Privacy policy
How we handle personal data on muroagency.com, under the GDPR and the Austrian Data Protection Act (DSG). Last updated: 3 October 2026.
1. Who is responsible
The controller under Art. 4(7) GDPR is:
Ilja Nasedkins, Muro AgencyBertha-von-Suttner-Gasse 12/103
1220 Wien, Austria
Email: hello@muroagency.com
Phone: +43 660 966 3688
We have not appointed a data protection officer, as there is no legal obligation to do so. For all privacy questions, write to the email address above.
2. What we process at a glance
- Visiting the site: technical data such as IP address and browser information, processed by our host to deliver the site securely.
- Forms: the information you enter when you request a video review, take the website check, ask for a quote or order an audit.
- Direct contact: what you send us by email, phone or WhatsApp.
- No tracking: analytics run only after you agree in the cookie banner (see section 6).
We do not sell personal data and do not use it for automated decisions with legal effect (Art. 22 GDPR).
3. Visiting the website
Our website is hosted by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When you open a page, the server automatically processes data your browser sends: IP address, date and time of the request, the page requested, the referring page, browser type and version, and operating system. This is necessary to deliver the website and to protect it against attacks.
Cloudflare delivers the website through its global network, including servers in the EU, and processes this data on our behalf under a data processing agreement (Art. 28 GDPR). Data may be processed in the USA. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR); in addition, standard contractual clauses apply. More information: Cloudflare Privacy Policy.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the website. Server logs are deleted after a short period by the host, unless they are needed to investigate a security incident.
Fonts: all fonts are delivered with the website itself. Your browser does not connect to Google Fonts or any other font service.
Encryption: the site uses TLS (HTTPS), so data you enter is transmitted encrypted.
4. Forms and enquiries
We offer the following forms:
- Free video review: website URL and email address.
- 40-second website check: your answers to five multiple-choice questions. If you ask for the free review at the end, also your email address and, optionally, your website URL.
- Quote brief: information about your business and project, links you share, your name, preferred contact channel and the contact detail you provide (email, phone or Telegram).
- Audit order and contact requests: the information you enter.
Purpose and legal basis: we use this data to answer your request, prepare an estimate or review and, if you wish, a contract. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract at your request) and Art. 6(1)(f) GDPR (our legitimate interest in answering enquiries). The consent checkbox confirms that you want us to contact you.
Anonymous website-check answers: when you finish the website check without leaving an email address, we store your multiple-choice answers without any contact data to improve the check and our services. Legal basis: Art. 6(1)(f) GDPR. These answers cannot be linked to you.
Spam protection: forms contain a hidden field that people do not see. We discard submissions where it is filled in. No personal data is used for this.
reCAPTCHA: to protect our forms from automated spam, we use Google reCAPTCHA v3, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA is loaded only after you tick a form's consent box, which names it; before that, no data is sent to Google. reCAPTCHA then analyses technical data such as your IP address, browser and device information and how you interact with the page, and stores data in your browser, to assess whether the input comes from a person. Data may be processed by Google LLC in the USA, which is certified under the EU-US Data Privacy Framework. Legal basis: your consent (Art. 6(1)(a) GDPR, § 165(3) TKG 2021, § 25(1) TDDDG). You can withdraw it at any time with effect for the future; if you prefer not to use reCAPTCHA, contact us by email, phone or WhatsApp instead. More information: Google Privacy Policy.
Where the data goes: form submissions are sent to a Google Apps Script, which checks them for spam and forwards enquiries to our customer relationship management system (see below). Anonymous website-check answers are saved in a private Google Sheet. Enquiries are only saved in that sheet and emailed to our inbox if the CRM is temporarily unavailable. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which processes the data on our behalf under a data processing agreement (Art. 28 GDPR). Data may also be processed by Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR); in addition, standard contractual clauses apply. Enquiries that include contact details are stored as leads in our customer relationship management system, Zoho CRM, provided by Zoho Corporation B.V. (Netherlands), on servers in the EU, under a data processing agreement (Art. 28 GDPR).
Providing this data is voluntary. Without it, we cannot answer your request.
5. Email, phone and WhatsApp
When you contact us by email or phone, we process your details and message to answer your request. Legal basis: Art. 6(1)(b) and (f) GDPR.
WhatsApp: the WhatsApp buttons are plain links. No data is sent to WhatsApp until you click one. If you then message us, WhatsApp Ireland Limited (Meta) processes your phone number, profile and messages under its own privacy policy, and data may be transferred to the USA. Use email or the forms if you prefer not to use WhatsApp.
7. External services and links
Links to Instagram, LinkedIn and other websites are plain links. No data is sent to these services until you click a link. After that, the privacy policy of the respective provider applies.
Our website does not embed social media plugins, maps or videos from third parties.
8. How long we keep data
- Enquiries that do not lead to a project: deleted at the latest 12 months after our last contact.
- Project and invoice data: kept for 7 years as required by Austrian tax law (§ 132 BAO), or longer while legal claims can be raised.
- Anonymous website-check answers: they contain no personal data, so no deletion obligation applies; we delete them when no longer needed.
9. Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Art. 15)
- have incorrect data corrected (Art. 16)
- have your data deleted (Art. 17)
- restrict processing (Art. 18)
- receive your data in a portable format (Art. 20)
- object to processing based on legitimate interest (Art. 21)
- withdraw consent at any time, with effect for the future (Art. 7(3))
To use these rights, email hello@muroagency.com. We answer within one month.
You also have the right to complain to a supervisory authority. In Austria this is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, dsb.gv.at. If you live in Germany or Switzerland, you can also contact the authority in your country.
10. Other information
This website is not directed at children under 14.
We update this policy when our website or the law changes. The current version is always available on this page.
Last updated: 3 October 2026