Privacy policy
How reactsurvey.com handles personal data. The short version: no cookies, no cross-site tracking, and only the data we need to run the site and answer your e-mails.
Last updated:
This policy explains which personal data we process when you visit reactsurvey.com or write to us, why we do it, and which rights you have under the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
Controller
The controller responsible for this website is:
blackmirror media gmbh
Cobenzlgasse 79/1/1
1190 Wien, Austria
E-mail: [email protected]
Phone: +43 676 710 9803
Managing directors: Adam Eri, Balazs Pinter. Please send any question about your data to the e-mail address above.
Scope
This policy covers the website reactsurvey.com only. It does not cover surveys run on the reactsurvey platform. If you take part in such a survey, the organisation that runs it decides how your answers are processed and informs you in its own privacy notice.
Hosting and delivery
This website consists of pre-built HTML pages hosted on Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Every page is delivered over an encrypted HTTPS connection.
When you open a page, your browser automatically sends technical data. Cloudflare processes it to deliver the page and to protect the site against attacks and misuse:
- your IP address
- the date and time of the request
- the page requested and the page you came from (referrer)
- your browser, operating system and device type (user agent)
Legal basis: our legitimate interest in delivering the website securely and reliably (Art. 6(1)(f) GDPR). Cloudflare processes this data on our behalf under a data processing agreement (Art. 28 GDPR). We run no web server of our own and keep no access logs.
Visitor statistics
We use Cloudflare Web Analytics to see how many people visit the site, which pages they read and how fast those pages load. For this, Cloudflare adds a small measuring script to the pages it delivers. The service is built for privacy:
- It sets no cookies and stores nothing on your device, not even in local storage.
- It does not fingerprint your browser, and it does not track you across websites or over time.
- We only see aggregated figures, such as page views, referring sites, countries, browser types and load times. We cannot identify individual visitors.
Legal basis: our legitimate interest in understanding the reach and performance of our website (Art. 6(1)(f) GDPR). You can object at any time (see your rights). If you block scripts in your browser, no measurement takes place.
Cookies, fonts and embeds
This website sets no cookies, neither our own nor third-party ones, so there is no cookie banner. Our only script opens and closes the menu on small screens; it stores nothing.
Our typeface is served from our own domain, so your browser does not contact Google Fonts or any other font service. We embed no videos, maps, social media plugins or other third-party content, and the site has no forms.
Contact by e-mail
When you write to [email protected], for example to book a demo or to ask for our security and compliance pack, we process your e-mail address, your name and anything else you include in your message, such as your company or role, to answer you. The e-mail links on this site open your own e-mail program; nothing is sent through the website itself.
Legal basis: steps prior to entering into a contract at your request (Art. 6(1)(b) GDPR) when your message concerns a demo, an offer or a contract, and otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
Recipients and transfers outside the EU
We share personal data only with service providers that process it on our behalf and on our instructions (Art. 28 GDPR): Cloudflare for hosting and visitor statistics, and our e-mail provider for handling e-mail. We do not sell personal data and do not use it for advertising.
Cloudflare, Inc. is based in the USA. Transfers to the USA are covered by the European Commission’s adequacy decision for the EU–US Data Privacy Framework, under which Cloudflare is certified (Art. 45 GDPR), and by the EU standard contractual clauses in Cloudflare’s data processing agreement (Art. 46(2)(c) GDPR).
How long we keep data
- Connection data: processed by Cloudflare only for as long as it takes to deliver the page and secure the service. We keep none of it.
- Visitor statistics: available to us only as aggregated figures that do not identify anyone.
- E-mails: kept until your request has been dealt with. If the correspondence leads to a business relationship or must be kept by law, we keep it for the statutory periods, usually seven years under Austrian commercial and tax law (§ 212 UGB, § 132 BAO).
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have your data erased (Art. 17)
- have processing restricted (Art. 18)
- receive your data in a portable format (Art. 20)
- object at any time to processing based on our legitimate interests (Art. 21)
To exercise any of these rights, e-mail [email protected]. We reply within one month. There is no automated decision-making or profiling on this website.
Right to lodge a complaint
If you believe we process your data unlawfully, you can lodge a complaint with a supervisory authority. In Austria, that is the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Wien, Austria
E-mail: [email protected]
Web: www.dsb.gv.at
We would still appreciate hearing from you first, so we can put things right straight away.
Changes to this policy
We update this policy when our website or the law changes. The version published on this page is the one that applies. Last updated: .