY
Privacy Policy
Protecting your personal data matters to us. This statement explains which data we process on this website, why we do so, how long we keep it and which rights you have. We deliberately wrote it so that it is understandable without specialist knowledge.
Data Controller
UNFINISHED e.U. · Bülent Toluay
Hackhofergasse 1, 1190 Wien, Österreich
Company register number: FN 633859x, Handelsgericht Wien
VAT ID: ATU82781456
Phone: +43 677 634 639 10 · Email: office@unfinished.at
For questions about data protection, you can reach us using the contact details above. We are not required to appoint a data protection officer, as the legal conditions for this do not apply to us.
Hosting and server logs
This website runs on a server operated by abaton EDV-Dienstleistungs GmbH, Conrad-von-Hoetzendorf-Strasse 165, 8010 Graz, Austria. The server is located in Austria, so no transfer to a third country takes place. The company processes the data solely on our behalf and is contractually bound to confidentiality (processing agreement pursuant to Art. 28 GDPR).
Every time a page is opened, the server automatically writes a log entry. It contains your IP address, the date and time, the address requested, the page you came from and details about your browser and operating system. We need these logs for secure operation and to fend off attacks. They are overwritten automatically and are only available for a few days, usually around a week. The legal basis is our legitimate interest in a secure, functioning service (Art. 6(1)(f) GDPR).
We also keep a technical error log. If something goes wrong in our application, we record the time, the type of error, the file and line concerned and a shortened message text (300 characters at most). Email addresses that may appear in such a message are automatically replaced with the note "[E-Mail]". Your IP address is not recorded there. The log sits outside the publicly accessible area, serves solely to track down faults and keep the service secure (Art. 6(1)(f) GDPR) and does not grow without limit: from 5 MB onwards we start a new file and keep at most one previous file, so older entries are deleted.
Enquiries and checks
If you send us the contact form, a quote request or the result of one of our checks, we process the details you enter there: first and last name, email address, phone number, subject and message, where applicable also company and website, a preferred appointment (date, time, preferred type of meeting) and, for the checks, your answers from the questionnaire.
In addition, we store your IP address with each enquiry. It serves solely to protect against automated spam: we accept only a limited number of enquiries per hour from the same IP address.
The enquiry is stored in our database and is also delivered to us by email. The legal basis is the performance of pre-contractual measures at your request (Art. 6(1)(b) GDPR), or, for purely general matters, our legitimate interest in replying (Art. 6(1)(f) GDPR). Providing the details is voluntary, but without them we cannot reply to you.
Retention: we delete enquiries automatically twelve months after we receive them. If an enquiry leads to an assignment, the related documents form part of our accounting records and are subject to the statutory retention period of seven years (Section 132 BAO). You may request earlier deletion at any time.
Anonymous mailbox from the founder check
In the founder check you can tell us about your idea anonymously. This path is built so that we cannot know who you are: we ask for no name, no email address and require no sign-up. We store no IP address with your submission.
We only store your text, the answers you tapped during the check and a five-character code. That code is the only way into your mailbox. It never appears in the address bar but is typed in, so it does not end up in server logs. If you lose it, we cannot restore it.
Your mailbox page (/answer) is not counted and not analysed: no visit statistics, no Meta Pixel, no marketing tools. Only the technically necessary session cookie against form abuse runs there.
So that nobody floods the mailbox or guesses their way through the five-digit code, we build a checksum from IP address, browser signature and a secret value that changes daily, just as we do for the visit statistics. The IP address itself is never stored. We delete the checksums after seven days, those for mistyped codes after a single day.
If you want to be notified as soon as your answer is there, you can voluntarily leave an email address. We use it only for that one message, never for advertising. The legal basis is your consent (Art. 6(1)(a) GDPR), otherwise our legitimate interest in answering your message (Art. 6(1)(f) GDPR).
A person at our office reads your text. It is not passed on and not published. Write into your mailbox that you want it closed and we delete the entire exchange. Without that request we delete it at the latest twelve months after the last message.
Visitor statistics without cookies
We want to know which pages are being read, but we deliberately use no cookies for this and do not embed any external service such as Google Analytics. The counting runs on our own server and is built so that it does not recognise you.
So that we do not count visits twice, we create a checksum from your IP address, your browser identifier and a secret value that changes daily. The IP address cannot be reconstructed from this checksum, and because the secret value changes every day, recognition beyond that day is impossible. Your IP address itself is not stored. We delete the checksums after 90 days.
Only aggregated figures without any personal reference are kept: page views per day, time spent, the country of origin (determined offline, your IP address does not leave our server for this), the referring website and markers from advertising links (such as utm_source). The legal basis is our legitimate interest in designing our service to meet demand (Art. 6(1)(f) GDPR).
Cookies & Consent
On your first visit we ask for your consent via a banner. Optional categories are switched off by default and only become active after you agree. You can change or withdraw your choice at any time via "Cookie settings" (in the banner or in the footer). Withdrawal applies to the future; processing that has already taken place remains unaffected. We distinguish the following categories:
- Necessary cookies: required for the operation of the website (e. g. security/CSRF protection, storing your cookie choice, dark/light mode). Legal basis: legitimate interest or technical necessity (Art. 6(1)(f) GDPR).
- Analytics: analysis of usage via third-party services. This category is currently empty because our visitor statistics work without cookies (see above).
- Marketing: advertising and reach measurement, currently the Meta Pixel (see below). Only with your consent.
- External content: embedding of third-party services, currently Google Maps (see below). Only with your consent.
In detail, we store the following on your device:
| Name | Category | Purpose | Duration | Provider |
|---|---|---|---|---|
PHPSESSID |
Necessary | Keeps your session together and protects forms against misuse. | Ends with the browser session | UNFINISHED e.U. |
unf_mkt |
Necessary | Remembers that you consented to the marketing category, so that we can respect this on the server side as well. | 180 days | UNFINISHED e.U. |
unfinished-cookie-consent |
Necessary | Stores your choice in the cookie banner. Kept in the browser local storage, not as a cookie. | Until you clear your browser storage | UNFINISHED e.U. |
unfinished-theme |
Necessary | Remembers whether you read the website in light or dark mode. Kept in the browser local storage, not as a cookie. | Until you clear your browser storage | UNFINISHED e.U. |
_fbp |
Marketing | Identifies your browser so that Meta can measure the effectiveness of our advertising. | Up to 90 days | Meta Platforms Ireland Limited |
_fbc |
Marketing | Records which advertisement you arrived from. | Up to 90 days | Meta Platforms Ireland Limited |
The two Meta entries are only created if you consent to the marketing category. Without consent, none of them is set. You can also delete cookies at any time in your browser settings or refuse them altogether.
Meta Pixel
On this website we use the Meta pixel exclusively after your explicit consent (category "Marketing"). The provider is Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland). The pixel helps us measure how effective our advertising on Facebook and Instagram is and to reach visitors to our website again there. When it loads, data (including your IP address, browser information and pages visited) is transmitted to Meta; this may involve a transfer to third countries (USA). Meta may link this data with your Meta account and use it for its own purposes. If you do not give consent, the pixel is not loaded and no data is sent to Meta. The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future via the cookie settings. Further information can be found in Meta's privacy policy.
If you have given marketing consent and submit an inquiry via our contact form or a check, we additionally report this event to Meta server-side (Conversions API). Only technical matching data is transmitted (IP address, browser identifier, Meta cookies), no names and no email addresses. Without consent this transmission does not take place at all.
Google Maps
On the contact page we embed a Google Maps map, exclusively after your explicit consent (category "External content"), in order to show our location. The provider is Google Ireland Limited or Google LLC (USA). When the map loads, data (including your IP address) is transmitted to Google; this may involve a transfer to third countries (USA). If you do not give consent, a placeholder is shown instead of the map and no data is sent to Google. The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future. Further information can be found in Google's privacy policy.
Client portal
Existing clients can log in to our portal to view quotes, invoices and the status of their project. For this we process the login details and the data belonging to the assignment. Failed login attempts are recorded briefly together with the IP address in order to slow down attacks on passwords. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and, for securing the login, our legitimate interest (Art. 6(1)(f) GDPR).
Failed logins in detail: If a login fails, both in the client portal and in our internal administration, we store the IP address, the e-mail address that was entered, the area concerned (portal or administration) and the point in time. We need this information to slow down password guessing: after three failed attempts, logging in from that address stays blocked for one hour. Successful logins are not recorded there. The legal basis is our legitimate interest in secure access (Art. 6(1)(f) GDPR). We delete these entries automatically once they are older than one day, and immediately after a successful login.
Emails to you
We send replies, quotes, invoices and appointment confirmations via our own mail server hosted by the same Austrian provider that runs the website. We do not send newsletters or advertising emails. We keep an internal log of what was sent so that we can prove a document actually went out.
This dispatch log holds, for each message: the recipient address, the subject, the number of attachments, the point in time and a note on whether the message went out successfully. The text of the message and the attachments themselves are not stored there. The log is our proof that a quote, an invoice or a reply really was sent, which is why we keep it permanently. The legal basis is our legitimate interest in that proof (Art. 6(1)(f) GDPR). On request we will tell you which entries exist for your address.
Disclosure to third parties
We do not sell data and do not pass it on without reason. Access is limited to: our hosting provider (see above), Meta within the marketing measurement you have permitted, Google when you voluntarily load the map, as well as our tax advisors and authorities where we are legally obliged to do so.
Your Rights
You have the right to obtain information about the data stored about you, to rectification, to erasure, to restriction of processing, to data portability and to object to processing that we base on a legitimate interest. You may withdraw consent you have given at any time with effect for the future. An informal message to the email address above is sufficient.
If you believe that we are not processing your data correctly, you can lodge a complaint with the supervisory authority. The competent authority is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, phone +43 1 52 152-0, dsb@dsb.gv.at, dsb.gv.at.
Last updated
This privacy statement was last revised on 10 August 2026. If we change anything about our website or the services we use, we will update it.