Legal
Privacy notice
This page describes the processing designed into the Maintenzo application. Before production launch, hosting providers, processors and the actual deployment configuration must be checked against this notice.
1. Controller
Levi Wriessnegger
Hohenrainstrasse 48 8042 Graz
Email: office@maintenzo.at
2. Technical operation and logs
Technical connection data such as IP address, timestamp, requested resource, user agent and error information may be processed by the hosting infrastructure to provide, secure and troubleshoot the service.
3. Contact and analysis requests
When you contact Maintenzo or request a website analysis, the information you provide may be stored and processed to answer the request, prepare the requested assessment and communicate with you.
4. Automated website checks
The submitted public website URL is fetched server-side and technically analysed. Public metadata, HTTP status, redirects, technical characteristics and derived findings may be stored with the request. Private, local and link-local network targets are blocked by the scanner.
5. Customer accounts and Maintenzo Control
For customer accounts, Maintenzo processes the account, organisation, website, subscription, request, activity, report, scan and project data required to provide the contracted service. Necessary session cookies are used for authentication and access protection.
6. Transactional email and two-factor verification
Security emails and two-factor codes may be delivered through the configured Resend email service. Only the information required for delivery is submitted. Verification codes are not stored in plaintext by Maintenzo.
7. AI-assisted features
Where an AI-assisted feature is explicitly used, the content required for that feature may be transmitted server-side to the configured AI provider. Provider details and actual processing must be reflected in this notice before production use.
8. Cookies
Necessary authentication and security mechanisms are used for protected areas. Optional analytics, advertising or marketing cookies must not be enabled without the legally required consent and corresponding updates to this notice.
9. Retention
Data is retained only for the period required for the relevant purpose, customer relationship, security requirements or statutory retention duties. Concrete retention schedules must be aligned with the final operating processes.
10. Data subject rights
Subject to applicable law, data subjects may have rights including access, rectification, erasure, restriction, portability, objection and withdrawal of consent. Complaints may be lodged with the competent data protection authority.