Privacy Policy
Information under Art 13 GDPR / Austrian DSG. Last updated: 2026-05-17.
1. Controller
Harun Samardzic, Kaiserschützenstraße 6/16, 5020 Salzburg, Austria — .
2. Your media stays on your device
Your videos and telemetry (GPS, OBD, heart-rate, etc.) are processed entirely in your browser. They are never uploaded to or stored on our servers; we have no access to your footage.
3. Processing, purposes & legal basis
- Site delivery & security — IP address and request metadata, to deliver and secure the site. Legitimate interest, Art 6(1)(f). Processor: Cloudflare.
- Payments — name, email, billing/tax country, payment data, subscription status, to perform the contract (Art 6(1)(b)) and meet accounting obligations (Art 6(1)(c)). Stripe acts as an independent controller for payment processing.
- Sign-in & entitlement — email address and entitlement status, to grant paid access via a passwordless email link. Performance of the contract (Art 6(1)(b)). Email delivered by Resend; record stored in Cloudflare KV.
- Launch waitlist — your name and email, to notify you once when Magictive launches. Legal basis: consent (Art 6(1)(a)), confirmed by a double-opt-in email; you can withdraw/unsubscribe anytime with future effect. Stored by Resend (our email processor); we do not use it for anything else and delete the list after launch.
- Anti-bot — the waitlist form is protected by Cloudflare Turnstile, which checks browser/session signals to block bots. It sets no cookies and does not track you across sites. Legal basis: legitimate interest in preventing abuse (Art 6(1)(f)).
- Contacting us — your message and contact details, to handle the request (Art 6(1)(b) or (f)).
Analytics is cookieless and privacy-first (Cloudflare Web Analytics): aggregate page metrics only, no cookies, no cross-site tracking, no personal profiles, no advertising. We use no ad pixels and no third-party marketing trackers.
4. Recipients & transfers
Processors: Cloudflare (hosting, DNS, edge functions, KV), Resend (transactional email). Independent controller: Stripe (payments). Processing may occur in the EU and the USA; US transfers are safeguarded by EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. We do not sell your data.
5. Retention
Waitlist data is kept only until launch (or until you unsubscribe) and then deleted. Entitlement data is kept while your access is active. Invoice and accounting records are retained for 7 years (§132 BAO). Request and security log data (IP, request metadata) is processed by Cloudflare to deliver and secure the site, under Cloudflare's terms.
6. Is providing data required?
The free features need no account or personal data. For a paid plan, your email and payment data are necessary to conclude and perform the contract; without them we cannot grant paid access. We use no automated decision-making within the meaning of Art 22 GDPR.
7. Your rights
You have the right of access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests; where processing rests on consent you may withdraw it at any time with future effect. Contact . You may also lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at).