Skip to content

Privacy Policy

Information according to General Data Protection Regulation (GDPR) and EU AI Act

Note: The legally binding version is available in German. This English version is provided for your convenience.

1. Data Controller

Blck Alpaca e.U.

Maria-Lassnig-Straße 33/1/29
1100 Vienna, Austria

Email: office@blckalpaca.at
Phone: +43 676 451 43 83

2. Data Collection on This Website

Server Log Files

Each time you access our website, information is automatically stored in server log files that your browser automatically transmits to us. This includes: IP address, browser type and version, operating system, referrer URL, hostname of the accessing computer, and time of server request. This data is collected based on Art. 6(1)(f) GDPR.

Delivery and protection by Cloudflare

Our website, our interfaces and our images and videos (media.blckalpaca.at) are delivered through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Every request to blckalpaca.at therefore passes through Cloudflare servers. Cloudflare processes the data that every request involves: IP address, requested address, time, browser identifier and referrer. The purpose is fast delivery through caches close to visitors and protection against attacks and abusive automated access. Images and videos are stored with Cloudflare (R2).

To detect automated access, Cloudflare runs a script in your browser and sets two cookies: “cf_clearance” records the result of the check (stored in the browser for up to one year, although the result itself expires after a short time), and “__cf_ob” holds counters on interaction with the page and is deleted when you close the browser. These cookies serve only to protect the website and are therefore set without consent (§ 165(3) of the Austrian Telecommunications Act, TKG 2021).

Cloudflare also provides the tool for your cookie consent (Cloudflare Zaraz). We store your choice in the cookies “zaraz-consent” (one year) and “ba-consent” (180 days) so that the notice does not appear on every visit. Zaraz also sets the technical cookie “cf_zaraz_client” (one year), which contains no identifier. Zaraz loads services that require consent only after you have agreed; they are listed under “Analytics and marketing with your consent”.

The legal basis is our legitimate interest in a secure website that loads quickly (Art. 6(1)(f) GDPR). Cloudflare processes this data as our processor (Art. 28 GDPR). Data may be transferred to the USA in the process. Cloudflare is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR); in addition, the EU Standard Contractual Clauses apply (Art. 46(2)(c) GDPR). Cloudflare’s privacy information: www.cloudflare.com/privacypolicy/

Contact Form

When you contact us via our contact form, your details from the form including the contact data you provided will be stored for the purpose of processing your inquiry and for follow-up questions. We do not share this data without your consent. Legal basis is Art. 6(1)(b) GDPR.

Cookies

Our website uses cookies. These are small text files stored on your device. We set strictly necessary cookies without consent, for example to protect the website and to remember your cookie choice. Cookies for analytics and marketing are set only with your consent. You can change your choice at any time in the cookie settings.

Web Analytics

Without consent we only use Umami, self-hosted analytics software that works without cookies and without passing data to third parties. With your consent, Google Analytics and Microsoft Clarity are added (see “Analytics and marketing with your consent”).

Web Analytics with Umami

We use Umami, a privacy-friendly, self-hosted analytics solution. Umami collects only anonymized usage data without cookies and without personal information.

Data collected:

  • Anonymized page views
  • Device category (Desktop/Mobile/Tablet)
  • Browser and operating system
  • Approximate location (Country/Region)
  • Referral source
  • UTM parameters for marketing campaigns
  • Scroll depth on pages

Data NOT collected:

  • IP addresses (not stored)
  • Cookies or local storage
  • Personal identification markers
  • Cross-site tracking

Legal basis: Legitimate interest pursuant to Art. 6(1)(f) GDPR for statistical analysis to optimize our website.

Storage location: Own servers in Germany (Hetzner Online GmbH)

Retention period: Aggregated, anonymized data is stored indefinitely for statistical purposes. No individual user profiles are created.

Right to object: Since no personal data is collected, identification and therefore objection is technically not possible. However, you can enable "Do Not Track" in your browser, which is respected by Umami.

Analytics and marketing with your consent

We load the following services through Cloudflare Zaraz only after you agree to the respective category in the cookie settings (“Analytics” or “Marketing”). The legal basis is your consent (Art. 6(1)(a) GDPR, § 165(3) TKG 2021). You can withdraw it at any time with effect for the future in the cookie settings. All three providers belong to groups headquartered in the USA, so data may be transferred to the USA. Google LLC, Microsoft Corporation and LinkedIn Corporation are certified under the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR); the contracts also provide for the EU Standard Contractual Clauses. After your consent, Zaraz also sets the cookie “cfz_zaraz-analytics” (one year), which holds a random identifier that Zaraz uses to count visits.

Google Analytics (category “Analytics”)

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics shows us how visitors use our website, for example which pages they open, where they come from and which devices they use. We integrate Google Analytics server-side through Cloudflare Zaraz: your browser does not connect to Google, Cloudflare transmits the data. We do not pass your IP address on to Google, and we shorten the browser identifier. To recognise your browser on later visits, Zaraz stores a random identifier in the cookies “cfz_google-analytics_v4” (one year) and “cfzs_google-analytics_v4” (until you close the browser) on blckalpaca.at. We have enabled the “Audiences” feature (Google Analytics Audiences): Google can use the visit data to build audiences for advertising in Google services. Google processes the data as our processor (Art. 28 GDPR). Google deletes user-level and event-level data after 14 months at the latest; aggregated reports are kept. Google’s privacy information: policies.google.com/privacy

Microsoft Clarity (category “Analytics”)

The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Clarity records how visitors interact with our pages (clicks, scrolling, mouse movements, page structure) and turns this into heatmaps and session recordings. Input in form fields is masked and not transmitted. Clarity runs in your browser and sends the data directly to Microsoft, including your IP address. On blckalpaca.at Clarity sets the cookies “_clck” (one year) and “_clsk” (one day). Microsoft is an independent controller for this data and also uses it for its own purposes, for example to provide Microsoft Advertising and to build profiles for advertising. We allow Clarity ad-related storage only if you also agree to the “Marketing” category; in that case Microsoft also sets cookies on clarity.ms and bing.com, among them “MUID” (about 13 months). Microsoft keeps session recordings for 30 days, heatmaps and labelled sessions for 9 months. Microsoft’s privacy information: www.microsoft.com/privacy/privacystatement

LinkedIn Insight Tag (category “Marketing”)

The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The Insight Tag measures whether visitors come to us after seeing an ad on LinkedIn (conversion tracking), allows us to show ads on LinkedIn to visitors of our website (retargeting) and gives us aggregated reports, for example on the industry and job function of our visitors. We do not see individual people. For this, your browser sends the address of the page, the referrer, your IP address, the browser identifier and the time directly to LinkedIn. LinkedIn may set cookies on linkedin.com, such as “bcookie” (one year), “lidc” (24 hours) and “UserMatchHistory” (30 days). LinkedIn processes the data as an independent controller. According to LinkedIn, direct identifiers are removed within 7 days and the remaining data is deleted after 180 days. You can also switch off advertising based on your visit in your LinkedIn settings. LinkedIn’s privacy information: www.linkedin.com/legal/privacy-policy

Preferred source on Google

In our articles you will find a link that lets you mark Blck Alpaca as a preferred source in your Google settings. It is an ordinary link to google.com: no Google script is embedded, and no data is transmitted to Google unless you click it. If you do click it, the Google privacy policy applies to your visit to google.com (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; policies.google.com/privacy). The legal basis for providing the link is our legitimate interest in the visibility of our content under Art. 6(1)(f) GDPR.

3. Newsletter

Data Processed & Purpose

When you subscribe to our newsletter, we process your email address along with the timestamp of your registration and confirmation. Processing occurs solely for sending newsletters containing information about our services, products, and offers.

Double Opt-In Procedure

Newsletter registration uses a double opt-in procedure. After signing up, you will receive an email with a confirmation link. Your registration becomes effective only upon clicking this link. This step ensures that no third party can misuse your email address.

Legal Basis

Processing of your data for newsletter delivery is based on your explicit consent pursuant to Art. 6(1)(a) GDPR. We store the time and content of your consent (double opt-in record) to fulfill our documentation obligations.

Service Provider / Data Processor

We use SendGrid (Twilio Inc., 375 Beale Street, Suite 300, San Francisco, CA 94105, USA) for newsletter delivery. Data transfers are governed by EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and the EU-US Data Privacy Framework. The Data Processing Addendum (DPA) is available at twilio.com/legal/data-protection-addendum and forms part of our service agreement.

Email Tracking (Opens & Clicks)

Our newsletters may contain tracking pixels and tracked links that allow us to detect whether and when an email was opened and which links were clicked. We use this information to optimize our newsletters. Processing is based on your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 165(3) of the Austrian Telecommunications Act (TKG 2021). You can prevent tracking by disabling image loading in your email client.

Retention Period

Your email address is stored for as long as your newsletter subscription is active. After unsubscribing, we remove your email address from the active distribution list. The consent record (double opt-in log) is retained for 3 years after unsubscription to fulfill our statutory documentation obligations.

Withdrawal & Unsubscription

You may withdraw your consent to receive newsletters at any time with effect for the future. To unsubscribe, click the unsubscribe link at the bottom of any newsletter or send an email to office@blckalpaca.at. The lawfulness of processing carried out prior to withdrawal remains unaffected.

4. Your Rights under GDPR

Right of Access (Art. 15 GDPR)

You have the right to request information about your personal data stored with us.

Right to Rectification (Art. 16 GDPR)

You have the right to request correction of inaccurate data or completion of incomplete data.

Right to Erasure (Art. 17 GDPR)

You have the right to request deletion of your data, provided there are no legal retention obligations or legitimate interests.

Right to Restriction (Art. 18 GDPR)

You have the right to request restriction of processing of your data.

Data Portability (Art. 20 GDPR)

You have the right to receive your data in a structured, commonly used and machine-readable format.

Right to Object (Art. 21 GDPR)

You have the right to object at any time to the processing of your data for reasons arising from your particular situation.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority:

Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna
dsb@dsb.gv.at

5. Data Security

We use the widespread SSL procedure (Secure Socket Layer) in connection with the highest level of encryption supported by your browser during your website visit. All data you submit to us is transmitted encrypted.

6. AI and Automation

As an AI marketing agency, we use automated systems for data analysis and campaign optimization. This processing always complies with GDPR and the EU AI Act. We guarantee:

  • No automated individual decisions with legal effect without human review
  • Transparency about the use of AI systems
  • Your right to human intervention in automated decisions
  • Regular review of AI systems for fairness and non-discrimination

Is-Agentic EU

Is-Agentic EU examines a website you enter to see how well AI agents can work with it. The check requests only publicly reachable pages of that address. It reads nothing behind a login and changes nothing on the checked site.

For every run we store the checked address, the date and the measurement result. For a run without a report request those are the only details: neither your IP address nor your browser is stored. We process your IP address only transiently to limit requests per hour. If you request the detailed report we additionally store your email address, IP address and user agent, in order to document the delivery and detect abuse. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in being able to trace reports we sent. You can request deletion at any time at office@blckalpaca.at.

Shareable result page

Every run gets a result page at a random, unguessable address. Anyone holding that address sees the measurement findings — the requester’s email address, IP address and user agent are neither shown there nor served through the interface. The page is excluded from search engine indexing.

Result pages are deleted 90 days after the run, together with the entire record. After that the address is invalid. Longer retention happens only on explicit request; you can ask for earlier deletion at any time at office@blckalpaca.at.

Observed agent run (consent required)

Optionally, you can let an AI agent use the checked site. Text content from the publicly retrieved pages is then transmitted to OpenRouter, Inc. (United States) and processed there by a language model. This is a transfer to a third country within the meaning of Chapter V GDPR.

This feature runs only with your explicit consent under Art. 6(1)(a) and Art. 49(1)(a) GDPR. It is off by default and is only offered once you enable the “AI Assistant” category in your cookie settings. Without that consent the run is neither offered nor executed server-side. You can withdraw your consent at any time with effect for the future via the cookie settings.

Only publicly retrievable content of the website you entered, plus the task description, is transmitted. Personal data is transmitted only if such data appears on the public pages of the checked website.

Use through AI assistants (MCP interface)

You can also use the Knowledge Base and our website check (see Is-Agentic EU) through AI assistants such as ChatGPT, Claude, Gemini, Grok or Perplexity. The assistant calls our interface at https://blckalpaca.at/mcp (Model Context Protocol). We receive the individual request, for example a search term, the address of a website to check or the identifier of an article, plus an IP address and the technical identifier of the calling program. We do not receive your conversation with the assistant.

Which IP address we see depends on where the assistant runs. If it runs at the provider, such as ChatGPT or Claude in the browser, it is the address of one of that provider’s servers. If you use a program on your own computer, such as Claude Code or Gemini CLI, the request comes directly from your device and we see your IP address. What the assistant does with your input is the responsibility of its provider under the provider’s own privacy policy.

Apart from the server log files and Cloudflare (section 2), we use the IP address only to limit the number of requests per hour and discard it after one hour at the latest. We do not store search terms. For a website check we store the checked address, the date, the scores and the name of the assistant the request came through, but no IP address. We delete this data and the shareable result page after 90 days. To run the check, our server fetches the website you named. We pass on no data about you, and from the checked page we keep only measurements, not its content.

Links in our answers carry a note on which assistant they came through (UTM parameters). If you open such a link, the visit is treated like any other (section 2). We do not sell this data, build profiles from it or train AI models with it. The legal basis is our legitimate interest in a stable service protected against misuse (Art. 6(1)(f) GDPR). Send questions and requests about your rights to office@blckalpaca.at.

7. Social Media Publishing on Behalf of Clients

For clients who engage us to manage their social media channels, we operate a publishing platform on our own infrastructure within the European Union (Hetzner Online GmbH, Germany). Clients connect their channels themselves via the authorisation process of the respective platform (OAuth). We never receive passwords.

Data processed

Access and refresh tokens of the connected account, public account data (display name, username, profile picture, account identifier), the publishing options for that account as reported by the platform, and the post content released by the client (video, image, text, tagging) including publication time and status messages from the platform.

Purpose and legal basis

Performance of the service contract with the client, Art. 6(1)(b) GDPR. Towards the respective platform we act on behalf of the client.

Recipients

The content and the details required for publication are transmitted to the platform connected by the client, in the case of TikTok to TikTok Technology Limited, Ireland. Processing by TikTok is governed by their privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en

Retention period

Tokens are deleted as soon as the client disconnects the channel or the engagement ends, at the latest 30 days thereafter. Post content and publication logs are kept for the duration of the engagement and deleted afterwards, unless a statutory retention obligation applies.

Withdrawal

Clients can disconnect a channel at any time in our platform as well as in the settings of the respective platform. Our access ends immediately.

8. Retention Period

We only store your personal data for as long as necessary for the purposes for which it was collected or as required by legal retention periods. After the respective period expires, the data is routinely deleted.

9. Disclosure to Third Parties

Your data will only be disclosed to third parties if this is necessary for contract fulfillment, you have expressly consented, or we are legally obligated to do so. Our processors are contractually obligated to comply with GDPR.

10. International Data Transfer

If we transfer data to countries outside the EEA, we ensure through appropriate safeguards (standard contractual clauses, adequacy decision) that your data is adequately protected.

To exercise your rights please contact: office@blckalpaca.at

Last updated: October 2026