Privacy policy
How we process personal data both on this website and while working together.
Controller
The controller responsible for processing personal data is twopeaks digital GmbH, Neue Schanze 22/6, 6900 Lochau, Austria, hello-from-website@twopeaks.email.
Principles
We process personal data only to the extent necessary for the respective purpose. Depending on the processing activity, we rely on steps taken before entering into a contract or performance of a contract, legal obligations, consent, or our legitimate interests pursuant to Art. 6 GDPR.
When visiting the website
When the website is accessed, technically necessary access data is transmitted to the hosting provider we use. This may include the IP address, time, page accessed, amount of data transferred, referrer, browser, and operating system. Processing serves the secure and stable provision of the website, error analysis, and prevention of misuse. The legal basis is Art. 6(1)(f) GDPR.
Server logs are deleted as soon as they are no longer required for these purposes. They are retained for longer only where necessary to investigate a security incident or comply with a legal obligation.
Archia and Nunito Sans are served locally from our own server. No connection to an external font provider is established.
When you select a language, we store the selection as a technically functional preference named twopeaks_locale in a cookie and in your browser's local storage. It is stored for no more than twelve months. The preference is used solely to retain the selected language for future visits; it is not used for audience measurement or profiling.
For external links, data is transmitted to the respective provider only when you open the link.
Audience measurement with Piqo
We use Piqo Analytics, a service provided by MVP Stack LLC, to understand how our website is found and used. The analysis helps us improve content, navigation and contact options. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Piqo processes the page address accessed, including query parameters, the referrer, UTM campaign parameters, browser, device and operating system type, the time, and an approximate region derived from the IP address. A short-lived hash based on the IP address, user agent, website and a daily rotating salt is used for recognition within a single day. According to the provider, the IP address itself is not stored.
We also record clicks on links and buttons, outbound links, submission of the enquiry form, and whether it was successful or returned an error. Form fields and their contents are not transmitted to Piqo. We embed Piqo in cookieless mode. As a result, Piqo does not set analytics cookies, use local storage for recognition, or create a persistent visitor identifier.
According to the provider, Piqo stores analytics data for up to three years and uses Cloudflare to deliver the tracker script. Where data is processed outside the European Economic Area, Piqo states that the transfer is based on standard contractual clauses. For more information, see the Piqo privacy policy. Opens in a new tab and the Piqo data processing agreement. Opens in a new tab.
Enquiry form
When you submit the enquiry form, we process your name, company, business email address, role, company size, existing team, requested service and form of collaboration, desired start date, budget range and budget status, information about the decision-maker, and your project description.
We use this data to assess and respond to the enquiry and prepare possible pre-contractual steps. The legal basis is Art. 6(1)(b) GDPR; for general business enquiries, it also includes our legitimate interest in handling business communications pursuant to Art. 6(1)(f) GDPR.
We use Formspark, a service provided by Trampoline Software SRL, Rue de Marsannay-la-Côte 16, 5032 Mazy, Belgium, to receive form submissions. Formspark processes the form data, IP address, and technical request data on our behalf. The data is stored in Ireland and Germany. The data processing agreement pursuant to Art. 28 GDPR forms part of our agreement with Formspark.
We delete form content from Formspark in accordance with the periods stated in the Retention period section. Deleted submissions can remain recoverable there for up to 30 days. According to Formspark, it retains the IP address and approximate location data derived from it for up to twelve months to prevent misuse. For more information, see the Formspark privacy policy. Opens in a new tab.
Email and video calls
When you contact us by email, we process the sender, recipient, time, technical metadata, and content of the message. The website does not embed a video conferencing service. If a video call is arranged, we identify the service used in the invitation. A connection to that provider is established only when the invitation link is opened. Recordings are made only with the prior express consent of all participants.
Data in projects
If we gain access to our clients' personal data during a project, we act as a processor where appropriate to the engagement. In that case, we enter into a data processing agreement pursuant to Art. 28 GDPR and agree the necessary technical and organizational measures.
Use of AI tools
Our default is development without AI tools. If AI assistance is agreed, we document the tools, permitted areas, provider, region and retention periods in the statement of work in advance. Inputs are not used for training; on request, we work under the client's contracts or with locally operated models.
Recipients and service providers
Access to personal data is limited to people and service providers who need it for the respective purpose. This may include providers of hosting and technical infrastructure, email and calendars, project and ticketing systems, accounting, and, following a separate invitation, video conferencing. Where a service provider processes data on our behalf, we enter into an agreement pursuant to Art. 28 GDPR.
A transfer outside the European Economic Area takes place only where required for the respective service and where the conditions of Art. 44 et seq. GDPR are met, in particular through an adequacy decision or appropriate safeguards such as standard contractual clauses.
Retention period
We retain personal data only for as long as it is needed for the respective purpose. Enquiry data that does not result in an engagement is generally deleted no later than twelve months after the last substantive contact. If we are commissioned, we retain project and contract data for the duration of the collaboration and subsequently in accordance with statutory retention obligations, in particular generally seven years for tax and corporate-law records. Legal claims or ongoing proceedings may require longer retention.
Your rights
Subject to the GDPR, you have the right of access, rectification, erasure, restriction of processing, data portability, and objection. You may withdraw consent at any time with effect for the future. Send requests to hello-from-website@twopeaks.email. You also have the right to lodge a complaint with the Austrian Data Protection Authority.
Security
We are certified to ISO/IEC 27001 and use technical and organizational measures including encrypted transmission, role-based access, multi-factor authentication, and tested recovery procedures.
Last updated: September 2026