Legal

Privacy Policy

Information on how Blackvolt Energy GmbH processes personal data under the GDPR and the Austrian Data Protection Act.

This is a non-binding English translation of the legally required Austrian privacy policy (Datenschutzerklärung), provided for the convenience of international visitors.

The German version at German version (Datenschutz) remains the legally binding text under the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

Information on the processing of your personal data on this website.

Last Updated

14 September 2026

Who We Are

The controller within the meaning of the EU General Data Protection Regulation (GDPR) and other data protection provisions is:

 

Blackvolt Energy GmbH

Währinger Straße 6-8/11

1090 Vienna

Austria

Phone: +43 676 6237708

Email: fabian.wasef@blackvolt.at

Website: www.blackvolt.at

Contacting the Data Protection Officer

The data protection officer of the controller is:

 

DataCo GmbH (DataGuard)

Sandstraße 33

80335 Munich

Germany

Phone: +49 89 7400 45840

Email: privacy@dataguard.com

Website: www.dataguard.de

General Information

This page informs you about the processing of your personal data on this website. How we collect and use your personal data depends on how you interact with us or which services you use. We collect, use, or share your personal data only where we have a legitimate purpose and a legal basis for doing so.

What Do We Mean by Legal Basis?

Consent (Art. 6(1)(a) GDPR) – You have given us your consent to process your personal data for a specific purpose that we have explained to you. You have the right to withdraw your consent at any time with effect for the future; the lawfulness of processing carried out until the withdrawal remains unaffected.

Contract (Art. 6(1)(b) GDPR) – We need to use your data to enable the performance of a contract concluded with you, or to carry out pre-contractual measures at your request.

Legal Obligation (Art. 6(1)(c) GDPR) – We need to use your data in order to comply with legal obligations.

Vital Interests (Art. 6(1)(d) GDPR) – Processing is necessary to protect your vital interests or those of another person.

Public Task (Art. 6(1)(e) GDPR) – Processing is necessary for the performance of a task carried out in the public interest.

Legitimate Interests (Art. 6(1)(f) GDPR) – Processing is necessary to safeguard our legitimate interests or those of a third party, unless your interests or fundamental rights override them.

Please note: if your data is required for the performance of a contract or a legal obligation and you do not provide the requested data, we may not be able to make the relevant services available to you.

Data Sharing and International Transfers

We use various service providers who support us in delivering our services and securing your data. Where necessary, we share your personal data with these service providers. With all service providers who process data on our behalf, we have concluded data processing agreements pursuant to Art. 28 GDPR that oblige them to protect your data.

Where your personal data is processed outside the EU or the EEA, we ensure that your data is adequately protected there as well. For this purpose we use the safeguards provided for by the GDPR, for example an adequacy decision of the European Commission for the country in question, or the use of so-called Standard Contractual Clauses (SCCs) of the European Commission with the processor (Art. 46 GDPR).

When using US service providers, we rely – depending on the provider – on the SCCs or on a certification under the EU–US Data Privacy Framework. You can request a copy of the concluded SCCs using the contact details provided above.

Your Rights

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:

1. Right of Access (Art. 15 GDPR)

You have the right to obtain confirmation from us as to whether personal data concerning you is being processed. If this is the case, you have a right of access to that data and to the following information:

  • the purposes of the processing
  • the categories of personal data
  • the recipients or categories of recipients
  • the envisaged storage period or the criteria used to determine it
  • the existence of the rights to rectification, erasure, restriction, and objection
  • the right to lodge a complaint with the competent supervisory authority
  • where applicable, the origin of the data (if not collected from you)
  • where applicable, the existence of automated decision-making including profiling, with meaningful information about the logic involved, the significance, and the envisaged consequences
  • where applicable, transfer to a third country or an international organisation together with the appropriate safeguards

2. Right to Rectification (Art. 16 GDPR)

Should your personal data be inaccurate or incomplete, you have the right to request its immediate rectification or completion.

3. Right to Restriction of Processing (Art. 18 GDPR)

Where one of the following conditions is met, you may request the restriction of the processing of your personal data:

  • You contest the accuracy of your data – processing is restricted for the period we need to verify its accuracy.
  • The processing is unlawful, you oppose erasure, and instead request the restriction of use.
  • You have objected to the processing – for as long as it has not yet been established whether our legitimate grounds override yours, processing is restricted.

4. Right to Erasure (Art. 17 GDPR)

Where one of the following grounds applies, you may request the immediate erasure of your personal data:

  • Your data is no longer necessary for the purposes for which it was collected.
  • You withdraw your consent and there is no other legal basis.
  • You object to the processing and there are no overriding legitimate grounds, or you object to direct marketing pursuant to Art. 21(2) GDPR.
  • Your data is being processed unlawfully.
  • Erasure is required to comply with a legal obligation.
  • The data was collected in relation to information society services offered pursuant to Art. 8(1) GDPR.

Exceptions to the Right to Erasure

These grounds do not apply insofar as processing is necessary: for exercising the right of freedom of expression and information; for compliance with a legal obligation or for the performance of a task carried out in the public interest; for reasons of public interest in the area of public health; for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes; or for the establishment, exercise, or defence of legal claims.

In particular, statutory retention obligations (e.g. under the Austrian Commercial Code (UGB) and the Federal Fiscal Code (BAO)) may preclude immediate erasure; in such cases, processing is restricted for any further active use.

5. Right to Data Portability (Art. 20 GDPR)

You have the right to receive the personal data you have provided to us and that we process by automated means on the basis of consent or a contract, in a structured, commonly used, and machine-readable format, or – where technically feasible – to request its direct transmission to another controller.

6. Right to Object (Art. 21 GDPR)

You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.

Where your personal data is processed for direct marketing purposes, you have the right to object at any time and without giving reasons to the processing for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing. Following an objection to marketing, your data will no longer be processed for these purposes.

7. Right to Withdraw Consent Given (Art. 7(3) GDPR)

You have the right to withdraw consent given under data protection law at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent until the withdrawal remains unaffected.

8. Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. The supervisory authority responsible for us is:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna. Telephone: +43 1 52 152-0 · Email: dsb@dsb.gv.at · Web: www.dsb.gv.at

Exercising Your Rights

To exercise your rights, an informal message to Blackvolt Energy GmbH, Währinger Straße 6-8/11, 1090 Vienna, Austria, telephone +43 676 6237708, email fabian.wasef@blackvolt.at is sufficient.

We will respond to your request without undue delay, at the latest within one month.

Website Provision and Server Log Files

Our website is provided as a static website via Firebase Hosting, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information: https://firebase.google.com/support/privacy. The technical maintenance of the website is carried out by Webnique GmbH on our behalf.

When you access this website, the hosting provider processes technical access data in server log files. This includes the IP address of the requesting device, the date and time of access, the requested URL, the referrer URL, the browser and operating system used, the volume of data transferred, and the HTTP status code.

This processing serves solely the technical provision, security, and stability of the website. This data is not exported to any logging system controlled by us. We have no access to this data, do not evaluate it, and do not combine it with other data. The storage period is determined by the hosting provider's specifications.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of this website. Insofar as content is delivered via Google's global infrastructure, data may also be transferred to third countries outside the EU, including the United States; such transfers are safeguarded by Standard Contractual Clauses (SCCs) and, where applicable, by the EU–US Data Privacy Framework.

All data transmitted between your browser and our website is encrypted via HTTPS/TLS.

Cookies and Comparable Technologies

This website does not use cookies. No cookies are used, whether technically necessary, analytical, or advertising cookies. Likewise, no comparable technologies for storing information on your device are used, in particular no local storage, no session storage, and no fingerprinting methods. The website's language selection is reflected solely via the address (URL) accessed.

Since no information is stored on or read from your device when you visit this website, no consent under Section 165(3) of the Austrian Telecommunications Act (TKG 2021) is required; for this reason, no cookie banner is shown to you. The web analytics we use operate without cookies; details can be found in the section "Web Analytics with Plausible Analytics".

No Integration of External Content and Services

We have deliberately designed our website so that no connections to third-party servers are established when the pages are accessed, with the exception of the hosting provider and the analytics service Plausible. In particular:

Self-hosted content, no third-party integration

  • The fonts used are served from our own web space; no connection to external font services (e.g. Google Fonts) takes place.
  • Videos are exclusively self-hosted; no content from video platforms (e.g. YouTube, Vimeo) is embedded.
  • No map services, no social media plugins, no advertising or retargeting pixels, and no tag manager are used.
  • No external captcha services (e.g. reCAPTCHA) are integrated; the contact form's spam protection works without third-party scripts.

Contact Form

1. Description and Scope of the Data Processing

Our website has a contact form through which you can contact us electronically. Transmission takes place technically via the processor Formspree, Inc., 1207 Delaware Ave #727, Wilmington, DE 19806, USA ("Formspree"), which receives the data on our behalf and forwards it to us. Further information on Formspree's data protection: https://formspree.io/legal/privacy-policy

Data is only transmitted to Formspree when you actively submit the form; no transmission takes place when the page is merely accessed. Protection against automated spam submissions is provided by a form field invisible to you as well as server-side at Formspree; no third-party script is embedded in the website.

At the time of submission, the data you have entered is processed. The following categories may arise:

  • first name
  • last name
  • email address
  • telephone number (if provided)
  • content of the message
  • technical metadata during transmission (e.g. timestamp), insofar as logged by the form service

2. Purpose of the Data Processing

The processing of the personal data from the input form serves solely to handle your enquiry. The other data processed during the submission process serves to prevent misuse of the contact form and to ensure the security of our information technology systems.

3. Legal Basis

The legal basis for processing the data transmitted via the contact form is Art. 6(1)(f) GDPR; our legitimate interest lies in handling your enquiry. Where the contact is aimed at concluding a contract, the additional legal basis is Art. 6(1)(b) GDPR.

4. Storage Period

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the data from the input form, this is the case when the respective conversation has ended, i.e. when it can be inferred from the circumstances that the matter concerned has been conclusively clarified. If the enquiry leads to a business relationship, the statutory retention periods apply.

5. Transfer to Third Countries

Formspree, Inc. is based in the United States. The transfer of your personal data to the USA is safeguarded by the Standard Contractual Clauses (SCCs) adopted by the European Commission.

Contact by Email

Alternatively, you can contact us using the email address provided. In this case, the personal data transmitted with the email (sender address, content, attachments) is processed. Processing takes place solely to handle your enquiry; the legal basis is Art. 6(1)(f) GDPR or – for pre-contractual enquiries – Art. 6(1)(b) GDPR. Our email service is operated via Microsoft 365 (Exchange Online); storage takes place in European data centres. The storage period corresponds accordingly to what is stated for the contact form.

Applications

If you apply to us – via the karriere.at platform, via our career information on the website, or directly by email – we process the applicant data you provide (in particular name, contact details, CV, references, qualifications) solely to carry out the application process. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures). The karriere.at platform (karriere.at GmbH, Linz) processes your data as an independent controller; information can be found in its privacy policy.

If no employment results, your applicant data is deleted at the latest seven months after the conclusion of the process, unless you have expressly consented to it being retained for a longer period. In the event of employment, the data is transferred to the personnel file; you will then receive our privacy policy for employees.

Company Presence on Professional Networks

1. Scope of the Data Processing

We maintain a company presence on LinkedIn. This is used for applications, information/PR, and active sourcing. We provide information there and offer the possibility of communication. If you carry out an action on our company presence (e.g. comments, posts, likes), you may thereby make personal data (e.g. your real name or the photo from your user profile) public. We do not have complete information about the processing of your personal data by the platform operator as a (joint) controller; further information can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy

2. Purpose and Legal Basis

Our company presence serves to inform users about our services and to communicate with customers, prospective customers, and potential applicants. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in public relations and communication. Where the contact is aimed at concluding a contract, the additional legal basis is Art. 6(1)(b) GDPR.

3. Storage Period

The data generated by the company presence is not stored in our own systems. We process messages you send us via the platform until the matter has been conclusively clarified.

4. Exercising Your Rights

You can exercise your rights as a data subject, as set out in the section "Your Rights", vis-à-vis us at any time – most easily by an informal email to fabian.wasef@blackvolt.at. For processing by the platform operator, please also contact LinkedIn: https://www.linkedin.com/legal/privacy-policy

Web Analytics with Plausible Analytics

1. Scope of the Processing

We use Plausible Analytics, a privacy-friendly web analytics tool from Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible works without cookies: no IP addresses are stored, no device-related identifiers are set, and no fingerprinting is used. Individual visitors are not recognised across multiple websites. The data collected is processed exclusively in aggregated, anonymised form; tracing individual visitors is not possible.

2. Purpose and Legal Basis

The processing serves the statistical evaluation of the use of our website in order to optimise content and user-friendliness. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in optimising our website on the basis of anonymised usage statistics. Data processing by Plausible takes place on servers within the EU.

3. Exercising Your Rights

The configuration used aims at the most data-minimising evaluation possible. You can control the execution of scripts in your browser at any time (e.g. via script blockers). Further information can be found in Plausible's privacy policy: https://plausible.io/privacy

Changes to This Privacy Policy

We adapt this privacy policy as soon as the processing on our website changes or legal requirements make this necessary. The current version published on this page applies in each case; the date of the current version can be found at the beginning of this policy.