Plastered floor slabs with a reddish-brown wooden joint between them

Privacy Policy

Plastered floor slabs with a reddish-brown wooden joint between them

Privacy Policy

Privacy Policy

Privacy Policy

Privacy Policy

The protection of your personal data is of particular concern to us.

We therefore process your data exclusively on the basis of the statutory provisions (GDPR, Austrian Telecommunications Act TKG 2021). In this privacy notice we inform you about the most important aspects of data processing on our website.


We follow a data-minimisation approach: we deliberately refrain from using external advertising trackers, social media pixels or complex analytics suites such as Google Analytics in order to protect your privacy as best we can.

Controller

The controller responsible for data processing on this website within the meaning of Art. 4(7) GDPR is


JM-Locations GesbR
Jan and Markus Schmoltner
Zösenberg 51A, 8045 Weinitzen, Austria

VAT ID: ATU74759148
E-mail: info@jm-locations.com
Phone: +43 664 5403399

Data security (SSL/TLS)

To protect the transmission of confidential content and for security reasons, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the browser's address bar changing from "http://" to "https://" and by the padlock symbol in your browser bar.

Hosting and technical infrastructure (Framer)

This website is not operated on our own servers but is hosted by a specialised service provider ("cloud hosting").


Service provider used

We use the services of Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands ("Framer"). Framer provides the technical infrastructure (web servers, databases, content delivery network) through which our website is delivered. We have concluded a data processing agreement (DPA) with Framer in accordance with Art. 28 GDPR.


Sub-processor Amazon Web Services (AWS)

Framer uses the infrastructure of Amazon Web Services (AWS) as a technical subcontractor. When you visit our website, technically necessary connection data (e.g. your IP address) is transmitted to AWS servers in order to deliver the content to your browser. AWS is a US-based provider.


Third-country transfer and legal basis

Processing is based on our legitimate interest in a secure, fast and reliable provision of our online services (Art. 6(1)(f) GDPR).

Insofar as data is transferred to the USA (third-country transfer), we rely on the following legal mechanisms:


  • Adequacy decision (EU-US Data Privacy Framework):

    The parent company of AWS (Amazon.com Services LLC) is certified under the DPF. The European Commission has determined that certified US companies provide an adequate level of data protection.


  • Standard Contractual Clauses (SCCs): In addition, the EU Commission's Standard Contractual Clauses have been agreed in relation to Framer and its subcontractors.


Server log files

The provider automatically collects and stores information in so-called server log files, which your browser transmits automatically. These are:


  • Browser type and browser version

  • Operating system used

  • Referrer URL (the previously visited page)

  • Host name of the accessing computer

  • Time of the server request

  • IP address


This data is technically essential in order to display the website and ensure security (e.g. to ward off cyberattacks). This data is not merged with other data sources.

Retention period: the log files are stored for a maximum of 30 days to allow analysis in the event of security incidents, and are then deleted automatically.

Content delivery & media hosting (Cloudflare)

So that our videos and media content can be played quickly, securely and smoothly on your device, we use an external storage service (content delivery network / object storage) for these files.


The video files on this website are provided by

Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA ("Cloudflare") (service "Cloudflare R2").


When you open a page containing a video, your browser automatically establishes a direct connection to Cloudflare's servers to load the video file. In doing so, your IP address and technical log data (e.g. browser version, time of access) are transmitted to Cloudflare. Cloudflare processes this data exclusively to deliver the content and to ensure security (DDoS protection). No tracking cookies are set in this context.


This use is based on our legitimate interest in the performant and secure delivery of large media files (Art. 6(1)(f) GDPR). Cloudflare is a US company. The transfer of data to the USA is safeguarded by the following mechanisms:


  • Adequacy decision: Cloudflare, Inc. is certified under the

    EU-US Data Privacy Framework (DPF).


  • Standard Contractual Clauses: In addition, the EU Standard Contractual Clauses (SCCs) are in place.

Web analytics: Framer Insights (cookie-free)

To statistically evaluate the reach of our website, we use the integrated analytics function "Framer Insights".


How it works and anonymisation

Framer Insights works without cookies. No files are stored on your device and no information is read from your device (no use of local storage or "fingerprinting" within the meaning of § 165 TKG 2021).

To count visitors, Framer uses a privacy-friendly procedure:


  • Your IP address and the "user agent" (browser identifier) are transmitted to Framer when a page is accessed.

  • This data is combined server-side with a random value ("salt") and cryptographically hashed.

  • This "salt" rotates automatically every 24 hours.


Result: due to the daily rotation of the key, recognising you across several days or across different websites (cross-site tracking) is technically impossible. No usage profiles are created.


Legal basis:

Since no information is stored on your device, no consent (no cookie banner) is required under § 165(3) TKG 2021. The processing of the IP address (held briefly in the server's working memory) is based on our legitimate interest (Art. 6(1)(f) GDPR) in measuring reach and troubleshooting. Due to the strong pseudonymisation, our interests in statistical evaluation outweigh the intrusion into your privacy.

Communication and forms

If you send us enquiries via the contact form, the details you enter in the enquiry form, including the contact data you provide there (name, e-mail, phone number, message text, selection), are stored by us for the purpose of processing the enquiry and in case of follow-up questions.


Processing is based on Art. 6(1)(b) GDPR (implementation of pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in efficient communication).


Disclosure and infrastructure (e-mail delivery)

The contact form is technically provided by Framer. When you submit it, the data is processed automatically and forwarded to us by e-mail. Framer uses specialised sub-processors for transactional e-mail delivery (e.g. AWS SES or comparable services). This transfer is contractually safeguarded. We delete enquiries once they are no longer required and no statutory retention obligations stand in the way.


Spam protection

To protect against abusive automated submissions (spam bots), the website uses integrated mechanisms (e.g. honeypot fields). This serves the security of our IT systems (Art. 6(1)(f) GDPR).

Locally hosted fonts (web fonts)

This site uses so-called web fonts for the uniform display of typefaces. To protect your data, these fonts are not loaded from external servers (such as Google Fonts) but are stored directly with our hosting provider (Framer).


When you visit our site, your browser downloads the required font files together with the other website data from the Framer infrastructure. No connection to Google's servers is established. Consequently, no data is passed on to Google LLC for the purpose of displaying fonts.

Your rights as a data subject

With regard to your data stored by us, you are in principle entitled to the following rights:


  • Access (Art. 15 GDPR): You can request confirmation as to whether we process data about you.

  • Rectification (Art. 16 GDPR): You can request the correction of inaccurate data.

  • Erasure (Art. 17 GDPR): "Right to be forgotten", provided no retention obligations stand in the way.

  • Restriction (Art. 18 GDPR): You can have processing restricted.

  • Data portability (Art. 20 GDPR): Provision of the data in a machine-readable format.

  • Objection (Art. 21 GDPR): Where processing is based on a legitimate interest (see Framer Insights), you have the right to object at any time on grounds relating to your particular situation.

  • Withdrawal (Art. 7(3) GDPR): Where processing is based on your consent, you may withdraw it at any time.


If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been infringed, you can lodge a complaint with the supervisory authority.

In Austria this is the: Austrian Data Protection Authority

Barichgasse 40-42, 1030 Vienna

E-mail: dsb@dsb.gv.at

LAST UPDATED: 24 August 2026