Skip to content
Z DLS Web Design, Hosting & Automation
Back to home

Last updated: 24 August 2026

1. Controller

Dominik Lehner Solutions (DLS)
Owner: Dominik Lehner
Kaisergasse 20, 4020 Linz, Austria
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
Website: https://dl-solutions.at

2. Scope and principles

This privacy policy provides information under Article 13 GDPR about the processing of personal data when you visit this website, submit a project request, submit a support request or contact us directly. DLS processes only the data required for each purpose and uses local processing for support data.

3. Hosting, server logs and strictly necessary cookies

The website and email services are operated by Avernis Communications GmbH, Seeweg 157, 78467 Konstanz, Germany. The provider processes data as a processor. Its systems are located in Germany and therefore within the EU.

When you access the website, technically necessary log data may be generated, in particular the IP address, time, requested address, amount of data transferred, HTTP status, referring page and browser and operating-system information. Processing is required for secure and reliable delivery and to prevent and investigate attacks. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is the operation and security of the website. Log data is deleted when it is no longer required for operation and security. Data affected by a specific security incident may be retained until the incident and any related claims have been resolved.

Joomla uses only strictly necessary session functions, for example to protect forms against misuse. They are not used for audience measurement or advertising. This website currently does not use analytics, marketing or social-media tracking services.

4. Project and general contact requests

When you submit a project or contact request, we process the contact details and message content you provide to answer the request, prepare an offer or take pre-contractual steps. The legal basis is Article 6(1)(b) GDPR. Where no contractual relationship is intended, processing is based on our legitimate interest in orderly communication under Article 6(1)(f) GDPR.

Requests that do not lead to a contract and are no longer required are generally deleted no later than six months after the last substantive contact, unless a legal obligation or legitimate reason requires longer retention.

5. Support requests and local Mission Control

For support requests, we process the name, reply email address, customer number, subject, description, affected website or service, category, priority, additional instruction, desired outcome, technical notes and acceptance criteria.

The support form encrypts the entered content in the browser. Joomla and the email provider transport only an encrypted data package and technical delivery information. Decryption and further processing take place in the local DLS Mission Control. Support content is not automatically transmitted to external AI services. Credentials, passwords and attachments must not be submitted through the form.

Processing is required to assign, handle, document and invoice support services. The legal basis is Article 6(1)(b) GDPR; security, evidence and misuse-prevention measures are based on Article 6(1)(f) GDPR. The required checkbox merely records that this privacy policy has been read and is not consent used as a legal basis.

Support data is retained for the duration of handling and, where required for ongoing contracts, warranty, legal defence or service history, beyond that period. Ticket content that is no longer required is regularly deleted. Data forming part of accounting or business records is retained for the applicable statutory periods.

6. Direct email communication

When you communicate directly by email, the sender and recipient addresses, metadata and message content are processed through the email provider. Depending on the content, the legal basis is Article 6(1)(b) or (f) GDPR. Emails are deleted when they are no longer required for communication or evidence, unless statutory retention duties apply.

7. Customer, contract and invoice data

If an order is placed, we process master data, contact details, service, contract, payment and invoice data to perform the contract, maintain accounts and comply with legal duties. The legal bases are Article 6(1)(b) and (c) GDPR. Accounting records and related documents are generally retained under section 132 of the Austrian Federal Fiscal Code for seven years from the end of the relevant calendar year and, where proceedings are pending, for longer if required.

8. Recipients and transfers

Access is limited to the controller and necessary processors, in particular the hosting and email provider. Disclosure to tax advisers, payment providers, authorities or courts takes place only where required for contract performance, legal duties or the establishment, exercise or defence of legal claims. Personal website and support data is currently not transferred to third countries.

External links lead to services controlled by other organisations. Their respective privacy policies apply.

9. Retention

We retain personal data only for as long as required by the respective purpose, a contract, statutory retention duties or the establishment, exercise or defence of legal claims. It is then deleted or anonymised.

10. Your rights

Subject to the GDPR, you have rights of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is exceptionally based on consent, you may withdraw that consent with future effect. To exercise your rights, email This email address is being protected from spambots. You need JavaScript enabled to view it.. Additional information may be required to verify your identity.

You may also lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, Austria, https://www.dsb.gv.at.

11. Automated decision-making

No decision producing legal or similarly significant effects is made solely by automated means, and no profiling within the meaning of Article 22 GDPR takes place.

12. Updates

This privacy policy is updated when functions, service providers or the legal framework change. The version published on this page applies.