Move to Austria

    Privacy Policy

    Controller

    Azra Mehanic
    Move to Austria – Consulting
    Gablenzgasse 112-118/8/6, 1160 Vienna, Austria
    Email: office@movetoaustria.at

    General Information

    We process personal data in accordance with the General Data Protection Regulation ("GDPR") and applicable Austrian data protection law. This Privacy Policy explains which personal data we process, for which purposes, on which legal basis, how long we retain the data, to whom it may be disclosed, and which rights data subjects have. The information must be provided in a concise, transparent, intelligible and easily accessible form.

    Categories of Personal Data We Process

    Depending on how you interact with us, we may process the following categories of personal data:

    • identification and contact data, such as name, email address, telephone number, postal address
    • communication data, such as the content of emails, messages, enquiries, and attachments
    • booking and appointment data, such as selected service, appointment date, time, and related notes
    • payment and transaction data, such as billing details, payment status, amount, date of purchase, and limited payment-related information made available to us by the payment provider
    • website usage and technical data, such as IP address, date and time of access, log files, browser information, and device-related technical information
    • consent data, such as whether and when you gave or withdrew consent to cookies or advertising technologies

    Purposes and Legal Bases of Processing

    1. Contact by Email or Messaging Services

    If you contact us, we process your personal data to respond to your enquiry, communicate with you, and take pre-contractual steps if your request relates to a possible booking or service. The legal basis is Art. 6(1)(b) GDPR where the request is linked to a potential or existing contract, and Art. 6(1)(f) GDPR where processing is necessary for handling general enquiries and communication.

    2. Appointment Booking and Scheduling

    If you book or manage an appointment, we process your contact details, appointment details, and related communication in order to arrange and administer the consultation. The legal basis is Art. 6(1)(b) GDPR. For scheduling, we use Google services. Google's privacy documentation explains that Google collects and processes information when its services are used.

    3. Payment Processing

    If you purchase a paid consultation or package, we process the data necessary to initiate, document, and manage the payment and the contractual relationship. The legal basis is Art. 6(1)(b) GDPR. Payments are processed through Stripe. Stripe states that transaction data may include name, email address, billing address, payment method information, purchase amount, purchase date, payment status, refund or chargeback information, and support interactions.

    4. Website Hosting and Security

    When you visit this website, technical data may be processed to ensure website functionality, stability, and security, including server log processing. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website. Basic GDPR guidance also recognizes legitimate interest as one possible legal ground, subject to the required conditions.

    5. Cookies and Similar Technologies

    This website uses technically necessary cookies where required for website operation. If analytics, advertising, retargeting, or similar non-essential technologies are used, they are activated only on the basis of your consent under Art. 6(1)(a) GDPR. Consent must be freely given and withdrawable without disadvantage.

    6. Online Advertising

    If we use online advertising tools such as Google Ads or Meta Ads, personal data may be processed for campaign delivery, conversion measurement, remarketing, or similar advertising purposes. Such processing will only take place where legally required on the basis of your prior consent under Art. 6(1)(a) GDPR. If no such tools are active on the website, this section does not apply. Consent-based processing also requires that withdrawal be possible at any time.

    Recipients / Categories of Recipients

    Your personal data may be disclosed, where necessary, to the following categories of recipients:

    • IT and hosting providers
    • email and communication providers
    • calendar and scheduling providers, including Google
    • payment service providers, including Stripe
    • tax advisers, accountants, or legal advisers where necessary
    • public authorities or courts where there is a legal obligation or a lawful request

    Under the GDPR information duties, individuals must be told who may receive their data.

    Google Services

    Where Google services are used for scheduling or related business administration, Google may process personal data in accordance with its own privacy documentation. Further information is available in Google's Privacy Policy.

    Stripe

    Where Stripe is used for payment processing, Stripe processes transaction-related personal data in accordance with its own privacy documentation. Further information is available in Stripe's Privacy Policy.

    International Data Transfers

    Some recipients may process personal data outside the EU/EEA. Where this occurs, we rely on an adequacy decision or other appropriate safeguards under applicable data protection law, where required. The European Commission explains that transfers to third countries require safeguards such as adequacy decisions, standard contractual clauses, or binding corporate rules. Stripe states that it may transfer personal data to countries including the United States and India and that, where required, it uses mechanisms including adequacy decisions and EU Standard Contractual Clauses, and also refers to the EU-U.S. Data Privacy Framework for Stripe, LLC.

    Data Retention

    We retain personal data only for as long as necessary for the respective purpose and, where applicable, for as long as statutory retention obligations require.

    • enquiry and communication data: generally up to 12 months after the last contact, unless further retention is required for follow-up matters or legal defence
    • booking and appointment data: for the duration of the contractual relationship and thereafter as long as necessary to document the service or handle disputes
    • invoice and payment-related records: for the legally required retention period under applicable tax and accounting law
    • consent records: for as long as necessary to demonstrate valid consent and manage its withdrawal
    • server logs and technical security data: for as long as necessary for security, troubleshooting, and operational integrity

    The GDPR requires that individuals be informed how long data will be kept, or the criteria used to determine that period.

    Obligation to Provide Data

    You are not generally obliged by law to provide personal data. However, certain data is necessary in order to respond to enquiries, schedule appointments, conclude a contract, or process payment. If you do not provide the required data, we may be unable to offer the requested service or complete the booking. The EU information duties include explaining what information must be given when data is collected and what is necessary to provide the service.

    Data Subject Rights

    You have the following rights under the GDPR, subject to the applicable legal conditions:

    • right to be informed
    • right of access
    • right to rectification
    • right to erasure
    • right to restriction of processing
    • right to data portability
    • right to object
    • right not to be subject to a decision based solely on automated processing, where applicable

    The European Data Protection Board lists these as core GDPR rights.

    Right to Withdraw Consent

    Where processing is based on consent, you may withdraw your consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. The European Commission states that people must be able to withdraw consent, and that the right to withdraw consent must be communicated.

    Right to Lodge a Complaint

    You also have the right to lodge a complaint with a supervisory authority. In Austria, the competent supervisory authority is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, email: dsb@dsb.gv.at. The complaint right and the authority's contact details are reflected in official EU and Austrian guidance.

    Automated Decision-Making

    We do not carry out automated decision-making, including profiling, which produces legal effects concerning you or similarly significantly affects you. If this changes, this Privacy Policy will be updated accordingly. The GDPR information duties require this point to be disclosed where applicable.

    Data Protection Requests

    To exercise your rights or for any privacy-related questions, please contact: office@movetoaustria.at

    Last Updated

    22 April 2026