Legal
Privacy policy
Information under Articles 13 and 14 of the General Data Protection Regulation (GDPR). Last updated: September 2026.
Controller
Christian Weninger, BuildMy.Agency, Badgasse 103, 2831 Scheiblingkirchen, Austria. Email: Info@buildmy.agency. I am the controller for the personal data described below.
What data I process
Account data: email address, password hash, sign-in metadata, optional profile details such as your name, photo, about text and contact options you add for your offers.
Usage data: the leads you claim, demo websites you generate, letters you prepare or dispatch, pipeline and revenue entries you record, plan and package balance, and technical logs needed to run and secure the service.
Business contact data: publicly available details of local businesses (company name, category, address, phone where public) that you use as prospects.
Billing data: subscription status, plan, renewal date and payment identifiers. Card details are handled by the payment provider and never reach my systems.
Demo page analytics: anonymous visit and QR-scan counts for the demo websites you generate, stored without profiling of individual visitors.
Why and on what legal basis
To provide the service and fulfil the contract with you (Art. 6(1)(b) GDPR): account, usage, lead and billing data. To comply with legal obligations such as bookkeeping and tax law (Art. 6(1)(c) GDPR). To keep the service secure, prevent abuse and improve reliability, based on my legitimate interests (Art. 6(1)(f) GDPR). Where I ask for your consent, for example for optional emails, the basis is Art. 6(1)(a) GDPR, and you may withdraw it at any time.
Your role when contacting businesses
When you use BuildMy.Agency to contact a business, you decide who to contact and what to send, so you are the controller for that outreach, and I act as your processor for the data involved. You are responsible for complying with applicable direct-marketing, competition and data-protection rules in the recipient's country, including honouring opt-out requests and marketing-suppression lists.
Processors and recipients
I use carefully selected service providers who process data only on my instructions and under a data processing agreement: hosting and database/authentication infrastructure, AI providers for generating demo websites, letters and offer text, mapping and business-data providers for lead discovery, print and mail providers for physical letters, the payment provider for subscriptions, and email delivery for transactional messages. Where a provider processes data outside the EEA, transfers are safeguarded by EU standard contractual clauses or an adequacy decision.
AI providers are instructed not to use content submitted through the service to train their models. Printed letters are transmitted to the mail provider only for the country you send to.
Bring-your-own mail provider keys
If you connect your own PostGrid or Pingen account, the API key is stored encrypted and used only to dispatch your own letters. You can remove it at any time in your settings.
Cookies and local storage
I use strictly necessary cookies and browser storage to keep you signed in, remember interface preferences and protect against abuse. No advertising or cross-site tracking cookies are set, so no consent banner is required.
Retention
Account and usage data are kept while your account exists and deleted after closure, except where longer retention is legally required — invoices and payment records are kept for seven years under Austrian tax law. Security logs are kept for a short period. Demo websites and letter records you delete are removed from active systems promptly.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent. Write to Info@buildmy.agency and I will respond within one month. You may also lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at).
Security
Data is transmitted over TLS, stored with row-level access rules so each account can only reach its own records, and files are held in private storage accessible only through short-lived signed links. Provider keys are encrypted at rest.
Automated decision-making
The service uses AI to generate content, but no decision with legal effect for you is made automatically.