Status: August 2026
1. Introduction
We, thym.IT, take the protection of your personal data very seriously.
We process your data exclusively on the basis of the applicable legal provisions, in particular:
- General Data Protection Regulation (GDPR)
- Austrian Data Protection Act (DSG)
- Telecommunications Act 2021 (TKG 2021)
This privacy policy informs you about which data we collect, how we use it, and which rights you have.
2. Controller
thym.IT
Contact person
Matthias Thym
admin@thym.it
3. Data collection on our website
a) Server log files
When you access our website, technically necessary information is automatically recorded in server log files, for example:
- IP address
- browser type and version
- operating system used
- referrer URL
- date and time of access
- accessed pages/files
This data is used exclusively for secure operation, error analysis, and defense against misuse. It is not merged with other data.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in the secure and stable operation of the website).
b) Cookies and consent management
This website currently uses no non-essential cookies.
In particular, we do not use tracking via third-party cookies such as classic marketing or profiling cookies.
With the current website setup, no cookie banner requiring consent is generally necessary because no cookies or trackers requiring consent are used.
4. Contacting us
If you contact us by e-mail or via the contact form, we process the data you provide in order to answer your request. This may include, in particular:
- name
- e-mail address
- company or organisation
- phone number
- subject
- message content
Legal basis:
- Art. 6 para. 1 lit. b GDPR (pre-contractual measures / performance of a contract), insofar as your request aims at a business relationship or service engagement
- Art. 6 para. 1 lit. f GDPR (legitimate interest in communication and handling inquiries)
- in the case of the contact form, additionally any consent granted by you under Art. 6 para. 1 lit. a GDPR, insofar as the form requests such consent for the handling of the inquiry
We do not pass this data on to uninvolved third parties.
5. Services and tools used
Plausible Analytics (self-hosted)
We use Plausible Analytics for reach measurement in a self-hosted setup on our own server.
Important points:
- No tracking cookies are set.
- No profiling of individual users takes place.
- No personal visitor data is transmitted to external third parties such as large advertising networks.
This use serves exclusively the privacy-friendly, statistical evaluation of website usage.
The resulting data is processed exclusively on servers within the European Union. No processing takes place on servers outside the European Union.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in privacy-friendly reach measurement and improvement of the website).
6. Storage period
We store personal data only for as long as necessary for the respective purposes or for as long as statutory retention obligations exist.
- Server log data is generally stored only for a short period.
- Contact requests are stored for as long as necessary for processing, follow-up communication, or for as long as legal obligations exist.
7. Your rights under the GDPR
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
- right of access to stored data (Art. 15 GDPR)
- right to rectification of inaccurate data (Art. 16 GDPR)
- right to erasure of your data (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object to processing (Art. 21 GDPR)
- right to withdraw granted consent (Art. 7 para. 3 GDPR)
If you believe that the processing of your data violates data protection law, you can lodge a complaint with the competent supervisory authority:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Website: https://www.dsb.gv.at/
8. Security
We use technical and organisational security measures to protect your data against loss, manipulation, unauthorised access, and unauthorised disclosure.
9. Changes to this privacy policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or reflects changes to our services.
The current version is available on this website at any time.
Legal bases and further information
- GDPR (EU Regulation): https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Austrian Data Protection Act (DSG): https://www.ris.bka.gv.at/
- Telecommunications Act 2021 (TKG 2021): https://www.ris.bka.gv.at/
- Plausible Analytics – Data Policy: https://plausible.io/data-policy
- Plausible Analytics – Self-hosting: https://plausible.io/docs/self-hosting