Last updated: March 2026 — Version 1.0

1. Data Controller / Verantwortlicher

Austrian Pharma Services ("APS")
Email: datenschutz@austrianpharmaservices.com

APS is the controller within the meaning of Art. 4(7) GDPR / DSGVO for the processing of personal data described in this policy.

2. Data We Collect

2.1 Account Data

When you register, we collect:

2.2 Usage Data

We automatically collect:

2.3 User-Generated Data

3. Legal Basis for Processing (Art. 6 GDPR)

PurposeLegal Basis
Account creation and Service deliveryPerformance of contract (Art. 6(1)(b))
Payment processingPerformance of contract (Art. 6(1)(b))
Service improvement and analyticsLegitimate interest (Art. 6(1)(f))
Security monitoring and fraud preventionLegitimate interest (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a))
Legal obligations (tax, accounting)Legal obligation (Art. 6(1)(c))

4. Data Processors and Third Parties

We share personal data with the following categories of processors, all bound by data processing agreements:

ProcessorPurposeLocation
Hostinger / HetznerServer hosting and infrastructureEU (Lithuania / Germany)
StripePayment processing and subscription managementEU / US (EU SCCs in place)
OpenAIAutomated event analysis and summarisationUS (EU SCCs in place)
Keycloak (self-hosted)Identity and access management (SSO)EU (Germany, Hetzner)

No personal data is sold to third parties. Data transfers outside the EU/EEA are safeguarded by Standard Contractual Clauses (SCCs) or adequacy decisions pursuant to Art. 46 GDPR.

5. Data Retention

Data CategoryRetention Period
Account dataDuration of account + 30 days after deletion request
Usage/analytics data12 months (anonymised thereafter)
Billing and invoice data7 years (Austrian tax law, BAO § 132)
Server access logs90 days
Support correspondence3 years after resolution

6. Your Rights (Art. 15–22 GDPR)

You have the following rights regarding your personal data:

To exercise these rights, contact us at datenschutz@austrianpharmaservices.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, www.dsb.gv.at).

7. Cookies and Tracking

7.1 Essential Cookies

We use strictly necessary cookies for session management and authentication. These do not require consent under Art. 5(3) ePrivacy Directive.

CookiePurposeDuration
session_tokenUser authenticationSession / 24 hours
PHPSESSIDServer-side sessionSession

7.2 Analytics Cookies

We currently do not use third-party analytics or tracking cookies. If this changes, we will update this policy and implement a consent mechanism in accordance with GDPR and the Austrian Telecommunications Act (TKG 2021).

7.3 Local Storage

We use browser local storage to persist user preferences (e.g., selected filters, UI settings). This data remains on your device and is not transmitted to our servers.

8. Security Measures

We implement appropriate technical and organisational measures to protect your data, including:

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "last updated" date at the top of this page indicates the most recent revision.

10. Contact / Kontakt

Austrian Pharma Services
Data Protection Inquiries / Datenschutzanfragen:
datenschutz@austrianpharmaservices.com