Privacy policy
Information about how personal data is processed and about your rights.
Last updated: July 2026
1. Controller
Division by Heroes e.U.DI Andreas Braumann
Liniengasse 48/22, 1060 Wien, Austria
Email: info@andreas-braumann.at
2. Hosting and server logs
When you access this website, the hosting provider processes technically necessary connection data, including the IP address, time, requested address, referrer, browser and device information, and status codes. This processing ensures secure and stable delivery and error analysis and is based on our legitimate interest under Article 6(1)(f) GDPR. Log data is retained only for as long as required for operation, security, and the prevention of misuse.
3. Contact enquiries
If you contact us by email or through a contact form, we process your contact details, company information, and message to handle and answer your enquiry. The legal basis is Article 6(1)(b) GDPR for pre-contractual steps and Article 6(1)(f) GDPR for other business communications. Data is deleted when it is no longer needed for the relevant purpose unless statutory retention duties or legitimate legal claims require continued storage.
4. AI opportunity quiz and double opt-in
When you use the AI opportunity quiz, we process your answers to create a personal, non-binding AI assessment. The answers are processed server-side through the configured AI service. If you request the assessment by email, we also temporarily store your email address, assessment, consent wording, and consent timestamp. Registration is handled through Brevo using double opt-in. Only after you click the confirmation link is your email added to the German or English quiz list and the assessment sent. The legal basis is your consent under Article 6(1)(a) GDPR. Unconfirmed records are intended to be retained for seven days and then marked for deletion. You may withdraw your consent for the future at any time through the unsubscribe link in emails or by contacting us.
5. Client portal
An authenticated client portal may be provided to authorised clients. Identity, contact, access, project, and usage data is processed to authenticate access and deliver agreed services. The legal basis is Article 6(1)(b) GDPR. Security and access logs may also be processed based on Article 6(1)(f) GDPR.
6. Google Calendar
Appointment booking is embedded as external Google content. A connection to Google is established only when you explicitly load the calendar or open the booking page. Your IP address, browser information, and details entered in the booking form may be transferred to Google, and cookies may be stored. Google is responsible for processing on its service under its privacy information. Use is voluntary; you can contact us by email instead.
7. Cookies and local storage
The website uses technically necessary storage for language selection, any login session, and consent status. These functions are required to provide the service expressly requested. Optional analytics or marketing services are activated only after prior consent under Article 6(1)(a) GDPR and section 165(3) of the Austrian Telecommunications Act 2021. Consent is voluntary and can be changed or withdrawn at any time for the future through “Cookie settings” in the footer.
| Storage item | Purpose | Duration |
|---|---|---|
| locale | Language preference | 1 year |
| ab-cookie-consent-v1 | Stores your consent choice locally | Until deleted in the browser |
| _fbp | Meta Pixel: browser and conversion attribution | Typically up to 90 days |
| _fbc | Meta Pixel: advertising click attribution | Typically up to 90 days |
| Login storage items | Authentication and security | Session-dependent |
8. Meta Pixel und Conversions API
After your explicit consent to marketing services, we use the Meta Pixel and Meta Conversions API provided by Meta Platforms Ireland Limited. Page views, interactions with appointment booking, contact and quiz conversions, the requested address, browser identifiers (_fbp and _fbc), IP address, and browser information may be processed. For qualified quiz conversions, the normalized email address may be transferred to Meta only as a SHA-256 hash. Browser and server events use a shared event ID so Meta can identify duplicate events. The legal basis is your consent under Article 6(1)(a) GDPR and section 165(3) of the Austrian Telecommunications Act 2021. Processing starts only after consent and can be withdrawn for the future at any time through cookie settings. Meta may also process data outside the EEA using the transfer mechanisms and safeguards it provides.
9. Recipients and service providers
Where required to operate the website or deliver services, carefully selected hosting, database, authentication, email, and IT providers may access data. Where applicable, they are contractually bound as processors. For transfers outside the EEA, appropriate safeguards under Chapter V GDPR are used unless an adequacy decision applies.
10. Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction of processing, data portability, and objection. You may withdraw consent at any time for the future. To exercise your rights, contact the email address above.
You may also lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna. www.dsb.gv.at
11. Automated decisions
No solely automated decision-making with legal or similarly significant effects takes place.
