This Privacy Policy explains how personal data is processed when you visit this website, apply for a service or work with Anna-Carina Hausegger. Processing is governed by the General Data Protection Regulation (GDPR), the Austrian Data Protection Act and other applicable legislation.
1. Controller
Anna-Carina Hausegger
Sole proprietorship
Grazer Vorstadt 64/4
8570 Voitsberg
Austria
Email: annachausegger@gmail.com
Telephone: +43 650 855 6131
2. General principles and legal bases
Personal data is processed only where necessary to operate the website, communicate with you, assess an application, enter into or perform a contract, process payments and provide the agreed service. Depending on the activity, processing is based in particular on consent under Article 6(1)(a) GDPR, pre-contractual measures or contract performance under Article 6(1)(b), legal obligations under Article 6(1)(c), or legitimate interests under Article 6(1)(f).
3. Website and hosting
The website is provided through GitHub Pages and the related GitHub infrastructure. When the website is accessed, technically necessary information may be processed, including IP address, time of access, requested resource, referring page, browser and device information, and server logs. This is necessary to provide a secure, stable and functional website.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure operation of the website. Recipients may include GitHub, Inc., affiliated entities and infrastructure providers. We also use Cloudflare for DNS, security and content-delivery functions. Cloudflare, Inc. and its affiliated entities may process IP addresses, technical connection data and security information. This processing is necessary for the secure, fast and stable operation of the website and is based on Article 6(1)(f) GDPR.
GitHub and Cloudflare may process data outside the European Economic Area. Transfers are based on an applicable safeguard under Chapter V GDPR, in particular an adequacy decision or Standard Contractual Clauses.
4. Google Analytics
Where you consent through the consent banner, we use Google Analytics to obtain statistical information about the use of this website. The provider for users in the EEA is generally Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data processed may include usage, device and browser information, approximate location data and online identifiers.
Google Analytics is activated only after consent. The legal basis is Article 6(1)(a) GDPR. You may withdraw consent at any time with future effect through the cookie settings. Google LLC may also process data in the United States. Transfers are based, where applicable, on the EU–US Data Privacy Framework or Standard Contractual Clauses.
5. Contact by email or telephone
When you contact us, we process your name, contact details, message and related information to answer your enquiry and, where relevant, prepare a contract. The legal bases are Article 6(1)(b) and, for orderly business communication, Article 6(1)(f) GDPR.
6. Appointment booking through Cal.com
Cal.com is used to arrange application calls. Data may include your name, email address, appointment, time zone and technically required usage data. Sensitive personal information is not intended to be requested in the calendar form. Processing serves appointment organisation and pre-contractual measures under Article 6(1)(b) GDPR.
The provider is Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, United States. Data may be processed in the United States. Cal.com provides contractual data-protection safeguards for international transfers; EU data residency is not assumed by default. The applicable Cal.com data-protection terms and transfer mechanisms govern the processing.
7. Application call and selection
During an application call, information may be processed about your current circumstances, a decision already made, your expectations, willingness to implement change and the desired support. The purpose is to assess mutual suitability and potentially prepare a contract under Article 6(1)(b) GDPR.
If no contract is concluded, substantive call notes are generally deleted within seven days, unless legal obligations or legitimate grounds require longer retention.
8. Contracts, invoices and Stripe payments
We process master data, invoice information, contract information, payment status and tax-related evidence for contract administration, bookkeeping and payment. Payments are handled through Stripe, which processes payment and transaction data. The legal bases are Article 6(1)(b) and (c) GDPR. Contracts, invoices and tax records are retained for the applicable statutory periods.
For a Stripe account based in Austria, the party to Stripe’s Data Processing Agreement is generally Stripe Payments Europe, Limited (SPEL), Ireland. Depending on the payment service, additional Stripe entities, banks or payment-method providers may be involved. Stripe may process data outside the EEA and relies in particular on the EU–US Data Privacy Framework and Standard Contractual Clauses for international transfers. Stripe’s Data Processing Agreement forms part of the applicable Stripe contractual terms.
9. Onboarding and intake
After the agreed initial payment has been completed, we may process:
- name, contact, invoice and delivery details;
- telephone number, time zone and preferred programme language;
- full birth name, date and exact time of birth, confidence in the recorded time, and place of birth;
- information about the decision already made, current circumstances and desired change;
- flower preferences, intolerances, allergies and relevant pet information.
This information is used to prepare, organise and provide REINVENTION under Article 6(1)(b) GDPR. To the extent information may reveal health data, it is processed only with explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR. Voluntary consent may be withdrawn at any time with future effect.
10. Metaphysical tools
Birth data may be used for individual reflections involving Human Design, Gene Keys, numerology and complementary astrology. These tools are used only for personal orientation and reflection. They are not binding instructions and do not replace autonomous decision-making.
HUMDES is used to prepare these reflections. Full birth name, date, time and place of birth may be transferred to and processed by HUMDES. Further information is available in HUMDES’s privacy information. Other external chart providers will be used only after a data-protection assessment and an appropriate update to this Privacy Policy.
11. Zoom sessions and recordings
Live sessions take place through Zoom. Processing may include name, connection and device information, audio, video, chat messages and shared content. The legal basis for the session is Article 6(1)(b) GDPR.
Sessions are recorded only after prior, express and voluntary consent under Article 6(1)(a) GDPR. Refusing or withdrawing recording consent does not prevent participation. Recordings are used solely by Anna for internal review, follow-up communication and preparation of the REINVENTION Map. Clients do not receive access to internal recording links.
Recordings are stored in the Zoom Cloud and are subsequently used only for the internal purposes described above. The provider is Zoom Video Communications, Inc. or the relevant group entity under the applicable Zoom terms. Zoom may process personal data outside the EEA, particularly in the United States. International transfers are based on the safeguards provided by Zoom, including the EU–US Data Privacy Framework or Standard Contractual Clauses.
Recordings stored in the Zoom Cloud and any local working copies are deleted no later than 60 days after the Integration & Handover Session, unless earlier deletion is requested or mandatory grounds require otherwise. Withdrawal operates prospectively and does not affect the lawfulness of earlier processing.
12. Personal WhatsApp Business chat
A personal WhatsApp Business chat is used as a space for reflection and communication between sessions. Telephone number, profile and communication data, and content voluntarily shared may be processed. WhatsApp is not an emergency or crisis channel. Replies are generally provided within 24 hours on business days; weekend and public-holiday messages are answered by the next business day.
The provider for users in the EEA is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Processing is based on Article 6(1)(b) GDPR and, where required, consent under Article 6(1)(a). WhatsApp Ireland may transfer data to WhatsApp LLC, Meta Platforms, Inc. and further subprocessors outside the EEA. Such transfers are based in particular on the EU–US Data Privacy Framework or Standard Contractual Clauses.
WhatsApp Business access to the device address book is limited to business contacts required for the service. Please share through WhatsApp only information you wish to communicate using that service.
13. iCloud and client folders
Programme documents, working notes and recordings are stored in a separate, protected iCloud folder for each client. Only Anna-Carina Hausegger has access to the complete client folders. Access to the Apple ID is protected by two-factor authentication, client folders are not shared with third parties, and Apple’s available security and encryption functions are used. Processing is based on Article 6(1)(b) GDPR and, for security and organisation, Article 6(1)(f). Apple may process data as a technical provider, including through international transfers supported by the applicable safeguards.
14. Flower delivery
To send the personalised flower arrangement, the necessary name, delivery address, preferences and safety notes may be shared with a selected florist or delivery provider. Only the data required for delivery is shared under Article 6(1)(b) GDPR. For international deliveries, processing may occur in the destination country.
15. Follow-up emails and programme communication
After sessions, follow-up emails may summarise key insights, decisions, next steps and observations. This communication forms part of the contracted service and is processed under Article 6(1)(b) GDPR. It is separate from promotional email communication.
16. REINVENTION Map
A personal REINVENTION Map may be prepared at the conclusion of the programme. It can consolidate relevant reflections, orientation, decisions, warning signs, anchors and agreed next steps. Its digital or printed format is agreed individually. If printing or delivery is selected, necessary details may be shared with a carefully selected production or delivery provider.
17. Recipients and processors
Depending on the service, recipients may include IT and hosting providers, booking and video-conferencing providers, payment providers, cloud-storage and communication services, accounting and tax advisers, florists, printers and delivery providers. Data is shared only where lawful and necessary for the relevant purpose.
18. International transfers
Some providers may process data outside the EEA. In such cases, transfers are based on an appropriate legal mechanism, such as an adequacy decision, the EU–US Data Privacy Framework where the recipient is validly certified, or Standard Contractual Clauses together with any necessary supplementary measures.
19. Retention
Personal data is retained only for as long as required for its purpose. In particular:
- Zoom recordings and local working copies: no later than 60 days after the Handover Session;
- substantive application-call notes where no contract is concluded: seven days;
- administrative application and correspondence data where no contract is concluded: 30 days;
- intake data and programme working notes: for the duration of the engagement; deleted after its conclusion unless legal obligations or legitimate grounds require continued retention;
- contracts, invoices and tax records: for statutory retention periods;
- correspondence: while required for contract performance, evidence or legal claims.
20. Your rights
Subject to statutory requirements, you have rights of access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn at any time with future effect. Requests may be sent to annachausegger@gmail.com.
You may lodge a complaint with a supervisory authority. In Austria, the competent authority is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
21. Security
Appropriate technical and organisational measures are used to protect personal data against loss, unauthorised access, alteration and disclosure. These include separate client folders, access restrictions, current device security and two-factor authentication where available.
22. Changes to this Privacy Policy
This Privacy Policy may be updated when services, processing activities or legal requirements change. The version made available on the website applies.
In the event of discrepancies, the German version is the legally relevant reference text, subject to mandatory law.