Privacy Notice
1. Controller
Controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the Member States as well as other data protection provisions is: Benedikt Auer - Bennows Benedikt Auer Lindengasse 19 3383 Hürm Österreich VAT ID: ATU78862205 Email: freddymail@bennows.at
The competent supervisory authority is the Austrian Data Protection Authority (Datenschutzbehörde, DSB), Barichgasse 40-42, 1030 Vienna, Austria, phone: +43 1 52 152-0, email: dsb@dsb.gv.at, web: www.dsb.gv.at. We are not legally required to appoint a data protection officer.
2. Definitions
This privacy notice uses the terms defined in the GDPR. In particular, "personal data", "processing", "controller", "processor", "recipient", "consent" as well as the rights of the data subject follow the definitions in Art. 4 GDPR. We deliberately omit a full glossary here for readability.
3. Hosting and server logs
This website is delivered as a purely static site (HTML, CSS, JavaScript, fonts and images) by an nginx web server on a self-administered virtual private server (VPS) running Cloudpanel. No server-side PHP logic and no database are used on the marketing website itself; all dynamic features (forms, licensing) are handled by clearly separated endpoints described below.
On every request, nginx writes an entry to its access and error logs. The following data are processed: the requesting device's IP address, date and time of the request, requested URL and HTTP method, referrer (where transmitted by the browser), user agent (browser and operating system identifier), volume of data transferred and HTTP status code. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the stable operation, the prevention of attacks and the traceability of technical incidents. Logs are automatically deleted or anonymised at the latest after 14 days unless a concrete security incident requires longer retention in a specific case.
Physical delivery is performed from a data centre located within the EU/EEA. A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider. We will provide the name and contact details of the concrete hosting provider on request.
4. Provision of the website and transport encryption
The website is delivered exclusively over encrypted HTTPS (TLS 1.2/1.3). The certificate is issued and renewed automatically by Let's Encrypt (Internet Security Research Group, US). Issued certificates are logged in publicly viewable Certificate Transparency logs (RFC 6962); these logs contain the domain name but no personal data of visitors. The legal basis for using Let's Encrypt is Art. 6(1)(f) GDPR (legitimate interest in a secure, state-of-the-art delivery).
5. Cookies and local storage
We use only the client-side storage mechanisms listed below. Technically, most entries are not classic HTTP cookies but values stored in your browser's "localStorage"; for the sake of transparency we nevertheless treat them like cookies in this notice. The legal basis for technically necessary storage is § 165(3) TKG 2021 in conjunction with Art. 6(1)(f) GDPR; for non-necessary storage (in particular statistics) we obtain your prior consent pursuant to Art. 6(1)(a) GDPR.
- Necessary
- "freddyMailLang" (localStorage) stores the selected language (de/en) so that the site is displayed in your preferred language on subsequent visits; lifetime approx. 12 months. "freddyMailCookies" (localStorage) stores your consent decision as an object of the form { n, a, m, ts }, where n = necessary (always true), a = statistics, m = marketing (currently reserved, not in use) and ts is the timestamp of the decision; lifetime approx. 12 months. These entries are essential for the operation of the site and are set without consent.
- Statistics (consent required)
- "_ga" and "_ga_<measurement ID>" are set by Google Analytics 4 once you have consented to the "Statistics" category (a:true) in the consent banner. Lifetime per Google defaults, typically up to 2 years. Purpose and recipient are described in detail in section 7.
- Marketing
- We currently do not set any marketing cookies and do not embed any corresponding third-party services (e.g. Meta Pixel, LinkedIn Insight Tag, Google Ads). The "m" field in the consent object is reserved for future use and currently defaults to false.
You may withdraw or change your consent decision at any time via the "Cookies" page; the consent banner can be re-opened the same way. In addition, you may delete localStorage and cookies in your browser manually at any time.
6. Consent management
On the first visit, a consent banner is shown that leaves all non-necessary processing (currently only Google Analytics 4) disabled by default. The "Accept all" and "Reject" buttons on the first layer are designed as equivalents (no dark patterns, no colour-preferred button, no pre-ticked boxes). A detail layer allows granular selection of individual categories.
Your decision is recorded together with a timestamp in the "freddyMailCookies" localStorage entry, enabling us to demonstrate consent pursuant to Art. 7(1) GDPR. Withdrawal is possible at any time with effect for the future (Art. 7(3) GDPR), for example by clicking "Change cookie settings" in the footer or on the cookies page, or by clearing the corresponding browser data. The lawfulness of processing carried out before withdrawal remains unaffected.
7. Web analytics with Google Analytics 4
Where you have given your consent, we use Google Analytics 4 (GA4), a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The sole legal basis is Art. 6(1)(a) GDPR. The measurement ID is maintained via the configuration variable PUBLIC_GOOGLE_ANALYTICS_ID and can be inspected in the source code of the served pages.
GA4 processes pseudonymised usage data for reach measurement and the improvement of our offering. The following data in particular are processed: truncated/anonymised IP address (IP anonymisation is a built-in default of GA4 and the full IP is not stored), pseudonymous device and browser identifier, date and time of the request, pages viewed, time spent, click and scroll events, approximate location at city/region level, and technical characteristics (screen resolution, browser, operating system, language). No cross-site tracking across third-party websites takes place and no merging with other data held by us occurs.
For certain parts of the processing (in particular product improvement of GA4) Google acts as an independent controller; for the measurement itself a data processing agreement pursuant to Art. 28 GDPR (Google Ads Data Processing Terms) is in place. The retention period for user-level event data in the GA4 property is configured to 14 months; thereafter the data are automatically deleted. Aggregated report data are retained beyond that period.
A transfer to the United States to Google LLC cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework (DPF); in addition, Standard Contractual Clauses (Art. 46(2)(c) GDPR) are used. Further information: Google Privacy Policy and Google Ads Data Processing Terms.
You may object to the processing at any time by (1) resetting your consent decision via the cookies page, (2) installing the browser add-on to disable Google Analytics at https://tools.google.com/dlpage/gaoptout, or (3) manually deleting the GA cookies and the "freddyMailCookies" localStorage entry in your browser.
8. Checkout, payment and license management via Freemius
The sale, billing and license management of the paid WordPress plugin FreddyMail is handled exclusively by Freemius, Inc., 410 N Scottsdale Rd, Suite 1000, Tempe, AZ 85288, USA ("Freemius"). Freemius acts as Merchant of Record, i.e. Freemius becomes your contractual counterparty for the purchase, handles VAT/tax assessment (incl. EU MOSS/OSS), invoicing, payment processing, license key issuance, subscription management and refunds. We only receive settled payouts and aggregated or transaction-related reports from Freemius in order to comply with our own tax and commercial obligations.
In the course of checkout, the following data — depending on your input — are processed: first and last name, email address, billing address, country, where applicable company name and VAT identification number, payment method (card details are processed exclusively by Freemius or its PCI DSS certified payment service providers, never by us), transaction ID, products purchased, license status, subscription terms and technical metadata (IP address, user agent for fraud prevention). In relation to you, Freemius acts as an independent controller within the meaning of Art. 4(7) GDPR for the purchase transaction; with regard to the provision of licenses to us, an additional processor relationship (DPA) is in place.
The legal basis is Art. 6(1)(b) GDPR (initiation and performance of the purchase contract) and Art. 6(1)(c) GDPR in conjunction with § 132 BAO and § 11 UStG (retention of tax- and commercial-law-relevant records, in Austria generally 7 years). Transfers to the United States are based on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with supplementary technical and organisational measures. The checkout is integrated either via redirection to checkout.freemius.com or by loading the Freemius Overlay Checkout script; in both cases data are only transmitted to Freemius domains once you actively invoke the checkout.
Further information from Freemius: Freemius Privacy Policy, Freemius Terms and Freemius Data Processing Addendum.
9. Support form (Bennows Hub)
When you use the support form on this website, the data you enter are transmitted via HTTPS POST to our own endpoint at https://hub.bennows.at/api/support. "Bennows Hub" is a PHP application with an SQLite database operated by ourselves on a Cloudpanel server we administer in the EU/EEA. The operator and controller is the same entity as for this website (see section 1); it is therefore not a third party but a separate technical component of the same controller.
The following data are processed: name (optional), email address, license key or order reference where applicable, subject, message body, browser and WordPress diagnostics if you submit them, and technical metadata of the submission (timestamp, IP address, user agent). We explicitly do not use any external form provider (e.g. Typeform, HubSpot, Zendesk) and no external bot protection such as Google reCAPTCHA or Cloudflare Turnstile.
The legal basis is Art. 6(1)(b) GDPR insofar as your request serves the initiation, performance or termination of a contract (e.g. license support), and otherwise Art. 6(1)(f) GDPR (legitimate interest in efficient and traceable handling of inquiries). We retain support requests for as long as is necessary to handle them and at most for 24 months after final resolution for traceability and quality assurance, after which they are deleted or anonymised. Tax- and commercial-law-relevant content is handled separately under the applicable statutory retention periods.
10. "Was this helpful?" and documentation feedback
In our documentation you can indicate per page whether an article was helpful and optionally leave an anonymous free-text comment. These data are transmitted via HTTPS POST to https://hub.bennows.at/api/helpful and https://hub.bennows.at/api/feedback respectively, and are only evaluated in aggregated form (counter "helpful"/"not helpful" per article, full text of the optional comment without personal reference). No name or email address is requested; please also refrain from entering personal data in the free-text field. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the continuous improvement of our documentation). Retention until withdrawal of the legitimate interest, at most 24 months.
11. Fonts — self-hosted
This website uses exclusively the "Outfit" font as a variable WOFF2 file, served by us from our own server (path /fonts/). No connection is made to Google Fonts (fonts.googleapis.com, fonts.gstatic.com) or any other font CDN. Therefore, no personal data are transferred to third parties when loading fonts.
12. Embedded content and third-party content
We do not embed any third-party content such as YouTube videos, Vimeo players, Twitter/X widgets, Facebook Like buttons, LinkedIn Insights or Google Maps on this website. The only exception is the Freemius checkout overlay (section 8), which loads scripts and styles from checkout.freemius.com and other *.freemius.com subdomains when you actively click a purchase button. Before this active click, no data are transferred to Freemius.
13. Recipients and processors
We disclose personal data only to the recipients listed below, and only to the extent necessary for the purposes described:
- Hosting provider (data centre operation of the marketing website and the Bennows Hub component) — processor pursuant to Art. 28 GDPR with a data processing agreement in place, data centre located within the EU/EEA; name and contact details available on request.
- Freemius, Inc., 410 N Scottsdale Rd, Suite 1000, Tempe, AZ 85288, USA — independent controller for the purchase transaction and, at the same time, processor for the license provisioning to us; transfer to the United States on the basis of Standard Contractual Clauses (SCC).
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (with possible sub-processing by Google LLC, USA) — processor for web analytics via Google Analytics 4; transfer to the United States under the EU-US Data Privacy Framework and supplementary Standard Contractual Clauses.
No disclosure to any other categories of recipients (e.g. ad networks, data brokers, newsletter providers, external CRM systems) takes place. Disclosure to authorities only occurs where we are legally obliged to do so.
14. Transfers to third countries
Personal data are transferred to third countries outside the EEA only in the following cases: (a) Google Analytics 4 — possible transfer to Google LLC in the United States; safeguarded by Google LLC's certification under the EU-US Data Privacy Framework (Commission adequacy decision of 10 July 2023) and additionally by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. (b) Freemius — transfer to Freemius, Inc. in the United States; safeguarded by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with supplementary technical and organisational measures. No further third-country transfers take place.
15. Retention periods (overview)
- Server logs (nginx, hosting): a maximum of 14 days; thereafter automatic deletion or anonymisation unless a concrete security incident requires otherwise.
- Support requests and documentation feedback (Bennows Hub): for as long as necessary to handle them, at most 24 months after closure; thereafter deletion or anonymisation.
- Google Analytics 4: user-level event data at most 14 months (or per GA4 property configuration); aggregated report data retained beyond that period.
- Freemius (purchase, license and invoicing data): per Freemius' retention policy and applicable statutory retention obligations (§ 132 BAO: typically 7 years).
- Consent record (localStorage "freddyMailCookies"): up to 12 months from the most recent decision; thereafter consent is obtained again.
16. Your rights as a data subject
You have the following rights vis-à-vis us with regard to the personal data concerning you: right of access (Art. 15 GDPR), right to rectification (Art. 16 GDPR), right to erasure (Art. 17 GDPR), right to restriction of processing (Art. 18 GDPR), right to data portability (Art. 20 GDPR) and the right not to be subject to a decision based solely on automated processing (Art. 22 GDPR).
Where processing is based on Art. 6(1)(e) or (f) GDPR, you also have the right to object to the processing at any time on grounds relating to your particular situation (Art. 21 GDPR). Where processing is based on your consent (Art. 6(1)(a) GDPR), you may withdraw it at any time with effect for the future (Art. 7(3) GDPR) without affecting the lawfulness of processing carried out prior to the withdrawal. An informal message to freddymail@bennows.at is sufficient to exercise these rights.
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). In Austria, this is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, phone: +43 1 52 152-0, email: dsb@dsb.gv.at, web: www.dsb.gv.at.
17. Automated decision-making including profiling
We do not carry out any automated individual decision-making including profiling within the meaning of Art. 22(1) GDPR. In particular, we do not perform any automated creditworthiness checks, scoring procedures or automated rejection of orders. Freemius may apply its own fraud prevention and risk mechanisms in the course of payment processing; we have no influence over these and refer to Freemius' privacy policy.
18. Data security
We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR to ensure the security of processing. These include in particular: end-to-end TLS encryption (HTTPS) for all transmissions, up-to-date versions of nginx, PHP (on the Hub component), SQLite and operating system with regular patch management, access restrictions at server and application level, a backup concept with encrypted backups, separation of the marketing website (purely static) from the Hub application, and a consistent principle of data minimisation. Payment data (in particular credit-card and bank data) are at no time stored on systems operated by us; such processing is carried out exclusively by Freemius or its PCI DSS certified payment service providers.
19. Minors
Our offering is directed at businesses, self-employed professionals and adult end users operating WordPress websites. It is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. Should we become aware that such data have been transmitted to us nevertheless, we will delete them without undue delay.
20. Note on the FreddyMail WordPress plugin
This privacy notice exclusively concerns your visit to this marketing website. The FreddyMail WordPress plugin itself runs on the WordPress installations of our customers and may, for example, communicate with Freemius for license validation purposes (Freemius SDK). The data processing performed inside the plugin is described in the plugin-internal privacy and telemetry notes and in the Freemius SDK disclosures, and is not the subject of this notice.
21. Changes to this notice
We reserve the right to adapt this privacy notice if the legal situation, the scope of features or the services used change. The current version is always available on this page. Version date: 14 May 2026; website version: 1.0.12.
22. Contact for data protection inquiries
For any questions, access requests, withdrawals, objections or other data protection matters please contact us informally at: Benedikt Auer - Bennows, Lindengasse 19, 3383 Hürm, Österreich, email: freddymail@bennows.at. We will process your request without undue delay, generally within the statutory period of one month (Art. 12(3) GDPR).