secinto GmbH
Poststraße 3
8530 Deutschlandsberg
Austria
datenschutz@secinto.com
+43 660 7724524
We process personal data only to the extent necessary to provide our website, our content and our services, and only on the legal bases set out below.
Where we obtain the data subject’s consent for processing personal data, Art. 6(1)(a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis.
Where processing is necessary for the performance of a contract to which the data subject is party, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing necessary for steps taken prior to entering into a contract.
Where processing is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis.
Where processing is necessary for the purposes of the legitimate interests of our company or a third party, and these interests are not overridden by the interests, fundamental rights and freedoms of the data subject, Art. 6(1)(f) GDPR serves as the legal basis.
The data subject’s personal data is erased or blocked as soon as the purpose of storage no longer applies. Data may be stored beyond this if provided for by European or national legislation in EU regulations, laws or other provisions to which the controller is subject. For example, we keep invoices and accounting records for seven years in accordance with Section 132 of the Austrian Federal Fiscal Code (BAO). Data is also blocked or erased when a storage period prescribed by these provisions expires, unless further storage is necessary for concluding or performing a contract.
We process our customers’ data on servers in the European Union. We use the following service providers, all based in the EU:
We do not transfer customer or scan data to external AI services.
Our website processes the data assigned to your computer listed below. This is necessary to deliver the content you request from our website to your computer (e.g. texts, images and files provided for download). We also process this data to detect and pursue misuse. This website is hosted by Key-Systems GmbH (domaindiscount24), St. Ingbert, Germany; the server is located in Frankfurt am Main.
The legal basis for the temporary storage of data and log files is Art. 6(1)(f) GDPR.
Temporary storage of the IP address by the system is necessary to deliver the website to the user’s computer. For this purpose, the user’s IP address must remain stored for the duration of the session.
Data is stored in log files to ensure the functionality of the website. We also use the data to optimise the website and to ensure the security of our IT systems. The data is not evaluated for marketing purposes in this context. These purposes also constitute our legitimate interest in data processing under Art. 6(1)(f) GDPR.
Data is erased as soon as it is no longer required to achieve the purpose for which it was collected. For data collected to provide the website, this is the case when the respective session has ended.
For data stored in log files, this is the case after seven days at the latest. Longer storage is possible. In this case, the users’ IP addresses are deleted or altered so that the accessing client can no longer be identified.
The collection of data to provide the website and the storage of data in log files is essential for operating the website. Consequently, the user has no right to object.
Our website uses cookies. Cookies are text files stored in or by the internet browser on the user’s computer system. When a user visits a website, a cookie may be stored on the user’s operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is accessed again.
We use technically necessary cookies to make our website more user-friendly. Some elements of our website require the accessing browser to be identified even after a page change. In addition, and only with your consent, we use cookies that enable an analysis of browsing behaviour.
To manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and the related consents, we use the consent tool “Complianz”. Details on how “Complianz” works can be found at this link. The legal bases for processing personal data in this context are Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the related consents. Providing the personal data is neither required by contract nor necessary for concluding a contract. If you do not provide the data, we cannot manage your consents.
The legal basis for technically necessary cookies is Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) in conjunction with Art. 6(1)(f) GDPR.
The legal basis for cookies used for analysis purposes is your consent under Section 165(3) TKG 2021 and Art. 6(1)(a) GDPR.
Technically necessary cookies are used to make the website easier to use. Some functions of our website cannot be offered without cookies. User data collected through technically necessary cookies is not used to create user profiles.
Analysis cookies are used to improve the quality of our website and its content. They tell us how the website is used, so we can continuously improve our offering.
Cookies are stored on the user’s computer and transmitted from it to our website. As a user, you therefore have full control over the use of cookies. You can withdraw your consent at any time via the cookie settings on our website. By changing the settings in your internet browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. If cookies are deactivated for our website, it may no longer be possible to use all functions of the website to their full extent.
If you have given your consent, this website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics uses cookies that enable an analysis of your use of the website. The information generated about your use of this website may be transferred to and stored on servers of Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision.
The legal basis for processing is your consent under Art. 6(1)(a) GDPR and Section 165(3) TKG 2021.
Google uses this information on our behalf to evaluate your use of the website and to compile reports on website activity. This helps us to continuously improve our website and its usability.
Sessions and campaigns end after a certain period of time. By default, sessions end after 30 minutes of inactivity and campaigns after six months. Further information on terms of use and data protection can be found at https://marketingplatform.google.com/about/analytics/terms/us/ and https://policies.google.com/?hl=en.
You can withdraw your consent at any time via the cookie settings on our website. This does not affect the lawfulness of processing carried out before the withdrawal.
When you request a free Security-Check, we process the contact details entered in the form and the domain to be checked in order to carry out the analysis and send you the result. The legal basis is Art. 6(1)(b) GDPR.
We may also use these contact details to send you information on cybersecurity topics, product updates and offers from CheckFix. We use Brevo (Sendinblue SAS, Paris, France) to send these emails. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is informing you about our services. You can object at any time by clicking the unsubscribe link in every email.
Providing your phone number is optional. If you provide it, we will call you to discuss your Security-Check result. The legal basis is your consent under Art. 6(1)(a) GDPR and Section 174 TKG 2021. You can withdraw your consent at any time, e.g. by email to datenschutz@secinto.com.
To protect the form against automated requests (spam), we use Google reCAPTCHA, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA checks whether an entry was made by a human. For this purpose, your IP address, browser and device information, your behaviour on the page and cookies, among other things, are evaluated and transmitted to Google. Data may be transferred to servers of Google LLC in the USA; Google LLC is certified under the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protecting our form against misuse. Further information is available at https://policies.google.com/privacy?hl=en.
Registration in the CheckFix portal is only possible with a company email address, which must be confirmed before first use. Login works without a password via a link that we send to this address. The link can only be used once and expires after 15 minutes. We process your email address, your account data and your company’s data for this purpose. The legal basis is Art. 6(1)(b) GDPR.
Emails required for using the portal (e.g. login links and notifications) are sent via our own mail server.
CheckFix analyses the domains you specify and the publicly accessible systems associated with them (e.g. subdomains, IP addresses, services and certificates). Only what is visible and reachable from the outside is analysed. The analyses run through the network service of CyberGhost S.R.L., Bucharest, Romania. We store the results on servers of Hetzner Online GmbH in Germany and Finland. The legal basis is Art. 6(1)(b) GDPR.
The AI Pentest runs on secinto GmbH’s own hardware in Austria. The system is continuously monitored by secinto GmbH pentesters. We do not pass data from the AI Pentest to external AI services or other third parties. The legal basis is Art. 6(1)(b) GDPR.
In CheckFix Risk Manager, we process the company data and contact details of the suppliers and partners specified by our customers in order to assess their external security posture and send them compliance questionnaires. The legal basis is Art. 6(1)(b) GDPR towards our customers and Art. 6(1)(f) GDPR towards the suppliers and partners; the legitimate interest lies in assessing our customers’ supply chain.
Payments for our paid services are processed via Stripe Payments Europe, Limited, Dublin, Ireland. The data required for payment (e.g. name, billing address and payment details) is transmitted to Stripe. The legal basis is Art. 6(1)(b) GDPR. Information on data protection at Stripe can be found at https://stripe.com/privacy.
We store data from the use of CheckFix for as long as it is required to perform the contract. After that, it is erased unless statutory retention obligations apply (see 1.4).
The privacy policy applicable to our regular business transactions can be downloaded via the following link.
Privacy policy for business transactions
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
You can request confirmation from the controller as to whether we process personal data concerning you.
If such processing takes place, you can request information from the controller about the following:
(1) the purposes for which the personal data is processed;
(2) the categories of personal data being processed;
(3) the recipients or categories of recipients to whom the personal data concerning you has been or will be disclosed;
(4) the planned storage period of the personal data concerning you or, if specific information on this is not possible, the criteria for determining the storage period;
(5) the existence of a right to rectification or erasure of the personal data concerning you, a right to restriction of processing by the controller or a right to object to such processing;
(6) the existence of a right to lodge a complaint with a supervisory authority;
(7) all available information about the source of the data if the personal data was not collected from the data subject;
(8) the existence of automated decision-making, including profiling, in accordance with Art. 22(1) and (4) GDPR and, at least in these cases, meaningful information about the logic involved and the scope and intended effects of such processing for the data subject.
You have the right to request information as to whether the personal data concerning you is transferred to a third country or to an international organisation. In this context, you can request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
You have a right to rectification and/or completion vis-à-vis the controller if the processed personal data concerning you is inaccurate or incomplete. The controller must carry out the rectification without undue delay.
You can request the restriction of processing of the personal data concerning you under the following conditions:
(1) if you contest the accuracy of the personal data concerning you for a period enabling the controller to verify the accuracy of the personal data;
(2) if the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
(3) if the controller no longer needs the personal data for the purposes of processing, but you require it for the establishment, exercise or defence of legal claims; or
(4) if you have objected to processing pursuant to Art. 21(1) GDPR and it has not yet been determined whether the legitimate grounds of the controller override your grounds.
Where processing of the personal data concerning you has been restricted, such data may, with the exception of storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
If processing has been restricted under the above conditions, you will be informed by the controller before the restriction is lifted.
a) Obligation to erase
You can request the controller to erase the personal data concerning you without undue delay, and the controller is obliged to erase this data without undue delay if one of the following grounds applies:
(1) The personal data concerning you is no longer necessary for the purposes for which it was collected or otherwise processed.
(2) You withdraw your consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR, and there is no other legal ground for the processing.
(3) You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21(2) GDPR.
(4) The personal data concerning you has been processed unlawfully.
(5) The erasure of the personal data concerning you is required to comply with a legal obligation under Union or Member State law to which the controller is subject.
(6) The personal data concerning you was collected in relation to information society services offered pursuant to Art. 8(1) GDPR.
b) Information to third parties
If the controller has made the personal data concerning you public and is obliged to erase it pursuant to Art. 17(1) GDPR, it shall take reasonable steps, including technical measures, taking into account the available technology and the cost of implementation, to inform controllers processing the personal data that you as the data subject have requested the erasure of all links to, or copies or replications of, this personal data.
c) Exceptions
The right to erasure does not apply to the extent that processing is necessary
(1) for exercising the right of freedom of expression and information;
(2) for compliance with a legal obligation which requires processing under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(3) for reasons of public interest in the area of public health in accordance with Art. 9(2)(h) and (i) and Art. 9(3) GDPR;
(4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Art. 89(1) GDPR, insofar as the right referred to in section a) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
(5) for the establishment, exercise or defence of legal claims.
If you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to notify all recipients to whom the personal data concerning you has been disclosed of this rectification, erasure or restriction of processing, unless this proves impossible or involves disproportionate effort. You have the right to be informed about these recipients.
You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to which the personal data was provided, where
(1) the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR, and
(2) the processing is carried out by automated means.
In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another, where technically feasible. This must not adversely affect the rights and freedoms of others.
The right to data portability does not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR.
The controller will then no longer process the personal data concerning you unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
If the personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing. If you object to processing for direct marketing purposes, the personal data concerning you will no longer be processed for these purposes.
In connection with the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.
You have the right to withdraw your declaration of consent under data protection law at any time. Withdrawing consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. In Austria, this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
The supervisory authority with which the complaint has been lodged will inform the complainant of the progress and outcome of the complaint, including the possibility of a judicial remedy under Art. 78 GDPR.
Last updated: October 2026