Privacy Policy
1. Privacy at a Glance
General Information
The following notes provide a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to identify you personally.
Data Collection on Our Website
Who is responsible for the data collection on this website?
The data processing on this website is carried out by the website operator:
1010 Works GmbH
Seitenstettengasse 5/37, 1010 Wien
Email: hello@postservice.at
2. General Notes and Mandatory Information
Data Protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
Note on the Responsible Controller
The controller responsible for data processing on this website is:
1010 Works GmbH
Seitenstettengasse 5/37, 1010 Wien
Email: hello@postservice.at
Phone: +43 1 9281230
3. Legal Bases of Processing
We process your personal data on the basis of the following legal bases pursuant to Art. 6 GDPR:
- Performance of a contract (Art. 6(1)(b) GDPR): Processing to provide our virtual office services, mail acceptance, scan services and billing.
- Legitimate interests (Art. 6(1)(f) GDPR): Website analysis, fraud prevention, IT security.
- Consent (Art. 6(1)(a) GDPR): Newsletter, marketing cookies, chatbot usage. You can withdraw your consent at any time.
- Legal obligation (Art. 6(1)(c) GDPR): Retention of invoice data pursuant to the Austrian Federal Tax Code (BAO) and Commercial Code (UGB).
4. Data Collection on Our Website
Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the technical provision of the website). The data is automatically deleted after 30 days.
Cookies
Our website uses technically necessary cookies as well as analytics cookies. Technically necessary cookies are required for the operation of the website and are set on the basis of Art. 6(1)(f) GDPR. Analytics cookies are only set with your consent (Art. 6(1)(a) GDPR). You can change your cookie settings at any time via the cookie banner or set your browser so that no cookies are stored.
Contact Form
If you send us enquiries via the contact form, your details from the enquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest). Your data will be deleted once the enquiry has been handled, unless statutory retention obligations apply.
5. Processors and Third-Party Providers
We use the following service providers as processors within the meaning of Art. 28 GDPR. Detailed information on registered office, place of processing, data categories and third-country safeguards can be found in Annex 2 of our data processing agreement.
- Vercel Inc.(USA, processing primarily in the Frankfurt region) – hosting of the website and storage of uploaded documents in Vercel Blob Storage (EU). Transfer on the basis of EU Standard Contractual Clauses.
- Neon Inc.(USA, processing in the Frankfurt region eu-central-1) – managed PostgreSQL database for the platform. Data remains in the EU; transfer on the basis of EU Standard Contractual Clauses.
- Microsoft Ireland Operations Limited(Ireland, EU Data Boundary) – business email communication via Microsoft 365 / Exchange Online.
- Resend, Inc.(USA) – sending of transactional emails. Transfer on the basis of EU Standard Contractual Clauses.
- Chargebee Inc.(headquartered in the USA, EU branch in Amsterdam, operationally also India) – payment processing and subscription management. Transfer on the basis of EU Standard Contractual Clauses.
- EVVA Sicherheitstechnologie GmbH(Vienna, Austria) – AirKey/Xesar access system for the business premises and coworking users. No third-country transfer.
- Google Ireland Limited(Ireland, parent Google LLC, USA) – Google Tag Manager and Google Analytics 4 for pseudonymous reach measurement; active only after consent (Consent Mode v2). Google Ads for conversion tracking. Transfer on the basis of EU Standard Contractual Clauses and an adequacy decision.
- OpenAI, L.L.C.(San Francisco, USA) – conversion pixel measuring contract sign-ups after a click on an ad in ChatGPT; active only after your consent to marketing cookies (Consent Mode v2), transmitting event data without names or email addresses. Transfer on the basis of EU Standard Contractual Clauses.
If you use our services for business purposes and have us process the personal data of third parties (e.g. your own customers) in doing so, we conclude a data processing agreement pursuant to Art. 28 GDPR with you.
6. Retention Periods
We store your personal data only for as long as is necessary for the respective purposes or for as long as statutory retention obligations apply:
- Contract data: For the duration of the contractual relationship and thereafter in accordance with statutory retention periods (7 years pursuant to the BAO).
- Invoice data: 7 years (Section 132 BAO).
- Contact enquiries: Until the enquiry has been handled, no longer than 6 months.
- Server logs: 30 days.
- Analytics data: 26 months (anonymized).
7. Your Rights
You have the right at any time:
- to obtain access to your personal data stored by us (Art. 15 GDPR)
- to request rectification of inaccurate personal data (Art. 16 GDPR)
- to request erasure of your personal data stored by us (Art. 17 GDPR)
- to request restriction of the processing of your personal data (Art. 18 GDPR)
- to object to the processing (Art. 21 GDPR)
- to receive your data in a structured, commonly used format (data portability, Art. 20 GDPR)
Right to Lodge a Complaint with the Supervisory Authority
You have the right to lodge a complaint with the competent data protection authority if you believe that the processing of your personal data infringes the GDPR:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42, 1030 Vienna
Email: dsb@dsb.gv.at
Website: dsb.gv.at
8. Analytics Tools
We use Vercel Analytics on our website to analyze user behavior. This data is collected anonymously and serves to improve our offering. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in optimizing our offering).
9. Secure Connection
For security reasons, this site uses an encrypted HTTPS connection. You can recognize an encrypted connection by the fact that the address bar of the browser begins with "https://".
10. Customer Account Area (Customer Portal)
At konto.postservice.at we offer you a customer account area where you can log in with your email address and view the data we store about you: your master data and booked package, your contract with mail handling profile and contact persons, the list of your shipments, scans of your own mail available for download, and your invoices (number, date, amount, status) including the invoice PDF. You can also set how often you want to be notified by email when new mail arrives.
Login and Session
For login, we process the email address you enter. We generate a one-time random token, of which only a hash value is stored, and send a login link by email. The token is valid for 15 minutes, can only be used once, and is automatically invalidated afterwards. The response to a login request is the same regardless of whether the entered address is known to us. After a successful login, we set a session cookie (see below).
The legal basis is Art. 6(1)(b) GDPR (performance of a contract): the customer account area is an additional access channel to services that are already part of the service contract existing with you. For customers without an active subscription, we base the login on Art. 6(1)(f) GDPR (legitimate interest in winding down the terminated contractual relationship, for example to continue giving you access to mail already delivered and to your contract documents).
Session Cookie
The cookie ps_konto_sessionis technically necessary to keep you logged in during a session in the customer account area. It is set as an httpOnly and Secure cookie with SameSite=Lax, contains no tracking information, and is not used for analytics or advertising purposes. It is valid for 7 days by default and is extended on a rolling basis while you remain active; if you additionally select "stay logged in for 30 days" when logging in, it is valid for a fixed 30 days instead. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a functional, secure login) or Art. 6(1)(b) GDPR. As with the technically necessary cookies described under item 4, no consent via the cookie banner is required for this.
Language Cookie
The customer account area is available in German and English. We store your language choice in the cookie ps_konto_spracheso that it is retained the next time you visit. The cookie only contains the value "de" or "en", no personal data and no identifier, and is valid for one year. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a comprehensible presentation); as a technically necessary cookie, no consent is required.
Recipients
The customer account area runs on the same infrastructure as our website and uses processors already named under item 5:
- Vercel Inc.(USA, processing primarily in the Frankfurt region) – hosting of the customer account area (konto.postservice.at). Transfer on the basis of EU Standard Contractual Clauses.
- Neon Inc.(USA, processing in the Frankfurt region eu-central-1) – storage of the login and account data of the customer account area in the same database as the rest of the platform. Data remains in the EU; transfer on the basis of EU Standard Contractual Clauses.
- Resend, Inc.(USA) – sending of the login email containing the one-time link. Transfer on the basis of EU Standard Contractual Clauses.
- Chargebee Inc.(USA, EU establishment in Amsterdam) – retrieval of your invoice data (number, date, amount, status) and the invoice PDF. Retrieval is performed exclusively server-side by us; your browser does not connect to Chargebee. Transfer on the basis of EU Standard Contractual Clauses, details under item 5.
No further processors are used for the customer account area. Details on location and safeguards can be found under item 5 and in Annex 2 of our data processing agreement.
Retention Period
- Login token: 15 minutes or until used, then automatically invalidated.
- Session cookie:until logout, or until it expires after 7 days (extended on a rolling basis while active) or after 30 days if "stay logged in" was selected.
- Language cookie: one year from your last language selection.
- Invoice data: not stored in the customer account area; it is retrieved from Chargebee on each visit and held in memory for at most five minutes. The retention of the invoices themselves is governed by item 6.
- Contract and master data, shipment list: The same rule applies as for other contract data under item 6: retention for the duration of the contractual relationship, thereafter in accordance with the statutory periods stated there.
- Scans of your mail: During the contractual relationship, scans remain available for retrieval in the customer account area. After the contractual relationship ends, we retain them for 90 days and then delete them.
No Analytics or Advertising Tools
We do not use any analytics or advertising tools in the customer account area: no Vercel Analytics, no Google Tag Manager, no Google Analytics, no cookies for marketing purposes.
Your Rights
The rights described under item 7 apply in full, in particular the right to access, rectification and erasure of the data stored for your customer account. A change to the notification setting made in the customer account area affects only your own record.
Last updated: September 2026