Data protection
Privacy Policy
How Diafunc collects, uses, and protects your personal data — and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who we are
The controller of the personal data processed under this Privacy Policy is:
Diafunc — Markus Pollak7083 Purbach, Austria
Email: contact@diafunc.com
Phone: +43 660 23 07 929
We are not required to appoint a Data Protection Officer under Article 37 GDPR. For any data-protection question, contact us at the address above.
2. What data we process and why
We process the following categories of personal data for the following purposes, on the following legal bases:
2.1 Account data
When you create a Diafunc account we collect: username, password (stored only as a salted bcrypt hash), full name, organisation name, postal address, email address, and phone number. We process this data to create and operate your account, authenticate you, and provide the platform service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
2.2 Content you submit
When you use the platform you may upload data files, run analyses, create projects, and produce other content. We process this content solely to provide the service you requested. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
2.3 Payment data
Payments are processed by Stripe Payments Europe Ltd. We do not receive or store your full card details; we receive only the transaction metadata required to associate the payment with your account (last 4 digits, brand, billing country, transaction ID). Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and a legal obligation to retain invoice records (Art. 6(1)(c) GDPR, § 132 BAO Austrian Federal Fiscal Code).
2.4 Technical data (server logs)
Our servers log technical data on every request: IP address, user-agent string, referring URL, request path, status code, and timestamp. We use these logs to operate the service, detect abuse, and diagnose errors. Legal basis: our legitimate interest in operating and securing the service (Art. 6(1)(f) GDPR).
2.5 Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and to remember your preferences. These cookies are required for the service to function and cannot be disabled separately from using the service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in providing a working service (Art. 6(1)(f) GDPR).
With your explicit, informed, and revocable consent — collected through our cookie banner before anything is set — we additionally use analytics cookies (Google Analytics 4) to understand how the site and product are used, and marketing cookies (Google Ads conversion measurement) to measure whether our advertising works. Without your consent these services stay fully disabled (Google Consent Mode v2, default denied). Legal basis for these optional cookies: your consent (Art. 6(1)(a) GDPR, § 165 (3) TKG 2021). You can withdraw consent at any time via "Cookie preferences" in the footer or by deleting cookies in your browser.
We do not use cookies for personalised advertising beyond the consent-gated conversion measurement described above, and we never build advertising profiles of signed-in users.
2.6 Communications you send us
If you contact us by email, the support form, or any other channel, we process the contents of that communication and your contact details so we can respond. Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), or our legitimate interest in responding (Art. 6(1)(f) GDPR).
3. Who we share data with
We share personal data only with the following categories of recipients, each bound by a data-processing agreement under Article 28 GDPR:
- Hosting and backup storage — Hetzner Online GmbH (Germany / EU): dedicated server hosting for the platform and offsite backup storage (Hetzner StorageBox). Hetzner infrastructure used for Diafunc is operated in their German (Falkenstein, Nuremberg) and Finnish (Helsinki) data centres — all within the EU/EEA.
- Error diagnostics (self-hosted) — technical error reports from the application (error type, stack trace, browser and app version, and the failing request's method and path — never request bodies or your content) are collected by an error-tracking service we host ourselves on the Hetzner infrastructure listed above, within the EU. No additional third party receives this data; it is used solely to detect and fix defects in the service.
- Payment processing — Stripe Payments Europe Ltd. (Ireland): credit-card and SEPA processing. Stripe may transfer data to its U.S. parent under EU Standard Contractual Clauses.
- Email delivery — Mailgun Technologies, Inc., EU region (
smtp.eu.mailgun.org, operated within the EU): transactional and notification emails. - Bot-protection on the contact form — Google Ireland Ltd. (reCAPTCHA v3). reCAPTCHA is loaded only on the public contact form. Google may transfer data to its U.S. parent under EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
- Analytics and advertising measurement (only with your consent) — Google Ireland Ltd. (Google Analytics 4, Google Ads conversion measurement). Active only after you accept analytics/marketing cookies in the cookie banner; disabled by default. Google may transfer data to its U.S. parent under EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
- Encrypted offsite backups — Google Cloud EMEA Ltd. (Google Cloud Storage, EU region), alongside the Hetzner StorageBox listed above; see section 5 for retention details.
We do not sell personal data to anyone, and we do not share personal data with third parties for their own marketing purposes.
4. International transfers
Our infrastructure, data storage, and email delivery are operated within the European Union. Where a sub-processor (e.g. Stripe, Google) transfers data outside the EU/EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (SCCs, Decision 2021/914) and, where applicable, the EU-U.S. Data Privacy Framework adequacy decision.
5. How long we keep it
- Account data — for the lifetime of your account; deleted within 30 days of account closure, except where retention is required by law.
- Content you submit — for the lifetime of your account; deleted within 30 days of account closure.
- Invoice and accounting records — 7 years, as required by § 132 (1) BAO (Austrian Federal Fiscal Code).
- Application logs — 14 days (TTL on the log store), then automatically deleted.
- Backups — encrypted offsite backups (Hetzner StorageBox + Google Cloud Storage) on an append-only basis; not automatically pruned. After account deletion we do not restore your data from backup, and the underlying backup records age out at the next periodic manual prune cycle.
- Support correspondence — up to 3 years from last contact.
6. Your rights under the GDPR
You have the following rights with respect to the personal data we hold about you:
- Access (Art. 15 GDPR) — request a copy of the personal data we hold about you.
- Rectification (Art. 16 GDPR) — have inaccurate data corrected.
- Erasure (Art. 17 GDPR) — request deletion, subject to retention obligations.
- Restriction (Art. 18 GDPR) — restrict processing while a request is reviewed.
- Portability (Art. 20 GDPR) — receive your data in a structured, machine-readable format.
- Objection (Art. 21 GDPR) — object to processing carried out on the basis of legitimate interest.
- Withdraw consent (Art. 7 (3) GDPR) — at any time, with effect for the future, for any processing based on your consent.
To exercise any of these rights, write to contact@diafunc.com. We will respond within one month (Art. 12 (3) GDPR).
7. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority for Diafunc is:
Österreichische Datenschutzbehörde (DSB)Barichgasse 40-42, 1030 Wien, Austria
www.dsb.gv.at
You may also lodge a complaint with the supervisory authority of the EU/EEA member state in which you reside or work.
8. Security
We apply appropriate technical and organisational measures to protect your personal data, including: TLS encryption for all data in transit, encryption at rest for backups, salted bcrypt password hashing, role-based access control on production systems, regular security review of our dependencies, isolated database access for application services, and logging of administrative actions. No method of transmission or storage is absolutely secure, but we take all reasonable steps to keep your data safe.
9. Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR.
10. Children
Diafunc is not directed at children under 16, and we do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy when our processing changes or to reflect legal developments. Material changes will be announced on this page and, where appropriate, by email to registered users. The current version is always available at diafunc.com/privacy.
12. Contact
For any question about this Privacy Policy or about our processing of your personal data, contact us at contact@diafunc.com or via the contact form.
Effective: 2026-05-24.