Last Updated: 27.01.2025
1. Introduction
Welcome to CYP Media, operated by Maximilian Weißenbäck (“we,” “us,” or “our”). We are committed to respecting and protecting your privacy in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Austrian Data Protection Act (Datenschutzgesetz), and other applicable data protection laws.
This Privacy Policy explains how we collect, use, share, and protect your personal information. By interacting with us—via our websites, services, or other channels—you agree to the practices described here.
2. Contact Information
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
- Name/Company: Maximilian Weißenbäck / CYP Media
- Address: Kinzerplatz 3/1/6, 1210 Vienna, Austria
- Phone: +43 676 9191090
- Email: office@cyp.media
3. Personal Data We Collect
1. Identification and Contact Details
- Name
- Phone number
- Email address
- Company name, company address, UstID
- Birthday
2. Financial and Payment Information
- Payment details (e.g., billing data for Qonto)
3. Communications
- Email or WhatsApp messages, phone call records, Zoom meeting recordings, and other correspondence.
4. Usage Data
- IP address, geolocation, and browsing behavior (via Google Analytics, Google Tag Manager, etc.)
4. How We Collect Personal Data
- Contact Forms & Newsletter Sign-up: When you fill out a contact form or subscribe to our newsletter.
- Client Onboarding & Direct Communication: When you become a client or communicate with us (email, WhatsApp, Zoom, phone).
- Analytics & Tracking: Through cookies and other tracking technologies (e.g., Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Pixel).
- Third-Party Tools:
- HubSpot (CRM)
- MailerLite (newsletter service)
- Make (automation platform)
- Webflow (website hosting)
- Spaceship (domain hosting)
5. Purpose of Data Collection
We use your data for the following purposes:
- Providing Services: To respond to inquiries, provide professional services, and manage client relationships.
- Processing Payments: Using Qonto for secure payment handling.
- Marketing & Remarketing:
- Newsletters and email campaigns via MailerLite.
- Ads and remarketing campaigns via Google Ads, Meta Ads, and LinkedIn Ads.
- Analytics & Improvements: Monitoring website traffic and user behavior (e.g., Google Analytics) to improve our services and user experience.
- Legal & Compliance: To comply with obligations under the GDPR, Austrian law, and to establish or defend legal claims.
6. Legal Basis for Processing
In line with Article 6(1) of the GDPR, we rely on:
- (a) Consent: When you subscribe to our newsletter or accept non-essential cookies.
- (b) Contract: When processing is necessary to fulfill a contract with you or take steps at your request before entering into a contract.
- (c) Legal Obligation: To comply with Austrian and EU laws (e.g., tax, accounting).
- (f) Legitimate Interests: For website analytics, security measures, and certain marketing activities, unless overridden by your interests or fundamental rights.
7. Data Sharing and Disclosure
We share your data with third parties only as necessary to achieve the purposes outlined in this Policy:
- Qonto – For business banking and payment processing.
Privacy Policy: https://qonto.com/en/legal/privacy-policy - HubSpot – For CRM management and storing customer records.
Privacy Policy: https://legal.hubspot.com/privacy-policy - Google Services – For website analytics, conversion tracking, advertising.
Google Analytics & Tag Manager, Google Ads
Privacy Policy: https://policies.google.com/privacy - Cookie Script – For cookie consent management.
Privacy Policy: https://cookie-script.com/privacy-policy.html - MailerLite – For sending newsletters and email marketing.
Privacy Policy: https://www.mailerlite.com/legal/privacy-policy - Meta (Facebook/Instagram) – For remarketing and advertising campaigns.
Privacy Policy: https://www.facebook.com/privacy/policy - LinkedIn – For remarketing and advertising campaigns.
Privacy Policy: https://www.linkedin.com/legal/privacy-policy - Webflow – For website hosting and management.
EU/EEA Privacy Policy: https://webflow.com/legal/eu-privacy-policy - Spaceship – For domain hosting.
Privacy Policy: https://www.spaceship.com/legal/privacy-policy/ - Calendly – We use Calendly for scheduling appointments.
We use Calendly to schedule appointments and manage our availability. When you book a meeting through Calendly, the personal data you provide (e.g., name, email address, and any additional information requested in the booking form) is transmitted to Calendly. Calendly may process this data on servers located outside the European Union and uses Standard Contractual Clauses or other recognized safeguards to ensure GDPR compliance.
Privacy Policy: https://calendly.com/pages/privacy
Where data is transferred outside the European Economic Area (EEA), these providers rely on Standard Contractual Clauses (SCCs) or other recognized legal mechanisms to ensure GDPR compliance.
8. Cookies and Tracking Technologies
- Cookie Usage:
We use session and persistent cookies for core site functionality, improving user experience, and tracking marketing efforts.
- Tracking Tools:
- Google Analytics (GA4) automatically anonymizes IP addresses, though it may derive general location data.
- Google Tag Manager, Meta Pixel, and LinkedIn Pixel track user interactions and conversions for remarketing or advertising
- Consent Banner:
A cookie banner (via Cookie Script) allows you to opt in or out of non-essential cookies. Disabling certain cookies may affect your user experience.
9. International Data Transfers
Because we use services like Google, HubSpot, and MailerLite, your data may be transferred and stored outside the EEA. Where such transfers occur, these providers typically rely on Standard Contractual Clauses (SCCs) or similar safeguards, ensuring your data remains protected under GDPR standards.
10. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law (e.g., tax and accounting regulations). Once data is no longer needed, we will securely delete or anonymize it.
11. Security Measures
We take appropriate technical and organizational measures to protect your personal information:
- HTTPS & SSL Certificates: Secure online data transmission through encryption.
- Controlled Access: Only authorized team members can access sensitive personal data; others only see essential info needed for their tasks.
- Secure Hosting: Hosted on Webflow, with domain management via Spaceship, both using industry-standard security protocols.
12. Your Rights Under GDPR
Under the GDPR, you have rights regarding your personal data, including:
- Right of Access (Art. 15 GDPR): Obtain a copy of your personal data.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17 GDPR) (“Right to be Forgotten”): Ask us to delete your data under certain circumstances.
- Right to Restrict Processing (Art. 18 GDPR): Request restriction of certain processing.
- Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, commonly used machine-readable format.
- Right to Object (Art. 21 GDPR): Object to certain data processing, such as direct marketing.
- Right to Withdraw Consent (Art. 7(3) GDPR): If we rely on your consent, you can withdraw it at any time.
To exercise your rights, contact us at office@cyp.media.
13. Minors
Our services are not intended for individuals under the age of 18 without parental or guardian consent. If you believe we may have collected information from a minor without appropriate consent, please contact us so we can address it promptly.
14. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Austrian Data Protection Authority within 72 hours of becoming aware, in accordance with Articles 33 and 34 of the GDPR. We will also notify affected individuals where required by law.
15. Dispute Resolution
If you have concerns or complaints about our handling of personal data, please contact us at office@cyp.media. You also have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be reflected by the “Last Updated” date at the top. We encourage you to review this Policy periodically to stay informed about our privacy practices.
17. Contact Us
If you have questions about this Privacy Policy or your data, please contact:
Maximilian Weißenbäck / CYP Media
Kinzerplatz 3/1/6
1210 Vienna, Austria
+43 676 9191090