Legal
Privacy Policy
Information on the processing of personal data in accordance with the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG). Last updated: July 2026.
This is a courtesy translation. The German version (Datenschutzerklärung) is the legally binding version.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) is:
XENTRA GmbH
Leopold-Kronsteiner-Straße 5
4060 Leonding
Austria
Phone: +43 720 302010
Email: office@xentra.at
Companies Register number: FN 678593g
Companies Register court: Landesgericht Linz
VAT ID: ATU83306012
2. Data Protection Officer
Under Art. 37 GDPR, our company is not required to appoint a data protection officer. If you have any questions about data protection, please contact us directly using the contact details listed under section 1.
3. General Information on Data Processing
3.1 Scope of Processing
As a matter of principle, we process personal data of our users only to the extent necessary to provide a functioning website and our content and services. Processing takes place regularly only with the consent of the data subject or where a statutory legal basis applies.
3.2 Legal Bases
Where we obtain consent for processing operations, Art. 6(1)(a) GDPR serves as the legal basis. For processing necessary for the performance of a contract or for pre-contractual measures, Art. 6(1)(b) GDPR serves as the legal basis. Where processing is necessary to comply with a legal obligation (for example statutory retention obligations under tax law), Art. 6(1)(c) GDPR serves as the legal basis. Where processing is necessary to safeguard a legitimate interest of our company or a third party, and the interests of the data subject do not override that interest, Art. 6(1)(f) GDPR serves as the legal basis.
3.3 Storage Period and Erasure
Personal data is erased or blocked as soon as the purpose of storage no longer applies. Storage beyond that period only takes place where required by statutory retention obligations (for example 7 years pursuant to Section 132 of the Austrian Federal Fiscal Code, BAO, for tax-relevant records).
4. Provision of the Website
4.1 Hosting
Our website is hosted on our own server, operated in a data centre in Austria. Since the server is operated under our own responsibility, no data processing within the meaning of Art. 28 GDPR by an external web host takes place in this respect.
4.2 Server Log Files
Each time our website is accessed, data and information are automatically collected from the system of the accessing device. The following data is collected:
- IP address of the user (shortened/anonymised where technically possible)
- Date and time of access
- Page/file accessed and volume of data transferred
- Notification of successful retrieval (HTTP status code)
- Browser used and its version
- Operating system used
- Referrer URL (previously visited page)
This data is stored in the log files of our server. It is not combined with other personal data. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and stable operation of the website and in defending against attacks). Storage period: 30 days.
4.3 SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the browser address bar changing from "http://" to "https://" and by the padlock symbol in your browser bar.
5. Use of Cloudflare (CDN and Security Service)
On our website we use the Cloudflare service provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) as a content delivery network (CDN) and for protection against abusive use and DDoS attacks. Cloudflare routes the traffic between your browser and our server through its globally distributed servers. In doing so, Cloudflare processes in particular:
- IP address of the visitor
- Content accessed and time of access
- Browser and device information
- Technically necessary cookies (for example "__cf_bm" for bot detection)
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website in a secure, high-performance and fail-safe manner and in protecting it against cyberattacks. A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with Cloudflare. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, EU Standard Contractual Clauses are used. Personal data may be transferred to the USA. Further information: cloudflare.com/privacypolicy
6. Contact and Applications
If you contact us by email, phone, WhatsApp or via the contact form on our website, we process the data you provide (in particular your name, contact details, the content of your message and the time of transmission) in order to handle your enquiry.
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures or performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in the efficient handling of enquiries). Your data is erased once your enquiry has been fully dealt with and no statutory retention obligations stand in the way.
WhatsApp: If you contact us via WhatsApp, WhatsApp Ireland Limited (4 Grand Canal Square, Dublin 2, Ireland; parent company Meta Platforms, Inc., USA) additionally processes metadata of your communication in accordance with its own privacy policy (whatsapp.com/legal). Use of this channel is voluntary; you can always address the same matters to us by email or phone.
Applications: If you submit an application to us, we process your applicant data (CV, qualifications, references, contact details) to carry out the application process and to place you with or assign you to our client companies. The legal basis is Art. 6(1)(b) GDPR. Your data is only passed on to client companies after consultation with you. Applicant data is erased no later than 7 months after the process has been completed, unless you have consented to a longer storage of your data in our applicant database (talent pool) (Art. 6(1)(a) GDPR); you may withdraw this consent at any time.
7. Cookies
This website does not use any cookies for analytics, marketing or tracking purposes. Only technically necessary cookies are used that are required for the secure operation of the website (in particular the Cloudflare security cookie "__cf_bm" for bot detection, see section 5).
Legal basis: Art. 6(1)(f) GDPR and Section 165(3) of the Austrian Telecommunications Act (TKG 2021). As no cookies requiring consent are set, no cookie banner is required. Should analytics services be used in the future, this will only take place with your express consent; this Privacy Policy will then be updated accordingly.
8. Google Maps (Only with Your Consent)
On our contact page we offer a directions map from Google Maps, a map service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), parent company Google LLC (USA).
When the page is loaded, the map is initially deactivated. No data is transferred to Google. Only when you actively click "Load map" is the map embedded. In doing so, your IP address, browser and device information and, where applicable, location data are transferred to Google; Google may set its own cookies. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you give by clicking. Personal data may be transferred to the USA (see section 10).
Further information: policies.google.com/privacy
9. Recipients of Personal Data
In providing our website, we use the following service providers:
- Cloudflare, Inc. (USA): CDN, DDoS protection, security
- Google Ireland Limited (Ireland) / Google LLC (USA): Google Maps map service, only with your consent (click)
- WhatsApp Ireland Limited / Meta Platforms, Inc. (USA): only if you contact us via WhatsApp (see section 6)
In addition, we pass on applicant data to our client companies after consultation with you, where this is necessary for placement or assignment (see section 6).
Where required, data processing agreements pursuant to Art. 28 GDPR have been concluded with the service providers mentioned. Our website also contains links to external services (for example WhatsApp, our job portal). Simply visiting our website does not transfer any data to these services; only when you click such a link do you enter the area of responsibility of the respective provider.
10. Data Transfers to Third Countries
In connection with the services mentioned under sections 5, 6 (WhatsApp) and 8, personal data may be transferred to the USA. Such transfers take place on the following bases:
- EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023) for certified companies
- EU Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR
- Where applicable, your express consent pursuant to Art. 49(1)(a) GDPR (in particular for Google Maps)
Please note that the USA currently does not provide a level of data protection comparable to EU law within the meaning of the GDPR. In particular, US authorities may gain access to personal data on the basis of US surveillance laws (for example FISA 702, Cloud Act).
11. Your Rights as a Data Subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights against us:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, an informal message to the contact details listed under section 1 is sufficient.
Notice of your right to object under Art. 21 GDPR: Where we process personal data on the basis of our legitimate interest (Art. 6(1)(f) GDPR, see sections 4, 5, 6 and 7), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms.
12. Right to Lodge a Complaint with the Supervisory Authority
Under Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. In Austria, the competent supervisory authority is:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42
1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
13. Validity and Amendments to This Privacy Policy
This Privacy Policy is currently valid and has the status indicated above. As our website and services develop, or due to changes in legal or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version of the Privacy Policy can be accessed and printed on this page at any time.