Privacy Policy
1. An overview of data protection
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information on data protection can be found in the following privacy policy.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. The operator’s contact details can be found in the section “Information about the controller” below.
How do we collect your data?
Some data is collected when you provide it to us. This may, for example, be data that you enter into a contact form or send to us by email.
Other data is collected automatically or after your consent when you visit the website. This primarily includes technical data such as your browser, operating system, IP address and the time the page was accessed. This data is collected automatically as soon as you access this website.
What do we use your data for?
Some data is collected to ensure that the website is provided securely and without errors. Other data may be used to process enquiries, initiate or perform contractual relationships, protect the website against misuse and ensure its technical maintenance.
We do not use Google Analytics on this website.
What rights do you have regarding your data?
You have the right to obtain information about the origin, recipients and purposes of your stored personal data free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you may withdraw this consent at any time with effect for the future.
You also have the right, under certain circumstances, to request restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with a competent supervisory authority.
You may contact us at any time if you have further questions about data protection.
2. Hosting
External hosting by DreamHost
This website is hosted by an external service provider:
DreamHost, LLC
PMB #257
417 Associated Road
Brea, CA 92821
United States
The personal data collected on this website is stored on the hosting provider’s servers. This may include IP addresses, website requests, metadata and communication data, contact details, names, website accesses and other data generated through the use of the website.
The use of the hosting provider is based on Art. 6(1)(b) GDPR insofar as hosting is necessary for the performance of a contract or for steps prior to entering into a contract. In all other cases, processing is based on Art. 6(1)(f) GDPR. We have a legitimate interest in providing our website securely, reliably and efficiently.
DreamHost is based in the United States. The transfer of personal data to the United States is carried out on the basis of the safeguards provided for by Chapter V of the GDPR, in particular the Standard Contractual Clauses of the European Commission included in DreamHost’s data processing terms, unless another valid transfer mechanism or adequacy decision applies.
We have concluded a data processing agreement with DreamHost in accordance with Art. 28 GDPR. This agreement ensures that DreamHost processes personal data only in accordance with our instructions and applicable data protection law.
Further information is available at:
3. General information and mandatory information
Data protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection legislation and this privacy policy.
When you use this website, various items of personal data may be collected. This privacy policy explains what data we collect, how we process it and for what purposes it is used.
Please note that data transmission over the Internet, for example when communicating by email, may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information about the controller
The controller responsible for data processing on this website is:
Nomad Automate GmbH
Hahngasse 17/1
1090 Vienna
Austria
Telephone: +43 1 226 00 19 11
Email: office@nomadautomate.com
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
Storage period
Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for processing no longer applies. If you submit a justified request for deletion or withdraw your consent, your data will be deleted unless we have other legally permissible grounds for retaining it, such as statutory retention obligations. In the latter case, deletion will take place after these grounds no longer apply.
Legal bases for processing
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. Where special categories of personal data are processed, Art. 9(2)(a) GDPR may also apply. Consent may be withdrawn at any time with effect for the future.
If processing is necessary for the performance of a contract or in order to take steps at your request prior to entering into a contract, processing is based on Art. 6(1)(b) GDPR. If processing is necessary to comply with a legal obligation, it is based on Art. 6(1)(c) GDPR. Processing may also be based on Art. 6(1)(f) GDPR where we or a third party have a legitimate interest and your interests, fundamental rights and freedoms do not override that interest.
Where information is stored on or accessed from your terminal device, this is carried out in accordance with Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021). Consent is obtained where legally required. Consent is not required where storage or access is strictly necessary to provide a service expressly requested by you or to transmit a communication.
Recipients of personal data
In the course of our business activities, we work with external service providers. Personal data is disclosed only where this is necessary for the performance of a contract, compliance with a legal obligation, the pursuit of a legitimate interest or where you have consented to the disclosure.
Where service providers process personal data on our behalf, we conclude data processing agreements in accordance with Art. 28 GDPR where required.
Transfers to third countries
Some service providers used by us are based outside the European Union or the European Economic Area, or use subprocessors located in third countries. Personal data is transferred to such countries only if the requirements of Art. 44 et seq. GDPR are met.
Depending on the recipient and destination country, transfers may be based on an adequacy decision of the European Commission, the Standard Contractual Clauses of the European Commission or other suitable safeguards. Despite these safeguards, transfers to certain third countries may involve risks, particularly because local authorities may have access to data and European data protection rights may not be fully enforceable.
Withdrawal of consent
Many data processing operations are possible only with your consent. You may withdraw consent at any time. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to object pursuant to Art. 21 GDPR
If data processing is based on Art. 6(1)(e) or Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data, including profiling based on those provisions.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights and freedoms, or processing is necessary for the establishment, exercise or defence of legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to processing for such marketing. If you object, your personal data will no longer be used for direct marketing purposes.
Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a competent supervisory authority, in particular in the EU or EEA member state of your habitual residence, place of work or the place of the alleged infringement.
The supervisory authority responsible for Austria is:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria
Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/
Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or in fulfilment of a contract in a commonly used, machine-readable format. Where technically feasible, you may also request that this data be transmitted directly to another controller.
Access, correction and deletion
Within the framework of the applicable legal provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients, the purposes of processing and, where applicable, a right to have this data corrected or deleted.
Right to restriction of processing
You have the right to request restriction of the processing of your personal data where:
- You contest the accuracy of the personal data, for the period required to verify its accuracy.
- The processing is unlawful and you oppose deletion and request restriction instead.
- We no longer need the data for processing purposes, but you require it for the establishment, exercise or defence of legal claims.
- You have objected to processing pursuant to Art. 21(1) GDPR and it has not yet been determined whose interests prevail.
SSL and TLS encryption
This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content. You can recognise an encrypted connection by the “https://” address and the lock symbol in your browser.
If SSL or TLS encryption is activated, data that you transmit to us cannot generally be read by third parties while it is being transmitted.
4. Cookies, consent management and data collection
Cookies and similar technologies
This website may use cookies and similar technologies. Cookies are small data records stored on your terminal device and do not cause any damage.
Cookies that are technically necessary for the provision of the website, its security or consent management are processed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and legally compliant operation of the website. Storage or access on your terminal device is based on the strictly necessary exception in Section 165(3) TKG 2021.
All other cookies and similar technologies are used only after your consent. The legal basis is Art. 6(1)(a) GDPR and Section 165(3) TKG 2021. Consent may be withdrawn at any time with effect for the future.
Consent management with Real Cookie Banner
We use Real Cookie Banner to manage legally required consent and to document your privacy preferences. The provider is:
devowl.io GmbH
Tannet 12
94539 Grafling
Germany
Real Cookie Banner is integrated locally into this website. It is used to obtain, manage and document consent and to prevent services requiring consent from loading before consent has been granted.
For this purpose, information such as a consent identifier, your consent decisions, the version of the consent configuration, the time of your decision and technical information relating to the consent process may be stored. A technically necessary first-party cookie or comparable local storage technology may be used.
Processing is based on Art. 6(1)(c) GDPR insofar as it is necessary to comply with legal documentation and accountability obligations. It is additionally based on Art. 6(1)(f) GDPR. Our legitimate interest lies in legally compliant consent management. Storage on your terminal device is strictly necessary within the meaning of Section 165(3) TKG 2021.
You can change or withdraw your decision at any time through the privacy or cookie settings provided on this website. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Further information is available in the provider’s privacy policy:
Contact form
If you send us an enquiry using the contact form, the information entered into the form, including the contact details you provide, will be processed for the purpose of dealing with your enquiry and any follow-up questions.
Depending on the form, this may include your name, email address, organisation and the content of your message.
If your enquiry relates to a contract or pre-contractual measures, processing is based on Art. 6(1)(b) GDPR. In all other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in processing enquiries addressed to us efficiently. If consent is requested, processing is based on Art. 6(1)(a) GDPR.
The data submitted through the contact form will remain with us until you request its deletion, withdraw your consent or the purpose for storing it no longer applies. Mandatory statutory provisions, particularly retention periods, remain unaffected.
Spam protection with WP Armour
We use the WordPress plugin WP Armour to protect contact forms and other input forms against automated spam messages and misuse.
WP Armour uses a so-called honeypot method. Hidden form fields and technical plausibility checks are used to determine whether a submission is likely to have been made by a human or by an automated program. Regular visitors do not have to solve an image puzzle or transmit data to an external CAPTCHA provider.
For spam detection, technical request information, time stamps, browser information, IP addresses and the content entered into a form may be processed where this is necessary to assess and prevent misuse. According to the current configuration, spam checks are carried out locally on our website and no external CAPTCHA service is contacted.
Processing is based on Art. 6(1)(f) GDPR. We have a legitimate interest in protecting our website, forms and technical systems against spam, automated attacks and misuse.
Information classified as spam may be stored temporarily for security and verification purposes and subsequently deleted. Legitimate enquiries are processed in accordance with the retention periods described for the respective form.
Enquiries by email or telephone
If you contact us by email or telephone, your enquiry and the associated personal data will be stored and processed for the purpose of handling your request.
If your request relates to a contract or pre-contractual measures, processing is based on Art. 6(1)(b) GDPR. In all other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in processing enquiries addressed to us efficiently. Where consent has been obtained, processing is based on Art. 6(1)(a) GDPR.
The data you send to us will remain with us until you request deletion, withdraw your consent or the purpose for storage no longer applies. Mandatory statutory provisions and retention periods remain unaffected.
Email delivery through Google Workspace and Gmail
We use Google Workspace and Gmail for receiving, transmitting and storing business email correspondence. Messages submitted through the contact form may also be transmitted to our email account through the locally installed WP Mail SMTP plugin.
The provider in the European Economic Area is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States, and other Google group companies or subprocessors may also be involved in providing the service.
When an email is sent, personal data such as the sender and recipient addresses, names, subject line, message content, attachments, IP addresses, time stamps and technical transmission data may be processed.
If email communication relates to a contract or pre-contractual measures, processing is based on Art. 6(1)(b) GDPR. In all other cases, processing is based on Art. 6(1)(f) GDPR. We have a legitimate interest in reliable, secure and efficient business communication. Where consent has been obtained, processing is based on Art. 6(1)(a) GDPR.
We have concluded a data processing agreement with Google in accordance with Art. 28 GDPR. Where personal data is processed in the United States or another third country, transfers are based on the requirements of Art. 44 et seq. GDPR, particularly applicable adequacy decisions or the Standard Contractual Clauses of the European Commission contained in Google’s data processing terms.
Email messages are stored for as long as necessary for the respective communication and business purpose. Statutory retention obligations remain unaffected.
Further information is available at:
5. Website maintenance and security
Website maintenance and security with WP Umbrella
We have commissioned a web service provider to provide technical maintenance, monitoring and security services for this website. As part of the ongoing support, the service provider uses WP Umbrella. The provider of WP Umbrella is:
LIVEN STUDIO SAS
4 rue de la République
69001 Lyon
France
WP Umbrella is used in particular to monitor the availability, performance and security of the website, manage technical updates, generate maintenance reports and, where enabled, create and manage backups.
As part of these services, technical system and connection data may be processed. This may include IP addresses, log data, time stamps, website addresses, version and status information and technical identifiers.
If backups of the website are created or technical errors and security incidents are investigated, data stored on the website may also be processed. Depending on the content stored on the website, this may include names, email addresses, telephone numbers, messages, documents and other content transmitted to or stored on the website.
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and error-free operation of the website, the early detection of technical disruptions and security risks, and the ability to restore the website following a technical or security-related incident.
The service provider commissioned by us to maintain the website processes personal data under a data processing agreement in accordance with Art. 28 GDPR. LIVEN STUDIO SAS is used as a further processor. According to WP Umbrella, the required data processing agreement forms part of the service contract.
According to the provider, the application and associated data are generally processed on servers located within the European Union or the European Economic Area. Data is encrypted both during transmission and storage.
If subprocessors outside the European Economic Area are used in individual cases, transfers are made in accordance with Art. 44 et seq. GDPR and on the basis of suitable data protection safeguards, particularly the Standard Contractual Clauses of the European Commission or a valid adequacy decision.
After termination of the contractual relationship, personal data processed on our behalf is deleted or returned in accordance with the contractual deletion periods. Remaining backup copies are deleted within the applicable backup and retention periods.
Further information is available at:
6. Plugins and external services
Locally hosted Google Fonts
This website uses fonts originally provided as Google Fonts. The fonts are stored locally on our own server and are delivered from our website.
When you access the website, no connection to Google’s font servers is required for the locally hosted fonts. In particular, your IP address is not transmitted to Google merely for displaying these fonts.
The local use of these fonts is based on Art. 6(1)(f) GDPR. We have a legitimate interest in a consistent, technically efficient and privacy-friendly presentation of the website.
OpenStreetMap
This website may use map material from OpenStreetMap. The provider is the OpenStreetMap Foundation:
OpenStreetMap Foundation
St John’s Innovation Centre
Cowley Road
Cambridge CB4 0WS
United Kingdom
The map is blocked when the page is first accessed and is loaded only after you have given your consent through the consent management system. Before consent, no connection to OpenStreetMap’s servers should be established.
If you consent to loading the map, your browser establishes a direct connection to OpenStreetMap’s servers. In this process, your IP address, browser and device information, time of access, requested page and technical connection data may be transmitted to OpenStreetMap. OpenStreetMap may also use cookies or similar technologies where these are required for the service.
The processing is based on your consent pursuant to Art. 6(1)(a) GDPR. Storage of or access to information on your terminal device is based on your consent pursuant to Section 165(3) TKG 2021.
You may withdraw your consent at any time with effect for the future through the privacy or cookie settings on this website. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
The United Kingdom is recognised by the European Commission as providing an adequate level of data protection. If data is transferred by the provider to other third countries, the provider is responsible for ensuring an appropriate transfer mechanism.
Further information is available in the OpenStreetMap Foundation’s privacy policy:
OpenStreetMap Foundation Privacy Policy
7. Changes to this privacy policy
We reserve the right to amend this privacy policy if the legal requirements, our website or the services we use change. The version published on this website at the time of your visit applies.
Last updated: August 25, 2026