Skip to content
// legal · privacy

Privacy.
Accountable.

How CU Development GmbH, trading as seeu agency, collects, processes and protects personal data — structured along the GDPR.

// Effective: May 2026.
// contents

This policy describes how we process personal data in connection with the website seeu.agency and our agency services. The GDPR, the Austrian Data Protection Act (DSG) and § 165 TKG 2021 apply.

// 01.

Controller

CU Development GmbH
Brand name: seeu agency
Grazer Straße 62, 8111 Gratwein-Straßengel, Austria
Managing director: Christian Lenz

A data protection officer is not required by law and has not been appointed.

// 02.

Principles

We process personal data only on a legal basis under Art. 6(1) GDPR: consent (lit. a), contract or pre-contractual steps (lit. b), legal obligation (lit. c) or legitimate interest (lit. f). We name the basis for each individual processing activity.

We retain data only as long as it is needed for the purpose or as long as statutory retention obligations apply — in particular seven years under § 132 of the Austrian Federal Fiscal Code (BAO).

// 03.

Visiting the website (server log files)

When you visit the website, our hosting provider Vercel automatically processes: IP address, date and time, page requested, referrer, browser type and version, operating system, HTTP status and volume of data transferred.

Purpose. Technical delivery, stability and security of the website.

Legal basis. Legitimate interest (Art. 6(1)(f) GDPR).

Retention. Log files are deleted after 30 days at the latest.

Provider. Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Data processing agreement under Art. 28 GDPR; transfers to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR) and standard contractual clauses. Privacy policy: vercel.com/legal/privacy-policy

// 04.

Cookies and consent

We use strictly necessary cookies (storing your cookie choice in the cookie “seeu_consent”, lifetime 6 months). Legal basis: legitimate interest (Art. 6(1)(f) GDPR), § 165(3) TKG 2021.

All other cookies and comparable technologies (sections 5 and 6) are only set after your explicit consent given through our cookie banner (Art. 6(1)(a) GDPR, § 165(3) TKG 2021). You can change or withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer.

// 05.

Web analytics (PostHog)

We use PostHog to understand how the website is used and to improve it.

Without consent. PostHog records anonymous page views without cookies and without storing anything on your device. The IP address is discarded on receipt; recognising you across visits is not possible. Legal basis: legitimate interest in aggregated reach measurement (Art. 6(1)(f) GDPR).

With consent (“Statistics”). PostHog sets cookies (ph_*, lifetime up to 12 months), recognises returning visits and records sessions (session replay: mouse movement, clicks, scrolling, the parts of the page displayed). Input into form fields is masked and not recorded. Legal basis: consent (Art. 6(1)(a) GDPR).

Retention. Analytics data and recordings are deleted after 12 months at the latest.

Provider. PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. The data is processed exclusively in PostHog’s EU cloud (data centre Frankfurt, Germany). Data processing agreement under Art. 28 GDPR; standard contractual clauses (Art. 46 GDPR) cover any support access from the USA. Privacy policy: posthog.com/privacy

// 06.

Advertising and conversion measurement (OpenAI Ads)

We advertise inside ChatGPT (OpenAI). To measure whether that advertising leads to enquiries, we use the OpenAI Ads pixel — only after your consent (“Marketing”).

Browser pixel. When you reach a page through an ad, OpenAI passes a click identifier (URL parameter “oppref”). The pixel stores that identifier in the cookie “__oppref” and transmits events (e.g. page view, enquiry submitted) together with the identifier, IP address and browser information to OpenAI.

Server-side transmission (Conversions API). If you submit the intro-call form and have accepted marketing cookies, we transmit your email address and phone number in hashed form (SHA-256, never in clear text) together with the click identifier to OpenAI, so that OpenAI can attribute the enquiry to an ad. Without marketing consent, nothing is transmitted.

Legal basis. Consent (Art. 6(1)(a) GDPR, § 165(3) TKG 2021). Withdrawal at any time via “Cookie settings” in the footer.

Retention. Cookie “__oppref” up to 90 days; retention at OpenAI follows their own terms.

Provider. OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland (controller for users in the EEA). Data may be transferred to OpenAI, L.L.C., San Francisco, USA on the basis of the EU-US Data Privacy Framework or standard contractual clauses. Privacy policy: openai.com/policies/privacy-policy

// 07.

Contact and intro call

Contact form and email. When you get in touch, we process the data you send us (name, email address, company, message) in order to handle your enquiry. Legal basis: pre-contractual steps (Art. 6(1)(b) GDPR) or legitimate interest in answering (lit. f).

Intro-call form. At /intro-call you can request a free intro call. We process: company name, first and last name, email address, phone number, the size bracket of your business, the topics you selected and — where given — your website and free text. We also record where the enquiry came from (landing page visited, campaign parameters, referring page) in order to understand which route produced it (legitimate interest in evaluating our advertising, Art. 6(1)(f) GDPR). For a referral we process name, email address and your request.

Contact by phone. We use your phone number to contact you for the intro call and to agree on appointments. The call is not recorded. Legal basis: pre-contractual steps (Art. 6(1)(b) GDPR) and the consent you give in the form (lit. a), which you can withdraw at any time.

Appointment booking (Cal.com). In the last step of the form, the Cal.com booking calendar is loaded — only once you reach that step. Your browser then connects to Cal.com (transmitting your IP address; Cal.com may set its own cookies). Name, email address, phone number, the slot you choose and your time zone are transmitted to Cal.com. Legal basis: pre-contractual steps (Art. 6(1)(b) GDPR). Provider: Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. Data processing agreement; transfer to the USA on the basis of standard contractual clauses. Privacy policy: cal.com/privacy

Recipients. Your enquiry reaches us by email (sent via Resend) and is stored in our customer management system monday.com. Both are processors under Art. 28 GDPR. monday.com Ltd., 6 Yitzhak Sadeh St., Tel Aviv, Israel — adequacy decision of the EU Commission for Israel (Art. 45 GDPR). Resend (Plus Five Five, Inc.), 2261 Market Street #5039, San Francisco, CA 94114, USA — standard contractual clauses.

Retention. If no business relationship comes about, we delete the enquiry data 12 months after the last contact at the latest. If a contract is concluded, section 8 applies.

// 08.

Business relationships (clients, partners, suppliers)

Within contracts we process master data of contact persons (name, position, contact details), communication data (emails, meeting notes), project data (briefings, content, feedback) and billing data (invoice address, bank details).

Purpose. Performance of the contract, invoicing, compliance with legal obligations.

Legal basis. Contract (Art. 6(1)(b)), legal obligation (lit. c), legitimate interest in the proper conduct of business (lit. f).

Recipients. Tax advisors and accounting, monday.com (customer management), Resend (email delivery), Vercel (hosting).

Retention. For the duration of the business relationship, then in line with statutory retention obligations (seven years).

// 09.

Data in project work (processing on behalf)

When we build or maintain systems for clients, we come into contact with personal data of third parties (e.g. customer records in a CRM, imagery, access to third-party systems). In those cases we act as a processor on behalf of the client, exclusively on the basis of a data processing agreement under Art. 28 GDPR and the client’s documented instructions. The client is the controller.

Use of AI tools. We use AI tools when delivering our services. Which tools these are, where they process data and how we exclude the use of inputs for training purposes is described at seeu.agency/en/legal/ai. We only pass client data to AI tools where this is necessary for the commissioned service and covered by the data processing agreement.

// 10.

Recipients and third-country transfers at a glance

  • Service: Vercel
    Provider, seat: Vercel Inc., USA
    Purpose: Hosting
    Transfer basis: DPF / SCC
  • Service: PostHog
    Provider, seat: PostHog Inc., USA — data held in the EU (Frankfurt)
    Purpose: Web analytics
    Transfer basis: SCC (support access)
  • Service: OpenAI Ads
    Provider, seat: OpenAI Ireland Ltd., IE / OpenAI L.L.C., USA
    Purpose: Ad conversion measurement
    Transfer basis: DPF / SCC
  • Service: Cal.com
    Provider, seat: Cal.com, Inc., USA
    Purpose: Appointment booking
    Transfer basis: SCC
  • Service: monday.com
    Provider, seat: monday.com Ltd., Israel
    Purpose: Customer management
    Transfer basis: Adequacy decision
  • Service: Resend
    Provider, seat: Plus Five Five, Inc., USA
    Purpose: Email delivery
    Transfer basis: SCC

Data processing agreements under Art. 28 GDPR are in place with all providers. For transfers to the USA we rely on the adequacy decision for the EU-US Data Privacy Framework where the provider is certified, otherwise on standard contractual clauses (Art. 46(2)(c) GDPR).

// 11.

Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR).

Write to hi@seeu.agency; for security we may ask you to verify your identity. We answer within one month.

Right to complain. Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at (Art. 77 GDPR).

// 12.

Security

We take technical and organisational measures under Art. 32 GDPR, in particular TLS encryption, access controls, regular security updates and the careful selection of our processors. Please note that data transmission over the internet can have security gaps; complete protection against third-party access is not technically possible.

// 13.

Minors

Our services are addressed to businesses. We do not knowingly process data of persons under 18; should we become aware of such data, we delete it.

// 14.

Changes

We update this policy when the law, the technology or our services change. The version published on this page, with its effective date, is the one that applies.