Privacy Policy
Last updated: September 22, 2025
I. General Information
II. Data Processing When Visiting Our Website
III. Data Processing When Using the 23° Platform (Customer Account Required)
IV. Data Processing Regarding Publication and Embedding of Statistics
V. Data Processing Within External Online Presences
VI. Financing via Advertising and Pur Subscription Model
I. General Information
1. Scope
With the following data protection notices, we inform you about the types of your personal data we process, for what purposes, and to what extent. These data protection notices apply to all processing of personal data carried out by us, both within the scope of providing our services and, in particular, on our website as well as within external online presences, such as our social media profiles. These notices are directed at all visitors to our website (https://app.23degrees.io/) and our social media profiles, employees, applicants, customers, and partners of 23 degrees GmbH.
2. Information on the Controller
Responsible for the processing of personal data under data protection law is:
23 degrees GmbH Tigergasse 3/5 1080 Vienna Austria
Phone: +43 1 9901039 Email: office@23degrees.io
3. General Information on Data Processing
We take the protection of your personal data very seriously. We will therefore use your personal data only in accordance with applicable data protection law, in particular the GDPR and the Austrian Data Protection Act (DSG). If we use your data for purposes other than those stated in these data protection notices, we will inform you about these purposes and—where necessary—obtain your consent.
4. Duration of Storage of Personal Data
Data processed during the use of our internet presence will be deleted or blocked as soon as the purpose of storage no longer applies, provided that no statutory retention obligations oppose the deletion of the data and no other information is given regarding individual processing procedures below.
5. Financing of Our Offer and Choice (Pur Subscription Model)
In order to be able to finance our free services, we rely on advertisements and analysis procedures by third-party providers. Within the framework of our Pur Subscription Model ("Pur-Abo-Modell"), we offer you a choice: You can either use our offer free of charge by consenting to the associated data processing or take out a paid subscription for a largely tracking-free and ad-reduced usage.
6. Data Transfer to Third Countries
If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in the context of using third-party services or disclosing/transferring data to third parties, this takes place exclusively on the basis of the legal requirements of Art. 44 ff. GDPR.
6.1 Data Transfer to the USA For data transfers to the USA, we rely on the adequacy decision of the EU Commission for the EU-U.S. Data Privacy Framework (DPF) of July 10, 2023. In addition, we secure data transfers by concluding Standard Contractual Clauses (SCC) according to the requirements of the EU Commission. These guarantees ensure an adequate level of protection for your personal data. In the descriptions of the individual service providers, we inform you whether a DPF certification exists or Standard Contractual Clauses have been concluded. A list of companies certified under the DPF is viewable on the US Department of Commerce website: https://www.dataprivacyframework.gov/.
6.2 Data Transfer to Other Third Countries For data transfers to third countries for which there is no adequacy decision by the EU Commission, we ensure the protection of your data through other appropriate guarantees. This is usually done by concluding EU Standard Contractual Clauses. In exceptional cases, a transfer may also take place on the basis of your express consent or a legal requirement. Information on third-country transfers and the applicable adequacy decisions is provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
7. Rights of Data Subjects
As a result of the processing of your personal data, you are a data subject, meaning that you are entitled to the following rights under the GDPR:
- Right to Object (Art. 21 GDPR): You have the right to object at any time to the processing of personal data concerning you which is based on Art. 6 (1) lit. e) or f) GDPR; this also applies to profiling based on these provisions . If personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right of Revocation for Consents (Art. 7 (3) GDPR): You have the right to revoke consents granted at any time with effect for the future, without stating a reason.
- Right of Access (Art. 15 GDPR): You have the right to request information free of charge at any time as to whether and what personal data we process about you, as well as further information on data processing and a copy of the data in accordance with legal requirements.
- Right to Rectification (Art. 16 GDPR): You have the right to demand the immediate correction of incorrect data or the completion of incomplete data.
- Right to Erasure and Restriction of Processing (Art. 17, 18 GDPR): According to the legal requirements, you have the right to demand that data concerning you be deleted immediately or, alternatively, that the processing of the data be restricted.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format or to request its transmission to another controller.
- Right not to be subject to automated decision-making (Art. 22 GDPR): You have the right not to be subject to a decision based solely on automated processing—including profiling—which produces legal effects concerning you or similarly significantly affects you.
- Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement if you consider that the processing of personal data relating to you infringes data protection regulations.
- LinkedIn: https://www.linkedin.com/; Operator: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Privacy Policy: https://www.linkedin.com/legal/privacy-policy
- Reddit: https://redditinc.com/; Operator: Reddit Netherlands B.V., Euro Business Center, Keizersgracht 62, 1015CS Amsterdam, Netherlands, Privacy Policy: https://www.reddit.com/de-de/policies/privacy-policy.
Within the scope of the Austrian Data Protection Act (DSG), special regulations apply in particular to the right to information, the right to rectification or erasure, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases.
8. Updates to the Privacy Policy
We adapt these data protection notices as soon as changes in our data processing make this necessary, for example, through the further development of our offered services or the implementation of new technologies. Please inform yourself regularly about the current content. Should the changes require an act of cooperation on your part (e.g., renewed consent), we will inform you naturally. The addresses and contact information of companies and organizations given in these data protection notices may change over time. Please check the details before contacting them.
II. Data Processing When Visiting Our Website
1. Provision of the Website and Creation of Log Files
When you access our website without registering or otherwise sending us information ("Informational Use"), we only collect the personal data that your web browser transmits to our server. For technical reasons, particularly to ensure a secure and stable internet presence, access to our offers is logged in so-called log files for statistical purposes.
The following data is collected: Your IP address, browser ID, name of the accessed content, date and time of access, and a message indicating whether the access was successful. These data have no direct reference to a person and are only stored temporarily, not together with other data from you. The log files are deleted after 30 days at the latest, provided no further retention is required for evidentiary purposes (e.g., to clarify security incidents). The collection and temporary storage take place on the legal basis of Art. 6 (1) lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality, and security of our internet presence.
Webspace Provider: We use Google Cloud, a service of Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. According to Google, IP address data in EU traffic is used exclusively on EU-based servers to derive rough geographic location data (e.g., city, country, region) and is deleted immediately thereafter. The IP address is not logged, is not accessible, and is not used for other purposes. The security of data transmission to the USA is guaranteed by the DPF certification and the conclusion of Standard Contractual Clauses. Further privacy information is available at https://cloud.google.com/security/privacy?hl=de.
CDN: We also use the Content Delivery Network (CDN) of Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany (Cloudflare), to increase the security and delivery speed of our website. This corresponds to our legitimate interest (Art. 6 (1) lit. f GDPR). A CDN is a network of globally distributed servers capable of delivering optimized content to the website user. For this purpose, personal data may be processed in Cloudflare server log files. The security of data transmission to the USA is guaranteed by the DPF certification and the conclusion of Standard Contractual Clauses. Further privacy information is available at https://www.cloudflare.com/de-de/trust-hub/gdpr/.
2. Use of Cookies, Analysis, and Marketing Services
2.1 General Information on Cookies
Cookies are small text files stored on your computer or mobile device. They allow us to capture certain information without endangering your personal data. Cookies cannot run programs or transmit viruses. Below we explain which types of cookies we use:
Technically necessary cookies: We use cookies on our website that are technically necessary for the basic function of the website and to ensure network security.
Temporary cookies (also session cookies): These cookies are stored only for a short time while you visit our website. As soon as you close your browser, these cookies are automatically deleted.
Permanent cookies: These cookies remain stored on your computer or mobile device even after you close your browser. This allows, for example, your login status to be saved and preferred content to be displayed directly when you visit our website again. Permanent cookies are automatically deleted after a specified duration, which may differ depending on the cookie.
Insofar as cookies are not technically strictly necessary, we only use them with your previously declared consent, which you can also revoke at any time. The legal basis is Art. 6 (1) lit. a) GDPR. You can prevent or restrict the installation of cookies at any time via your internet browser settings. You can also delete already stored cookies at any time. The steps required for this depend on your specific internet browser. If you have questions, please use the help function or documentation of your internet browser or contact its manufacturer or support.
2.2 Analysis and Marketing Services Used
For the free use of our website, we use the following services from the areas of analysis and marketing. The legal basis for this is your express consent pursuant to Art. 6 (1) lit. a) GDPR. As an alternative to consent-based use, we offer you the conclusion of a paid Pur Subscription, in which the use of these services is largely dispensed with. We obtain this consent via a Consent Management Tool, where you can also view the services categorized and select or deselect them individually. Revocation of your consent is possible at any time.
2.2.1 Google Analytics 4 / Google Signals
We use Google Analytics 4 on our website, a web analysis service of Google Ireland Limited, Gordon House, Barrow St, Dublin, D04 E5W5, Ireland. The service enables us to perform a detailed analysis of user behavior to continuously improve our offer. Google Analytics uses cookies and similar technologies to capture information such as your page views, click paths, interactions with content, your approximate location, your shortened IP address, as well as browser and device information. By activating Google Signals, we can also create cross-device reports and recognize demographic characteristics of users who have agreed to personalized advertising. The data is stored for a period of 14 months, whereby this period is reset with every new activity of the user on the website. Regardless of your consent via our Consent Tool, you can prevent the collection of data generated by the cookie and related to your user behavior (incl. your IP address) as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de. The parent company of Google Ireland Limited is Google LLC in the USA. Security for any data transmission to the USA is guaranteed by the conclusion of Standard Contractual Clauses and the DPF certification of Google LLC. Further information on data processing by Google can be found at https://policies.google.com/privacy.
2.2.2 Google Tag Manager
We use Google Tag Manager, a service of Google Ireland Limited. Tags are small code elements on our website used to record and analyze visitor activities. This technology helps us improve our website and the content offered on it. The service itself does not create user profiles, does not store cookies, and does not carry out independent analyses. Nevertheless, when using Google Tag Manager, your IP address is transmitted to Google for technical reasons. The Tag Manager only serves to manage and trigger other services; its use therefore takes place, insofar as it controls services requiring consent, also on the basis of your consent. Security for any data transmission to the USA is guaranteed by the conclusion of Standard Contractual Clauses and the certification of Google LLC under the DPF.
2.2.3 Google Ads – Enhanced Conversions and Remarketing
We use the "Enhanced Conversions" and "Remarketing" functions of Google Ads based on your consent pursuant to Art. 6 (1) lit. a) GDPR. With the "Enhanced Conversions" function, data entered by you on our website (e.g., email address, name, phone number) is transmitted to Google after privacy-compliant hashing (SHA256) to measure the success of advertisements more precisely. The Remarketing function serves to address you again with targeted advertising on other websites within the Google advertising network (e.g., on Google itself or on partner websites), based on your previous interactions with our website. For this purpose, cookies or comparable technologies are used to record your user behavior and recognize you during a later visit to display interest-based advertising. The required level of protection for any data transmission to the USA is guaranteed by the DPF certification of Google LLC and the conclusion of Standard Contractual Clauses. Further information on data processing by Google can be found at https://policies.google.com/privacy.
2.2.4 LinkedIn Insight Tag
This website uses the LinkedIn Insight Tag of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Based on your consent pursuant to Art. 6 (1) lit. a) GDPR, we collect information about your website visits (including URL, Referrer, IP address, device and browser characteristics) to enable conversion tracking, retargeting, and website analysis. Your IP address is shortened or hashed. We do not receive personal data from LinkedIn, only aggregated reports. The storage duration of the data is generally 90 days. The parent company of LinkedIn Ireland Unlimited Company is LinkedIn Corporation in the USA. Security for data transmission to the USA is guaranteed by Standard Contractual Clauses and the DPF certification of LinkedIn Corporation. Further information is available at https://de.linkedin.com/legal/privacy-policy.
2.2.5 LinkedIn Matched Audiences
We use the "Matched Audiences" function of LinkedIn. Here we can transmit encrypted (hashed) personal data (e.g., email addresses) of existing customers to LinkedIn to target them in remarketing campaigns. The legal basis for this is your express consent pursuant to Art. 6 (1) lit. a) GDPR, which you give us during registration or via our Consent Management Tool. The required level of protection for any data transmission to the USA is guaranteed by the DPF certification of LinkedIn Corporation and the conclusion of Standard Contractual Clauses. Further information is available at https://de.linkedin.com/legal/privacy-policy.
2.2.6 Reddit Pixel
We use the Reddit Pixel Tag of Reddit Netherlands B.V., Euro Business Center, Keizersgracht 62, 1015CS Amsterdam, Netherlands. This service allows us, based on your consent pursuant to Art. 6 (1) lit. a) GDPR, to analyze the effectiveness of Reddit advertising campaigns by recording events such as page views or clicks. Reddit processes the data as an independent controller. The storage duration is a maximum of 90 days. The parent company of Reddit Netherlands B.V. is Reddit, Inc. in the USA. Security for data transmission to the USA is guaranteed by Standard Contractual Clauses and the DPF certification of Reddit, Inc.. Further information can be found at https://www.reddit.com/policies/privacy-policy.
3. Your Data in Contact Requests
If you contact us via contact form or email through the platform, the data provided by you will be used to process your request. The provision of data is necessary to process and answer your request—without it, we cannot answer your request or can only answer it to a limited extent. The legal basis for this processing is Art. 6 (1) lit. b) GDPR. Your data will be deleted once your request has been conclusively answered and no statutory retention obligations oppose deletion, such as in the case of any subsequent contract execution.
4. Your Data Upon Newsletter Registration
You can register for our newsletter on our platform. For successful registration, providing the required mandatory data—your name and email address—is necessary. This information provided by you is subsequently transmitted to us. Registration for our newsletter takes place using the Double-Opt-In procedure. After your registration, you will receive an email asking you to confirm your registration. The newsletter dispatch is only activated after this confirmation. If no confirmation is received within the stated period, your data will be blocked and automatically deleted after one week. To prove the registration, we store your IP address and the time of registration and confirmation based on our legitimate interests. This data is used exclusively for sending the newsletter and is not passed on to third parties.
To analyze and optimize the effectiveness of our newsletter communication, we use tracking pixels (also called web beacons) in our newsletters. These are small, invisible graphics loaded when opening the newsletter. By retrieving the tracking pixels, we can capture technical information, such as your IP address, as well as information about your reading behavior, for example, whether and when you opened the newsletter and which links you clicked. This data is used exclusively to improve and optimize our newsletter offer, in particular to make the content more relevant, optimize the presentation, and adjust the frequency of dispatch. The legal basis for sending the newsletter is Art. 6 (1) lit. a) GDPR. To the extent processing is otherwise based on our legitimate interests, the legal basis is Art. 6 (1) sent. 1 lit. f) GDPR. You can revoke your consent to the newsletter dispatch at any time with effect for the future pursuant to Art. 7 (3) GDPR. To do this, you simply need to inform us of your revocation or click the unsubscribe link contained in every newsletter.
We use MailChimp for newsletter dispatch. MailChimp is a service of The Rocket Science Group, LLC, 512 Means Street, Suite 404, Atlanta, GA 30318, USA. The required level of data protection for data transmission to the USA is ensured by the DPF certification of MailChimp as well as supplementary Standard Contractual Clauses. The Rocket Science Group provides further data protection information at http://mailchimp.com/legal/privacy/.
5. Appointment Scheduling via Google Calendar
We offer you the opportunity on our website to schedule appointments for meetings or consultations directly online with us. For this purpose, we use the service Google Calendar, a service of Google Ireland Limited, Gordon House, Barrow St, Dublin, D04 E5W5, Ireland. If you schedule an appointment via the Google widget integrated on our site, the data entered by you in the input mask, such as your name, email address, and possibly other information provided by you (e.g., phone number, notes on the appointment) as well as your IP address and the time of booking, are transmitted to Google's servers and processed there. The purpose of this processing is the efficient, uncomplicated, and user-friendly coordination of appointments. The legal basis for processing your data is Art. 6 (1) lit. b) GDPR, as the appointment scheduling takes place at your request for the initiation or execution of a contractual relationship. Since the parent company of Google Ireland Limited, Google LLC, is located in the USA, a data transmission to the USA may also take place. The security of the transmission is guaranteed by the conclusion of Standard Contractual Clauses and the DPF certification of Google LLC. Further information on data processing by Google can be found at https://policies.google.com/privacy.
III. Data Processing When Using the 23° Platform (with Customer Account)
1. Registration and Management of the Customer Account
When you create a customer account on our platform, we collect and store your name and email address on the basis of Art. 6 (1) lit. b) GDPR for pre-contractual measures, contract fulfillment, or customer support. This allows us, for example, to provide you with an overview of your previous orders. Additionally, we store your IP address as well as the date and time of your registration. Transfer of this data to third parties does not take place. In the course of the further registration process, we also obtain your consent to this processing pursuant to Art. 6 (1) lit. a) GDPR. You can revoke the consent granted to us for opening and maintaining the customer account at any time with effect for the future pursuant to Art. 7 (3) GDPR. To do so, you simply need to inform us of your revocation. The data collected in this regard will be deleted as soon as processing is no longer necessary. However, we must observe retention periods under tax and commercial law.
For managing your customer data, we use the Customer Relationship Management platform of Pipedrive Inc., 530 Fifth Avenue, 8th Floor, Suite 802, New York, NY 10036, USA ("Pipedrive"). The security of transmission to the USA is guaranteed by the conclusion of Standard Contractual Clauses and the DPF certification of Pipedrive. Further information on data protection at Pipedrive can be found at: https://www.pipedrive.com/en/privacy.
2. Storage and Management of Statistics in the Customer Account
As a registered customer, you have the option to store, manage, and edit statistics and graphics created by you in your customer account. To enable this service within the scope of our contract (Art. 6 (1) lit. b) GDPR), we process the necessary data. This includes, in particular, content data provided by you (e.g., raw data from tables), technical metadata (such as title and creation date) linked to your account, and usage data relating to your interaction with the platform. Your content and metadata are generally stored as long as your customer account exists or until you actively delete a specific statistic.
3. License Purchase and Payment Processing
For the purchase of licenses and the processing of payments on our platform, we work with specialized external service providers. The transfer of your data to these service providers takes place exclusively for the purpose of contract processing pursuant to Art. 6 (1) lit. b) GDPR.
To process payments, we use the service provider Stripe, a service of Stripe Inc., 510 Townsend Street, San Francisco, CA 94103, USA. When you make a paid license purchase, your payment data such as name, address, credit card information, VAT ID number (VAT/UID), and your IP address are transmitted directly to Stripe and processed by Stripe as an independent controller. The processing of this data takes place for the fulfillment of the contract. Additionally, Stripe may use cookies to ensure the security of the transaction and prevent fraud. We base this additional processing on our legitimate interest in secure and smooth payment transactions pursuant to Art. 6 (1) lit. f) GDPR. The security of the transmission is guaranteed by the conclusion of Standard Contractual Clauses and the DPF certification of Stripe. Further information on data protection at Stripe can be found at: https://stripe.com/at/privacy.
To ensure that the correct VAT rate is shown on your invoice, we additionally use the service Octobat of Octobat SAS, 230 rue du General Leclerc, 95120 Ermont, France, for automated invoicing. In the course of billing, billing-relevant data such as your name, address, credit card information, VAT ID number (VAT/UID), and your IP address are also processed by Octobat. This processing is necessary for proper contract execution pursuant to Art. 6 (1) lit. b) GDPR. Further information on data protection at Octobat can be found at: https://www.octobat.com/privacy-notice.
IV. Data Processing Regarding Publication and Embedding of Statistics
1. Embedding of Statistics on External Websites
On our internet presence, 23°-statistics are integrated in the form of graphics and maps, which can also be displayed on third-party sites or social media platforms (e.g., via iFrame). We point out that 23°-statistics integrated on third-party sites do not set cookies. You can refer to the use of 23°-statistics in your own privacy policy as follows:
"Interactive infographics from 23degrees.io: Through the 'Embed' function, interactive infographics from 23degrees.io are integrated into the internet offer. Privacy policy of 23degrees.io: https://www.23degrees.io/privacy/."
2. Public Availability on the 23° Platform
As a registered user, you have the option to specifically publish statistics created by you on our platform and thus make them visible to third parties. If you make use of this option, the graphic or map created by you, the assigned title, and your public username become visible to every visitor of our website. This publication takes place exclusively upon your active instruction. The legal basis for the associated processing and making available to the public is your express consent pursuant to Art. 6 (1) lit. a) GDPR, which you grant us by clicking the "Publish" button. You can revoke this consent at any time by terminating the publication in your customer account.
V. Data Processing Within External Online Presences
We maintain online presences within social networks and platforms to communicate with customers, interested parties, and users active there and to inform them about our services. We point out that user data may be processed outside the European Union area and that we are partially jointly responsible with the respective operator for data processing on our profiles (Art. 26 GDPR). The processing of user data on these platforms, particularly interaction data and public profile data, is based on our legitimate interests in effective information and communication pursuant to Art. 6 (1) lit. f) GDPR.
Specifically, this concerns our appearances on the following platforms:
VI. Financing via Advertising and Pur Subscription Model
To be able to offer the informational use of our website free of charge, our offer is partially financed by displaying third-party advertising and through analysis procedures. We use the technologies employed for this, particularly the Google AdSense service described below, exclusively based on your express consent pursuant to Art. 6 (1) lit. a) GDPR, which you grant via our Consent Management Tool and can revoke at any time.
Please note: The data processing described below only takes place if you have agreed to the free use.
We integrate advertisements via Google AdSense on our website, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google AdSense uses cookies and so-called Web Beacons (invisible graphics). Through these technologies, usage data such as your IP address, information about your browser, the visited subpages of our website, and your interaction with the displayed advertisements are recorded and analyzed. This information is transmitted to a Google server in the USA and stored there to evaluate your user behavior and deliver advertising formats accordingly. Google will not merge your IP address with other data stored by you. The security of data transmission to the USA is guaranteed by the DPF certification and the conclusion of Standard Contractual Clauses. Further information on data processing can be found at https://policies.google.com/privacy.
Alternative: Tracking-Free Use in the Pur Subscription As an alternative to consent-based use, we offer you a paid subscription. By concluding this subscription, you can use our website largely free of tracking and advertisements by third-party providers. Please note that this Pur Subscription is independent of an existing customer account for the use of the 23° platform. A customer account alone does not lead to freedom from advertising.