MK-i Workflow Automations GmbH in Gründung
M.-Lang-Gasse 5
2380 Perchtoldsdorf
Austria
Email: [email protected]
Our website is designed to collect and process as little personal data as possible.
When you visit our website, your browser automatically transmits data to our server, which is temporarily stored in server log files:
This data cannot be directly attributed to specific individuals and is not merged with other data sources. Processing serves the technical security and proper functioning of the website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Retention period: Log files are automatically deleted after 7 days.
When you use our contact or inquiry form, or send us an email, we process the data you provide (e.g. name, email address, phone number, company name, address) as well as your message.
Purposes of processing:
Note: The transmitted data is used exclusively to process your inquiry and fulfil the agreement. Transmission to external processors may occur and is explained in section 4. You may withdraw your consent at any time with effect for the future.
This website provides a chat assistant that answers questions about our services. This assistant is an AI system, not a human. You are informed of this with the very first message in the chat window (Art. 50(1) of Regulation (EU) 2024/1689 on artificial intelligence).
Data processed: the messages you enter in the chat and a randomly generated technical session identifier used solely to keep the conversation together within one session. No sign-in is required; the chat does not ask for your name or contact details.
Purpose and legal basis:
Recipients: To generate the responses, your input is transmitted to a provider of cloud-based AI language models (third country: USA). The same safeguards and data processing agreements apply as described in section 4; inputs are not used to train the provider's models.
Retention: The conversation is kept together for the duration of your session. Technical processing logs in our automation system are retained only as long as required for operation and error analysis; otherwise section 3 applies.
Please note: Do not enter special categories of personal data (such as health data) or any credentials in the chat. For confidential matters please use the contact form or [email protected]. Responses are generated automatically and do not constitute legally binding information; they do not involve automated decision-making within the meaning of Art. 22 GDPR.
We store personal data only for as long as necessary to fulfil the respective purposes: during the processing of your inquiry, for the duration of a customer relationship, and beyond that only where statutory retention obligations exist or where necessary for the establishment, exercise or defence of legal claims. Data is deleted after expiry of the retention period or when the purpose no longer applies.
Transmission of your personal data to third parties only occurs where necessary for contract performance or required by law. Standard recipients:
Additionally, external data processors are engaged for order processing. Only those data categories required for the respective purpose are transmitted:
Notes on AI processing: Data processing agreements pursuant to Art. 28 GDPR are in place with the providers used. The inputs are processed exclusively to fulfil the specific order and are not used for training purposes by the provider. The retention period at the AI provider is limited to the duration of the respective request plus technically required security logs (usually 30 days). Please note that generative AI systems produce statistically probable content - the final content review remains with MK-i Workflow Automations or with you.
A copy of the Standard Contractual Clauses and further information on the third-country safeguards employed are available on request at [email protected].
Banking and billing-relevant data are not transmitted to the external data processors named above (AI language models, cloud infrastructure, messaging services). Payment-transaction data is exclusively transmitted to the banks required for payment execution.
Our website contains links to our profiles on external platforms (Twitter/X and Telegram). Clicking these links will redirect you to the respective platforms, where the privacy policies of those providers apply:
Please note: a connection to the servers of the respective network is only established when you actively click one of these links. At that point, your IP address and the fact that you came from our site (referrer) are transmitted to the provider. In the case of X (Twitter) in particular, this data may be transferred to the USA. We have no influence over any further processing of personal data by these providers.
Our website is operated in our own data centre in Austria. We do not transfer any personal data to third countries outside the EU as part of our hosting. For information on data transfers by external services (Telegram, X), please refer to the respective sections of this policy.
To exercise your rights, a simple informal email to [email protected] is sufficient.
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
Competent authority in Austria:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40-42, 1030 Vienna
Email: [email protected]
www.dsb.gv.at
As part of processing your redesign request, MK-i Workflow Automations performs an automated visual analysis of the URL you provide. The publicly accessible homepage is loaded and a screenshot is taken. Only publicly accessible content is analysed. There is no access to password-protected areas or internal systems.
The data collected (screenshot, visual analysis, order content you submit) is used exclusively to prepare the redesign offer. External data processors are engaged for the technical preparation (see Section 4).
Retention period: Screenshots and analysis results are retained for the duration of the redesign offer and deleted no later than 6 months after refusal or non-engagement.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) for inquiries via the form, or Art. 6(1)(f) GDPR (legitimate interest) for analyses in the context of business initiation.
If you request a website check via our audit form on websitecheck.mk-i.net, we process the URL you provide and your email address in order to compile and deliver the audit report.
Processing steps:
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in business initiation).
Retention period: Audit reports and accompanying data are retained for up to 6 months after the request; if you are entered on the internal suppression list, only the domain and the date of objection are recorded permanently in order to prevent future contact.
Once we have delivered a redesign draft, an audit result, or a follow-up email to you, we evaluate whether and when you have responded to the content delivered. The aim is to manage the specific case appropriately - timely reminders, classification as „no interest", and avoidance of unnecessary follow-up emails.
Legal basis: Art. 6(1)(b) GDPR (contract initiation and performance) or Art. 6(1)(f) GDPR (legitimate interest in resource-efficient, non-intrusive customer support).
Cookies: No cookies are set for this tracking. Evaluation takes place purely on the server and mail side.
Retention period: raw web server logs are deleted after 7 days (see Section 2.a). Aggregated visit counters and assigned replies remain part of the order record and are subject to the retention rules described in Section 12.
Right to object: you may object to this processing at any time by email to [email protected]. New visits and replies will then no longer be assigned to your case.
As part of order processing, we store your master data (salutation, name, company, address, VAT ID, email, phone) and the contents related to the order (URL, order description, drafts produced, correspondence, invoices, payment status) in our internal ERP system. The ERP system is operated on our own infrastructure in Austria.
Retention periods:
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (statutory retention obligations in conjunction with § 132 BAO and § 212 UGB).
If, as an existing customer or referrer, you pass on a referral code to a new prospective client and that prospect places a paid order, this gives rise to a cashback claim in your favour.
In this context we process the following data:
Payout or waiver in favour of an occasion-based donation: you may choose between having your cashback paid out to you and waiving the payout in favour of our donation partner. In the case of a waiver, MK-i Workflow Automations makes its own corporate donation on the occasion of your referral instead of paying out the cashback.
Publication on the donation list: on our public donation-partner page we maintain a list of occasion-based donations. A named entry (full name or company) is made solely with your express consent, which you grant by selecting the option „Donate with name" via the corresponding button in our confirmation email. If you choose „Donate anonymously", only a non-attributable short form (e.g. initials) is shown - your full name is not published.
Withdrawal of consent: you may withdraw your consent at any time with effect for the future by email to [email protected]. We will then promptly remove the entry from the public list; donations already made remain unaffected.
Legal bases:
Retention period: referral and cashback data are subject to the commercial and tax retention periods set out in Section 12. Entries on the public donation list remain visible until you withdraw your consent.
In individual cases we contact commercial recipients who have not previously contacted us, with a non-binding proposal for a new website or with a supplementary audit notice (so-called „acquisition demo"). Recipients and the occasion are determined on the basis of publicly available sources (own website, imprint, business directories) as well as on the basis of the technical initial check that we have conducted on your website.
We process exclusively:
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in initiating business relationships with commercial recipients). Such contact is made exclusively with substantive professional content and an offer of concrete cooperation; it is designed as a single proposal per recipient.
Information pursuant to Art. 14 GDPR: as we did not collect the data directly from you, this privacy policy serves as the information notice within the meaning of Art. 14 GDPR. Storage takes place for the duration of case processing and is subject thereafter to the periods set out in Section 12. No transmission to third parties takes place; the data processors named in Section 4 are only involved insofar as this is necessary for preparing the demo preview.
Right to object and suppression list: you may object to the processing of your data for acquisition purposes at any time without giving reasons - by email to [email protected] or via the button „Not interested" on the demo response page. We will then add your domain to an internal suppression list so that you will not be contacted again as part of our acquisition. Only the domain and the date of objection are stored permanently on the suppression list.
MK-i Workflow Automations automatically audits publicly accessible websites of Austrian businesses for technical defects (for example an expired certificate, no mobile rendering, outdated software, opening hours that differ from Google) and offers businesses with a verified finding as a sales contact ("lead") to agencies and service providers who wish to approach such businesses. Two groups of persons are affected.
Source of the data: We do not collect the data from you but from publicly available sources: the domain from public web archives (Common Crawl), open geodata (OpenStreetMap), public certificate registers (Certificate Transparency logs) and, where enabled, from business directories; the company details from the imprint and the publicly accessible pages of your website; opening hours and contact details from your Google Business Profile; the technical measurements produced when your website is loaded. There is no access to password-protected areas or internal systems.
Data processed: company name, domain, industry, address, phone number, e-mail address, contact persons named in the imprint, VAT ID and company register number, company size, province, the defects found together with their evidence, consisting of the text evidence, a screenshot of the page concerned and the time of the check, each finding under a finding ID, an opening line derived from them, and the audit date and processing status. This information is personal data in particular for sole proprietors and for contact persons named individually. No special categories of personal data are processed.
Purpose and legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in selling technically pre-qualified business contacts to sales organisations. You have published the information processed yourself, as a business, for the purpose of business contact; only business contact details and technical properties of your website are processed.
Recipients: A record is delivered to exactly one buyer, an agency or a service provider, and to no further buyer afterwards. Upon delivery the buyer becomes a data controller in its own right; it is contractually obliged towards us to use the data only for its own sales activities, not to pass it on and to delete it upon request. We supply buyers established outside the European Economic Area only under the conditions of Art. 44 et seq. GDPR. To verify findings we use providers of cloud-based AI language models; to compare against the Google Business Profile and to check for classification as a dangerous website we use the Google interfaces named in Section 4. Prospective buyers receive in advance only anonymised sample data from which company name, domain and all contact details have been removed, as well as screenshots of individual websites on which contact details are blacked out. If a buyer disputes a delivered finding, it receives the stored documentation of that finding, namely the text evidence, the screenshot and the time of the check; an accepted incorrect finding is replaced by another record, which is likewise delivered only to that buyer.
Retention: Records remain in our inventory for as long as the business is eligible for a delivery; undelivered findings are re-checked against the website at regular intervals. We delete the company and contact details of a business whose website has shown no finding for more than six months or is no longer reachable; the domain remains in the inventory without these details. Delivered records are retained as part of the invoice documentation pursuant to Section 12.
Information pursuant to Art. 14 GDPR: as we did not collect the data from you, this privacy policy serves as the information notice within the meaning of Art. 14 GDPR.
Right to object: you may object to this processing at any time without giving reasons by e-mail to [email protected]. We will then delete your record from our inventory, exclude your domain from further audits and deliveries, and instruct any buyer who has already received your record to delete it. To honour the exclusion permanently, only the domain and the date of objection are retained. Your other rights under Section 7 remain unaffected.
When you e-mail [email protected] to express interest in sales leads, we process your e-mail address, your name, your company and the content of your message. Incoming enquiries are automatically categorised by subject in our automation system. Requests for information are answered automatically with a sample package (anonymised sample data, price sheets, terms of delivery); questions about our offer are answered with the help of an AI language model (Section 4) from a fixed knowledge base. Complaints, requests for access or erasure, and all questions outside this knowledge base are handled by a human. Your address is recorded together with the time of the enquiry so that the same address does not receive the same package more than once within 30 days. No automated decision within the meaning of Art. 22 GDPR is involved.
When you place an order, we additionally process company, address, VAT ID, invoicing and payment data and the content of the delivery, i.e. which records were sent to you. The latter also serves to avoid selling the same records a second time and to forward erasure requests from affected businesses to you.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures and contract performance); for avoiding repeated mailings and for the double-sale protection, Art. 6(1)(f) GDPR.
Retention: enquiries pursuant to Section 3; order, delivery and invoice data pursuant to Section 12.
Last updated: September 2026