What this website collects, why, who else sees it, and what you can ask us to do about it.
The controller for the processing described here is:
IDCanopy FlexCo
Dr. Karl-Lueger-Platz 5, 1010 Vienna, Austria
Registered with the Commercial Court of Vienna, company register number FN 628013 z
VAT identification number: ATU80719046
Managing director: Bernhard Reiterer, MBA
Data protection contact: gdpr@idcanopy.com
Questions about this notice, and requests under the rights set out below, go to that address.
This is a static information website. It sets no cookies. It runs no analytics, no advertising and no social media trackers. It loads no fonts, scripts or images from third parties. It carries no contact form, no login and no account. There is no profiling and no automated decision making of any kind on this website. The only personal data that reaches us through the site is what a web server records about a request, and whatever you choose to send us yourself.
Every request to this website is recorded by the hosting provider that serves it, in the way web servers ordinarily do: the requesting IP address, the date and time, the page or file requested, the referring page where your browser sends one, the browser and operating system your browser identifies itself as, and the size and status of the response. We use this to operate the site, keep it secure, and investigate faults and attacks. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in a working and secure website. We do not use log data to identify individual visitors and do not combine it with any other data. It is kept only as long as those purposes require and is then deleted.
The email addresses on this website are ordinary mailboxes. If you write to us we process your address, your name where you give it, and whatever you put in the message, in order to answer you and, where you are asking about our services, to take steps at your request before a contract. The legal basis is Article 6(1)(b) GDPR where your message concerns a contract or its preparation, and Article 6(1)(f) GDPR, our legitimate interest in answering enquiries, in every other case. We keep correspondence for as long as the matter and the business relationship require, and longer where Austrian commercial and tax law requires us to retain it.
The booking link on this website opens a scheduling page hosted by Microsoft as part of our Microsoft 365 tenant. If you book, the name, email address and any message you enter reach us as the meeting organiser and are used to arrange and hold the meeting. The legal basis is Article 6(1)(b) GDPR where the meeting concerns a contract or its preparation, and Article 6(1)(f) GDPR otherwise. Microsoft processes that booking data on our behalf. What Microsoft collects on its own account when you visit that page is governed by Microsoft's own privacy statement, not by this notice.
Two categories, and no others: the hosting provider that serves this website, and Microsoft, which provides our email and the meeting booking. Both act as processors on our behalf under Article 28 GDPR. We do not sell personal data, do not pass it to advertising networks, and do not share it with anyone else unless the law requires it or you ask us to.
We keep processing inside the European Union and the European Economic Area wherever we can. Where a processor transfers personal data to a country outside the EEA, that transfer is covered either by an adequacy decision of the European Commission or by the Commission's standard contractual clauses, with the additional safeguards each case requires.
This website links to other websites, including our own product pages on separate addresses and pages operated by third parties. This notice covers this website only. Once you follow a link, the privacy notice of the site you reach applies.
Under the GDPR you can ask us for access to the personal data we hold about you, for it to be corrected or erased, for its processing to be restricted, and to receive it in a portable form. Where we process data on the basis of a legitimate interest you can object at any time on grounds relating to your particular situation. Where we ever process on the basis of consent you can withdraw that consent at any time, with effect for the future. Write to gdpr@idcanopy.com and we will answer within the period the GDPR sets.
You also have the right to complain to a supervisory authority. The authority responsible for us is the Austrian Data Protection Authority (Datenschutzbehörde), which publishes its contact details at dsb.gv.at.
We update this notice when the website changes in a way that affects it. Who we are and how to reach us is on the legal notice page.
Last updated 18 August 2026.