1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Pavel Glivinskiy
Individual/Sole Trader under Australian law
Website and business name: WebAktive
14 Thorpe Street
White Rock QLD 4306
Australia
Telephone: +61 488 644 683
Email: info@webaktive.com
Further legal information is available in our Legal Notice.
Representative in the European Union under Article 27 GDPR
Oleg Glivinskii
Kastanienweg 2
79790 Küssaberg-Reckingen
Deutschland
alegagliv86@gmail.com
+49 157 55145693
No data protection officer has been appointed. You may send privacy enquiries directly to info@webaktive.com.
2. Scope and legal bases
This Privacy Policy explains how we process personal data when you visit webaktive.com, use our contact options, submit an enquiry or work with us on a customer project.
Personal data means information relating to an identified or identifiable natural person. We process such data only where a legal basis applies and limit the processing to what is necessary for the relevant purpose.
Depending on the processing activity, we rely in particular on:
- Article 6(1)(a) GDPR — consent;
- Article 6(1)(b) GDPR — performance of a contract or steps taken at the data subject’s request before entering into a contract;
- Article 6(1)(c) GDPR — compliance with a legal obligation;
- Article 6(1)(f) GDPR — legitimate interests, especially secure website operation, prevention of misuse, efficient communication and the establishment, exercise or defence of legal claims.
3. Processing in Australia and territorial scope of the GDPR
The controller is established in Australia. If you contact or work with us, your data will therefore also be processed in Australia.
WebAktive specifically offers services to individuals and organisations in Germany and other European Union countries. Where personal data of people in the Union is processed in connection with that offering, the GDPR applies under Article 3(2) GDPR.
Australia is not currently covered by an adequacy decision of the European Commission under Article 45 GDPR. This means that the general level of data protection in Australia has not been formally recognised as equivalent to the EU level through such a decision. WebAktive applies the requirements of the GDPR to processing within its scope. However, because the controller is located outside the EU, practical enforcement of rights may be more difficult.
Where we transfer data to external recipients in third countries, we use appropriate safeguards such as Standard Contractual Clauses or another legally recognised transfer mechanism where required. Relevant safeguards are described in the applicable sections below.
4. Website hosting and delivery
The website is delivered using Cloudflare services. These may include a content delivery network, security functions, Cloudflare Workers and the technical delivery of the website.
Provider:
Cloudflare, Inc.
101 Townsend Street
San Francisco, CA 94107
United States
When the website is accessed, technically required data is processed. This may include:
- IP address;
- date and time of the request;
- requested address and amount of data transferred;
- referrer URL;
- browser type, browser version, operating system and device characteristics;
- HTTP status and technical error information;
- security and network characteristics needed to prevent abusive access.
The processing is necessary to display the website, maintain stability, investigate errors and protect the service against attacks, spam and other misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website.
Cloudflare uses globally distributed infrastructure. Where Cloudflare processes personal data on our behalf, the processing is governed by Cloudflare’s contractual data protection terms. For relevant international transfers, Cloudflare’s Data Processing Addendum provides safeguards including Standard Contractual Clauses.
Further information:
- https://www.cloudflare.com/privacypolicy/
- https://www.cloudflare.com/cloudflare-customer-dpa/
Technical log data is processed only for as long as necessary for website operation, security, prevention of misuse and compliance with legal obligations. The precise technical retention period may depend on the type of event and the Cloudflare account settings. Security data relating to a specific incident may be retained until the incident has been resolved and associated claims have expired.
5. Contact form
When you use our contact form, we process the information you enter. The current form may collect:
- your name;
- your email address;
- an optional telephone number;
- the selected service;
- your message and any information you voluntarily include in it;
- technical data required for transmission, security and spam prevention.
The information is processed through a Cloudflare Worker and delivered over an authenticated, TLS-encrypted SMTP connection to our mailbox info@webaktive.com, hosted with MXroute on a mail server located in Germany. You also automatically receive a confirmation email at the address you provided, so you know your enquiry arrived. We do not currently intend to keep a separate permanent copy of the form content in our own form database. Cloudflare may nevertheless generate technical security and error logs.
The purposes are to respond to your enquiry, assess a possible project and prepare a quotation or contract. Where your enquiry concerns a possible contract, the legal basis is Article 6(1)(b) GDPR. For general communication, the legal basis is Article 6(1)(f) GDPR; our legitimate interest is the organised and efficient handling of enquiries.
Recipients are limited to people responsible for handling the enquiry and the hosting and email providers technically required for the process. We do not disclose enquiry information for unrelated third-party advertising.
If an enquiry does not lead to a contract, we generally delete the communication no later than six months after the matter has been conclusively closed. We may keep it longer where necessary to comply with a legal obligation, document consent, or establish, exercise or defend legal claims.
6. Contact form protection with Cloudflare Turnstile
We use Cloudflare Turnstile to protect the contact form against automated submissions and misuse. Turnstile performs technical checks in the browser and creates a short-lived token that is validated by Cloudflare on the server side.
The processing may include the IP address, browser and device characteristics, information about interactions with the website, security signals and the verification result. Turnstile is used only for security and abuse prevention, not for our advertising analytics.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is protecting the website and our communication channels against spam, bots and technical attacks. To the extent that Turnstile accesses or stores information on the user’s device for this expressly requested security service, we rely on section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
Depending on the Cloudflare security configuration, technically necessary tokens or cookies may be used. The optional Turnstile “Pre-Clearance” feature and resulting cf_clearance cookies are used only if that feature is actually enabled in the Cloudflare configuration.
Further information is available in Cloudflare’s privacy and Turnstile documentation:
- https://www.cloudflare.com/privacypolicy/
- https://developers.cloudflare.com/turnstile/
7. Contact by email and telephone
If you contact us by email or telephone, we process your contact details, the content of the communication and any other information you voluntarily provide in order to handle your request.
The legal basis is Article 6(1)(b) GDPR where the communication concerns a contract or pre-contractual steps. For other enquiries, the legal basis is Article 6(1)(f) GDPR. The retention rules for contact enquiries described above generally apply.
For email communication, our email service provider processes the technically required data. Once the final provider for info@webaktive.com has been selected, its specific details and any relevant international safeguards will be added to this Privacy Policy.
8. Customer, contract and project data
When a contract is discussed or entered into, we may process in particular:
- names, business contact details and positions of contact persons;
- business and billing data;
- quotation, contract, service and payment information;
- project requirements, content, files, credentials and technical information;
- communication and approval records;
- support and maintenance information.
We process this information to prepare quotations, perform contracts, manage projects, issue invoices, provide support and comply with legal record-keeping obligations. The legal bases are Article 6(1)(b) and (c) GDPR. Where we process the details of a customer’s business contact persons, Article 6(1)(f) GDPR may also apply; our legitimate interest is the performance of the business relationship.
We keep contract and project information for the duration of the business relationship and afterwards for as long as necessary for warranties, support, statutory record keeping, or the establishment or defence of claims. Under Australian tax record-keeping rules, records concerning most business transactions generally need to be retained for five years, and longer periods may apply in specific cases. Once the applicable periods have expired, personal data is deleted or, where possible, permanently anonymised.
9. Recipients and service providers
Personal data is available only to people and service providers that need it for the relevant purpose. They may include:
- responsible team members;
- hosting, security and infrastructure providers;
- email and communication providers, currently MXroute (hosting and mail provider; the mail server used is located in Germany);
- project specialists where required to perform the requested or agreed service;
- tax advisers, legal advisers, payment or accounting providers;
- authorities, courts or other bodies where disclosure is legally required.
Where required, service providers are contractually bound to protect data and confidentiality. We publish or use identifiable customer information for promotional purposes only where a separate legal basis applies, such as prior consent.
10. Cookies, local storage and tracking
We do not use Meta Pixel, LinkedIn Insight Tag, Microsoft Clarity or Hotjar. The service described below is loaded only after your consent, with analytics and advertising selectable separately.
Technically necessary information may be stored or accessed where required for website transmission, security functions, form protection or a function expressly requested by the user. Such strictly necessary processes are based on section 25(2) TDDDG.
Non-essential analytics or marketing technologies will be activated only after prior consent under section 25(1) TDDDG and Article 6(1)(a) GDPR. If we introduce such technologies later, we will first implement a consent management system, update this Privacy Policy and provide a permanently accessible way to withdraw consent.
Google Analytics 4
With your consent we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Without consent the Google script is not loaded and no data is transmitted to Google.
Purpose. To understand which content is used, how visitors reach the site, and where enquiries are started or abandoned, so that content and structure can be improved.
Data processed. Pages viewed and times, referrer, approximate location derived from a truncated IP address, device, browser and operating system details, screen resolution, and a pseudonymous identifier that recognises your device across page views. IP anonymisation is enabled, so the IP address is truncated before any storage.
Legal basis. Consent under Article 6(1)(a) GDPR and § 25(1) TDDDG. Consent is voluntary; the website remains fully usable without it.
Recipients. Google Ireland Limited as processor, and affiliated companies within the Google group.
Third-country transfer. Transfer to Google LLC in the United States cannot be excluded. Google LLC is certified under the EU-US Data Privacy Framework and Standard Contractual Clauses apply in addition. Despite these safeguards, access by US authorities cannot be entirely ruled out.
Advertising features. Google Signals, advertising and remarketing features are not enabled. Through Consent Mode we explicitly signal that no consent for advertising purposes has been given.
Retention. Event and user data is deleted automatically in Google Analytics after 14 months. Aggregated, non-personal reports may be retained beyond that.
Withdrawal. You may withdraw your consent at any time with effect for the future, via the "Cookie settings" link in the footer of every page. After withdrawal the script is no longer loaded. The lawfulness of processing carried out before withdrawal is unaffected.
Further information. https://policies.google.com/privacy
Advertising consent
The "Advertising" category is separate from the analytics consent and entirely voluntary. Without it the website and all contact options remain fully usable.
Effect. If you give this consent, we transmit the Consent Mode signals ad_storage, ad_user_data and ad_personalization as granted. Google may then also use the collected data for advertising purposes, in particular audience building, remarketing and advertising campaign measurement, where corresponding Google advertising accounts are linked to the property.
Current status. No advertising campaigns are currently active and no Google Ads account is linked to this property. The category exists so that valid, separately given consent is in place before any advertising activity begins. While no campaigns are running, this consent results in no additional processing.
Legal basis. Consent under Article 6(1)(a) GDPR and § 25(1) TDDDG.
Withdrawal. As with analytics consent, at any time via "Cookie settings" in the footer, and separately withdrawable.
11. Fonts
Fonts used on this website are delivered locally from our own website. Loading a font therefore does not establish a connection to Google Fonts, Fontshare or another external font provider.
This statement is valid only after the technical migration to local hosting has been fully completed. This version must not be published while external font URLs remain embedded.
12. External links and social networks
Our website may link to external websites, customer projects or social networks. The operator of the destination website processes data under its own responsibility only after you follow such a link. The destination provider’s privacy information then applies.
The current website does not load social media feeds, like buttons or embedded social network content. Placeholder links without a genuine destination should be removed.
13. No solely automated decisions
We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, solely through automated processing including profiling within the meaning of Article 22 GDPR.
The website cost calculator uses the selected project parameters only to display a non-binding price range and does not decide whether a contract will be entered into.
14. Your rights
Subject to the applicable legal requirements, you have in particular the right to:
- obtain access to your personal data;
- have inaccurate data corrected;
- request deletion of your data;
- request restriction of processing;
- receive data in a structured, commonly used and machine-readable format;
- object to processing based on Article 6(1)(e) or (f) GDPR;
- withdraw consent at any time with effect for the future;
- lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA country of your habitual residence, place of work or the place of the alleged infringement.
To exercise your rights, contact info@webaktive.com. To protect your information, we may request reasonable details to verify your identity.
15. Objection to processing based on legitimate interests
Where we process personal data under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.
16. Data security
We use appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other misuse. These measures include encrypted transmission via HTTPS, access controls, secure credentials, spam and attack protection, and need-based permissions.
Despite appropriate safeguards, data transmitted over the internet cannot be guaranteed to be completely risk-free in every situation.
17. Changes to this Privacy Policy
We update this Privacy Policy when our website, providers, processing purposes or legal requirements change. The current version published on this page applies.
Last updated: 9 August 2026