Privacy Policy
Last updated: 31 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
equipment.cafe GmbH
Slamastraße 43
1230 Vienna
Austria
Phone: +43 1 22 760 22
E-mail: [email protected]
Further company details can be found in the Imprint.
2. General information on data processing
Personal data is processed exclusively within the framework of the applicable data protection provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the relevant provisions of the Telecommunications Act (TKG).
Personal data is any information relating to an identified or identifiable natural person. This includes, for example, name, e-mail address, telephone number, IP address as well as booking or payment data.
Processing takes place only insofar as it is necessary to provide the website and the services offered, to carry out pre-contractual measures or to perform a contract, to comply with legal obligations, on the basis of legitimate interests or – where required – on the basis of consent.
3. Hosting and server log files
The website is operated on a dedicated server at Hetzner Online GmbH in Germany. When the website is accessed, the following data is processed automatically:
IP address
date and time of access
page or file requested
volume of data transferred
referrer URL
browser and browser version
operating system
HTTP status code
This processing serves the technical provision of the website, its stability and security, and the detection of technical errors or abusive access.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, stable and error-free operation of the website. Server log data is stored only for as long as required for these purposes or by legal obligations.
4. Cloudflare
Cloudflare is placed in front of the website as a protection and acceleration service. All requests are routed through Cloudflare’s infrastructure; the IP address is processed in order to fend off attacks, detect misuse and deliver content faster.
Legal basis: legitimate interest in the security and availability of the website (Art. 6(1)(f) GDPR). Cloudflare acts as a processor pursuant to Art. 28 GDPR.
5. Cookies and similar technologies
This website uses cookies and comparable storage technologies.
Technically necessary cookies are used where they are required for the operation of the website, for providing expressly requested functions, for security, or for storing privacy and consent settings. These include in particular storing the cookie decision, the selected language, the chosen list view, recently viewed products and the source of the visit.
Other cookies and technologies – in particular for external services – are only used where consent has been given via the consent management platform. Consent can be changed or withdrawn at any time with effect for the future via the link “Change preferences” in the footer of every page.
Further details on the specific cookies used, their purpose and storage period can be found in the Cookie Policy.
6. Consent management with Complianz
Complianz is used to manage privacy and cookie settings. Technically necessary information about the consent decisions made is stored – for documentation purposes and in order to apply the selected settings.
Legal bases: Art. 6(1)(c) and (f) GDPR.
7. Contacting us
If you contact us by e-mail, by telephone or by any other means, the personal data transmitted is processed in order to handle the respective enquiry – in particular name, company, e-mail address, telephone number, message content and any further information provided voluntarily.
Where contact is made in connection with an existing or prospective contractual relationship, the legal basis is Art. 6(1)(b) GDPR. In all other cases, processing is based on the legitimate interest in handling incoming enquiries pursuant to Art. 6(1)(f) GDPR.
The data is deleted as soon as it is no longer required for the respective purpose and no statutory retention obligations apply.
8. Enquiries, bookings and rentals
In connection with enquiries, reservations, bookings, rentals, quotations and contract processing, the personal data required for the respective business relationship is processed:
name and company
billing and contact details
e-mail address and telephone number
booking and rental data
products booked or rented
prices and payment information
communication and contract data
where applicable, data for identity or authorisation checks
Legal bases: performance of pre-contractual measures and performance of a contract (Art. 6(1)(b) GDPR) as well as compliance with legal obligations, in particular tax and commercial retention obligations (Art. 6(1)(c) GDPR).
9. Booqable
Booqable (Salad Days B.V., Blokhuisplein 40, 8911 LJ Leeuwarden, Netherlands) is used to manage rental products, availability, reservations and bookings. The rental and booking function is integrated directly into this website; the booking process takes place in a window on equipment.cafe.
When products are selected and enquiries or bookings are made, the personal data required for this purpose is processed via Booqable – in particular contact, customer, booking, product, rental and transaction data.
Legal basis: performance of pre-contractual measures or performance of a contract (Art. 6(1)(b) GDPR).
10. Payment processing with Stripe
No payment takes place on this website. For an online payment, a personal payment link is provided; the payment is then processed directly on the pages of the payment service provider Stripe (Stripe Payments Europe, Limited, Ireland). The data processed includes name, contact, billing and payment details, transaction data and the technical data required for payment processing and fraud prevention, including the IP address. Full payment details such as card data are processed exclusively by Stripe.
Legal bases: performance of a contract (Art. 6(1)(b) GDPR) and, where required, compliance with legal obligations (Art. 6(1)(c) GDPR). Within the Stripe services, data may also be processed outside the European Economic Area; international transfers take place using the applicable transfer mechanisms.
11. Audience measurement with Burst Statistics
Burst Statistics is used for statistical analysis of website usage – software that runs on our own server. The data collected does not leave the company; no external analytics provider is involved.
Measurement is configured at the most data-minimising setting available:
– no cookies are set and no recognition identifiers are stored on the device
– an encrypted identifier is calculated from the IP address, the browser signature and a randomly generated value that changes daily; because this value changes every day, recognition beyond the same day is not possible
– the IP address itself is not stored
– if the browser sends “Do Not Track”, no measurement takes place
– what is stored: page requested, time, approximate time on page, referring page, device type and browser
Legal basis: legitimate interest in data-minimising audience measurement (Art. 6(1)(f) GDPR). As no cookies or comparable access to the device take place, consent is not required.
12. Location map
The location is displayed as a static image file served from our own server; no connection to Google is established. The link to Google Maps in the footer is an ordinary link – data is transmitted to Google (Google Ireland Ltd.) only once it is clicked.
13. YouTube
Product videos are embedded via YouTube (Google Ireland Ltd.) in extended privacy mode using youtube-nocookie.com. These videos are also loaded only after consent; before that, a placeholder is displayed.
Once loaded, Google receives the IP address and may process usage data.
Legal basis: consent (Art. 6(1)(a) GDPR), revocable at any time.
14. Google Forms and feedback
Google Forms (Google Ireland Ltd.) is used for the feedback function. The information entered in the form is stored by Google and made available to the company. Participation is voluntary; alternatively, feedback can be sent by e-mail to [email protected].
Legal basis: consent given by submitting the form (Art. 6(1)(a) GDPR).
15. Fonts
The fonts used on this website are served locally from our own server. External font services – such as Google Fonts – are not called; no data is transmitted to third parties in this context.
16. Newsletter with Mailchimp
Mailchimp (The Rocket Science Group LLC d/b/a Mailchimp, USA – part of Intuit Inc.) is used to send newsletters. The data required for delivery is processed, in particular name and e-mail address, along with technical delivery information.
There is currently no sign-up option on this website; inclusion in the mailing list takes place solely in connection with an existing customer relationship.
Receipt can be cancelled at any time via the unsubscribe link in every newsletter or informally by e-mail to [email protected]. Within the Mailchimp services, personal data may also be processed outside the European Economic Area; international transfers take place using the applicable transfer mechanisms.
17. Website security
Wordfence is used to protect the website against attacks. Security-relevant access is logged in the process – for example failed login attempts including the IP address. These logs are reviewed only where there is a specific reason to do so and are deleted regularly.
Legal basis: legitimate interest in the security of our systems (Art. 6(1)(f) GDPR).
18. Social media and external links
This website contains links to profiles on social networks and to external websites. These are plain links – a connection to the respective provider is only established once such a link is clicked. The respective provider is responsible for data processing on the linked pages.
19. Methods not used
This website does not use any advertising or tracking pixels; in particular, neither Google Analytics nor advertising pixels of social networks are used. Personal data is not sold and is not passed on to third parties for advertising purposes.
20. Storage period
Personal data is stored only for as long as necessary for the respective purposes. Beyond that, data is retained where statutory retention obligations apply – in particular tax and commercial retention periods.
21. Recipients and processors
Personal data is passed on to service providers insofar as this is necessary for operating the website and delivering the services – in particular to hosting and infrastructure providers, the booking system, the payment service provider and the newsletter delivery service. Where these service providers act on instructions, they are bound as processors pursuant to Art. 28 GDPR.
Any transfer beyond this only takes place where there is a legal obligation or where consent has been given.
22. Transfers to third countries
With some of the services mentioned, personal data may be processed outside the European Economic Area. Such transfers only take place where the requirements of Art. 44 et seq. GDPR are met – in particular on the basis of an adequacy decision or standard contractual clauses.
23. Rights of data subjects
You have the right to access the data processed about you, as well as the rights to rectification, erasure, restriction of processing, data portability and to object to processing based on a legitimate interest. Consent given can be withdrawn at any time with effect for the future.
These rights can be exercised informally at [email protected].
24. Right to lodge a complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with the supervisory authority: Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, [email protected], www.dsb.gv.at
25. Obligation to provide data
Providing personal data is neither required by law nor by contract. However, certain information is necessary in order to conclude and perform a rental or purchase contract; without this information, a contract cannot be concluded or performed.
26. Automated decision-making
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.
27. Data security
This website is delivered exclusively via an encrypted connection (HTTPS/TLS). In addition, technical and organisational measures are in place to protect the data processed against loss, misuse and unauthorised access.
28. Changes to this privacy policy
Where changes to the website or the services used are relevant under data protection law, this policy will be updated. The version published here applies in each case.