Privacy policy
Status: 13/01/2026
This Privacy Policy informs you about the processing of personal data on the website buddycare-med.com (hereinafter “Website”).
1. Controller
BUGSLOCK GmbH
St. Stefan 106, Gewerbe-Zone West, A-9142 Globasnitz, Austria
Tel.: +43 1 236 1919
E-mail: info@bugslock.at
Data protection contact:** Thomas Thonhofer
Contact: info@bugslock.at (subject: “Data Protection – attn. Thomas Thonhofer”)
2. Legal bases
We process personal data only if a legal basis applies. Depending on the purpose, the following legal bases may apply in particular:
– Art. 6(1)(f) GDPR (legitimate interests, e.g. secure operation of the Website)
– Art. 6(1)(a) GDPR (consent, e.g. web analytics / external media)
– Art. 6(1)(b) GDPR (pre-contractual measures/contract, e.g. inquiries)
– Art. 6(1)(c) GDPR (legal obligation)
In addition, for the use of cookies/similar technologies, the provisions of the **Austrian Telecommunications Act 2021 (TKG 2021)** apply (in particular consent for non-essential technologies).
3. Hosting (Hetzner) and server log files
Our Website is hosted by **Hetzner Online GmbH, Germany.
When you access the Website, so-called server log files are processed for technical reasons, in particular:
– IP address or technically necessary connection data
– Date/time, page/file accessed, status codes
– Referrer URL
– Browser type/version, operating system
Purpose: delivery of the Website, stability, error analysis, IT security.
Legal basis: Art. 6(1)(f) GDPR.
Storage period: as short as possible; in the event of security incidents until clarification.
An data processing agreement (Art. 28 GDPR) exists with the hosting provider.
4. Contact (contact form, e-mail, telephone)
If you contact us (e.g. via the contact form, e-mail or by telephone), we process the data you provide (e.g. name, e-mail address, telephone number, message/inquiry) to process and respond.
Purpose: processing your inquiry and communication.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures/contract) or Art. 6(1)(f) GDPR (legitimate interest in efficient processing).
If consent is requested in the form, additionally Art. 6(1)(a) GDPR.
Storage period: until the inquiry has been fully processed; beyond that only if statutory retention obligations apply or this is necessary for legal enforcement.
5. Cookies / consent management
We use cookies and similar technologies in the following categories:
– Necessary (required for the operation of the Website)
– Statistics (Google Analytics 4 – only with consent)
– External media (Google Maps – only with consent)
Non-essential cookies/technologies are only set or read after your **consent**. You can change your selection at any time or withdraw consent with effect for the future (via the cookie/consent settings).
6. Google Analytics 4 (web analytics)
We use Google Analytics 4 to measure reach and improve the Website.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: statistics/analysis, optimization of our web presence.
Data processed (typically):
– usage/interaction data (e.g. page views, clicks, time spent)
– device/browser information
– approximate location information (derived)
– cookie/device identifiers
Legal basis: Art. 6(1)(a) GDPR (consent).
Google Analytics is only activated when you consent to “Statistics” in the cookie banner.
IP address: Google Analytics 4 does not log IP addresses. For EU-based traffic, the IP address may be used to derive approximate location data and then discarded.
Storage period: We use a retention period for event data of up to 14 months.
If Google Signals is used, longer retention (e.g. up to 26 months) may be possible.
Withdrawal: You can withdraw your consent at any time (via the cookie/consent settings).
Further information: Google Privacy Policy: https://policies.google.com/privacy
7. Google Maps (maps)
We integrate Google Maps to display maps/location information.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When the map is loaded, a connection to Google servers is established. In particular, the IP address, device/browser data and usage data (e.g. map access/interactions) may be processed.
Legal basis: Art. 6(1)(a) GDPR (consent).
Google Maps is only loaded when you consent to “External media” in the cookie banner (or actively enable the map).
Google Privacy Policy: https://policies.google.com/privacy
8. Recipients / processors
Recipients of your data may include:
– Hetzner Online GmbH** (hosting; processor)
– Google** (Analytics/Maps – only with consent)
9. Transfer to third countries (e.g. USA)
With Google services, processing outside the EU/EEA (e.g. USA) cannot be ruled out.
Where required, transfers take place on the basis of appropriate safeguards (e.g. adequacy decision and/or standard contractual clauses) and additional protective measures.
10. External links (e.g. webshop / pharmacy finder)
Our Website may contain links to external websites. If you click such a link, you leave our Website. The respective operator is solely responsible for processing your data on the linked pages.
11. Social media links
The Website may contain links to social media platforms (e.g. Facebook, Instagram, LinkedIn). With pure links, personal data is generally only transmitted to the respective platform when you actively click the link.
12. Storage period (general)
We store personal data only for as long as this is necessary for the purposes stated or as long as statutory retention obligations exist.
13. Your rights
You have the right to:
– access (Art. 15 GDPR)
– rectification (Art. 16 GDPR)
– erasure (Art. 17 GDPR)
– restriction of processing (Art. 18 GDPR)
– data portability (Art. 20 GDPR)
– objection (Art. 21 GDPR)
You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
Right to lodge a complaint: You can lodge a complaint with a supervisory authority. In Austria, the competent authority is the Austrian Data Protection Authority (DSB), Barichgasse 40–42, 1030 Vienna, Austria
Tel.: +43 1 52 152-0, E-mail: dsb@dsb.gv.at, Website: https://dsb.gv.at
14. Data security (TLS/SSL)
We use technical and organizational security measures. Transmission is generally encrypted (HTTPS/TLS), provided your browser supports this.
15. Changes
We will adapt this Privacy Policy if our data processing, the Website or the legal situation changes. The respective current version on the Website applies.