Privacy policy
Version: July 2026 – hosting and SMTP providers will be added before publication
Scope
This privacy policy applies to the public OneTwoSync website and its form API. Privacy information for the iOS app will be provided separately before the app is released.
Controller
SAVVATA IT Services e.U.
Kohlagasse 43, 9020 Klagenfurt am Wörthersee, Austria
DI Alexander Steinwender, MBA
Alexander.Steinwender@savvata.com
www.savvata.com
Website access and hosting
Technically necessary connection data is processed when you access the website. This may include the IP address, date and time, requested address, amount of data transferred, referrer, browser, and operating system. Processing is necessary to provide the website securely and reliably and to defend against attacks. It is based on our legitimate interests under Article 6(1)(f) GDPR. The selected hosting provider and its log retention periods will be added before publication.
Language selection
Your selected language is stored only in your browser's local storage under the key ots_language. On your first visit, the browser language may be read to select the appropriate language version. This information is not transmitted to us and can be removed through your browser data settings.
Launch notification
If you ask to be notified when OneTwoSync is released, we process your email address, language, status, and the necessary creation, delivery, and confirmation timestamps. A securely generated confirmation token is stored only as a hash. We send a confirmation email after signup, and registration is completed only after you follow the confirmation link (double opt-in). The data is used solely for release notifications. The legal basis is your consent under Article 6(1)(a) GDPR. Providing the data is voluntary; without it, we cannot notify you. You may withdraw your consent at any time by email with effect for the future.
Contact form
When you use the contact form, we process your name, email address, subject, message, language, delivery status, and necessary timestamps. The request is stored in a MariaDB/MySQL database and forwarded through an authenticated SMTP service to a recipient address configured exclusively on the server. Processing is based on Article 6(1)(b) GDPR where the request relates to contractual or pre-contractual matters, and otherwise on our legitimate interest in communication under Article 6(1)(f) GDPR. Providing the data is voluntary but necessary for us to respond.
Abuse prevention
The forms are protected by a honeypot, a self-hosted ALTCHA CAPTCHA, and rate limiting. For rate limiting, the IP address is processed only temporarily and converted together with the relevant endpoint into a non-reversible HMAC key; only this key, a counter, and the time window are stored for no more than one hour. A hash of an already used CAPTCHA solution is stored for no more than 15 minutes to prevent reuse. Processing is based on our legitimate interest in website security and abuse prevention under Article 6(1)(f) GDPR.
Recipients and processors
Access is limited to authorised persons and to the hosting, database, and SMTP providers required to operate the service, and only to the extent necessary. Form data is not sold or used for advertising or profiling. The specific providers will be added after hosting has been selected and before publication.
International transfers
No transfer of personal form data outside the European Economic Area is currently intended. If a future service provider requires an international transfer, this policy will be updated before the service is put into operation to identify the recipient, legal basis, and appropriate safeguards.
Retention
The launch-notification confirmation link is valid for 48 hours; unconfirmed entries are deleted no later than seven days after expiry. Confirmed entries are retained until the release notification is sent or consent is withdrawn, unless statutory proof or retention obligations apply. Contact requests are deleted after they have been fully handled as soon as they are no longer needed for communication, legal claims, or statutory obligations. Expired rate-limit and CAPTCHA records are removed regularly.
Cookies, tracking, and automated decisions
The website uses no tracking, analytics, or advertising services and no cookies intended for such purposes. No profiling or solely automated decision-making producing legal or similarly significant effects takes place.
Your rights
Subject to the GDPR, you have rights including information, access, correction, deletion, restriction, portability, and objection. You may withdraw consent at any time with effect for the future. To exercise your rights, contact the email address stated above. You also have the right to complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, at dsb.gv.at.