Privacy · GDPR
Privacy Policy
Protecting your personal data is important to us. This policy explains which personal data is processed when you visit this website or contact us.
Last updated: August 2026
01
Controller
Christian Mayhofer Psychotherapy Mölker Bastei 3/4/19 1010 Vienna, Austria Phone: +43 699 114 40 114 Email: christian@mayhofer.eu
02
Data-processing principles
We process personal data solely in accordance with the General Data Protection Regulation (GDPR), the Austrian Data Protection Act and other applicable laws. In particular, we observe the principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and confidentiality.
03
Website delivery and server logs
When you access this website, your device transmits technically necessary data to the web server. This may include your IP address, date and time of access, requested page or file, referrer URL, browser and operating-system information, HTTP status code and transferred data volume. This data is processed to deliver the website, ensure its stability and security, and investigate technical faults or attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of this website. Server logs are generally retained for no longer than 14 days. They are retained longer only when necessary to investigate a specific security incident.
04
Hosting by Hetzner
This website is hosted on a cloud server provided by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. Hetzner processes technically necessary data on our behalf under a data-processing agreement pursuant to Article 28 GDPR. The server used for this website is operated within the European Union or European Economic Area.
05
Contact by email or telephone
If you contact us by email or telephone, we process the information you provide—particularly your name, contact details, enquiry and, where applicable, appointment information—to respond and to prepare or provide the requested services. The legal basis is Article 6(1)(b) GDPR where processing concerns pre-contractual steps or performance of a contract, and otherwise Article 6(1)(f) GDPR. Where you provide health data or other special-category data and processing is necessary for psychotherapeutic care, processing is based on Article 9(2)(h) GDPR and applicable professional rules. Please send only the information necessary for initial contact by unencrypted email.
06
Retention of enquiry data
Enquiry data is retained only for as long as necessary to handle the enquiry, provide services, or comply with statutory documentation and retention duties. If no professional relationship is established, enquiry-only data is generally deleted after six months unless legal obligations or legitimate reasons require longer retention. Statutory documentation, retention and limitation periods remain unaffected.
07
Cookies, analytics and external content
The publicly accessible website does not use cookies. We do not use web analytics, advertising or tracking services, social-media plugins, or externally hosted fonts. Fonts and images are delivered directly from our server. Consequently, no consent banner is required.
08
Recipients and international transfers
Personal data is disclosed only where necessary for the stated purposes, required by law, or based on your consent. Hetzner receives technically necessary access as our hosting processor. Any other technical service providers are used only where required and on an appropriate contractual basis. Website data is not intended to be transferred outside the European Union or European Economic Area. Personal data is not sold or disclosed for advertising purposes.
09
Your rights
Subject to the applicable legal requirements, you have rights of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, you may withdraw that consent at any time with future effect. To exercise your rights, contact christian@mayhofer.eu. You also have the right to lodge a complaint with a data-protection authority. In Austria, the competent authority is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, phone +43 1 52 152-0, email dsb@dsb.gv.at, www.dsb.gv.at.
10
Data security and updates
We use appropriate technical and organisational measures to protect personal data against loss, unauthorised access and misuse. This website is transmitted using HTTPS encryption. This privacy policy will be updated if the website, the services used or legal requirements change. The version published on this page applies.