This policy covers marlies.app, including marlies.app/en, redirects from www.marlies.app, marlies.finance and getmarlies.at, and downloads via downloads.marlies.app.
Who is responsible (controller)
The controller is Macherjek GmbH, Hauptstraße 2/1/5, 2630 Ternitz, Austria. For privacy questions and your rights, contact support@marlies.app.
Website visits and redirects
Cloudflare delivers our website through Workers Static Assets and handles the redirects listed above. It processes IP addresses, request times, requested addresses, referring pages where transmitted (referrers), browser/operating system information (user agents) and encryption connection data (TLS).
The purposes are delivery and protection against faults and attacks, including DDoS. The legal basis is Article 6(1)(f) GDPR: our legitimate interest is a secure, reliably accessible website.
We keep no request logs ourselves and do not analyse usage behaviour. However, Cloudflare shows us statistics and security samples of individual requests with IP addresses, user agents and paths. We use these samples solely to identify faults and attacks; retention is explained below.
Downloads
When you download an available file via downloads.marlies.app, Cloudflare R2 delivers it. This involves the same connection data and security samples as website visits; the address identifies the file. Our legitimate interest in secure, reliable delivery and protection against attacks provides the basis under Article 6(1)(f) GDPR. We keep no download logs ourselves and do not track downloads.
Cloudflare
The recipient is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. The Cloudflare DPA governs processing on our behalf; Cloudflare publishes a list of sub-processors.
International transfers
Processing may take place outside the European Economic Area (EEA), particularly in the United States. Cloudflare is certified under the EU-US Data Privacy Framework; covered US transfers rely on the adequacy decision under Article 45 GDPR. If that decision ceases to apply or does not cover a transfer, EU Standard Contractual Clauses with necessary supplementary safeguards apply (Article 46 GDPR). The safeguards are accessible through the linked DPA or available from us.
Retention
On our behalf: Cloudflare retains the statistics and request samples in Security Analytics and Security Events for up to 31 days. This applies even with additional request logging disabled.
As a separate controller: Cloudflare also processes network data to operate, protect and improve its services. Retention depends on purpose, data type and volume, risks and legal obligations. Its privacy policy, particularly “Data Retention”, explains the details and your rights in relation to Cloudflare.
Enquiries by email or phone
When you email us, for example at support@marlies.app, we process your sender address, message content and name if provided, to reply. When you call us at the number in our imprint, we process your phone number, if transmitted, and the content of the call to the extent we note it down to handle your enquiry.
For contracts with you or pre-contractual steps you request, Article 6(1)(b) GDPR applies. We handle other enquiries, including those from company contacts, based on our legitimate interest in communicating with you and handling your enquiry (Article 6(1)(f) GDPR). We handle privacy rights requests to fulfil our legal obligations (Article 6(1)(c), together with Articles 12–22 GDPR).
Email hosting
For @marlies.app, Domaintechnik, Ledl.net GmbH & Co. KG, Lederergasse 6, 5204 Straßwalchen, Austria, processes emails on our behalf under Article 28 GDPR. Under our data processing agreement, processing takes place exclusively within the EU/EEA; no third-country transfers are envisaged for this hosting.
Retention
We delete correspondence and call notes after resolving your enquiry once it is no longer needed for further communication. Exceptions:
Business correspondence and accounting records subject to statutory retention: seven years under section 212 of the Austrian Commercial Code (UGB) or section 132 of the Federal Fiscal Code (BAO), starting at the end of the year of receipt/sending or the year to which the record relates; longer where required for pending court or administrative proceedings (Article 6(1)(c) GDPR).
Messages needed for legal claims: until that need ends, particularly following resolution of a dispute or expiry of limitation periods. Our legitimate interest is establishing, exercising or defending our legal claims (Article 6(1)(f) GDPR).
Domaintechnik deletes backups within six months at the latest.
No cookies or tracking
The website uses no cookies or similar browser storage, such as local storage. We use no analytics/marketing tools or embedded third-party content; we serve fonts ourselves.
There is no login, contact form, newsletter or comment feature here. Registration, login and subscriptions at konto.marlies.app are covered by the Marlies account privacy policy available there. This website policy does not cover processing within the desktop app.
Voluntary provision of data and automated decisions
You have no statutory or contractual obligation to provide data. Without connection data, we cannot deliver pages or files; without a sender address and necessary information, we cannot answer an email enquiry.
We create no personal usage profiles and make no solely automated decisions with legal or similarly significant effects on you.
Your rights
Subject to the statutory conditions, you can:
obtain access to and a copy of your data (Article 15 GDPR);
have data corrected or completed (Article 16 GDPR);
have data erased (Article 17 GDPR);
have processing restricted (Article 18 GDPR);
receive data you provided in a structured, commonly used, machine-readable format and transmit them, including directly where technically feasible, if we process them automatically based on a contract or consent (Article 20 GDPR).
Contact support@marlies.app. We respond within one month; complex or numerous requests may require up to two further months. We will inform you of this and the reasons within the first month.
Your right to object
You can object to processing under Article 6(1)(f) GDPR at any time on grounds relating to your particular situation (Article 21 GDPR). We will stop unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or processing serves to establish, exercise or defend legal claims. Contact: support@marlies.app.
Right to lodge a complaint
For suspected data protection infringements, you can complain to a supervisory authority, particularly in your place of habitual residence, work or the infringement. In Austria: Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, Austria; dsb@dsb.gv.at, dsb.gv.at.
Changes
We update this policy when processing or legal requirements change. The current version appears here; the date above shows when it was updated.