Privacy Policy
Last updated: 20 August 2026
1. Controller
UtileMedia e.U. Owner: Anupal Bains Münchner Bundesstraße 107E/1 5020 Salzburg, Austria
E-mail: hello@utilemedia.com Phone: +43 660 294 04 28 Legal notice: https://www.utilemedia.com/en/legal-notice
2. Overview of processing activities
We process personal data in the course of our business activities (B2B lead generation, outbound systems, automation, consulting, training) and in operating this website.
- Categories of data: master and contact data (e.g. name, company, e-mail address, phone number), contract and payment data, content data (e.g. messages and documents), usage and metadata (e.g. IP address, time of access), and professional contact data of contact persons at companies.
- Data subjects: clients and their contact persons, prospective clients, website visitors, communication partners, participants of trainings and coachings, professionally contacted persons (B2B), job applicants.
- Purposes: provision of contractual services, communication and appointment scheduling, B2B direct outreach, accounting and payment processing, operation and security of the website, trainings and coachings, business organisation.
3. Legal bases
We process personal data on the basis of the GDPR, in particular:
- Consent (Art. 6(1)(a) GDPR), e.g. when you actively load third-party content on this website.
- Performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR), e.g. for inquiries, appointment bookings and client projects.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR), e.g. retention obligations under tax and commercial law.
- Legitimate interests (Art. 6(1)(f) GDPR), e.g. secure operation of the website, business organisation, B2B direct outreach.
In addition, the national data protection provisions of Austria apply, in particular the Austrian Data Protection Act (DSG). For access to information stored on terminal equipment (e.g. the setting of cookies), Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) applies.
Note for persons in Switzerland: Where the Swiss Federal Act on Data Protection (FADP) applies, we process personal data in accordance with its principles (lawfulness, good faith, proportionality, purpose limitation). For readability, we consistently use GDPR terminology; within the scope of the Swiss FADP, the corresponding terms of that act apply.
4. Security measures
We take appropriate technical and organisational measures in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk. These include, in particular, encryption of data in transit (TLS/HTTPS), access controls, separation of data sets, and the privacy-conscious selection and configuration of software and service providers.
5. Disclosure of data, processors and international transfers
We only disclose personal data where this is necessary for the provision of our services, where a legal obligation exists, or where another legal basis permits it. Recipients may include, in particular: IT and hosting providers, communication and collaboration services, payment service providers, tax advisors and public authorities. With service providers that process data on our behalf, we conclude data processing agreements in accordance with Art. 28 GDPR.
Where data is processed in third countries (in particular the USA), this is done on the basis of an adequacy decision of the EU Commission (in particular the EU-US Data Privacy Framework for certified providers) or on the basis of appropriate safeguards, in particular the EU Standard Contractual Clauses pursuant to Art. 46 GDPR. The applicable basis is stated for each individual service. Information on the Data Privacy Framework and the list of certified companies: https://www.dataprivacyframework.gov
On request, we will inform you about the specific recipients used and the respective safeguards.
6. Retention and deletion
We delete personal data as soon as the purpose of processing no longer applies and no statutory retention obligations prevent deletion. In Austria, the following periods apply in particular:
- 7 years: books, records, receipts and business documents pursuant to Section 132 of the Austrian Federal Fiscal Code (BAO) and Sections 190, 212 of the Austrian Commercial Code (UGB) (longer where documents are relevant to pending proceedings).
- 3 years: data required to assert or defend contractual claims within the general limitation periods of the Austrian Civil Code (ABGB).
For persons in Switzerland, the following applies in addition: where relevant, we retain business books and records for 10 years pursuant to Art. 958f of the Swiss Code of Obligations (CO).
7. Your rights
Subject to the statutory requirements, you have the following rights:
- Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20).
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
- Objection (Art. 21 GDPR): You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. You may object to processing for direct marketing purposes at any time and without giving reasons; we will then no longer contact you for marketing purposes. An informal message to hello@utilemedia.com is sufficient.
- Complaint to a supervisory authority, in Austria: Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at
Persons in Switzerland have the rights provided under the Swiss FADP, in particular access, rectification, erasure and data release.
8. Business services
We process data of our clients, prospective clients and their contact persons in order to provide our services. These include in particular:
- Agency and lead generation services: building and operating outbound systems (e.g. cold e-mail and LinkedIn campaigns), e-mail infrastructure, list building and data enrichment, copywriting, campaign management and reporting.
- Consulting on outbound, automation and sales processes.
- Project and development services, e.g. automations, CRM setups and workflows.
- Data analyses and evaluations within campaigns and projects.
- Coachings, trainings and online courses (see Section 9).
For these purposes we process in particular master, contact, contract, payment and content data. Legal bases are the performance of a contract (Art. 6(1)(b) GDPR), legal obligations (point (c)) and our legitimate interests in proper business management (point (f)).
Processing on behalf of clients: Where we carry out campaigns and data processing on behalf of our clients (e.g. outbound campaigns using contact data for which the client is responsible), we act as a processor pursuant to Art. 28 GDPR. The respective client is the controller for these processing activities; we process the data on the basis of a data processing agreement and in accordance with the client’s instructions.
9. Coachings, trainings and online courses
We process data of participants in our coachings, trainings and online courses (e.g. name, contact details, organisation, content and results from the sessions) in order to provide these services, organise appointments, provide materials and handle invoicing. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR); for organisational purposes we additionally rely on legitimate interests (point (f)).
10. B2B direct outreach (outbound)
We contact persons at companies for which our services may be relevant, in a business context (e.g. by e-mail or via professional networks). In doing so, we process exclusively professional contact data, in particular: name, role and position, company, business e-mail address, business profile on professional networks, and publicly available company information.
Sources of this data (information pursuant to Art. 14 GDPR): publicly accessible sources such as company websites, legal notices, company registers and professional networks (e.g. LinkedIn), as well as B2B data providers.
The purpose is the initiation of business relationships in the B2B sector. The legal basis is our legitimate interest in direct marketing towards business customers (Art. 6(1)(f) GDPR, cf. Recital 47 GDPR).
Categories of recipients: For building, sending and managing this outreach, we use service providers as processors, in particular from the following categories: e-mail sending and sequencing platforms, data providers and enrichment services, e-mail validation services, CRM systems, tools for outreach via professional networks, automation and workflow software, and AI-supported text services. Individual providers may be located in third countries (in particular the USA); transfers are then based on the EU-US Data Privacy Framework or EU Standard Contractual Clauses. On request, we will name the specific providers used.
Retention: We store this data for as long as it is relevant to business initiation and delete it once it is apparent that there is no interest, at the latest as part of regular clean-ups. After an objection, we add the address concerned to an internal suppression list to prevent renewed contact (Art. 6(1)(f) GDPR).
Objection: You may object to the processing of your data for direct outreach purposes at any time and without any formal requirements (see Section 7).
11. Business operations and services used
To organise our business operations (communication, accounting, payments, client and project management, IT infrastructure), we use the following services. Unless stated otherwise, the legal bases are the performance of a contract (Art. 6(1)(b) GDPR), legal obligations (point (c)) and our legitimate interests in efficient and secure organisation (point (f)).
- sevDesk (invoicing and accounting): sevDesk GmbH, Hauptstraße 115, 77652 Offenburg, Germany. Privacy policy: https://sevdesk.com/privacy-policy
- CRM system (management of contacts, inquiries and client relationships): depending on configuration, self-hosted on our servers or operated as a cloud service by a provider under a data processing agreement.
- Google Workspace and Google Cloud (e-mail, calendar, documents, cloud storage, video conferencing via Google Meet, forms and surveys via Google Forms): Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://policies.google.com/privacy. Third-country transfer: EU-US Data Privacy Framework.
- Microsoft 365 and Microsoft Teams (documents, communication, video conferencing): Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Privacy policy: https://privacy.microsoft.com/en-us/privacystatement. Third-country transfer: EU-US Data Privacy Framework.
- Server infrastructure (operation of self-hosted software, e.g. automation workflows with n8n and our own AI systems): Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Server location: EU. Privacy policy: https://www.hetzner.com/legal/privacy-policy
- GitHub (version control for software projects): GitHub, Inc., USA, and GitHub B.V., Netherlands. Privacy policy: https://docs.github.com/en/site-policy/privacy-policies. Third-country transfer: EU-US Data Privacy Framework.
- Zoom (video conferencing): Zoom Communications, Inc., 55 Almaden Blvd., San Jose, CA 95113, USA. Privacy policy: https://explore.zoom.us/en/privacy/. Third-country transfer: EU-US Data Privacy Framework.
- Slack (team communication): Slack Technologies Limited, Level 1, Block A Nova Atria North, Sandyford Business District, Dublin 18, Ireland (part of Salesforce). Privacy policy: https://slack.com/trust/privacy/privacy-policy. Third-country transfer: EU-US Data Privacy Framework.
- Discord (community communication): Discord Inc., 444 De Haro Street, San Francisco, CA 94107, USA. Privacy policy: https://discord.com/privacy. Third-country transfer: EU Standard Contractual Clauses and/or EU-US Data Privacy Framework.
- WhatsApp (messenger communication, where you contact us via this channel or agree to it): WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland. Message content is end-to-end encrypted; the provider processes metadata (e.g. who communicates with whom and when). We do not transmit your contact details to WhatsApp for the first time without your involvement; you can always reach us by e-mail or phone instead. Privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea
12. Payment methods
Invoicing is generally carried out by invoice and bank transfer. In addition, depending on the agreement, we may use payment service providers. These process payment data (e.g. name, payment amount, payment method) under their own responsibility; we do not receive complete payment instrument data, only confirmations of the payment status. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Stripe: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Privacy policy: https://stripe.com/privacy. Third-country transfer: EU-US Data Privacy Framework.
- PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg. Privacy policy: https://www.paypal.com/legalhub/privacy-full
- Wise: Wise Europe SA, Rue du Trône 100, 1050 Brussels, Belgium. Privacy policy: https://wise.com/gb/legal/privacy-policy
13. Website, hosting and log data
This website is provided as a static website via Cloudflare Pages: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (with European locations). Each time the website is accessed, the hosting provider processes technically necessary connection data, in particular IP address, date and time, page accessed, browser type and referrer URL (server log data). This processing serves the delivery of content, stability and the defence against attacks (e.g. DDoS). Legal basis: legitimate interest in the secure operation of the website (Art. 6(1)(f) GDPR). Log data is only stored for a short period, unless it is required to investigate security incidents. Privacy policy: https://www.cloudflare.com/privacypolicy/. Third-country transfer: EU-US Data Privacy Framework.
Fonts, images and the videos embedded on the website (e.g. our introduction videos) are delivered locally from our website. When simply visiting the pages, no content is loaded from third-party servers.
14. Cookies and third-party content
Our website does not set any cookies when accessed and does not use any analytics or tracking services. Third-party content (appointment booking, YouTube videos) is only loaded once you actively start it by clicking. By clicking, you consent to the loading of the respective provider’s content (Art. 6(1)(a) GDPR, Section 165(3) TKG 2021); the providers may then set cookies or similar storage technologies in your browser. Without a click, no data is transmitted to these providers.
15. Appointment booking (TidyCal)
For online appointment booking, we use TidyCal, a service of Sumo Group, Inc. (AppSumo), Austin, Texas, USA. The booking widget is only loaded once you actively click on it. Connection data (e.g. IP address) is then transmitted to TidyCal and its content delivery network (bunny.net, BUNNYWAY d.o.o., Slovenia, EU). When you make a booking, we and TidyCal process the details you provide (e.g. name, e-mail address, selected time slot, optional information) in order to organise and conduct the appointment.
Legal bases: performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR) for the booking, consent (point (a)) for loading the widget. Transfers to the USA are based on EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework. Privacy policy: https://tidycal.com/privacy-policy. Alternatively, you can arrange appointments at any time by e-mail or phone.
16. Embedded YouTube videos
We embed individual videos via YouTube in privacy-enhanced mode (youtube-nocookie.com). These videos are also only loaded once you actively click on them; only then is data (e.g. IP address) transmitted to Google and cookies may be set by YouTube. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: consent through activation (Art. 6(1)(a) GDPR). Privacy policy: https://policies.google.com/privacy. Third-country transfer: EU-US Data Privacy Framework.
17. Contact
When you contact us by e-mail or phone, we process the information you provide (e.g. name, contact details, content of the inquiry) in order to handle and respond to the inquiry. Legal bases: performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR) and legitimate interests in efficient communication (point (f)). This website does not contain a contact form.
18. Artificial intelligence (AI)
We use AI systems to support our services, e.g. for research, text creation, data analysis and automations. We pay attention to data minimisation and only pass on personal data to AI providers where this is necessary for the respective purpose and a legal basis exists (generally legitimate interests in efficient work processes, Art. 6(1)(f) GDPR, or performance of a contract, point (b)). We do not make automated individual decisions with legal effect (Art. 22 GDPR).
Providers and systems used:
- Anthropic (Claude): Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, Ireland, and Anthropic PBC, San Francisco, USA. Privacy policy: https://www.anthropic.com/legal/privacy. Third-country transfer: EU Standard Contractual Clauses.
- OpenAI (ChatGPT, image generation): OpenAI Ireland Ltd, 117-126 Sheriff Street Upper, Dublin 1, Ireland. Privacy policy: https://openai.com/policies/eu-privacy-policy/. Third-country transfer: EU-US Data Privacy Framework and/or EU Standard Contractual Clauses.
- DeepL (translation and text correction): DeepL SE, Maarweg 165, 50825 Cologne, Germany. Privacy policy: https://www.deepl.com/en/privacy
- Self-operated AI software: AI models that we run on our own infrastructure (servers in the EU); the data remains under our responsibility.
19. Newsletter and promotional e-mails
Where we offer a newsletter, we send it only with your consent (Art. 6(1)(a) GDPR) and using a double opt-in procedure; the registration is logged so that it can be evidenced (Art. 6(1)(f) GDPR). You can unsubscribe from the newsletter at any time via the unsubscribe link or informally by e-mail. After unsubscribing, we may store the e-mail address for up to three years to evidence the consent previously given, and thereafter keep it solely on a suppression list to permanently honour your objection.
20. Affiliate links
Our website contains links to tools that we use ourselves or recommend (e.g. Clay, SmartLead). Some of these links are affiliate links: if you follow such a link and enter into a contract with the provider, we may receive a commission. When simply visiting our website, no data is transmitted to these providers. Only when you click on a link does your browser transmit the usual connection data to the target provider, and the provider may attribute the click to our partner account (e.g. via a link parameter or a cookie set by the provider). Legal basis on our side: legitimate interest in financing our services (Art. 6(1)(f) GDPR). In all other respects, the privacy notices of the respective provider apply.
21. Social media presences
We maintain profiles on LinkedIn, YouTube, Instagram, Facebook and X in order to provide information and communicate with users there. When you visit these profiles, the networks process user data under their own responsibility, regularly also for market research and advertising purposes, and also outside the EU. Legal basis for our presences: legitimate interest in public relations and communication (Art. 6(1)(f) GDPR). You can most effectively assert your data subject rights directly with the providers; we are happy to assist with any questions.
- LinkedIn: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. For the collection of data processed for “Page Insights”, we are jointly responsible with LinkedIn; the basis is the Page Insights Joint Controller Addendum (https://legal.linkedin.com/pages-joint-controller-addendum). Privacy policy: https://www.linkedin.com/legal/privacy-policy. Third-country transfer: EU-US Data Privacy Framework.
- YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://policies.google.com/privacy. Third-country transfer: EU-US Data Privacy Framework.
- Instagram and Facebook: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. For the collection of data processed for the “Page Insights” of our Facebook page, we are jointly responsible with Meta (https://www.facebook.com/legal/terms/page_controller_addendum). Privacy policies: https://privacycenter.instagram.com/policy and https://www.facebook.com/privacy/policy/. Third-country transfer: EU-US Data Privacy Framework.
- X (formerly Twitter): X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland. Privacy policy: https://x.com/en/privacy
22. Job applications
If you apply to work with us, we process your application data exclusively for the application procedure (Art. 6(1)(b) GDPR). If no collaboration comes about, we delete the documents no later than seven months after completion of the procedure, unless you consent to longer storage.
23. Changes to this privacy policy
We will adapt this privacy policy as soon as changes to our data processing make this necessary, and recommend that you review it regularly. The version published here at any given time applies.