Legal

Privacy Policy

What personal data we process, on what legal basis, who receives it and what rights you have under Regulation (EU) 2016/679 (GDPR) and the Austrian Data Protection Act (DSG).

Version 1.1 Effective 4 September 2026 Applies to this website and to our marketing and sales mandates

01Controller

The controller responsible for the processing described here within the meaning of Art. 4(7) GDPR is:

Controller
Gabriel Inreiter, trading as Halyard Partner, Audorf 15b, 4542 Nußbach, Austria
Legal form
Sole trader (Einzelunternehmen) under Austrian law. Halyard Partner is a trading designation, not a company; it is not entered in the Austrian company register (Firmenbuch) and has no managing directors or shareholders. The owner (Inhaber) is personally responsible for the business and is the controller.
Email
desk@halyardpartner.com
Data protection officer
None appointed. Art. 37(1) GDPR requires a data protection officer only where the controller is a public body, where the core activity consists of regular and systematic monitoring of data subjects on a large scale, or where the core activity is large-scale processing of special categories of data or of data relating to criminal convictions. None of those applies to a one-person business processing business contact data in modest volume, and § 5 DSG imposes no additional duty. Every enquiry under this policy is therefore handled by the owner personally, at the email address above.

No telephone number is operated for this business; email and post are the available channels. Full disclosure details are set out in our Imprint. To exercise a right under section 11, write to the address above; a plain email is enough and no particular form is required.

02Our approach in short

  • This website sets no analytics, advertising or tracking cookies and runs no visitor-tracking script, no pixel and no consent banner.
  • We collect no data through web forms — there are no forms on this site, and the only contact route is a plain email link.
  • One thing does leave your browser when you open a page: the request itself, which our host processes as a server log. It is described in section 3. Fonts are served from our own hosting, so no request reaches Google or any other third party.
  • We do not sell personal data, and we do not pass it to third parties for their own marketing purposes.
  • Where we contact people at prospective client companies, we do so in a professional capacity, on the bases set out in section 6, and we stop on request without asking why.
  • Where we run campaigns or outreach inside a client's own accounts, we act on that client's instructions as a processor, under a written agreement (section 5).

03Data processed when you visit this website

Server log data

This website is operated on the infrastructure of Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. The project is pinned to Vercel's Frankfurt region (fra1), so requests are served from within the European Union. Vercel acts as our processor under Art. 28 GDPR on the basis of its data processing addendum.

When you open a page, your browser necessarily transmits technical data, which the host processes to deliver the page and to keep the service secure and stable. This comprises: the IP address of the requesting device, the date and time of the request, the page or file requested, the HTTP status and volume of data transferred, the referring URL where applicable, and the browser type, version and operating system reported by your device.

Purpose: delivery of the website, security (defence against attacks and abuse), diagnosis of faults and capacity planning. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable and technically faultless operation of our web presence; we consider this not to be overridden by your interests, as the data is not used to identify you, to contact you or to build a profile. Retention: log data is held by the host for a short operational period and in no case longer than 30 days, and beyond that only where a specific security incident requires it. We do not maintain a log archive of our own and do not merge log data with any other source. Third country: Vercel is a US company — see section 8.

Cookies and local storage

The public pages of this website set no cookies, use no local storage and embed no tracking pixels. No consent banner is therefore shown, because there is nothing to consent to.

A strictly necessary session cookie is set only if you log into a password-protected area of the domain on which this site is served. That cookie holds no personal profile and no advertising identifier, is used solely to keep you signed in, and rests on § 165(3) TKG 2021 in conjunction with Art. 6(1)(b) GDPR. If you never log in, no cookie is ever written.

Web fonts

The typefaces used on this site (Sora and IBM Plex Mono) are hosted by us and served from the same origin as the rest of the page. They are not embedded from Google Fonts or any other external font service. Opening a page therefore causes no connection to fonts.googleapis.com, to fonts.gstatic.com or to any other third-party server, and your IP address is not disclosed to Google or to any font provider.

The font files were obtained from the Google Fonts library, which publishes them under the SIL Open Font License, and are stored on our own hosting. Loading them involves no processing beyond the server log described above.

No profiling

We carry out no automated decision-making and no profiling within the meaning of Art. 22 GDPR on the basis of website usage, and we build no visitor profiles of any kind.

04When you contact us

There is no contact form on this website. If you write to us — by email, including through the "Request a review" link, which simply opens a message in your own mail programme, or by post — we process the data you choose to give us: your name, your business email address and any telephone number you supply, your employer, your role, and the content of your message together with any company information, pricing or deal figures you send.

Purpose: to answer you, to assess whether a mandate would fit, and to prepare a possible agreement. Legal basis: Art. 6(1)(b) GDPR for steps taken at your request prior to entering into a contract; in addition Art. 6(1)(f) GDPR, our legitimate interest in dealing properly with business enquiries and in documenting the correspondence.

Retention: we keep enquiry correspondence for as long as needed to deal with your request and thereafter for as long as follow-up questions may realistically arise — as a rule 24 months from the last exchange — unless it becomes part of a contractual relationship, in which case section 9 applies. Enquiries we decline are deleted at the end of that period.

Please do not send us information subject to a duty of confidentiality, trade secrets you are not free to disclose, or special categories of personal data (Art. 9 GDPR) by unencrypted email. Email transmission is not secure against unauthorised access; if you require an encrypted channel, ask us and we will arrange one.

05Data processed under a mandate

Halyard Partner runs marketing and sales for business clients in the crypto, Web3 and fintech sectors. A mandate typically involves four kinds of processing, and our role under the GDPR is not the same in all of them. The paragraphs below say which role we hold in each case, because that determines whom you should approach to exercise your rights.

Your contact persons — we are controller

Where you engage us, we process the personal data of your own contact persons — name, role, business contact details, correspondence, meeting notes, and the commercial data needed to agree the setup fee and calculate our commission. Legal basis: Art. 6(1)(b) GDPR for the performance of the agreement with your company, and Art. 6(1)(c) GDPR for the statutory retention obligations described in section 9. For this data we act as controller in our own right.

Campaigns on your advertising accounts — we are processor

Advertising and media budget is contracted and paid for by the client on the client's own advertising accounts; we plan and steer the campaigns, we do not hold the budget. In practice this means we are given access to accounts that belong to you — on Meta, Google, X, LinkedIn or comparable platforms — and we build, launch, monitor and optimise campaigns inside them on your instructions.

Where we do so, you are the controller and we act as your processor within the meaning of Art. 4(8) and Art. 28 GDPR. We process the data in those accounts — audience definitions, campaign and conversion statistics, any customer or target lists you upload, and the contact data of people who respond — only on your documented instructions and for no purpose of our own. A data processing agreement under Art. 28 GDPR is concluded before any such access is granted and forms part of every mandate; where it applies, it takes precedence over this policy for the data covered by it. The same applies where we send outreach from a mailbox on your domain or work inside your CRM.

The advertising platforms themselves are a separate matter. Meta, Google, X and LinkedIn do not process advertising data solely on instructions: for parts of the processing they act as controllers in their own right, and for other parts — in particular audience-building and measurement features embedded on your own properties — the platform and you may be joint controllers within the meaning of Art. 26 GDPR. That relationship exists between the platform and you as the account holder. We are not a party to it, we cannot conclude it on your behalf, and we cannot control what a platform does with data once it has been collected in your account. The platforms' own terms and privacy information govern it, and each of them transfers data to the United States. Part of our setup work is to tell you where those obligations fall so that you can meet them.

Data you supply to us

In the course of a mandate you may hand us personal data yourself: target lists and named accounts, exports from your CRM, records of past customers, or contact data of people who have already responded to you. We process that data solely for the mandate and solely on your instructions, under the same processing agreement. We rely on you having a lawful basis for the data you pass to us and for our use of it; if we have reason to believe an instruction infringes the GDPR or Austrian data protection law, we will say so and, where necessary, decline it (Art. 28(3) GDPR).

End of a mandate

Every account we open is yours from the first email. When a mandate ends, the accounts, lists, creative and records stay in your possession, and any personal data we hold as your processor is either returned to you or deleted at your choice, save for copies we are required to keep by law (section 9). Access we held to your systems and advertising accounts is given up at the same time.

06Data of contacts at prospective clients

Part of our business consists of approaching decision-makers directly — both at companies that might engage us, and, under a mandate, at companies that might buy from a client. This section describes the processing for which we are the controller: our own prospecting. Where the same activity is carried out inside a client's systems on the client's instructions, the client is the controller and section 5 applies instead.

The data processed is business contact data: name, role, employer, business email address, business telephone number where publicly listed, publicly available professional profile information, and a record of what was discussed and when.

Sources: public company websites, public professional networks and business directories, trade and commercial registers, event and press publications, referrals, and — under a mandate — information supplied by our client.

Legal basis: Art. 6(1)(f) GDPR. The legitimate interest pursued is direct business-to-business marketing, expressly recognised in Recital 47 GDPR, together with the commercial interest of the recipient's employer in learning of a relevant offer. Balancing test. We have weighed that interest against the interests and fundamental rights of the people concerned, and record the outcome here so that you can check our reasoning: we process business contact data only, never private addresses or private accounts; we address people solely in their professional capacity and about matters within their professional responsibility; the volume is modest and the approach is individual rather than a bulk campaign; we carry out no profiling, no scoring and no enrichment from data brokers; we process no special categories of data under Art. 9 GDPR and no data relating to criminal matters; the data is not combined with website data, is not sold and is not disclosed for anyone else's marketing; and we stop, permanently and without asking for a reason, the moment we are asked to. On that basis we consider that a professional contacted at their place of work about a matter within their remit would reasonably expect such an approach, and that their interests do not override ours.

Electronic contact under Austrian law. Whether the GDPR permits the processing and whether Austrian telecommunications law permits the channel are two separate questions, and we treat them separately. § 174 TKG 2021 (formerly § 107 TKG 2003) governs unsolicited messages: paragraph 1 makes calls and faxes for advertising purposes admissible only with the recipient's prior consent, and paragraph 3 does the same for electronic mail, including SMS, where the message is sent for direct marketing purposes or to more than 50 recipients. The exemption in paragraph 4 is narrow: it covers messages sent to a customer whose contact details were obtained in the course of a sale, for direct marketing of the sender's own similar products, where the recipient was given a clear and free opportunity to object at the time and in every message, and where the recipient is not entered in the list maintained by RTR under § 7(2) ECG. We do not treat the fact that a recipient is a business as an exemption in itself, because § 174 TKG 2021 does not provide one. In practice this means: we obtain consent where the message requires it; we check the RTR list before sending; under § 6 ECG we identify the sender and the commercial nature of the communication clearly in every message and never disguise it; and every message carries a working means of refusing further contact at no cost beyond that of transmission. Breaches of these rules are administrative offences and we treat them as such.

Information under Art. 14 GDPR. Where we obtain contact data from a source other than the person concerned, we provide the information required by Art. 14 GDPR — who we are, what we hold, where it came from, on what basis we process it and what rights you have — in our first communication, together with a link to this policy. On request we will tell you the specific source from which your data was taken.

Right to object. You may object at any time to the processing of your data for direct marketing, with effect for the future and without giving reasons (Art. 21(2) GDPR). The objection is absolute: there is no balancing exercise and no exception. We will then stop contacting you and record the minimum details needed on an internal suppression list solely so that the objection is respected in future — a legitimate and expressly permitted use under Art. 21(3) GDPR, and one that is not itself marketing. A single email to desk@halyardpartner.com is sufficient, and we confirm it in writing.

Retention: prospect data is reviewed periodically and deleted once a contact is no longer commercially relevant, at the latest 36 months after the last meaningful interaction. Suppression-list entries are kept for as long as necessary to honour the objection, which in practice means indefinitely, since deleting them would defeat their purpose.

07Recipients and processors

Personal data is disclosed only where necessary and only to the following categories of recipient. Every processor is bound by an agreement under Art. 28 GDPR and may process the data solely on our documented instructions. We use no advertising network, no analytics provider and no data broker.

Hosting
Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA — delivery of this website and server logs, as processor. Serving region: Frankfurt (fra1). See sections 3 and 8.
Web fonts
None. The typefaces are served from our own hosting, so no font provider receives any data about visitors to this site.
Email and office
The provider of our business mailbox and office software, acting as processor under an agreement pursuant to Art. 28 GDPR. As a one-person business we use a single such provider; it is named on request at the address in section 1.
CRM and outreach tools
Where a mandate requires a CRM or sequencing platform, it is the client's own system and we work inside it as the client's processor (section 5). Any record-keeping tool of our own is bound by an agreement under Art. 28 GDPR and named on request. We operate no shared prospect database across clients.
Advertising platforms
Meta, Google, X and LinkedIn, through their Irish or other EU establishments, where we run campaigns on a client's own advertising accounts. Data flows between the client's account and the platform; the platform acts as controller, or jointly with the client under Art. 26 GDPR, and not as our processor. See section 5.
Professional advisers
Tax adviser and, where required, legal counsel — bound by professional secrecy.
Mandate clients
Where a prospect becomes a client of the company we act for, the account record is handed over to that company, which then processes it as controller in its own right.
Authorities
Courts and public authorities, where we are legally obliged to disclose.

08Transfers to third countries

One transfer to the United States is inherent in how this website works, and it is described above: the hosting of the site by Vercel Inc. (section 3). Fonts are served from our own hosting and involve no transfer. Under a mandate, the advertising platforms named in section 7 likewise transfer data to the United States on the client's account.

Such transfers take place on the basis of Art. 45 GDPR where the recipient is certified under the EU–US Data Privacy Framework, on which the European Commission adopted an adequacy decision on 10 July 2023, and otherwise on the basis of Standard Contractual Clauses under Art. 46(2)(c) GDPR together with supplementary technical and organisational measures. Vercel offers both routes in its data processing addendum. Pinning our deployment to the Frankfurt region keeps the serving of this site inside the European Union, but it does not by itself exclude access by a US parent company, and we do not present it as if it did.

We draw your attention to the residual risk that authorities in a third country may seek access to data on the basis of local law, that an adequacy decision may be challenged or annulled — as its two predecessors were — and that the legal remedies available there may not correspond in every respect to those available within the EEA. A copy of the safeguards in place can be requested from us at the address in section 1.

09Retention

We keep personal data only for as long as it is needed for the purpose for which it was collected, and thereafter only where a statutory retention obligation applies or where the data is required to establish, exercise or defend legal claims.

  • Accounting records, invoices, contracts and anything with a billing dimension: seven years under § 132 of the Federal Fiscal Code (BAO) and § 212 UGB, running from the end of the calendar year concerned; longer where a matter is pending before a court or authority. This obligation overrides a request for erasure for as long as it runs, and it covers setup-fee and commission records, which necessarily identify the client contacts involved.
  • Correspondence relating to a mandate: for the term of the mandate and thereafter for the duration of the general limitation period, as a rule three years (§ 1489 ABGB), and up to thirty years for claims subject to the long limitation period.
  • Data held as a processor for a client: for the term of the processing agreement, then returned or deleted at the client's choice (section 5), subject only to the statutory periods above for our own billing records.
  • Enquiries (24 months), prospect data (36 months), server logs (30 days): as stated in sections 3, 4 and 6.

Once the applicable period expires, the data is deleted or irreversibly anonymised as a matter of routine. Where data must be retained under one of the periods above but is no longer needed for any active purpose, we restrict its processing rather than continue to use it.

10Security

We apply technical and organisational measures appropriate to the risk under Art. 32 GDPR. These include TLS encryption of all traffic to this website, HTTP strict transport security, a restrictive content security policy and a strict referrer policy, full-disk encryption on the devices used for the business, multi-factor authentication on business accounts, and periodic review of the providers we use. Because this is a one-person business, access to the data described here is limited to the owner and, under a mandate, to the client's own named staff within their own systems; there is no wider internal circle.

No transmission over the internet can be made absolutely secure; we cannot therefore guarantee absolute protection, but we do commit to notifying the supervisory authority and, where the law requires it, you personally in the event of a breach, within the periods set by Art. 33 and Art. 34 GDPR.

11Your rights

In respect of the personal data we hold about you, you have the following rights. Exercising them is free of charge, and we respond within one month of receiving your request; where a request is complex we may extend that period by two further months and will tell you if we do.

  • Access (Art. 15) — confirmation of whether we process your data, a copy of it, and the accompanying information.
  • Rectification (Art. 16) — correction of inaccurate data and completion of incomplete data.
  • Erasure (Art. 17) — deletion where one of the listed grounds applies and no retention obligation under section 9 stands in the way.
  • Restriction (Art. 18) — suspension of processing while a dispute over accuracy or lawfulness is resolved.
  • Portability (Art. 20) — receipt of the data you provided in a structured, commonly used, machine-readable format, where processing rests on consent or contract and is automated.
  • Objection (Art. 21) — to processing based on Art. 6(1)(f). Against direct marketing the objection is absolute and needs no reasons; otherwise we will stop unless we can show compelling legitimate grounds that override your interests.
  • Withdrawal of consent (Art. 7(3)) — at any time, with effect for the future, where processing rests on consent. The lawfulness of processing before withdrawal is unaffected.

To exercise any of these, write to desk@halyardpartner.com. We may ask you for information sufficient to confirm your identity, and for nothing beyond that. Where we hold your data as a processor for one of our clients (section 5), the client is the controller: we will pass your request to them without delay and tell you that we have done so, since the answer is theirs to give.

Right to lodge a complaint. If you consider that our processing infringes the GDPR, you may lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the alleged infringement. The competent authority for us is:

Authority
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Address
Barichgasse 40–42, 1030 Vienna, Austria
Email
dsb@dsb.gv.at
Web
dsb.gv.at

We would ask you to raise the matter with us first — it is usually quicker, and your right to complain is unaffected either way.

12Is providing data required?

You are under no statutory or contractual obligation to provide us with personal data, and this site asks you for none: there are no forms and nothing to fill in. Providing the technical data described in section 3 is a necessary consequence of using the internet, and without the contact details you choose to send us under section 4 we cannot answer an enquiry or enter into an agreement with you. Declining a business approach under section 6 has no consequence whatsoever beyond our ceasing to contact you.


13Changes to this policy

We update this policy when our processing changes or when the law requires it. The version and effective date at the head of this page always identify the current text. Where a change materially affects a processing operation you are involved in, we will inform you of it directly.