Legal
Privacy Policy
Updated: 5 September 2026
1. Controller
NEXORA Unternehmensberatung GmbH, Franz-Josefs-Kai 27/DG/9, 1010 Wien, Austria · office@nexora-consulting.at · +43 690 200 210 14 · https://nexora-consulting.at.
2. Categories and sources
- Contact/communication data.
- Contract, project, invoice and payment data.
- KYC/compliance data where necessary and lawful, including identity/representation, ownership/control, beneficial-owner and screening data.
- Website/technical data including IP address, timestamps, device/browser, accessed content, referrer, log/security data and consent settings.
- Personal data processed in consulting projects concerning clients, their corporate bodies, employees, business partners or other participants.
3. Article 14 GDPR
Data may come from the data subject, clients and their bodies/employees, authorised representatives/professional advisers, public registers such as Firmenbuch/GISA, public authorities, lawfully accessible public sources, project counterparties and, where necessary and lawful, sanctions/PEP/compliance sources. Where data are not collected from the data subject, NEXORA provides Article 14 information within the statutory periods unless an Article 14(5) exception applies.
4. Purposes and legal bases
Enquiries/pre-contract steps: Article 6(1)(b) GDPR where the data subject is or intends to become the contracting party; otherwise Article 6(1)(f) GDPR for B2B communications.
Contract/project administration: Article 6(1)(b) GDPR for the contracting party; Article 6(1)(f) for contacts, corporate bodies/employees of legal entities and project organisation.
Accounting/legal duties: Article 6(1)(c) GDPR.
KYC/sanctions/compliance/conflicts: Article 6(1)(c) where a specific duty applies. AML duties under §§ 365m et seq. GewO apply to management consultants only where NEXORA performs an activity within the statutory scope, in particular § 365m1(2)(3) GewO. Outside that scope, necessary checks may rely on Article 6(1)(b) or (f).
IT security/legal claims: Article 6(1)(f) GDPR.
Newsletter/regulatory briefing: The permissibility of sending electronic mail for direct-marketing purposes is governed by § 174 TKG 2021. Prior consent is generally required under § 174(3) TKG 2021; the existing-customer exception in § 174(4) TKG 2021 applies only where all statutory conditions are satisfied. The processing of personal data for managing recipient lists, consents, objections and evidence of dispatch is additionally governed by the GDPR. Unsubscription or objection is possible at any time.
Optional analytics/marketing: Article 6(1)(a) GDPR together with § 165(3) TKG 2021 where consent is required.
5. Controller / processor roles
NEXORA generally acts as controller for its own contract administration, KYC/compliance, accounting, website operation and internal organisation. Where NEXORA processes personal data solely on behalf of and on documented instructions from a client, NEXORA acts as processor and enters into an Article 28(3) GDPR DPA before such processing. Mere access to personal data does not by itself make NEXORA a processor.
6. Recipients and providers
- Hosting/infrastructure/database providers; according to NEXORA’s currently published description, in particular Vercel Inc. and Neon Inc.
- Communications/email providers, in particular Google Ireland Ltd. / Google Workspace.
- Consent-based analytics/marketing providers; according to the currently published description, Google Ireland Ltd. (Google Analytics / Tag Manager), Microsoft Ireland Operations Ltd. (Clarity) and Meta Platforms Ireland Ltd. (Meta Pixel).
- External AI/digital-tool providers only where actually used and a lawful basis and appropriate safeguards exist.
- Subcontractors, independent regulated professionals, public authorities, courts, banks or other project bodies where necessary and lawful.
7. Third-country transfers
Transfers outside the EU/EEA occur only under Articles 44 et seq. GDPR, in particular an adequacy decision under Article 45 or appropriate safeguards under Article 46 such as EU Standard Contractual Clauses and supplementary measures. This Policy does not claim a specific recipient is certified unless separately verified.
8. Retention
Server/security logs: under NEXORA’s currently published configuration, generally 7 days unless longer retention is lawfully required.
Contact enquiries without a contract: until completion and thereafter only as required for documented follow-up, legal duties or legal claims.
Books/accounting/business records subject to statutory retention: generally 7 years under § 132 BAO and § 212 UGB, longer where required for proceedings.
AML/KYC records: where GewO AML rules apply, generally 5 years under § 365y GewO, subject to lawful extensions.
Other contract/project records and consent/newsletter evidence: as long as necessary for the relevant purpose, legal duties and legal claims.
9. Cookies
Strictly necessary functions are used to the extent required. Non-essential analytics/marketing technologies are activated only after valid consent where § 165(3) TKG 2021 requires consent. See Cookie Policy and consent-management tool.
10. Rights and complaints
Subject to statutory conditions, data subjects have rights under Articles 15–21 GDPR and may withdraw consent for the future under Article 7(3). Requests: office@nexora-consulting.at. Complaints may be lodged with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, https://dsb.gv.at.
11. Automated decisions
NEXORA does not, in connection with the website or ordinary onboarding, make solely automated decisions under Article 22 GDPR with legal or similarly significant effects.
12. Security and confidentiality
NEXORA uses risk-appropriate technical and organisational measures under Article 32 GDPR. Employees are bound by confidentiality/data-secrecy duties under § 6 Austrian DSG and other applicable rules.
13. Changes
This Policy is updated if the legal framework, processing activities or technologies actually used materially change. The current published version applies.