Privacy Policy
1. Data Controller
The data controller, as defined by the General Data Protection Regulation (GDPR), for the processing of personal data on this website is:
SAA Software Engineering GmbH
Gudrunstraße 184/3
1100 Vienna, Austria
Phone: +43 1 641 42 47-0
Email: office@saa.at
Commercial Register Number: FN 162840x, Vienna Commercial Court
VAT Number: ATU44589003
Management: Dr. Christian Hanser, Dipl.-Ing. Robert Neubauer, Stefan Maier, Bernhard Macher
2. Point of Contact for Data Protection Matters
We have not appointed a data protection officer as defined in Article 37 of the GDPR, as the legal requirements for doing so have not been met. For any questions regarding data protection and the exercise of your rights, please contact our Data Protection Coordinator: Bernhard Macher, Managing Director
SAA Software Engineering GmbH
Gudrunstraße 184/3, 1100 Vienna
Phone: +43 1 641 42 47-0
Email: office@saa.at
3. Scope
This Privacy Policy applies to the website at www.saa.at, including its subpages. It provides information about the processing of personal data that occurs when you visit the website, when you contact us, and in connection with the job openings posted on the website.
For customer portals, applications, and systems that we provide to our customers under contracts, the privacy notices published on those platforms apply. We provide separate information regarding the processing of data belonging to our customers, suppliers, and business partners in connection with the fulfillment of contracts.
4. Principles of Data Processing
The protection of your personal data is important to us. We process your data exclusively in accordance with legal requirements, in particular the GDPR, the Data Protection Act (DSG), and the Telecommunications Act of 2021 (TKG 2021).
Our website is powered by the WordPress content management system. Unless otherwise stated below, the data collected when you visit the website will not be further processed or used for any other purposes.
5. Access Data and Server Log Files
When you visit our website, we process technical access data that your browser automatically transmits. The following categories of data are processed:
- IP address of the accessing device
- Date and time of access, as well as the start and end of the session
- Name and URL of the retrieved file
- Amount of data transferred and notification of successful retrieval
- Referring website (referrer)
- Browser used, its version, and the operating system
The purpose of the processing is to technically deliver the website, ensure system security, and investigate instances of unauthorized access. The legal basis is our legitimate interest in maintaining a secure and functional website in accordance with Article 6(1)(f) of the GDPR. Log files are automatically deleted after 14 days. They are retained for a longer period only if necessary to investigate a specific security incident.
6. Cookies
Cookies are small text files that your browser stores on your device. Our website uses only technically necessary cookies.
These cookies are set in connection with logging into the WordPress admin area and are used for authentication and to recognize logged-in users. This applies exclusively to individuals with a user account, typically employees and contracted service providers. The cookies in question are wordpress_, wordpress_logged_in_, and wp-settings-.
No cookies are set for visitors who are not logged in for the purposes of analysis, marketing, or profiling. The web analytics described in Section 11, which uses Matomo, also operates without cookies. The legal basis for technically necessary cookies is Section 165(3) of the TKG 2021 in conjunction with our legitimate interest in a fully functional website pursuant to Article 6(1)(f) of the GDPR. Consent is not required for this purpose. For this reason, we do not use a cookie banner.
7. Making Contact
If you contact us via the contact form on our website, by email, or by phone, we will process the data you provide—specifically your name, company, contact information, and the content of your inquiry—to handle your request and in case of follow-up questions. The legal basis is Article 6(1)(b) of the GDPR if your inquiry relates to the conclusion or performance of a contract; otherwise, it is Article 6(1)(f) of the GDPR based on our legitimate interest in responding to inquiries.
If you use the contact form, the data you enter, along with the time of submission, will be forwarded to us via email and also temporarily stored in our website’s database for 30 days. This temporary storage serves solely to ensure that your inquiry reaches us even in the event of an email delivery failure; it is automatically deleted after 30 days. The same applies to the email transmission log. To protect against malicious submissions, we use a spam filter that runs entirely on our own server and does not transmit any data to third parties; we do not use an external service such as Google reCAPTCHA.
Your request will then be processed in our email and office system (Microsoft 365) and assigned to the appropriate staff members. Your information will not be shared with third parties, except for the service providers listed in Section 9.
We store the data from your inquiry until it has been fully processed and for an additional six months thereafter so that we can respond to any follow-up questions. If a business relationship is established, the statutory retention periods applicable to business records apply (Section 13).
8. Job Openings and Applications
We post job openings on our website. Applications are submitted via a link to the karriere.at platform operated by karriere.at GmbH, Hasnerstraße 123, 4020 Linz, Austria. Content from karriere.at is not embedded on our website; when you view job listings on www.saa.at, no data about you is transmitted to karriere.at.
If you follow the application link, you will leave our website. karriere.at GmbH is solely responsible for the processing of your data on karriere.at; its privacy policy at www.karriere.at/datenschutz applies. Your application submitted via karriere.at will then be forwarded to us and processed by us in accordance with the following principles.
As part of the application process, we process the data you provide, including, in particular, your name, contact information, resume, educational and professional background, certificates, cover letter, and interview notes generated during the selection process. This applies equally to applications we receive via email or by mail. The purpose of the processing is to conduct the application process and to decide whether to establish an employment relationship. The legal basis is Article 6(1)(b) of the GDPR (implementation of pre-contractual measures). To the extent that you voluntarily provide us with special categories of personal data—such as information regarding a disability—we base the processing of such data on Article 9(2)(b) of the GDPR in conjunction with labor law provisions.
Access to application documents is restricted exclusively to the executive board, human resources managers, and the managers responsible for the respective position. If you are not hired, we will delete your application documents seven months after the conclusion of the application process. This timeframe is based on the deadlines for asserting claims under the Equal Treatment Act. If you would like us to retain your documents beyond that period for future job openings, we will obtain your separate consent for this purpose in accordance with Article 6(1)(a) of the GDPR; you may revoke this consent at any time. If you are hired, the documents will become part of your personnel file.
9. Recipients of the data
Your data will only be shared with those parties necessary for the operation, maintenance, and security of our website. These service providers are data processors within the meaning of Article 28 of the GDPR and process the data exclusively in accordance with our instructions. The following service providers are used:
- Website maintenance and support: Gebrüder Pixel OG, Schließmanngasse 18/2, 1130 Vienna, Austria.
- Hosting: netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. The website is hosted on servers located in a data center in Vienna.
- Backup and Maintenance Monitoring: WP Umbrella, operated by LIVEN STUDIO SAS, 4 rue de la République, 69001 Lyon, France. Server location: France.
- Secondary backup: Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. Server location: Germany.
- Email and office software: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (Microsoft 365). Data processing takes place in data centers within the European Union.
Backups are stored at two independent locations for security reasons and to enable the restoration of the website in the event of a malfunction or disaster. The legal basis for this is our legitimate interest in maintaining a secure and accessible website, in accordance with Article 6(1)(f) of the GDPR. All service providers mentioned process the data within the European Union.
karriere.at GmbH is solely responsible for data processing on its platform (Section 8) and is not a data processor for us.
10. Data Transfers to Third Countries
No personal data is transferred to countries outside the European Union or the European Economic Area in connection with this website or the processing of your inquiries.
11. Web Analytics with Matomo
We use the open-source software Matomo to analyze statistics on the use of our website. Matomo is operated exclusively on our own web server; the data does not leave our server and is not shared with third parties.
Matomo is configured so that no personal data is stored. No cookies are set, and no other information is stored on or read from your device. Your IP address is truncated by the last three bytes at the time of collection and is used only in this form to determine the country of origin; a complete IP address is never stored. Individual visits or visitor profiles are not logged; no user IDs are assigned, and no heat maps or session recordings are created. Parameters in accessed URLs are not collected.
Only aggregated statistics are analyzed: number of page views and visits, pages viewed, referring websites, browsers and operating systems used, screen resolutions, and countries of origin. This information does not allow for the identification of individual persons. The raw data is deleted after 90 days; the aggregated reports are retained.
Since the statistics do not contain any personally identifiable information, they are not subject to the GDPR. However, if personally identifiable information is briefly assumed at the time of collection, we base the immediate anonymization on our legitimate interest in designing our website to meet user needs in accordance with Article 6(1)(f) of the GDPR. Consent under Section 165(3) of the TKG 2021 is not required because no information is stored on your device or read from it. Matomo respects your browser’s “Do Not Track” setting.
12. External Content and Services
Fonts, scripts, and other resources on our website are served from our own server. We do not use any ad networks, tracking pixels, or social media plugins. When you visit the website normally, no third-party content is loaded that transmits data to those third parties.
In some cases, we integrate external services, such as Microsoft Forms or Microsoft Dynamics 365 for event registration, or video platforms for video playback. Such content is not loaded until you have expressly consented to it at the respective location. No connection to the third-party provider’s server is established before you give your consent. Upon loading, the respective provider receives your IP address and technical access data and may set its own cookies; the provider is solely responsible for this processing. The legal basis is your consent pursuant to Article 6(1)(a) of the GDPR and Section 165(3) of the TKG 2021. You may revoke your consent at any time with future effect by reloading the page and not re-authorizing the content. The specific services that are integrated and the provider’s applicable privacy policy are indicated in the consent notice for each service.
13. Retention Period
We retain personal data only for as long as is necessary for the stated purposes or as required by statutory retention obligations. In particular, business records are subject to a retention period of seven years pursuant to Section 132 of the Federal Tax Code (BAO) and Section 212 of the Austrian Commercial Code (UGB). The retention periods applicable to individual processing activities are specified in the respective sections.
14. Necessity of Provision
Providing your data is not required by law or by contract. However, without the information you provide when contacting us, we cannot process your inquiry; without the information required for the application process, we cannot consider your application.
15. Automated Decision-Making
We do not engage in automated decision-making, including profiling, as defined in Article 22 of the GDPR. This also applies to our hiring processes.
16. Your Rights
With regard to the data we process, you have the rights to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR). If you have given your consent, you may revoke it at any time with effect for the future. The lawfulness of the processing carried out prior to the revocation remains unaffected.
To the extent that we process your data based on a legitimate interest, you may object to such processing at any time for reasons related to your particular situation.
To exercise your rights, please contact the point of contact listed in Section 2, by email at office@saa.at, or in writing at the address listed in Section 1.
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed upon in any other way, you may file a complaint with the supervisory authority. In Austria, the competent authority is the Austrian Data Protection Authority: Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
17. Changes to This Privacy Policy
We will update this Privacy Policy as soon as there are changes to data processing on our website or to the legal framework. The version published on this website is always the current one.
As of September 2026