Privacy

Information on the processing of personal data under Art. 13 and 14 GDPR — in plain language, without obfuscation.

24 July 2026

This is a convenience translation. In case of any discrepancy, the German version of these terms prevails.

1. Controller

The controller for the data processing on this website is:
VI4 Bernhard Reiter
Zauche 7
9904 Thurn
Email: hello@vi4.me

No data protection officer has been appointed, because the legal requirements under Art. 37 GDPR are not met.

2. The most important part first

This website is deliberately built to collect as little data as possible:

  • No cookies are set — not even technically necessary ones, because there is no login.
  • There is no analytics and no tracking. We do not know who visits this site.
  • No third-party content is embedded — no external fonts, no videos, no maps, no ad networks.
  • There is no contact form. Contact runs exclusively through your own email program.

Merely visiting this website therefore involves nothing beyond the technically unavoidable server logs (point 3).

3. Server logs when visiting the website

When this website is accessed, the hosting provider automatically processes connection data that your browser transmits for technical reasons: IP address, date and time of access, the address requested, amount of data transferred, browser type and operating system.

Purpose: delivering the website, operational security and defence against attacks. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure and undisrupted operation. Retention: these logs are kept by the hosting provider for a short period and deleted automatically. They are not combined with other data and not evaluated in relation to your person.

4. Hosting

This website is operated at Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Delivery takes place via the Frankfurt (Germany) region.

Vercel processes the connection data named under point 3 as a processor on the basis of a contract under Art. 28 GDPR.

An honest note: Vercel is a US company. Even with a European delivery location, access from the USA — for support or security purposes, for instance — cannot be entirely ruled out. Any such transfer is covered by the EU standard contractual clauses. Static files (fonts, images, scripts) are delivered through a globally distributed network; they contain no personal content.

5. Contact by email

If you write to us, we process your email address and the content of your message in order to answer the enquiry.

Legal basis: Art. 6(1)(b) GDPR for enquiries leading up to a contract, otherwise Art. 6(1)(f) GDPR. Retention: until the enquiry has been dealt with, beyond that only where statutory retention duties apply (in particular seven years under § 132 BAO (Austrian Federal Fiscal Code) for accounting-relevant records).

6. Processing in the course of working together

The following points do not concern visiting this website, but the later work together on a project.

Your systems remain yours. Cody Studio works on the principle that source code, database and AI access stay with the client. The data produced while running your application is therefore stored in your own infrastructure, not in ours.

Processing on your behalf. Where we gain access to personal data in your systems during build, operation or maintenance, this happens exclusively on your instructions and on the basis of a data processing agreement under Art. 28 GDPR. You remain the controller within the meaning of the GDPR.

AI processing. When designing and building your application, your descriptions are transmitted to an AI provider. Which provider that is, you decide, because access runs through your own key. Depending on the provider, this may involve a transfer to third countries; the details and safeguards are set out in writing before the project starts.

No training. We do not use your content to train AI models. The terms of the AI provider you choose are governed by that provider’s agreements, which we point out to you before the project starts.

7. Recipients of your data

Personal data is passed on only where this is necessary to provide the service or where a statutory duty exists. The recipients are:

  • Vercel Inc. — hosting of this website (Frankfurt region)
  • Tax advisors and authorities — where required by law

Data is not sold and not passed on for advertising purposes.

8. Your rights

Under the GDPR you have the right at any time to:

  • Access (Art. 15) — which data we process about you
  • Rectification (Art. 16) — correction of inaccurate data
  • Erasure (Art. 17) — unless a retention duty stands in the way
  • Restriction (Art. 18) — temporarily suspend processing
  • Data portability (Art. 20) — release in a common format
  • Objection (Art. 21) — against processing based on legitimate interests

An informal message to hello@vi4.me is enough to exercise these rights.

You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Wien — dsb.gv.at.

9. Data security

This website is transmitted encrypted over HTTPS. To protect data in projects we use technical and organisational measures — in particular access restriction, separation of tenants and encryption in transit.

We work to recognised security principles, but we are not ISO 27001 certified. No software can promise absolute protection.

10. Changes to this statement

We adapt this statement when the processing changes — for example through new features or a changed legal situation. The version published here is the one that applies. The date of the latest version is shown above.

The terms of working together are governed additionally by our general terms and conditions.

This statement was prepared carefully, but it does not replace legal advice in an individual case.