- Home
- Privacy policy
Privacy policy
AUTOMATA – Privacy Policy
Owner Jan-Michael Waiser, BFA, BBA · Last updated: 7 October 2026
This is a courtesy translation. The German version is legally binding.
This privacy policy explains, pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we process when you visit our website automata.at, contact us, buy from us or use one of our apps – for what purpose, on what legal basis, to whom it is disclosed and how long we keep it. Each app has its own part in section 9, which the apps link to directly (e.g. /en/privacy#klasso).
1. Controller
- AUTOMATA, owner Jan-Michael Waiser, BFA, BBA
- Address: Erdberger Lände, 1030 Wien, Austria
- Email: office@automata.at
- Phone: +43 676 531 7571
No data protection officer has been appointed. For all data protection questions you can reach us at the email address above.
2. Which services this policy covers – and our role
This policy applies to the website automata.at and to our products ADMISSIO, Offerta, TAXOS, Klasso, Bulli & Bär Desktop, Bulli & Bär, My Lucky Charm and Kernwert. Depending on the service, we act in different roles:
| Service | Our role |
|---|---|
| Website, contact, appointment booking, newsletter, chat assistant, purchases and subscriptions, licence checks | Controller |
| Your account in Offerta and TAXOS (registration, login, plan) | Controller |
| Bulli & Bär, My Lucky Charm (apps for iPhone and Android) | Controller for the app data; Apple and Google are themselves responsible for the store and payment |
| Bulli & Bär Desktop | Your data stays on your computer; we only process licence data |
| Data that businesses, schools or companies enter about other persons in Offerta, TAXOS, Klasso, Kernwert or in an ADMISSIO installation hosted by us | Processor – the respective customer (business, school, organiser) is responsible; please address questions to them first |
3. Visiting our website
Hosting and server logs
Our website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus; the subdomains of our apps admissio.automata.at, offerta.automata.at, taxos.automata.at and luckycharm.automata.at are also operated there. When you open a page, your browser technically transmits data to the server: IP address, date and time, requested address, referring page, browser and operating system (user agent), status code and amount of data transferred. The hosting provider processes this data in server logs in order to deliver the website and protect it against attacks; the retention period is determined by the hosting provider. We do not evaluate these logs for advertising purposes. The legal basis is our legitimate interest in secure and functioning operation (Art. 6(1)(f) GDPR). Hostinger acts as our processor.
Audience measurement without cookies
We count page views with our own solution on our server – without cookies, without storing anything on your device and without third parties. When a page is opened, a small script sends to our server: the page visited, the page title, the referring page, the window width (only to determine the device type) and, if present, a campaign identifier from the link. From this and from the IP address and browser identification, the server creates a shortened, encrypted checksum as a visitor identifier. The key for this is replaced daily and the old one deleted; your IP address is not stored and you are not recognised across several days.
We store: date, page, source (e.g. search engine, social media, AI assistant, direct), referring domain, device type (mobile, tablet, desktop), language version and the daily visitor identifier. While a page is visible, it sends a short signal every 30 seconds (at most 30 minutes per page) so that we can see how many people are currently online; these live entries are deleted after one hour. Recognisable bots, our own visits to the admin area and pages that should not appear in search engines (e.g. the checkout) are not counted. We keep the statistics for at most 26 months.
The legal basis is our legitimate interest in understanding the use of our website and improving it (Art. 6(1)(f) GDPR). You may object at any time (Art. 21 GDPR); technically, you can prevent counting by disabling JavaScript for our website or using a content blocker.
Cookies and browser storage
- Our website does not set any cookies for visitors.
- In the password-protected admin area we use a technically necessary session cookie (the "automata" login). It is only set after logging in and becomes invalid when the browser is closed or after eight hours of inactivity.
- If you use the chat assistant, the conversation and a random chat ID are kept in your browser's session storage (sessionStorage) so that the conversation is preserved when you change pages. It is deleted when you close the tab. This is strictly necessary for the service you requested (§ 165(3) TKG 2021).
- On the pages of the Stripe checkout, Stripe sets its own cookies, among other things to prevent fraud (see section 7).
- Our online apps (e.g. Offerta, TAXOS, Klasso) use technically necessary login cookies after you log in (see section 9).
Fonts, images and links
Fonts and images are loaded exclusively from our own server; there is no connection to Google Fonts or other content delivery networks. Links to social networks (e.g. Facebook, Instagram, LinkedIn), to Google Maps, our Google Business Profile or WhatsApp are simple links: data is only transmitted to the respective provider when you click the link; their privacy policy then applies.
Error reports and abuse protection
If an error occurs in one of our scripts in your browser, we receive the error message, the affected file and line and the path of the page (at most three reports per page) – without IP address or other information about you. Our server error log contains no passwords or form contents; email addresses are shortened in it. To protect forms, chat and checkout from abuse, we store with requests a pseudonymous value derived from your IP address using a key that changes monthly, together with the time; these entries are deleted after 24 hours. The legal basis is Art. 6(1)(f) GDPR (security and stability).
4. Contact, project enquiries, partner programme and appointment booking
If you contact us via the contact form, the project configurator ("start a project"), the partner programme form, online appointment booking, by email or by phone, we process your details: name, email address, where applicable phone number, company and website, your message, the options you selected (e.g. topic, service, type of project, starting point, company size, timeframe, budget range, preferred contact method), the language and, for appointment bookings, date, time and type of appointment (video, phone or on site).
We use the details to handle your enquiry, make you an offer or hold the appointment. For this purpose we create a customer record with your contact details and the history of your enquiries and messages. You receive an automatic confirmation of receipt by email; we receive a notification. The legal basis is the performance of pre-contractual measures or a contract (Art. 6(1)(b) GDPR) and our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
Partner programme: If you recommend a company to us, we additionally process the name of the recommended company and the contact person or their contact details you provide, in order to contact them and to settle your commission (Art. 6(1)(b) and (f) GDPR). Please only pass on third parties' contact details if you are entitled to do so. When we first contact the recommended person, we inform them of where their data came from.
Spam protection: Forms contain a hidden field and a timing check; the number of requests is limited as described in section 3.
Retention: We keep enquiries as long as they are needed for processing and possible follow-up questions. If a contract is concluded, the statutory retention periods apply (generally seven years, § 132 BAO, § 212 UGB). On request we delete your data earlier unless there is a retention obligation.
5. Newsletter
Subscription: For the newsletter we store your email address, language and – if provided – name and company. Subscription uses a double opt-in: you only receive our newsletter after clicking the confirmation link, followed by a short welcome email. We store the time of subscription and confirmation and a note on your consent. If you have given us your consent in another way (e.g. in person), we add you with a corresponding note. To select suitable content, we classify recipients as "business" or "private" – based on a company name provided or the type of email address (e.g. an address with a general email provider).
Content and legal basis: The newsletter informs you about our services, products, projects and guide articles. The legal basis is your consent (Art. 6(1)(a) GDPR, § 174 TKG 2021). Newsletter texts may be written with AI assistance; no recipient data is transmitted to the AI provider in the process.
Open and click measurement: Each issue contains a personal, invisible image (1 × 1 pixel) and links that redirect via our server. This allows us to record for each recipient whether and when an issue was opened (number of opens) and which links were clicked (time and target). We use this to see which content is of interest and to improve the newsletter (Art. 6(1)(f) GDPR). If you do not want this, you can object, switch off the loading of images in your email program (then no open is counted) or unsubscribe from the newsletter.
Sending and unsubscribing: The newsletter is sent in batches via our email service (section 11). Each issue contains an unsubscribe link; many email programs additionally offer one-click unsubscription. You can withdraw your consent at any time with effect for the future.
Retention: We store your data as long as you receive the newsletter. After you unsubscribe, we only keep your email address and the time of unsubscription in a suppression list so that we do not contact you again (Art. 6(1)(c) and (f), Art. 17(3) GDPR). Sending, open and click data is deleted together with the respective issue; on request we delete it earlier. Before major changes to the recipient list we create a backup copy in a protected area (the ten most recent are kept).
6. AI chat assistant
A chat assistant may be offered on our website. If you use it, we transmit your messages (up to the last twelve messages of the conversation) together with our instructions for the assistant to Anthropic PBC, 548 Market Street, San Francisco, CA 94104, USA, to generate an answer. Anthropic processes this data for us via its application programming interface; under its commercial terms it is not used to train AI models.
On our server we store each message and each answer with a random chat ID and a pseudonymous value derived from your IP address using a key that changes monthly, for quality assurance and abuse prevention, for at most 90 days. The number of messages per hour and day is limited.
The legal basis is our legitimate interest in answering questions about our services quickly (Art. 6(1)(f) GDPR), and for specific enquiries also Art. 6(1)(b) GDPR. For the transfer to the USA see section 12. Please do not enter sensitive data in the chat. The answers are generated by an AI and may contain mistakes.
7. Purchases, subscriptions and payments
Ordering via automata.at/kaufen
When you buy a plan, we process: product and plan, name and/or company, email address, for ADMISSIO the domain of the installation, a redeemed voucher and – if you come from an app – the ID of your account in that app and the return address. In the Stripe checkout you also enter your billing address, your VAT ID if applicable and your payment details; we never receive card details.
We store the subscription data (product, plan, name, company, email address, domain, account ID, Stripe customer and subscription IDs, status, amount, billing interval, end of term, cancellation, voucher and discount), payment events (type, amount, time) and the associated licence. We use the data to perform the contract, issue licences and send them by email, unlock plans in the app, issue invoices and keep our accounts; we are notified by email of new subscriptions, cancellations and failed payments. The legal basis is Art. 6(1)(b) GDPR, for retention Art. 6(1)(c) GDPR (§ 132 BAO, § 212 UGB: seven years) and for protection against abuse Art. 6(1)(f) GDPR.
Stripe
Our payment service provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. The payment page, invoices by email and the customer portal are provided by Stripe. Stripe processes your data to handle payments and partly as an independent controller, for example to prevent fraud and to comply with legal obligations. Data may be transferred to Stripe, Inc. in the USA in the process (section 12). More information: Stripe privacy policy.
Managing your subscription
The "manage subscription" link (for installed products in your order email, for online apps in the respective app) opens Stripe's customer portal. The link contains a secret, signed identifier. In the portal you can change your payment method, billing address and VAT ID, download invoices and – unless a minimum term is running – cancel.
Synchronisation with the apps
Our online apps (currently Offerta and TAXOS, in future also Klasso) ask our server, using an app key and the account ID, whether and which plan has been booked. Only plan, status, end of term, cancellation status and the links for booking or managing are transmitted – no payment data.
Vouchers
When a voucher is redeemed, we store the code together with the subscription and the email address in order to count redemptions. Incorrect codes are limited per pseudonymous IP value.
8. Licence checks, activation and updates
Installed software (e.g. ADMISSIO)
When installed software activates or checks its licence, looks for updates or downloads an update, it transmits to our server: serial number, product, domain, software version, an installation ID and – for technical reasons – the server's IP address. With the licence we store customer name, email address, domain, activation time, last check, last IP address and last version, as well as an event log (action, domain, IP address, version, result). The event log is deleted after 180 days.
Licence keys for Bulli & Bär Desktop
On activation and automatic renewal, the software sends the licence key, a device ID (a 16-character code derived from characteristics of your computer that contains neither your name nor your files) and the version. We bind the licence to this device ID and store the last check, IP address and version as well as an event log (180 days). In the last 30 days before expiry, the software asks for a renewal at most every twelve hours. Without an internet connection the software can be activated offline.
The purpose is to protect our licences, prevent abuse and deliver signed updates; the legal basis is Art. 6(1)(b) and (f) GDPR.
9. Our apps in detail
ADMISSIO
ADMISSIO is an application platform for exhibitors (e.g. for markets) and job applicants. The respective operator of the installation (e.g. organiser or employer) is the controller for applicants' data and provides information in its own privacy policy. Typical data includes contact and company details, bank details (for exhibitor applications), uploaded documents and photos, signature, application details, status, messages, chosen appointments and login data for the applicant portal. The installation sends emails via the operator's mailbox. If we host an installation (e.g. at admissio.automata.at with Hostinger) or support it with access, we process this data as the operator's processor (terms, Part E). From every installation we receive the licence data described in section 8.
Offerta
Offerta turns customer enquiries into finished quotes and runs at offerta.automata.at (hosted by Hostinger). An earlier Windows edition is no longer offered.
Your account (we are the controller): name, email address, password (stored only as a secure hash), company details for quotes and invoices (e.g. company name, address, logo, contact details, VAT ID, bank details), plan and billing status, consent to terms and privacy policy with timestamp, technically necessary login cookie. To protect against attacks, we briefly count failed logins per IP address and email address. Legal basis: Art. 6(1)(b) and (f) GDPR.
Content (we are the business's processor): customer enquiries, data of the business's customers (e.g. name, contact, address), quotes, service catalogue and prices, invoices and emails. Recipients of a quote open it via a personal link and can accept or decline it; the time and decision are stored.
AI: If the business stores its own account with an AI provider, the text of the enquiry and the details needed for the quote are transmitted to the chosen provider – Anthropic PBC, OpenAI, L.L.C. or X.AI LLC (all USA). The business concludes the contract with the provider itself. We store access keys encrypted (AES-256-GCM) and never display them in full again.
Windows editions already set up: The data is additionally stored on the business's PC and synchronised with the server.
Retention: As long as the account exists; daily backups are overwritten in the regular cycle. On request we delete the account.
TAXOS
TAXOS is an online app for bookkeeping and tax estimates at taxos.automata.at (hosted by Hostinger).
Your account (we are the controller): name, email address, password (stored only as a hash), confirmation of the email address, language and settings, plan and trial period, the ID used to match your subscription with automata.at, invited team members with their roles and access for your tax adviser, consent to terms and privacy policy. TAXOS uses a technically necessary login cookie. Legal basis: Art. 6(1)(b) and (f) GDPR.
Your accounting data: company details (country, legal form, VAT status, VAT ID), receipts (photos, PDF, e-invoices) and the details read from them (amount, date, business partner, tax), classifications, your invoices and customers, imported bank statements and transactions, deadlines and estimates. Where these contain data of other persons (e.g. your customers), we process it for businesses as a processor (terms, Part E).
Text recognition and AI: Photos of receipts are first read directly in your browser (text recognition on your device, without transmission). If AI recognition is switched on in TAXOS, the receipt is transmitted to our AI provider Anthropic PBC (USA) for recognition and a category suggestion; the tax classification itself is made by the TAXOS rule set.
Export and deletion: You can export your data as a ZIP file and delete your account in the app. Deleted receipts first go to the recycle bin because retention obligations apply to accounting records, which are your own obligations. After the account is deleted, the data is removed; backups are overwritten in the regular cycle.
Klasso
Klasso connects schools, kindergartens and after-school care with parents and pupils – in the browser at klasso.automata.at and as an app for iPhone and Android. The respective institution is the controller; we process the data on its behalf (terms, Part E). Please address requests concerning your data to the institution; we support it in this.
Data: names, roles, class or group, email address (for adults), password (stored only as a hash), chosen language; messages, parent letters, signatures and consents, sick notes and absence notices (the reason is visible only to the class teacher; health information is specially protected data under Art. 9 GDPR), timetable and changes, homework, stars and badges, test dates, childcare times and pick-up (authorised persons with phone number, visible only to those responsible), stored translations, device identifiers for notifications and a log of administrative actions. Pupils receive access via a code from their parents, without email address and password, and cannot write messages to others.
AI features: For the automatic translation of messages, letters and notices into each person's language, for "translate photo" and for reading in a timetable from a photo, the texts or photos are transmitted via our server to Anthropic PBC (USA). Photos are not stored; translations are cached per institution or account for up to 90 days.
Notifications: For notifications in the apps we use the Apple Push Notification service and Google's Firebase Cloud Messaging. No content of messages or sick notes is transmitted to Apple or Google, only a notice of a new message. In the apps, the camera and photos are only used when you take or select a photo.
Retention: Sick notes are deleted after one year, the administrative log after two years. Accounts can be deleted in the app (data is deleted or anonymised); if an institution deletes its school, all associated data is deleted.
Bulli & Bär Desktop
Bulli & Bär Desktop runs locally on your computer. Strategies, bots, trades, statistics, settings, client areas and your exchange access keys (encrypted with AES-256-GCM) remain on your computer; we have no access to them. The software connects directly from your computer to the exchanges (currently Kraken and Binance); they process your data as your contractual partners under their own privacy policies. Additional features that you set up yourself – such as notifications via Telegram, remote access in your network or via Tailscale, or webhooks – are used at your own responsibility with the respective providers. We only receive the licence data described in section 8 and, if you contact us, your message and any diagnostic report you send along (keys and passwords are automatically redacted in it).
Bulli & Bär
The Bulli & Bär app for iPhone and Android does not require an account. Watchlist, settings, Taler and progress are stored on your device. The app loads price data directly from public sources (e.g. Binance for crypto assets); the respective provider technically receives your IP address in the process. You only receive notifications if you allow them. Purchases and subscriptions are handled via Apple or Google and RevenueCat (section 10).
My Lucky Charm
On your device: Profile details (e.g. first name, nickname, birthday, greatest wish, name of the lucky charm), goals, to-dos, coins, progress and settings are stored on your device. You only receive reminders if you allow notifications.
Leaderboard (optional): If you take part in the leaderboard, we create an anonymous account with our database service Supabase (Supabase, Inc.) and store your nickname and weekly scores (e.g. coins of the week, lucky days). Nicknames are checked for offensive terms and replaced if necessary; reports and blocks are stored. Retention: anonymous accounts are deleted after 60 days without activity, reports after twelve months or 90 days after resolution, blocks after twelve months. The legal basis is Art. 6(1)(b) GDPR (providing the feature you chose) and (f) (moderation).
Purchases: Premium and coin packages are handled via Apple or Google and RevenueCat (section 10). How to delete your data is described on luckycharm.automata.at in the section "How do I delete my data?".
Kernwert
Kernwert is an app for food-safety self-checks in restaurants and food retail and is in preparation. The respective business is the controller for the data; we process it on its behalf (terms, Part E). We process the business's account (name, email address, company details), the names of team members who join via a team QR code, and the entries with time, measured value, person and, where applicable, the documented corrective action. We will add further details (in particular hosting and notifications) before publication.
10. App stores, in-app purchases and RevenueCat
You download our apps for iPhone and Android via the App Store (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) or Google Play (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Apple and Google process data about your account, downloads and payments as independent controllers. We only receive the analyses they provide to developers.
We manage purchases and subscriptions in Bulli & Bär and My Lucky Charm with RevenueCat, Inc. (USA). RevenueCat receives a random app user ID, purchase and transaction data from the store (product, time, price, currency, country) and technical details such as platform, app version and IP address, in order to verify purchases and unlock premium features (Art. 6(1)(b) GDPR). In the admin area of our website we only retrieve aggregated figures from RevenueCat (e.g. revenue, active subscriptions), no data about individual persons.
11. Recipients and processors
We only pass on personal data to the extent necessary for the purposes stated:
| Recipient | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Hosting of website and app servers, backups | Cyprus (EU) |
| Titan Mail (Titan Solution Ltd SEZC), obtained via our hosting provider | Email mailbox and email sending | Cayman Islands |
| Stripe Payments Europe, Limited | Payments, invoices, customer portal | Ireland (EU), partly USA |
| Anthropic PBC | Chat assistant; AI features in Klasso and TAXOS | USA |
| RevenueCat, Inc. | Management of in-app purchases | USA |
| Supabase, Inc. | Leaderboard in My Lucky Charm | USA |
| Apple, Google | App stores, notifications (APNs, FCM) | Ireland (EU), USA |
We also use services to which no visitor data is passed: Google Search Console and PageSpeed Insights (only addresses and content of our pages), IndexNow (reporting new page addresses to search engines), Anthropic for drafting guide and newsletter texts, and screenshot services for reference websites. In addition, we transmit data to tax advisers, banks, courts and authorities where we are obliged or entitled to do so.
12. Transfers to countries outside the EU
Some recipients are located in the USA or process data there. If a recipient is certified under the EU-US Data Privacy Framework, the transfer is based on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR); otherwise on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). There is no adequacy decision for the Cayman Islands; the transfer to our email service is based on the safeguards agreed by the provider under Art. 46 GDPR. You can obtain a copy of the respective safeguards on request.
13. Retention at a glance
| Data | Retention |
|---|---|
| Audience measurement | at most 26 months; live view 1 hour; daily key 1 day |
| Abuse protection (pseudonymous IP value) | 24 hours |
| Chat histories | at most 90 days |
| Enquiries and customer record | until completed or as long as needed for follow-up; if a contract is concluded, 7 years |
| Newsletter | until you unsubscribe; afterwards only the suppression-list entry |
| Subscription, payment and invoice data | 7 years (§ 132 BAO, § 212 UGB) |
| Licences | for the duration of the licence and retention obligations; event log 180 days |
| Accounts in our apps | until the account is deleted (details in section 9) |
14. Data security
All connections to our website and our online apps are encrypted (HTTPS). A strict security policy (Content Security Policy) only allows content from our own server. We store passwords only as a secure hash and access keys in encrypted form. The admin area is password-protected and locks after repeated failed attempts. Updates of our software are digitally signed. Data directories are protected against access from the internet.
15. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)). To do so, contact office@automata.at. For services in which we act as processor (section 2), please contact the respective controller; we forward requests that reach us.
You can lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
Providing your data is necessary to conclude a contract or use the respective feature; without it we cannot provide the service. There is no automated decision-making within the meaning of Art. 22 GDPR; we do not create profiles for advertising purposes.
16. Changes
We adapt this privacy policy when our services or the legal situation change. The version published here applies.