Skip to content

Legal — imprint and privacy policy

GDPR

Privacy policy

This website processes as little personal data as technically possible. There is no analytics, there are no advertising networks and no social media embeds. Typefaces, scripts, images and videos come exclusively from our own server; your browser loads nothing from third-party providers. The request itself, however, passes through our security and DNS provider Cloudflare — see the separate section below. Whatever you send through a form is stored encrypted in our database.

Last updated: 04.09.2026

Controller and principle

The controller within the meaning of the General Data Protection Regulation is Lantia Solutions GmbH, Dornhof 5, 9300 Frauenstein, reachable at office@lantia.at.

We only collect data where it is needed to operate the website or to answer an enquiry. Whatever is not needed is not stored.

This policy covers the lantia.at website including its English version under /en. Data we process within a project or a contract is governed by the agreements made there.

Hosting and logs

Server access log

This website runs on servers operated by our hosting provider. When you open a page, your browser transmits technical data that the server records in an access log: IP address, date and time, the resource requested, the response status, the amount of data transferred, the referrer and the browser identifier. These logs are not combined with any other data and are not analysed in order to recognise you.

The legal basis is our legitimate interest in secure and stable operation and in defending against attacks, Art. 6(1)(f) GDPR. The logs are deleted after 30. Hosting provider: Hosttech GmbH — a processor pursuant to Art. 28 GDPR with whom a data processing agreement is in place. Server location: Schweiz.

Application log

The application also keeps a log of its own for errors and security-relevant events — a rejected form submission, for instance, or a failed sign-in to the editorial area. It records the time, the event and the path requested, and for a failed sign-in also the email address entered. It holds no IP addresses. The legal basis is Art. 6(1)(f) GDPR; entries are deleted after 30.

Contact and applications

Contact form and email

Through the contact form we process your name, your email address and your message in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR where a contract is being prepared or performed, and otherwise our legitimate interest in answering enquiries, Art. 6(1)(f) GDPR. Providing the data is voluntary; without a name, an email address and a message we cannot reply. You are welcome to write to us directly at office@lantia.at instead.

How a submission is stored

Every submission is filed twice: in our database on the same server, and as an email notification to an internal Lantia mailbox. In the database, name, email address and message are stored encrypted; only the subject, any link you supplied, the time of receipt and the processing status are in plain text. In addition your IP address is stored as a pseudonym (HMAC-SHA256 with a secret key, never as plain text) so that we can detect abuse of the form; the legal basis for this is Art. 6(1)(f) GDPR. Enquiries and applications go into the same inbox.

We use no third-party CAPTCHA — that would be an additional third-party connection, and we avoid every one of those when a page is built. The protection runs entirely on our own server, in four stages. First, every form contains a field that is invisible to you and that only a script would fill in. Second, it carries a signed timestamp with which we check that a plausible amount of time passed between opening the page and sending; the same timestamp also protects the form against being submitted from someone else's site. Third, your browser solves a small computational task that you will barely notice but that makes bulk submission appreciably expensive; if you cannot or do not wish to run JavaScript, a simple text question takes its place, which you answer yourself. Neither the computational task nor the text question sets a cookie, and neither evaluates your behaviour. Fourth, a rate limit caps the number of submissions per sender; it stores your IP address only as a pseudonym (HMAC-SHA256 with a secret key) and deletes that entry after seven days. The legal basis is Art. 6(1)(f) GDPR — our interest in keeping the forms usable.

We delete a submission as soon as it has been dealt with. Independently of that, the application automatically deletes every submission from the database 90 days after it arrives — really deleted, not merely flagged. What remains in the log is an entry without personal data: number, action and time. The deletion run is scheduled; up to a day may pass between the deadline expiring and an entry disappearing. The email notification in the mailbox is not covered by that run; it is deleted there after 30. Where a statutory retention obligation applies — under company or tax law, for example — we hold the documents concerned until that period expires and process them for no other purpose.

Applications

For an application we process your name, your email address, your message, the position you are referring to and — if you supply one — the link to a portfolio, GitHub account or repository. The legal basis is Art. 6(1)(b) GDPR: the processing is necessary in order to carry out the application procedure and thereby to prepare an employment relationship. We do not ask for a photograph, a covering letter or any information about health, origin, religion or trade union membership; please do not send us such information unasked. When you submit the form you confirm with a checkbox that your details may be stored in order to process the application; we record the time of that confirmation.

Applications sit in the same encrypted inbox as enquiries and are visible only to the people involved in the procedure. No file can be uploaded through the form. A link you supply leads to a site we do not operate — what data is collected there is determined by its operator.

Applications, too, are automatically deleted by the application 90 days after arrival. We keep documents longer only where we need them to defend against claims — for example a claim under the Gleichbehandlungsgesetz, the Austrian Equal Treatment Act. In that case we restrict the processing to that purpose, for no longer than 30; the legal basis is Art. 6(1)(f) GDPR. Being added to a talent pool would require your express consent (Art. 6(1)(a) GDPR); we do not currently ask for it and we keep no such pool. Consent once given can be withdrawn at any time.

Cookies and local storage

This website sets no cookies for analytics, advertising or recognition purposes, and embeds no service that would. There is therefore nothing here for which we would need your consent, and nothing for you to click away. Exactly two entries are stored: one session cookie and one value in your browser’s local storage. Both are described here in full.

Session cookie

A single cookie is used: the PHP session identifier, named lantia_sid. It is set as soon as you open a page carrying a form — the home page and the careers page — and in the editorial area once someone has signed in; it is not created on the imprint or on this privacy notice. It holds a random identifier only, no information about you; the content behind it stays on our server. Purpose: it carries the protection against forms being submitted from elsewhere, holds the values you have already entered and the message you see after submitting, and in the editorial area the sign-in state. The cookie is limited to our domain, cannot be read by scripts (HttpOnly), is transmitted over HTTPS only and is not sent along to other sites (SameSite=Lax). Retention: the session — it expires when you close your browser and has no expiry date beyond that. Legal bases: § 165(3) TKG 2021, because it is strictly necessary for the service you requested and therefore needs no consent, and Art. 6(1)(f) GDPR for the processing behind it — our legitimate interest in keeping the forms safely usable (Art. 32 GDPR).

Local storage

We place a single value in your browser’s local storage: the key lantia-theme holds your choice of appearance — automatic, light or dark. It is written only if you actually use the switch in the header; if you merely open the page, local storage stays empty. Its sole purpose is that setting you chose yourself. The value stays on your device and is not transmitted to us. Retention: until you clear your browser’s site data — local storage has no expiry date. Legal bases: § 165(3) TKG 2021, because the access serves a service you expressly asked for, and Art. 6(1)(f) GDPR. The language is part of the page address and needs no storage at all.

Any further cookies or storage access on this website: Keine.

External content

This website runs behind Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Cloudflare operates our name resolution (DNS) and sits in front of the server as a security layer: it fends off denial-of-service attacks and in particular limits the number of sign-in attempts to the editorial area. Technically this means every request to this website reaches Cloudflare first and the encrypted connection terminates there. In doing so, Cloudflare processes your IP address, date and time, the address requested, the browser type and any details needed to repel attacks. Your browser still loads all content exclusively from our own server — Cloudflare serves no typefaces, scripts or videos. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protecting the website and the sign-in from automated attacks. A data processing agreement under Art. 28 GDPR is in place with Cloudflare, including the European Commission’s standard contractual clauses; processing in the United States cannot be ruled out. Cloudflare’s privacy policy is available at cloudflare.com/privacypolicy.

All scripts, typefaces and moving images are hosted on our own server. No libraries and no media files are loaded from third-party networks.

There are no embeds from map services, video platforms, social networks, font services or CAPTCHA providers. This site’s content security policy permits the browser to connect to our own domain only.

Recipients and third countries

Within the company, access is given only to the people who handle an enquiry or an application. They sign in to the editorial area with a personal account; every change to an enquiry is logged — without content, only number, action and time.

Outside the company three processors within the meaning of Art. 28 GDPR are involved: our hosting provider Hosttech GmbH, on whose servers the website, the database and the outgoing mail run, the provider of our mailbox Google, through which the notification is delivered and kept, and Cloudflare, Inc. as the DNS and security provider in front of the server (separate section below). A data processing agreement is in place with all three. There are no other recipients: no advertising networks, no analytics services, no payment providers, no applicant-tracking platform. We disclose data to authorities or courts only where we are obliged to.

The website, the database and the outgoing mail are located within the European Union; server location: Schweiz. A transfer to a country outside the European Union and the European Economic Area occurs solely through our use of Cloudflare: because the service operates data centres worldwide, processing of your connection data in the United States cannot be ruled out. This is safeguarded by a data processing agreement incorporating the European Commission’s standard contractual clauses. Beyond that, no data is transferred to any third country.

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Enquiries and applications are not assessed by machine and no profiles are built.

Security of processing

The connection to this website is encrypted with TLS, and the browser is instructed to establish it in encrypted form only. Database queries run exclusively through prepared statements, and every form that changes anything is protected against submission from other sites.

Name, email address and message are stored in the database encrypted with XChaCha20-Poly1305; every record gets its own random value, and any later tampering shows up when it is decrypted. This protects against a leaked database backup and against an attack that reaches the database only. It does not protect against anyone who can read files on the same server: the key sits on the same machine as the data. We say so explicitly, because we do not want to claim a level of security that does not exist here.

The editorial area can be reached only by signing in with an email address and a password and then entering a one-time code from an authenticator app on your own device; both are checked on the server before any page is delivered. Passwords are stored as hashes only, a rate limit caps sign-in attempts per origin, the account in question is locked temporarily after repeated failed attempts, and a session ends after 30 minutes without activity and after ten hours at the latest. There is no sign-in via third-party accounts such as Google; there is no other way into the editorial area.

Your rights

You have the right at any time to:

  1. Art 15 Access to information on what data we process about you.
  2. Art 16 Rectification of inaccurate data.
  3. Art 17 Erasure, where no retention obligation applies.
  4. Art 18 Restriction of processing.
  5. Art 20 Data portability in a common format.
  6. Art 21 Objection to processing based on legitimate interests.

You can withdraw consent at any time without affecting the lawfulness of the processing carried out up to that point. For any request, a message to office@lantia.at is enough. We reply within one month; should it take longer in an exceptional case, we will tell you so within that month.

You can also lodge a complaint with the supervisory authority, Art. 77 GDPR: Österreichische Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, dsb.gv.at.

Imprint