Scope
This notice applies to personal data processed during our proposal, client and project workflows. It particularly concerns prospects, client contacts, project participants and other people whose data is processed in connection with a business relationship with Lupinum OG.
It supplements our website privacy policy.
Controller
Lupinum OG
Innerzaun 26/1
3321 Kollmitzberg
Austria
Phone: +43 681 20303240
Email: info@lupinum.com
Website: www.lupinum.com
Categories of data
Depending on the engagement, we may process:
- identity and contact data such as name, company, role, email address, telephone number and billing information
- communications from emails, calls, meetings, forms, questionnaires, chats and other coordination
- project and service data such as briefs, requirements, content, access details, approvals, tickets, schedules, documentation and technical information
- contractual and billing data such as proposals, orders, invoices, payment information and records
- usage and metadata generated by the tools used in the relevant workflow
Purposes and legal bases
We process this data to:
- respond to enquiries and conduct introductory conversations
- prepare and follow up proposals
- take pre-contractual steps, perform contracts and deliver projects
- document communications, decisions and work results
- develop, provide and maintain client projects
- comply with legal obligations, particularly company and tax law
Depending on the context, processing is based on Article 6(1)(b) GDPR where necessary for pre-contractual steps or contract performance, and Article 6(1)(f) GDPR for the efficient, traceable and secure organisation of our business and project processes.
Proposals and communications
When you contact us, complete a proposal questionnaire or send project documents, we process the information to understand your project, communicate with you and prepare a potential engagement.
Where necessary, information from enquiries, questionnaires, emails or conversations is transferred to our internal systems so that we can document and continue handling the matter.
Communication channels
Depending on the context, we use email, telephone, video calls, messengers and project collaboration platforms. Contact details, communication content, metadata, appointment information, attachments and project documents may be processed through those channels.
We use ALL-INKL for email infrastructure, Slack for internal and shared project communication and, in individual cases, WhatsApp for direct client communication. Processing is based on Article 6(1)(b) GDPR and our legitimate interest under Article 6(1)(f) GDPR in practical, traceable and efficient business communication.
When you contact us through WhatsApp, personal data may also be processed by companies in the Meta group. This communication channel is voluntary. The provider's own privacy information also applies.
Close CRM
We use Close, provided by Elastic Inc. d/b/a Close, to manage enquiries, prospects, proposals and existing client relationships. Contact data, communication content, project information, proposal status and internal notes may be stored and processed.
This processing supports the structured management of our sales and communication processes and is based on Article 6(1)(b) and (f) GDPR.
Further information is available in the Close Privacy Policy and its GDPR information.
GitHub for project development and collaboration
We use GitHub to develop, document and organise client projects. Personal data may be processed where it appears in private repositories, issues, pull requests, commit metadata, documentation or project discussions. This can include names, business contact details, communications, technical project information and content provided during the engagement.
Processing is based on Article 6(1)(b) and (f) GDPR.
Convex for internal systems and project backends
We use Convex for internal systems, particularly CMS and back-office workflows, and in individual cases for project-related backend functions. Content, user data, project information, technical metadata and other data needed for the relevant process may be processed.
Processing is based on Article 6(1)(b) GDPR and our legitimate interest under Article 6(1)(f) GDPR in secure and efficient technical organisation.
Further information is available in the Convex Privacy Policy and Convex DPA.
AI-assisted work tools
We use AI-assisted tools in selected internal work and development processes, particularly to support programming, analysis, structuring, drafting and technical research. Depending on the context, project or client content may be processed where necessary for the relevant purpose.
We aim to minimise data and avoid or reduce personal data wherever possible. Sensitive or unnecessary personal data should not be entered into these systems.
Depending on the context, processing is based on Article 6(1)(b) or (f) GDPR. Providers such as OpenAI or Anthropic may be involved depending on the tool used.
Contracts, invoices and statutory records
We process personal data where required for contractual documents, invoicing, accounting, evidence, warranty matters and compliance with statutory retention and documentation duties. Processing is based on Article 6(1)(b) and (c) GDPR.
Recipients and international transfers
Within our company, data is available only to people who need it for the relevant purpose. Data may also be shared with external service providers and platforms where required for communication, project delivery, technical provision or legal and tax obligations.
Data may be transferred to countries outside the European Economic Area, particularly the United States. According to the relevant providers, transfers rely on appropriate safeguards such as an adequacy decision or standard contractual clauses.
Retention
We retain personal data only for as long as necessary to initiate, perform and document the business relationship or to meet statutory retention duties. Data is deleted or anonymised when no longer required and where no retention obligation applies.
Your rights
Subject to the GDPR, you may have rights to access, correction, deletion, restriction, data portability and objection to processing based on legitimate interests.
To exercise your rights, email info@lupinum.com.
Right to complain
If you believe that processing infringes data-protection law, you may complain to a supervisory authority. Our competent authority is:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
www.dsb.gv.at
Changes to this notice
We update this notice when legal requirements, our processes or the services we use change. The version published here is the applicable version.