- Home
- Privacy
Privacy Policy
How NGS Analytics GmbH processes personal data in connection with this website, enquiries and business administration.
Last updated: 27 September 2026
NGS Analytics GmbH (“we”, “us” or “the controller”) takes the protection of personal data seriously. This Privacy Policy explains how we process personal data in connection with visits to ngsalytics.com, enquiries, requests for quotations and related business administration. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Austrian data protection legislation.
This policy concerns website and business-contact data. It does not replace any separate privacy information required for project-specific processing of research datasets or personal genetic or health data.
Controller
- Company
- NGS Analytics GmbH, FN 679567 p, Handelsgericht Wien
- Address
- Karl-Farkas-Gasse 22, 1030 Wien, Austria
- Managing director
- Dr. Ádám Sturm
- Privacy contact
- info@ngsalytics.com
You may contact us at the email or postal address above with questions about this policy or to exercise your data protection rights. Our full company details are in the Impressum.
How we handle personal data
We process personal data lawfully, fairly and transparently, for specified purposes. We limit the data collected to what is necessary for those purposes, take reasonable steps to maintain accuracy, and retain identifiable data only for as long as necessary or legally required. We apply appropriate technical and organisational measures to protect personal data against unauthorised access, unlawful processing, loss, destruction or damage. Access is restricted to authorised persons who need the information for their responsibilities.
Visiting this website
This is a static website: it delivers pages, images and fonts from its own domain and loads nothing from any other server. When you visit it, the infrastructure delivering the website processes the technical connection data needed to transmit the requested content. This may include your IP address, the date and time of the request, the pages or files requested, browser and operating system information, referrer information where supplied, and technical status or error information.
Purpose: delivering the website, maintaining availability, diagnosing technical problems and detecting or investigating misuse and security incidents.
Legal basis: Article 6(1)(f) GDPR, based on our legitimate interest in operating a functioning and secure website.
What is recorded and for how long: we operate no web server of our own and keep no server logs. Our hosting and content delivery provider processes connection data, in particular IP addresses, at its network edge in order to deliver and protect the website. According to that provider, access data are stored only briefly at the network edge and deleted within a few hours, and detailed request logs are not retained unless log retention is enabled, which we have not done. Aggregated statistics that do not identify individual visitors may be available to us. Where records are needed to investigate a specific incident, or to establish, exercise or defend legal claims, they may be retained for that purpose for as long as necessary.
Cookies and analytics
This website uses none. It sets no cookies, uses no local or session storage, and contains no analytics, tracking or advertising technologies. We therefore ask for no consent to any such technology and show no cookie banner.
Storage or access strictly necessary to transmit a communication, or to provide a service you expressly requested, does not require consent under Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021). Any related processing of personal data must also have an appropriate GDPR legal basis. Your browser settings allow you to manage or delete cookies set by any website you visit.
If we introduce a cookie, an analytics tool or a contact form in future, we will describe it here, with its provider, purpose, legal basis and retention, and obtain consent where consent is required, before that technology is used.
External content and links
This website embeds no external content, such as fonts, maps, videos, social media plugins or advertising elements. Everything it displays is delivered from our own domain. Where a website links to an external service, the operator of that service is responsible for its own processing of personal data.
Contacting us and requesting a quotation
This website has no contact form. Enquiries reach us by email, telephone or post, and we process the information you provide in order to handle your request.
Data concerned: your name, professional contact details, company or institution, information about the requested services, correspondence and any attachments you choose to send.
Purpose: responding to enquiries, preparing quotations, discussing requested services and managing related communication.
Legal basis: Article 6(1)(b) GDPR where processing is necessary for a contract with you, or for steps taken at your request before entering into one. For general enquiries and communication with representatives of companies or institutions, Article 6(1)(f) GDPR and our legitimate interest in responding to requests and managing business relationships.
Retention: we retain enquiry data until the request and related follow-up have been completed. Information needed for a resulting contract, statutory records or a specific legal claim is retained under the relevant purpose and retention requirement.
Providing information is voluntary. However, without sufficient contact details and information about your request, we may be unable to respond or prepare a quotation. Please do not include personal genetic or health information in a general enquiry: contact us first so that an appropriate transfer method can be agreed where such information is necessary for a project.
Invoicing and business administration
Where a business relationship is established, we process the information necessary for invoicing, payment administration and statutory recordkeeping: customer and contact names, company or institution details, billing addresses, tax or VAT identification numbers, invoice details, payment information and related business correspondence.
Legal basis: Article 6(1)(c) GDPR where processing is required by Austrian accounting and tax legislation, including Section 132 of the Federal Fiscal Code (BAO) and Section 212 of the Austrian Commercial Code (UGB).
Retention: accounting records and supporting documents subject to the ordinary Austrian retention requirement are generally retained for seven years from the end of the relevant calendar year, and longer where required by law, including for pending tax or judicial proceedings. A request for deletion does not override a statutory obligation to retain records.
Processors and other recipients
We disclose personal data only where necessary for the purposes described in this policy and where an appropriate legal basis exists. Depending on the activity, recipients include authorised staff, website hosting and security providers, business email and IT service providers, accounting or professional advisers, banks and competent public authorities. Where a service provider processes personal data on our behalf, we require an appropriate data processing agreement and safeguards for confidentiality and security. Providers acting as independent controllers are responsible for their own processing.
- Website hosting and delivery
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, and its affiliates. Operates a distributed network and processes connection data, in particular IP addresses, in data centres in the European Union, the United States and elsewhere.
- Business email
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Workspace), with Google LLC in the United States and its sub-processors. Email you send us is processed on that service.
International data transfers
Where personal data are transferred to a recipient outside the European Economic Area, the requirements of Chapter V GDPR apply in addition to the ordinary processing requirements. Both providers named above are based in, or belong to a group based in, the United States. According to their published data processing terms, transfers from the European Economic Area to the United States are covered by certification under the EU–U.S. Data Privacy Framework and, in addition or as a fallback, by the European Commission’s Standard Contractual Clauses together with supplementary measures where necessary. You may contact us for information about the safeguards used and how to obtain a copy, subject to appropriate protection of confidential information.
Your rights
Subject to the applicable legal conditions, you may request access to and a copy of your personal data, correction, erasure or restriction of processing. Where processing is automated and based on consent or a contract, you may also request portability of the data you provided. You may withdraw consent at any time without affecting earlier lawful processing.
Right to object: where we rely on legitimate interests, you may object for reasons relating to your situation. We will stop unless compelling overriding legitimate grounds, or legal claims, justify continued processing. You may object to direct marketing at any time without giving reasons.
These rights are subject to legal conditions and exceptions, including mandatory record retention. To exercise them, contact us using the details above; we may request information reasonably necessary to confirm your identity. We respond without undue delay and within one month. Where legally permitted because of complexity or the number of requests, we may extend this by up to two further months and will tell you of the extension and the reasons within the first month.
Complaints
You may lodge a complaint with a competent data protection supervisory authority if you consider that the processing of your personal data infringes data protection law. You do not have to contact us first.
Applicable legislation and changes
This policy is based on the GDPR, the Austrian Data Protection Act (DSG), the relevant provisions of the Telecommunications Act 2021 (TKG 2021), and applicable Austrian accounting and tax legislation, including the BAO and the UGB. We update it when our processing activities or the relevant legal requirements change; the date above identifies the most recent update. Where additional information or consent is required for a new activity, we provide it or obtain it before that activity starts.