Privacy notice
This notice explains how personal data is processed when you visit lacopsystems.com. It is given under Articles 13 and 14 of the General Data Protection Regulation (GDPR) and follows the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021).
1. Controller
The controller within the meaning of Article 4(7) GDPR is:
Lacop Studio OG (Offene Gesellschaft), trading as Lacop Systems
Herderstrasse 40, 4600 Wels, Austria
Company register FN 659759i, Landesgericht Wels, VAT ATU82616723
Email: office@lacopstudio.com, telephone +43 677 62944601
We have not appointed a data protection officer because we are not required to do so under Article 37 GDPR. Data protection enquiries reach the partners directly at the address above.
2. Scope
This notice covers the website lacopsystems.com and the category of data subjects website visitors and people who contact us. Where we operate a Speak-Up reporting channel, a phishing simulation or another system for a client, that client is the controller and their own notice applies. Our role there is described in section 9.
3. Delivering the website
- Data: server log data, including the IP address, date and time, the resource requested, the referrer and the browser or device identification.
- Purpose: technical delivery, stability and security of the site, and defence against attacks.
- Legal basis: Article 6(1)(f) GDPR, our legitimate interest in secure and uninterrupted operation.
- Processor: Vercel Inc., 340 S Lemon Ave, Walnut, CA 91789, USA, as our processor under an Article 28 agreement, with delivery from European infrastructure. Where data reaches the United States, it is covered by the EU-US Data Privacy Framework and the standard contractual clauses in that agreement.
- Retention: log data is kept only for a short period and is not merged with other data or used to identify you.
4. Fonts, analytics and cookies
This website sets no cookies. It runs no analytics, no tag manager, no advertising pixels and no social media scripts, and it embeds no third party content. There is no consent banner because there is nothing to consent to.
The typefaces are served from our own domain. Your browser makes no request to Google Fonts or to any other font service, so no connection data leaves for that purpose.
5. Contact form and correspondence
- Data: name, organisation, email address, and optionally telephone number, country, size band and the message you write. The form has no tracking and no hidden fields other than a spam trap that is discarded.
- Purpose: answering your enquiry, arranging a demonstration, and preparing a contract if it comes to that.
- Legal basis: Article 6(1)(b) GDPR for steps taken at your request before entering into a contract, and Article 6(1)(f) GDPR for ordinary business correspondence.
- Processor: ALL-INKL.com, Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, which runs the mailbox the form delivers to. The message is transmitted over an encrypted connection to a mailbox in Germany.
- Retention: for as long as the enquiry is live, and afterwards for as long as commercial and tax law requires business letters to be kept, in particular section 132 of the Austrian Federal Fiscal Code and section 212 UGB.
- We do not use your address for a newsletter and we pass it to nobody for marketing.
6. Recipients
Recipients may be our technical processors named in this notice, our tax adviser, our bank and payment service providers, and public authorities where the law obliges us. We do not sell personal data and we do not trade it. A list of the processors we use for this website is in section 3 and section 5; the processors for an operated system are named in the agreement for that system.
7. Transfers to third countries
Data is processed inside the European Economic Area wherever possible. Where a recipient outside the EEA is involved, in practice our hosting provider, the transfer rests either on an adequacy decision under Article 45 GDPR, including the EU-US Data Privacy Framework, or on the standard contractual clauses under Article 46 GDPR that form part of our agreement with that provider.
8. Security
We apply technical and organisational measures appropriate to the risk under Article 32 GDPR, in particular transport encryption with TLS, encryption of stored report content, strict access control on a need-to-know basis, logging of administrative access, separation of client environments, and regular updates. Our systems are operated by the same people who wrote them.
9. When we operate a system for a client
Where a client engages us to run a Speak-Up channel, a phishing simulation or another system, that client is the controller and we act as processor under Article 28 GDPR. In that role:
- Report content and attachments are encrypted in the reporting person's browser and stored as ciphertext, with a separate key for each case.
- Only the impartial person the client designates can open a case. No one at Lacop Systems reads reports, and our access to a client instance is limited to operating it.
- For anonymous reports no IP address is stored and no cookie is set on the reporting page.
- Data is stored on servers in Germany. There is no transfer to a third country in normal operation.
- Retention follows the client's national law, and deletion runs on the schedule set in the agreement.
- Sub-processors are named in the agreement, and the client is informed before any of them changes.
- In a phishing simulation, individual results are not reported to management and are deleted after the campaign, unless a works agreement provides otherwise.
If you want to report something to an organisation that uses our system, please use the reporting page that organisation gave you, not this website, and do not send report content to the address above.
10. Your rights
You have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21). Where processing rests on our legitimate interest, you may object at any time on grounds relating to your particular situation. Where processing rests on consent, you may withdraw it at any time with effect for the future under Article 7(3) GDPR. Write to office@lacopstudio.com and we will answer within one month.
You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at, dsb.gv.at. You may also complain to the authority of the member state where you live or work.
11. Is providing data obligatory
Simply visiting the site requires no data from you beyond what is technically necessary to deliver the pages. For an enquiry, the fields marked as required are necessary for us to answer you. There is no obligation to contact us, and no disadvantage if you do not.
12. Automated decision making
We take no automated decision producing legal effects concerning you or similarly significantly affecting you, in the sense of Article 22 GDPR, neither on this website nor in the systems we operate. Where a reporting channel suggests a category or a severity for a report, that is a suggestion to a human reviewer and never a decision about a person.
13. Changes
We update this notice when our processing or the legal position changes. The version you are reading applies from the date below.
Last updated 4 September 2026.