PRIVACY POLICY
Information on data protection
Privacy statement
(Information pursuant to Art. 13 and Art. 14 GDPR)
1. Controller
The controller responsible for the processing of personal data in connection with the Cloudguardian Managed Service is:
beyond expectations GmbH
Modecenterstraße 22/D40
1030 Vienna, Austria
datenschutz@wolkenwaechter.at
External Data Protection Officer (DPO) pursuant to § 5 DSG
heyData GmbH
Schützenstr. 5
10117 Berlin, Germany
datenschutz@heydata.eu
2. Scope
This Privacy Policy informs you which personal data we collect, process and use in connection with the Cloudguardian Managed Service, as well as about your data protection claims and rights. It applies to:
- the contractual relationship in connection with the Cloudguardian monitoring and analysis service
- the related communication, e.g. reports, impact reviews, alerts
- onboarding and technical setup
- the use of the website at www.wolkenwaechter.at including the contact form and appointment booking
3. Data Subjects and Data Categories, Origin of the Data
We process the following categories of personal data from the following categories of data subjects:
3.1 Categories of data subjects
- Employees of the customer, such as users and administrators
- External partners of the customer, where created in the system
- Contact persons of the customer for contract processing
- Visitors to the website www.wolkenwaechter.at, when making contact or booking an appointment
3.2 Categories of personal data
- Technical identifiers, such as IP addresses, user IDs and hash values
- Log data, such as log files, audit logs and access times
- Contact data of administrators/users, such as name and email address, insofar as stored in the systems
- Configuration data, such as permissions and roles
- Contact data of website visitors, such as first name, last name and email address, insofar as provided in connection with an appointment booking or contact request
No special categories of personal data within the meaning of Art. 9 GDPR are processed.
3.3 Origin of the data
We process data that we receive from you:
- in connection with a contractual relationship
- when you contact us via the contact form
- when booking an appointment via our website using Google Calendar Appointment Scheduling
- when you visit our website
4. Purposes and Legal Bases of Processing, Storage Period
Personal data is processed for the following purposes and on the following legal bases:
4.1 Contractual relationship and performance of the monitoring and analysis service
Data processed:
Contact data of the customer, such as name, address and company, contact data of the contact person, such as name and email address, technical identifiers, such as IP addresses, user IDs and hash values, log data, such as log files, audit logs and access times, contact data of administrators/users, such as name and email address, insofar as stored in the systems, and configuration data, such as permissions and roles.
Purpose:
We process the stated data in order to provide the contractually agreed monitoring and analysis service for your cloud environments. This includes the automated review of technical functionality, security (governance) and cost efficiency (FinOps) based on the check catalogue, as well as the creation of reports, alerts and impact reviews.
Legal basis:
We process this data in order to take steps prior to entering into a contract or to perform our contractual obligations (Art. 6 para. 1 lit. b GDPR) in connection with the Cloudguardian service.
Storage period:
We store this data for the duration of the contract term.
4.2 Ensuring IT security and governance
Data processed:
Technical identifiers, such as IP addresses, user IDs and hash values, log data, such as log files, audit logs and access times, contact data of administrators/users, such as name and email address, insofar as stored in the systems, and configuration data, such as permissions and roles.
Purpose:
We process the stated data to ensure the IT security and governance of the monitored cloud environments and to provide a high-quality managed service that identifies security risks at an early stage. This processing is in our interest and in the interest of our customers and their employees, for the protection of the monitored systems.
Legal basis:
We process this data in order to take steps prior to entering into a contract or to perform our contractual obligations (Art. 6 para. 1 lit. b GDPR) in connection with the Cloudguardian service, as well as on the basis of our legitimate interests or the legitimate interests of third parties (Art. 6 para. 1 lit. f GDPR).
Storage period:
We store this data for the duration of the contract term.
4.3 Compliance with statutory retention obligations
Data processed:
Master personal data, contract data, communication data and other evidentiary data.
Purpose:
This data processing is necessary for the defence and assertion of legal claims and for compliance with legal obligations.
Legal basis:
We process this data to comply with a legal obligation to which we are subject (Art. 6 para. 1 lit. c GDPR).
Storage period:
Insofar as statutory retention obligations exist, e.g. tax-law and company-law obligations under the BAO and UGB, the data concerned is retained for the period prescribed by law and subsequently deleted.
4.4 Defence and assertion of legal claims
Data processed:
Master personal data, contract data, communication data and other evidentiary data.
Purpose:
This data processing is necessary for the defence and assertion of legal claims and for compliance with legal obligations.
Legal basis:
We process this data on the basis of our legitimate interests or the legitimate interests of third parties (Art. 6 para. 1 lit. f GDPR), namely for the defence and assertion of legal claims.
Storage period:
We store your data only for as long as is necessary for the stated purposes. Beyond that, we store your data only for as long as a legal obligation to do so exists or we have a corresponding overriding interest in its retention.
4.5 Visiting our website
Data processed:
Browser type, operating system, country, date, time and duration of access, IP address and pages visited on our website, including entry and exit pages.
Purpose:
This data processing is necessary to ensure the best possible user experience on our website and to guarantee the stability of the website. In particular, we use this data for the purpose of providing the following services: infrastructure and platform services, computing capacity, storage space and database services, security services as well as technical maintenance services that we use for the purpose of operating the website.
Legal basis:
We process this data on the basis of our legitimate interests or the legitimate interests of third parties (Art. 6 para. 1 lit. f GDPR), namely to be able to operate our website from a technical perspective.
Storage period:
Server log files are automatically deleted after 14 days.
Our website does not use cookies or tracking tools.
4.6 Customer service, contact form, chatbot, social media
Data processed:
Name, means of contact, such as email address and telephone number, postal address, order information, company and content of the request.
Purpose:
The processing of the data is necessary in order to respond to and handle your request.
Legal basis:
We process this data on the basis of our legitimate interest or the legitimate interests of third parties (Art. 6 para. 1 lit. f GDPR) in handling our customers' enquiries and requests appropriately.
Storage period:
We delete this data once the request has been dealt with and it is not expected to become relevant again in the future, but at the latest 6 months after the last contact regarding this request.
4.7 Appointment booking
Data processed:
First name, last name and email address.
Purpose:
Processing your appointment request, coordinating the desired meeting time, any preliminary queries, and conducting and following up on the meeting. When you click the booking link, you are redirected to the external service Google Calendar (Google Ireland Ltd.); from that point onwards, Google's privacy policy additionally applies:
Google Privacy Policy
The data transmitted in connection with the appointment booking, namely first name, last name and email address, is additionally stored by us in our own systems in order to carry out appointment coordination, the meeting and any preparation of an offer. If a specific interest in our services is expressed during the meeting, we also use your contact data to send you an individual offer or to make further contact.
Legal basis:
Taking steps prior to entering into a contract (Art. 6 para. 1 lit. b GDPR).
Storage period:
We delete this data once the request has been dealt with, but at the latest 6 months after the last contact.
5. Disclosure of Data to Third Parties
In order to achieve the intended purposes, it may occasionally be necessary to disclose personal data to the following recipients:
-
Google Cloud EMEA Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Location: EU, Ireland, Belgium, the Netherlands
Purpose: Cloud infrastructure and AI-supported data analysis (Google Vertex AI) for the provision of the monitoring and alerting service
Legal basis: Processing within the EEA -
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Location: EU, Ireland
Purpose: Appointment scheduling via Google Workspace (Google Calendar Appointment Scheduling)
Legal basis: Processing within the EEA -
Freshworks Inc., 2950 S. Delaware Street, Suite 201, San Mateo, California 94403, USA
Location: USA
Purpose: Ticket management and support
Legal basis: Adequacy decision pursuant to Art. 45 GDPR, otherwise appropriate safeguards pursuant to Art. 46 GDPR -
Legal representatives and tax advisors
Location: EU/EEA
Purpose: Advisory services
Legal basis: Processing within the EEA -
Courts and administrative authorities
Location: EU/EEA
Purpose: Defence and assertion of legal claims and compliance with legal obligations
Legal basis: Processing within the EEA
Any disclosure to third parties beyond this takes place only insofar as required by law.
6. Transfer to Third Countries
Data processing generally takes place within the EU/EEA. Insofar as a transfer to third countries is necessary, in particular the USA in connection with the use of Freshworks Inc., its permissibility is ensured by appropriate safeguards:
- Adequacy decision pursuant to Art. 45 GDPR, in particular the EU-US Data Privacy Framework for data transfers to the USA
- Appropriate safeguards pursuant to Art. 46 GDPR, in particular EU Standard Contractual Clauses pursuant to Art. 46 para. 2 lit. c GDPR, insofar as no adequacy decision exists
7. Rights of Data Subjects
Under the GDPR, data subjects have the following rights:
- Access to the personal data processed (Art. 15 GDPR)
- Rectification of inaccurate or incomplete data (Art. 16 GDPR)
- Erasure of the personal data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
Requests should be addressed to datenschutz@wolkenwaechter.at or by post to the address stated under points 1 and 12.
Note: As BE-X acts as a processor for the customer within the framework of a contractual relationship concerning the Cloudguardian service, the fulfilment of data subject rights in this context is incumbent on the customer as the controller. BE-X supports the customer in fulfilling these obligations in accordance with the provisions of the data processing agreement (DPA).
8. Right to Lodge a Complaint
In addition, you have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Vienna
dsb@dsb.gv.at
www.dsb.gv.at
9. Data Security
BE-X takes appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect personal data against accidental or unlawful destruction, alteration or loss and against unauthorised disclosure of, or unauthorised access to, such data.
10. Automated Decision-Making
We do not use automated decision-making as referred to in Art. 22 GDPR to reach decisions on the establishment and conduct of business relationships, or other decisions that would similarly significantly affect you.
11. Amendments to this Privacy Policy
We reserve the right to amend this Privacy Policy from time to time so that it always complies with current legal requirements or in order to implement changes to our services in the Privacy Policy. The new Privacy Policy will then apply to your next visit.
12. Contact
If you have any questions about this Privacy Policy or the processing of your personal data, please contact:
beyond expectations GmbH
Modecenterstraße 22/D40
1030 Vienna, Austria
datenschutz@wolkenwaechter.at
Last updated: 3 April 2026