Privacy Policy
Version 1.0 — effective 4 September 2026
1. Controller
Gabor Pais EU (Einzelunternehmer)Döblinger Hauptstraße 18/1/9
1190 Vienna, Austria
VAT ID: ATU83407136
Email: officebimfriend@gmail.com
2. Data we process
- Account data: username, name, email, company name, password hash, registration, activation and login information.
- Billing data: customer type, company, address, country, tax/VAT number, requested plan, price, payment request, invoice and access-period information.
- Bank-transfer data: payment date, amount, currency, payment reference and information visible on the incoming bank transaction, such as the payer or account holder. We do not collect or store payment-card details.
- Service data: spreadsheet data entered or uploaded for transformation, selected output and technical error information.
- Technical data: IP address, timestamps, browser/device details, security and server logs, and consent/cookie settings where generated by the relevant systems.
- Communications: subscription requests, agreement emails, support messages and information supplied for professional services.
3. Purposes and legal bases
- Account creation, authentication, CCC delivery, billing and support: performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR).
- Invoices, tax records and legally required disclosures: legal obligation (Art. 6(1)(c)).
- Security, fraud prevention, service improvement and establishment or defence of legal claims: legitimate interests (Art. 6(1)(f)).
- Non-essential cookies or similar technologies and optional marketing: consent where required (Art. 6(1)(a)).
4. Uploaded spreadsheet and generated files
Spreadsheet content is read in the browser and relevant structured data is transmitted to our server when you request server-side generation of an IDS, Excel, TXT or XML file. We process it to create and return the requested output. It is not intentionally stored in the application database. Temporary memory, security logs or short-lived technical copies may nevertheless arise. Do not upload unnecessary personal or confidential data.
5. Recipients and processors
Data is disclosed only as necessary to operate the service, comply with law or protect legal rights. Relevant providers may include:
- our bank and the customer's payment-service provider, for receiving and documenting bank transfers;
- hosting and infrastructure providers, including Google services where used for application hosting or operational email;
- Cookiebot by Usercentrics, for cookie-consent management;
- email providers, for subscription requests, agreements, activation, password-reset, billing and support messages;
- accounting and tax advisers, professional advisers and authorities where legally necessary.
Some front-end libraries or fonts may be delivered by Google or content-delivery networks. Their use and consent classification must match the active Cookiebot configuration.
6. International transfers
Some providers may process data outside the EEA. Where required, transfers rely on an adequacy decision, the EU–US Data Privacy Framework for participating recipients, Standard Contractual Clauses with supplementary safeguards, or another lawful transfer mechanism. Provider-specific details are available on request and in the relevant provider notices.
7. Retention
- Account data is kept while the account is active and then deleted or anonymised unless needed for legal claims or compliance.
- Contract, invoice and tax records are retained for the periods required by Austrian law, generally seven years and longer where a proceeding requires it.
- Support correspondence is normally retained for up to three years after resolution unless a longer contractual or legal period applies.
- Security and server logs are retained only for a proportionate operational period and longer only where needed to investigate an incident or legal claim.
8. Cookies and external resources
Strictly necessary technologies support login, security and preferences. Non-essential technologies are activated only where a valid consent or another lawful basis exists. You can review or change choices through the cookie-consent tool. See the cookie panel for the current provider, purpose and lifetime list.
9. Your rights
Subject to legal conditions, you may request access, rectification, erasure, restriction, portability and objection, and withdraw consent at any time without affecting earlier lawful processing. You may also complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
10. Account deletion
You may request or initiate account deletion from your profile. Active account data will be removed, but email correspondence, bank-transfer, billing, tax and legal-claim records may be retained where required. Deleting the CCC account does not delete records that our bank, email provider or tax advisers must retain independently.
11. Security
We use proportionate organisational and technical measures, including hashed passwords and access controls. No internet system is completely secure; please use a unique password and notify us promptly of suspected misuse.
12. Changes and contact
We may update this notice when processing or law changes. Material changes will be communicated appropriately. Privacy requests: officebimfriend@gmail.com.