Skip to content
LEGAL

Privacy Policy

This is a convenience translation. The German version is legally authoritative.

1. Privacy at a glance

General information

Personal data is any data that can be used to identify you personally. This policy describes which data is collected when you visit this website, what it is processed for, and which rights you have.

Data collection on this website

Data processing is carried out by the website operator. Data is collected through direct communication (e.g. contact form, lead magnet sign-up, contract check upload). Technical data is collected automatically when the website is visited (log files).

2. Controller

RiFa Holding & Advertising GmbH
Emil von Behringstraße 14
9500 Villach, Austria
Email: fabian@fulfillment-experte.com
Phone: +43 4242 38685

3. General information on data processing

Legal bases

  • Art. 6(1)(a) GDPR (consent)
  • Art. 6(1)(b) GDPR (contract performance, pre-contractual measures)
  • Art. 6(1)(f) GDPR (legitimate interest)

Storage period

Personal data is only stored for as long as is necessary for the respective purpose or as long as statutory retention periods apply. Specific storage periods can be found with the respective services below.

4. Your rights

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint with the supervisory authority

Contact to exercise your rights: fabian@fulfillment-experte.com

Competent supervisory authority in Austria: Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

5. Data collection on this website

Server log files

The hosting provider (Vercel Inc.) automatically collects information that your browser transmits: browser type and version, operating system, referrer URL, IP address (truncated), time of the request, HTTP status code. Legal basis: Art. 6(1)(f) GDPR. Storage period: 14 days.

Contact form and email

If you contact us via the contact form or by email, the data you provide is stored to process your enquiry and is not passed on without your consent. Legal basis: Art. 6(1)(b) GDPR. Storage period: until your enquiry has been fully dealt with, unless statutory retention obligations apply.

Cookies and consent management

This website uses no tracking or marketing cookies. In normal operation, only technically necessary cookies are used — in particular a first-party cookie (fe_consent) that stores your cookie decision together with the timestamp for a maximum of 180 days. The legal basis for this is § 165(3) TKG 2021 in conjunction with Art. 6(1)(c) and (f) GDPR (technical necessity and proof of consent).

External services that may transfer personal data to third parties (currently the Cal.com booking calendar) are only loaded after your explicit consent. As long as no consent has been given, a placeholder is shown in their place. You can change or withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer (Art. 7(3) GDPR). On your first visit, a notice banner also informs you; declining optional services is just as easy as accepting them.

6. External services

Hosting — Vercel

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel is certified under the EU-US Data Privacy Framework. A data processing agreement under Art. 28 GDPR exists between RiFa Holding & Advertising GmbH and Vercel Inc.

Database — Neon (Postgres)

Subscriber data (email, status, tokens, audit trail) is stored at Neon in an EU region (Frankfurt). Provider: Neon Inc., USA. EU-region data residency. Legal basis: Art. 6(1)(b) GDPR (contract performance to deliver the requested guide).

Email delivery — Resend

Confirmation and welcome emails are sent via Resend. Provider: Resend, Inc., USA. EU-US Data Privacy Framework certified. Data: email address, mail content. Legal basis: Art. 6(1)(b) and (a) GDPR.

Appointment booking — Cal.com (EU)

Cal.com (EU region: cal.eu) is used for appointment scheduling. The calendar is loaded only after your explicit consent (Art. 6(1)(a) GDPR); only then does your browser establish a connection to Cal.com. When you book an appointment, your name, email and preferred time are collected directly by Cal.com. You can withdraw your consent at any time via the cookie settings. Privacy policy: cal.com/privacy.

7. Newsletter / lead magnet

If you request the guide (“23 clauses every 3PL contract contains”), we collect your email address and send a confirmation email (double opt-in). Only after confirmation are you added to the newsletter list and sent the guide link.

Data: email address, confirmation and unsubscribe tokens, source of sign-up (audit trail), truncated IP address, user-agent at the time of sign-up.
Legal basis: Art. 6(1)(a) GDPR (consent).
Storage period: until you unsubscribe. Unconfirmed sign-ups are deleted automatically after 7 days.
Withdrawal: at any time via the unsubscribe link in every email or by message to fabian@fulfillment-experte.com.

8. Contract check (file upload)

If you upload a 3PL contract as part of the free contract check, the file, email address and company name are processed in order to send you a professional assessment within 48 hours.

Storage location: Vercel Blob (encrypted).
Storage period: a maximum of 90 days, then automatic deletion.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at your request).

9. Analytics and advertising

This website uses no classic analytics tools such as Google Analytics and no marketing or profiling cookies.

Vercel Web Analytics: Vercel Web Analytics is used for aggregated traffic measurement. Measurement is cookieless and without cross-site tracking; no personal profiles are created. Provider: Vercel Inc., USA (EU-US Data Privacy Framework). Data: anonymised page-view statistics, truncated technical details. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in data-minimising, anonymous traffic measurement). As no information is stored on or read from the device, no consent is required for this.

Plausible Analytics (optional): In addition, Plausible Analytics (cookieless, without personal data, provider: Plausible Insights OÜ, Estonia) may be used. Legal basis: Art. 6(1)(f) GDPR.

Fonts — Google Fonts (self-hosted)

This website uses fonts from the Google Fonts library, which are, however, delivered locally from our own server(self-hosting via the framework). When the page is loaded, no connection to Google servers is established and no personal data is transmitted to Google.

10. Security

Technical and organisational security measures are taken to protect data against loss and unauthorised access. Transmission takes place exclusively over TLS-encrypted connections (HTTPS).

11. Changes to this privacy policy

We reserve the right to adapt this privacy policy so that it always complies with current legal requirements.

LAST UPDATED: MAY 2026