This policy explains transparently which personal data Jürgen Mews processes when you visit this website or send an enquiry, why the data is needed and which rights you have.
Last updated: 14 August 2026 · GDPR · Austrian DSG · TKG 2021
NecessarySecure website operation
Session, form protection and technically required log data.
Your enquiryPurpose-bound processing
Contact details, project answers and optional technical documents.
Your controlRights under the GDPR
Access, rectification, erasure, restriction and objection.
1. Controller
Jürgen Mews
Obdacher Straße 116
9462 Bad St. Leonhard im Lavanttal
Austria
Email: info@mews-st.com
Phone: +43 4350 20177
Jürgen Mews is the controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG). You may also use the stated email address for access, rectification, erasure, withdrawal, objection or any other privacy-related request.
No data protection officer is currently appointed because, based on the present assessment, there is no statutory appointment obligation.
2. Principles and legal bases
We process personal data lawfully, transparently, for specified purposes and only to the extent necessary. Data usually comes directly from you or is generated technically when you use this website.
Depending on the activity, processing is based in particular on your consent (Art. 6(1)(a) GDPR), your enquiry and pre-contractual steps (Art. 6(1)(b)), compliance with legal obligations (Art. 6(1)(c)), or legitimate interests in secure, stable and economical website operation and in handling business enquiries (Art. 6(1)(f)).
3. Website access, hosting and server logs
When you access the website, your browser transmits technically required information to the server infrastructure. This may include IP address, date and time, requested address, referrer, browser and operating-system information, transferred data volume and status code.
Processing is required to deliver the website, maintain system security, analyse faults and prevent attacks and misuse. The legal basis is Art. 6(1)(f) GDPR. Hosting and infrastructure companies may be engaged as processors subject to instructions under Art. 28 GDPR.
4. Cookies and technically necessary technologies
The website uses technically necessary cookies for sessions, form protection and secure operation. Access to information on the terminal device is based, where strictly necessary to provide the service expressly requested, on section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021); optional technologies require prior consent.
External advertising, social media or analytics cookies are currently not active. An internal visitor identifier is set only if the internal statistics function is activated. Identifiers for Google Analytics, Meta, LinkedIn, TikTok, Microsoft Clarity or comparable services are currently not integrated.
Name
Purpose
Category
Duration
mews-studio-session
Session, form state and secure navigation
Technically necessary
Up to 120 minutes of inactivity
XSRF-TOKEN
Protects forms against unauthorised requests
Technically necessary
Up to 120 minutes
mews_visitor_id
Internal pseudonymous visitor statistics, if activated
5. Technical project check and questionnaire answers
When you open and use the technical project check, a random process identifier, status, current step, selected answers, source page, IP address, browser identifier and start, activity, completion or abandonment timestamps may be stored. This enables the process to be provided and improved and allows a subsequently submitted enquiry to be assigned correctly.
For a completed project enquiry, the enquiry category, type of requirement and urgency are attached to your contact data. All answers are included in the enquiry email. The legal basis is Art. 6(1)(b) GDPR and, for technical delivery and misuse prevention, Art. 6(1)(f) GDPR.
6. Contact form, project enquiry and file uploads
When you submit a contact form, we process first and last name, email address, optional telephone number, subject, message, language, source page and timestamp. Project enquiries additionally contain the company, questionnaire answers, technical details and any uploaded photographs, drawings or specifications.
The information is processed to contact you personally, perform a technical review, prepare an offer and take pre-contractual steps. Required fields are identified in the form. Without the necessary contact and enquiry data, the request cannot be handled. The legal basis is Art. 6(1)(b) GDPR and, where express consent is relevant, Art. 6(1)(a).
Please upload only documents necessary for the technical review and remove unnecessary personal or confidential information. Permitted files are stored with access protection together with the enquiry and may be attached to the enquiry email.
7. Email delivery and recipients of enquiries
Contact and project enquiries are stored in the protected application and are always transmitted to bitclub@eloquin.de for processing. Where technically possible, the email address you provide is used as the reply-to address so that a direct response can be sent.
Access is limited to Jürgen Mews and persons or technical service providers who require it for processing, IT operation, hosting, email delivery, maintenance or security. Email and hosting providers are engaged as processors under Art. 28 GDPR where required.
8. Location map using Google Maps
The contact page embeds a Google Maps map. When the map loads, your browser connects directly to Google servers. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland may receive and process in particular your IP address, device and browser information, referrer, time and map usage.
Google may also transfer data to Google LLC and other group companies in the United States. According to Google, transfers to third countries are based on applicable adequacy decisions, certifications or standard contractual clauses. Google’s privacy policy applies to Google’s further processing.
The purpose is to provide a convenient presentation of our location. The legal basis is Art. 6(1)(f) GDPR, reflecting our interest in clear directions; where consent is required for storing or accessing device information, Art. 6(1)(a) GDPR in conjunction with section 165(3) TKG 2021 applies.
The application provides an internal statistics and heatmap function. If activated, it may process a pseudonymous visitor identifier, hashed IP address, session identifier, requested URL, referrer, campaign parameters, country, browser, device, operating system, timestamp, click position and label of the clicked element.
Form contents and technical project details are not included in the heatmap. The function is currently disabled. Before optional analytics or third-party services are activated in the future, the required consent mechanisms and this privacy policy will be updated.
10. Retention and erasure
We retain personal data only for as long as it is required for the relevant purpose. It is then erased or anonymised unless statutory retention obligations, legitimate evidence requirements or pending claims require continued retention.
Session and CSRF data: generally up to 120 minutes after the last activity.
Unsubmitted project-check sessions: until they are recognised as abandoned and removed during regular data maintenance.
Contact and project enquiries including uploads: for the duration of processing and thereafter in accordance with applicable corporate, tax and civil-law retention and limitation periods.
Server logs: according to the security and deletion schedules of the hosting provider; longer retention only for a specific security incident.
Optional statistics: until the end of the defined analysis period or until withdrawal or deactivation, where attribution remains possible.
11. Your data protection rights
Subject to statutory requirements, you have rights to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Consent may be withdrawn at any time with future effect; processing carried out before withdrawal remains lawful.
To exercise your rights, send a message to info@mews-st.com. To prevent unauthorised disclosure, we may request suitable proof of identity. Under Art. 77 GDPR, you also have the right to lodge a complaint with a supervisory authority, in particular the Austrian Data Protection Authority.
We use appropriate technical and organisational safeguards, including encrypted transmission, CSRF protection, server-side validation, access restrictions and protected administration areas. Absolute protection of electronic communications cannot nevertheless be guaranteed.
The website is intended for businesses and professional users and is not specifically directed at children. We do not knowingly process children’s data for marketing purposes.
We update this policy when website features, recipients, service providers or the law change. The version published on this page is authoritative. New processing that requires consent will not be activated merely by changing this text.