Privacy.

How we handle personal data in the Cevio Workspace, under the GDPR (EU 2016/679) and the Austrian DSG.

Privacy Policy

01

Data Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):

Company
Cevio e.U.
Holder
Tobias Sonnleitner
Address
Stadlergasse 9a/3, 1130 Vienna, Austria
Email
contact@cevio.at
Service
cevioworkspace.at

For data protection matters, simply send an informal email to contact@cevio.at. A data protection officer is not appointed, because the conditions of Art. 37 GDPR are not met.

02

Scope

This policy applies to the Cevio Workspace at www.cevioworkspace.at, that is, to the sign-in page, the client area behind the login and every function it contains.

A separate policy applies to our company website: cevio.at/privacy. For websites we operate for clients, the operator of the website concerned is the controller.

Processing is based on the following legal bases under Art. 6(1) GDPR:

  • Art. 6(1)(a) GDPR, consent of the user.
  • Art. 6(1)(b) GDPR, performance of a contract (providing the client area, handling an order).
  • Art. 6(1)(c) GDPR, legal obligation (e.g. retention of invoices).
  • Art. 6(1)(f) GDPR, legitimate interest (IT security, abuse prevention, traceability).

Minimum age. The Workspace is intended for our business clients and for persons who have reached the age of 14 (§ 4(4) DSG, Austrian Data Protection Act). Should we learn that an account was created without the necessary consent, we will delete it together with its data.

03

Hosting & Server Infrastructure

The Workspace runs on servers in Austria. Web hosting and database are provided by World4You Internet Services GmbH (Hafenstraße 47-51, 4020 Linz, Austria). The application is written in PHP, the data is held in an SQLite database on the same server.

When our pages are accessed, the web server automatically records the following technical data in log files:

  • IP address
  • Date and time of the request
  • Address requested
  • Browser type and version
  • Operating system
  • Referrer address

This data is processed to ensure secure operation and to detect and defend against attacks (Art. 6(1)(f) GDPR). It is not merged with other data sources.

Hosting provider
World4You Internet Services GmbH, Linz, Austria
Server location
Austria (EU)
Transfer
Encrypted throughout via HTTPS, HTTP is redirected
04

User account

The Workspace is a closed client area. An account is created by invitation or by registration. In doing so we process:

  • Name
  • Email address
  • Password, stored exclusively as a bcrypt hash, never in plain text
  • Phone number, if provided
  • Profile picture, if uploaded
  • Role and permissions within the Workspace
  • Time of creation and of the most recent sign-in

This data is required in order to provide the client area. Legal basis: Art. 6(1)(b) GDPR.

Changes and deletion. You can change your name, phone number, profile picture and password yourself at any time in your profile. A change of email address is confirmed by a code sent to the new address. Using the button Delete account in your profile you can request deletion of your account; excluded is data we are legally required to retain (see section 17).

05

Two-factor authentication

Signing in is protected by a second factor. For this we process:

TOTP secret
The secret of your authenticator app, stored in order to verify the codes
Backup codes
One-time codes for cases where the app is unavailable; used codes are invalidated
Legal basis
Art. 6(1)(b) and (f) GDPR (contract performance, account security)

Trusted devices. On request the Workspace remembers a device, so that the second factor is not requested there at every sign-in. Stored for this purpose are a hash of the device token, the browser identification (user agent), the time of setup, the most recent use and an expiry date. Expired entries are removed automatically, existing ones can be revoked at any time.

06

Signing in with Discord

You may optionally link your account to a Discord account and then sign in via Discord. Linking uses OAuth 2.0 with Discord Netherlands B.V. respectively Discord Inc.

  • We request the identify scope only, that is, only your Discord user ID.
  • We therefore receive no email address, no messages and no server lists from Discord.
  • We store only the Discord user ID, in order to associate it with your account.
  • Signing in with Discord does not replace two-factor authentication.
  • You can unlink the connection in your profile at any time; the ID is then removed on our side.

The legal basis is your consent given by linking (Art. 6(1)(a) GDPR). When the Discord sign-in is opened, Discord processes data on its own account; the Discord privacy policy applies.

Provider
Discord Netherlands B.V., Amsterdam, Netherlands / Discord Inc., San Francisco, USA
Privacy Policy
discord.com/privacy
07

Projects, tasks & messages

At the heart of the Workspace is working together on projects. In doing so we process the content that you and we put there:

  • Project data such as name, description, status, dates and the people assigned
  • Tasks with title, description, priority, responsibility and progress
  • Messages in the project thread including time, author, reply reference and reactions
  • Feedback from the feedback tool, including the comment, the position on the page and, if one was generated, a screenshot of the view concerned

This content is accessible only to the people assigned to the respective project and to us as the operator. Legal basis: Art. 6(1)(b) GDPR (contract performance).

Messages and feedback can contain personal data if you enter such data there. Please do not enter special categories of personal data under Art. 9 GDPR, such as health data.

08

Files & uploads

Files can be uploaded in the Workspace, for example drafts, images, documents or project backups. Stored are the file itself as well as file name, size, time and the uploading person.

Files are held on the same server in Austria. Access is limited to the people assigned to the respective project. Legal basis: Art. 6(1)(b) GDPR.

Project previews. The preview function allows websites under construction to be viewed inside the Workspace. The respective draft is served; the content of those drafts is the responsibility of the respective project.

09

Contract and invoice data

As part of the business relationship we process the data required for the contract and for billing:

  • Company, contact person, address, email address, phone number and, where available, VAT identification number
  • Contract data and service periods
  • Invoices, amounts and payment status

Encrypted storage. The master data of our business partners, that is email address, phone number, address, postcode and city as well as VAT and ZVR number, is stored encrypted in the database (libsodium) and decrypted only when displayed.

The legal basis is contract performance (Art. 6(1)(b) GDPR) and the statutory retention obligation (Art. 6(1)(c) GDPR in conjunction with the Austrian Federal Fiscal Code). Invoice-related documents are kept for seven years.

10

Email communication

From the Workspace we send service-related emails only. We do not send advertising or newsletters unless you have expressly agreed to it.

Reasons for sending:

  • Invitation and registration confirmation
  • Confirmation codes, for example when resetting the password or changing the email address
  • Invoices and payment reminders
  • Notifications about projects, tasks and messages
  • Security notices about your account
Sent via
SMTP servers of World4You (Austria, EU), encrypted with STARTTLS
Processed data
Email address, name, reason for the message
Legal basis
Art. 6(1)(b) GDPR (contract performance) or (f) (legitimate interest)

No external newsletter or marketing services are used. All data remains in Austria (EU).

11

Cookies & local storage

The Workspace sets only a few cookies, namely those required for operation (Art. 6(1)(f) GDPR, § 165(3) TKG 2021, Austrian Telecommunications Act):

Session cookie
Maintains the sign-in, ends with the session
CSRF token
Protects forms against cross-site requests, valid within the session
Device token
Only if you mark a device as trusted, with an expiry date
cevio_lang
Remembers the language choice German or English, valid for 12 months

In addition, the interface stores individual settings in your browser's local storage. You can delete cookies and local storage at any time through your browser settings; you will then have to sign in again.

12

Logs & security

For traceability and to protect accounts, the Workspace logs security-relevant events:

Sign-in attempts
Email address, IP address, success or failure, time. Basis for the lock after too many failed attempts
Activity log
Who carried out which action and when, with IP address and browser identification

These logs serve IT security, abuse prevention and the traceability of changes to project and business data only. Legal basis: Art. 6(1)(f) GDPR. No evaluation for performance or behaviour monitoring takes place.

13

Usage measurement

We measure usage with a self-hosted solution on our own server. No data is transmitted to third parties, and no service such as Google Analytics is used.

Recorded are page views, the address requested and the page title, the referring address, time on page, pages per visit as well as coarse information about device, browser and operating system.

  • No IP address is stored.
  • No cookie is set. A random identifier in the browser's local storage is used to tell returning visits apart.
  • A visit is considered ended after 30 minutes without activity.
  • The identifier allows no conclusions about your person and is not linked to your account.

The legal basis is our legitimate interest in a data-minimising evaluation to improve the service (Art. 6(1)(f) GDPR). You can prevent the measurement by clearing this site's local storage or by blocking its use in your browser.

14

Third Parties & External Services

We deliberately keep the number of external services small. In use are:

World4You. Hosting of the application, the database and email delivery. All data remains in Austria (EU).

Provider
World4You Internet Services GmbH, Hafenstraße 47-51, 4020 Linz, Austria
Privacy Policy
world4you.com/de/datenschutz

Google Fonts. The Outfit and Syne fonts are loaded from Google servers. Your IP address is transmitted to Google in the process. Legal basis: Art. 6(1)(f) GDPR (consistent presentation).

Provider
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Privacy Policy
policies.google.com/privacy

Discord. Only if you link your account or sign in via Discord, see section 06.

Cloudflare. Individual program libraries are loaded through the cdnjs content delivery network. Your IP address is transmitted to Cloudflare in the process. Legal basis: Art. 6(1)(f) GDPR.

Provider
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Privacy Policy
cloudflare.com/privacypolicy

For transfers to the USA we rely on the Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where applicable, on the EU-U.S. Data Privacy Framework.

15

Processing on our behalf

Where external service providers process personal data on our behalf, data processing agreements under Art. 28 GDPR are in place.

World4You
Hosting, database and email delivery, processing in Austria
Cloudflare
Delivery of program libraries, Standard Contractual Clauses under Art. 46 GDPR

Where we look after your own website or your own bot under a contract and process data of your users in doing so, we act as processor and you as controller. For that case we conclude a separate agreement under Art. 28 GDPR on request.

16

Your rights

Under the GDPR you have the following rights regarding your personal data:

  • Access, you can find out what data we have stored about you (Art. 15 GDPR).
  • Rectification, you can have inaccurate data corrected (Art. 16 GDPR).
  • Erasure, you can request erasure, unless a retention obligation stands in the way (Art. 17 GDPR).
  • Restriction, you can request restriction of the processing (Art. 18 GDPR).
  • Data portability, you can receive your data in a common format (Art. 20 GDPR).
  • Objection, you can object to processing that is based on legitimate interest (Art. 21 GDPR).

Consent you have given, for example for the Discord link, can be withdrawn at any time (Art. 7(3) GDPR). The withdrawal does not affect the lawfulness of the processing carried out until then.

To exercise them, simply send an email to contact@cevio.at. We reply without undue delay, at the latest within one month.

Right to lodge a complaint. You have the right to lodge a complaint with the Austrian supervisory authority:

Supervisory authority
Austrian Data Protection Authority
Address
Barichgasse 40-42, 1030 Vienna
Web
dsb.gv.at
Email
dsb@dsb.gv.at
17

Data Retention

We store personal data only as long as necessary for the respective purpose:

User account
Until the account is deleted
Projects & messages
For the duration of the business relationship, deleted afterwards on request
Uploaded files
Until deleted by you or by us
Confirmation codes
15 minutes, removed automatically afterwards
Sign-in attempts
Short-term, old entries are cleaned up automatically
Trusted devices
Until expiry or revocation
Activity log
For the duration of the business relationship
Invoices and records
7 years (Austrian Federal Fiscal Code)
Usage measurement
Aggregated, without personal reference
Server log files
Short-term, for fault and attack detection
18

Data Security

We implement technical and organisational measures to protect your data from unauthorised access, loss and misuse:

  • TLS encryption throughout, HTTP is redirected to HTTPS, HSTS active
  • Passwords exclusively as a bcrypt hash, never in plain text
  • Mandatory two-factor authentication for access
  • Encrypted storage of sensitive master data and credentials (libsodium)
  • Lock after too many failed sign-in attempts
  • Protection of all forms against cross-site requests (CSRF tokens)
  • Content Security Policy, protection against embedding by third parties and against MIME sniffing
  • Database and configuration lie outside public reach
  • Role and permission system, access only to your own projects
19

Changes to this Privacy Policy

We adjust this policy when the legal situation or our services change. The current version can always be found on this page. We inform registered users by email about significant changes.

Last updated: 18 August 2026