Data protection
Privacy Policy
How Diafunc collects, uses, and protects your personal data, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who we are
The controller of the personal data processed under this Privacy Policy is:
Diafunc, Markus Pollak7083 Purbach, Austria
Email: contact@diafunc.com
Phone: +43 660 23 07 929
We are not required to appoint a Data Protection Officer under Article 37 GDPR. For any data-protection question, contact us at the address above.
2. What data we process and why
We process the following categories of personal data for the following purposes, on the following legal bases:
2.1 Account data
When you create a Diafunc account we collect: username, password (stored only as a salted bcrypt hash), full name, organisation name, postal address, email address, and phone number. We process this data to create and operate your account, authenticate you, and provide the platform service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
2.2 Content you submit
When you use the platform you may upload data files, run analyses, create projects, and produce other content. We process this content solely to provide the service you requested. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
2.3 Payment data
Payments are processed by Stripe Payments Europe Ltd. We do not receive or store your full card details; we receive only the transaction metadata required to associate the payment with your account (last 4 digits, brand, billing country, transaction ID). Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and a legal obligation to retain invoice records (Art. 6(1)(c) GDPR, § 132 BAO Austrian Federal Fiscal Code).
2.4 Technical data (server logs)
Our servers log technical data on every request: IP address, user-agent string, referring URL, request path, status code, and timestamp. We use these logs to operate the service, detect abuse, and diagnose errors. Legal basis: our legitimate interest in operating and securing the service (Art. 6(1)(f) GDPR).
First-party usage measurement (no cookies). To understand how visitors find Diafunc and where they get stuck, the site sends short usage events to our own servers: which page was viewed (as its page type, for example "a project in the Lab", never the project itself), which button was clicked, which step of the analysis wizard was reached, and similar. For a page visit we also note the website you came from (its domain only) and any campaign tags in the link you followed (for example utm_source or an ad click identifier). Nothing is stored on or read from your device for this. To count unique visitors per day, our server combines your IP address and user-agent string with a random value that changes every day and computes a one-way hash; the daily value is deleted after 48 hours, so the hash can no longer be recomputed and a visit today cannot be linked to a visit on another day. Your IP address and user-agent string are never stored: we keep only the hash, a device class (desktop, mobile or tablet) and the browser family. When you are signed in, the events are recorded with your account, so we can see, for example, how far new users get with their first analysis. Legal basis: our legitimate interest in understanding and improving the service and in measuring our marketing (Art. 6(1)(f) GDPR). You can object at any time (section 6).
Where you signed up from. When you create an account, we store with it where your first and most recent visit before sign-up came from (the referring domain, campaign tags, ad click identifiers, the page you landed on, and when), so we can tell which channels bring people who find Diafunc useful. Legal basis: our legitimate interest in measuring our marketing (Art. 6(1)(f) GDPR).
2.5 Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and to remember your preferences. These cookies are required for the service to function and cannot be disabled separately from using the service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in providing a working service (Art. 6(1)(f) GDPR).
With your explicit, informed, and revocable consent (collected through our cookie banner before anything is set), we additionally use analytics cookies (Google Analytics 4) to understand how the site and product are used, and marketing cookies (Google Ads conversion measurement) to measure whether our advertising works. Until you consent, the Google tags are not loaded at all: no script is fetched from Google, no cookies are set, no identifiers are created, and no request carrying your IP address is sent (Google Consent Mode v2, basic implementation, all signals defaulted to denied). They are loaded only for the categories you accept, and withdrawing consent stops the corresponding processing. Legal basis for these optional cookies: your consent (Art. 6(1)(a) GDPR, § 165 (3) TKG 2021). You can withdraw consent at any time via "Cookie preferences" in the footer or by deleting cookies in your browser.
With analytics consent, the site also remembers in your browser's local storage (key df.attribution) where your first and most recent visit came from, as described in section 2.4, so that the source of a visit is not lost if you sign up on a later day. Each entry is forgotten after 90 days, and withdrawing analytics consent removes it. Without consent, this is kept only in memory for the current visit.
We do not use cookies for personalised advertising beyond the consent-gated conversion measurement described above, and we never build advertising profiles of signed-in users.
2.6 Communications you send us
If you contact us by email, the support form, the feedback form, or any other channel, we process the contents of that communication and your contact details so we can respond. Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), or our legitimate interest in responding (Art. 6(1)(f) GDPR).
2.7 Feedback you give us
Answering any of our questions is always optional. When you do, we keep what you tell us: how likely you are to recommend Diafunc (a score from 0 to 10, and your comment), what you want to use Diafunc for, your thumbs up or down on an Assistant answer or an analysis result (with the reason and comment you add), and why you cancel your subscription. These answers are stored with your account. The reason you give when you delete your account, and the comment you write when you cancel, are also kept separately without your user ID, together with your plan, so they can still inform our work after your account is gone; they are no longer linked to you. Legal basis: our legitimate interest in improving the service (Art. 6(1)(f) GDPR).
2.8 Links in our emails
Links to diafunc.com in the emails we send carry campaign tags (utm_source=diafunc, utm_medium=email, and the kind of email as utm_campaign), so a visit from an email is counted as one in the measurement described in section 2.4. Our emails contain no tracking pixel and no redirecting links: we do not know whether you opened an email. Our email provider tells us whether an email was delivered, bounced, or reported as spam, which we keep without the recipient's address. Legal basis: our legitimate interest in understanding which of our messages are useful and in keeping our mail deliverable (Art. 6(1)(f) GDPR).
3. Who we share data with
We share personal data only with the following categories of recipients, each bound by a data-processing agreement under Article 28 GDPR:
- Hosting and backup storage: Hetzner Online GmbH (Germany / EU): dedicated server hosting for the platform and offsite backup storage (Hetzner StorageBox). Hetzner infrastructure used for Diafunc is operated in their German (Falkenstein, Nuremberg) and Finnish (Helsinki) data centres, all within the EU/EEA.
- Error diagnostics (self-hosted): technical error reports from the application (error type, stack trace, browser and app version, the page type in view, and the failing request's method and path; never request bodies, your content, or personal data such as your name or email) are collected by GlitchTip, an error-tracking service we host ourselves on the Hetzner infrastructure listed above, within the EU. No additional third party receives this data; it is used solely to detect and fix defects in the service. Error reports are deleted after 90 days.
- Payment processing: Stripe Payments Europe Ltd. (Ireland): credit-card and SEPA processing. Stripe may transfer data to its U.S. parent under EU Standard Contractual Clauses.
- Email delivery: Mailgun Technologies, Inc., EU region (
smtp.eu.mailgun.org, operated within the EU): transactional and notification emails. - Bot-protection on the contact form: Google Ireland Ltd. (reCAPTCHA v3). reCAPTCHA is loaded only on the public contact form. Google may transfer data to its U.S. parent under EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
- Analytics and advertising measurement (only with your consent): Google Ireland Ltd. (Google Analytics 4, Google Ads conversion measurement). Active only after you accept analytics/marketing cookies in the cookie banner; disabled by default. Google may transfer data to its U.S. parent under EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
- Encrypted offsite backups: Google Cloud EMEA Ltd. (Google Cloud Storage, EU region), alongside the Hetzner StorageBox listed above; see section 5 for retention details.
We do not sell personal data to anyone, and we do not share personal data with third parties for their own marketing purposes.
4. International transfers
Our infrastructure, data storage, and email delivery are operated within the European Union. Where a sub-processor (e.g. Stripe, Google) transfers data outside the EU/EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (SCCs, Decision 2021/914) and, where applicable, the EU-U.S. Data Privacy Framework adequacy decision.
5. How long we keep it
- Account data: for the lifetime of your account; deleted within 30 days of account closure, except where retention is required by law.
- Content you submit: for the lifetime of your account; deleted within 30 days of account closure.
- Invoice and accounting records: 7 years, as required by § 132 (1) BAO (Austrian Federal Fiscal Code).
- Application logs: 14 days (TTL on the log store), then automatically deleted.
- Usage events (section 2.4): 400 days, then automatically deleted, so a year can be compared with the one before. The daily value behind the visitor hash is deleted after 48 hours.
- Where you signed up from (section 2.4): for the lifetime of your account; deleted with it.
- Feedback (section 2.7): for the lifetime of your account; deleted with it. Deletion and cancellation reasons kept without your user ID are no longer linked to you.
- Error reports (section 3): 90 days, then automatically deleted.
- Email delivery events (section 2.8): 1 year, without the recipient's address.
- Backups: encrypted offsite backups (Hetzner StorageBox + Google Cloud Storage) on an append-only basis; not automatically pruned. After account deletion we do not restore your data from backup, and the underlying backup records age out at the next periodic manual prune cycle.
- Support correspondence: up to 3 years from last contact.
6. Your rights under the GDPR
You have the following rights with respect to the personal data we hold about you:
- Access (Art. 15 GDPR): request a copy of the personal data we hold about you.
- Rectification (Art. 16 GDPR): have inaccurate data corrected.
- Erasure (Art. 17 GDPR): request deletion, subject to retention obligations.
- Restriction (Art. 18 GDPR): restrict processing while a request is reviewed.
- Portability (Art. 20 GDPR): receive your data in a structured, machine-readable format.
- Objection (Art. 21 GDPR): object to processing carried out on the basis of legitimate interest.
- Withdraw consent (Art. 7 (3) GDPR): at any time, with effect for the future, for any processing based on your consent.
To exercise any of these rights, write to contact@diafunc.com. We will respond within one month (Art. 12 (3) GDPR).
7. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority for Diafunc is:
Österreichische Datenschutzbehörde (DSB)Barichgasse 40-42, 1030 Wien, Austria
www.dsb.gv.at
You may also lodge a complaint with the supervisory authority of the EU/EEA member state in which you reside or work.
8. Security
We apply appropriate technical and organisational measures to protect your personal data, including: TLS encryption for all data in transit, encryption at rest for backups, salted bcrypt password hashing, role-based access control on production systems, regular security review of our dependencies, isolated database access for application services, and logging of administrative actions. No method of transmission or storage is absolutely secure, but we take all reasonable steps to keep your data safe.
9. Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR.
10. Children
Diafunc is not directed at children under 16, and we do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy when our processing changes or to reflect legal developments. Material changes will be announced on this page and, where appropriate, by email to registered users. The current version is always available at diafunc.com/privacy.
12. Contact
For any question about this Privacy Policy or about our processing of your personal data, contact us at contact@diafunc.com or via the contact form.
Effective: 2026-09-19.