Legal Last updated: 28 September 2026

Privacy notice

We spend a good part of our working week helping firms put the GDPR into practice. Wrapping our own approach in vague legalese would therefore be a poor look. What follows sets out, in ordinary language, which information reaches us, the reasons, the lawful grounds, storage periods, the parties with access, and the rights you hold. The reference texts are the EU General Data Protection Regulation (GDPR) and Austria's Datenschutzgesetz (DSG).

Scope: the apply.at site, its enquiry form, and messages addressed to any @apply.at mailbox. Excluded is information we touch while working inside customer environments, such as a managed server or someone's Microsoft 365 tenant. In those situations our customer decides on purposes and means, while Apply works strictly on its behalf, bound by a processing contract in line with GDPR Art. 28.

Who is responsible

Responsibility for personal information collected here lies with the business operating apply.at under the Apply name. Although it is based beyond EU borders, it targets customers in Austria and elsewhere in the Union, which brings it within the GDPR's reach.

  • Legal name - Apply LLP, represented by Andrey Vasin as director
  • Postal address - Bukhar Zhyrau Boulevard 62B, 050057 Almaty, Kazakhstan
  • BIN - 220540005599 (national business ID, Kazakhstan)
  • Privacy contact - office@apply.at
  • EU representative - [offen: name and address of the representative under Art. 27 GDPR, if appointed]

Whoever in our team looks after data protection personally deals with privacy mail arriving at office@apply.at. Additional statutory information appears in our imprint.

Categories of information

Our rule is to request only what a reply or a contract actually needs. Through this site we never ask for ID documents, medical information or other special-category data. Children are not our audience.

  • Form submissions - name, preferred way of reaching you, chosen subject, and your free-text message.
  • Submission metadata - URL of the originating page, IP address, and browser user agent string, which help us weed out spam and abuse.
  • Customer relationship - names and contact data of people we deal with, invoicing particulars, and correspondence linked to an agreement.
  • Tickets - problem descriptions, ticket history and technicians' notes on actions taken.
  • Household card payments - sum, date and transaction reference only. Card numbers stay with the payment service provider and never reach Apply.

Keep passwords out of forms and plain email. Logins for your systems are shared exclusively through an encrypted method we set up together in advance.

Why we use it

  • To reply to you and draw up an offer.
  • To conclude an agreement with you or your employer and deliver on it.
  • To work through tickets and document the work performed.
  • To invoice and to comply with tax and commercial record-keeping rules.
  • To shield the site from junk submissions, bots and intrusion attempts.
  • To pursue or fend off legal claims if a disagreement ever escalates.

Profiling does not happen here. Neither do solely automated decisions with legal or comparably serious consequences for you, and promotional mail only goes out if you have opted in.

Lawful grounds and how long we keep things

Every purpose is anchored in one of the grounds listed in GDPR Art. 6(1), and each carries its own storage limit. After that limit, and provided no statutory duty to keep records remains, the information is erased or rendered anonymous.

PurposeLegal basisRetention
Responding to form submissions and emailsGDPR Art. 6(1)(b), pre-contractual steps you requested, plus point (f), our legitimate interest in replyingWhile the conversation and any follow-up need it, or until you raise an objection
Delivering contracted services, including supportGDPR Art. 6(1)(b), contract performanceContract term, then until limitation periods for possible claims have run out
Invoices and bookkeeping recordsGDPR Art. 6(1)(c), compliance with a legal dutyFor the statutory retention periods, for example seven years under the Austrian Federal Fiscal Code (BAO); longer in specific situations
Site security and abuse preventionGDPR Art. 6(1)(f), legitimate interest in keeping the site safeIP addresses and user agents only as long as detecting and investigating abuse requires
Preferences saved by your browserStrictly required for the site to functionUntil you wipe them in the browser

Cookies and local browser storage

Analytics software, ad pixels and tracking cookies are absent from apply.at. Two technically necessary cookies are set: one keeps your session, the other guards the form against cross-site request forgery (CSRF). Submitting an enquiry is impossible without them, and both disappear once the session ends. Since they are indispensable for the service you actively request, § 165 TKG 2021 does not require consent for them.

Separately, three preferences live in your browser's localStorage: the place chosen in the location picker, light versus dark display, and a flag recording that the cookie banner has been shown. None of these values is transmitted to our server; clearing site data in your browser removes them. Were we ever to consider analytics, this notice would change first, and your consent would be sought.

Who receives data

Selling information or exploiting it for ads is off the table. Only suppliers without whom we could not function get access. Those acting as processors follow our documented instructions under contract.

  • Web host - operates the machine serving the site and storing form submissions. The provider is named in the imprint.
  • Mail provider - runs the @apply.at mailboxes and keeps our correspondence with customers and prospects.
  • Notification service - forwards the name, contact detail, topic and text of a new form enquiry to a messaging app so that our team hears about it quickly. The messaging provider may process data outside the EU as well, see the section on transfers to third countries.
  • Payment service provider - processes household card payments and treats card data as a controller in its own right.
  • Public bodies and courts - solely where legislation compels disclosure, for instance on request from the tax office or a judge.

Processing outside the EEA

Plain facts first. Apply LLP is registered in Kazakhstan, and the European Commission has so far issued no adequacy decision for that country, meaning its data protection regime has not been formally recognised as equivalent to EU standards. On top of this, our distributed team includes people who reach systems from outside the European Economic Area. Processing of your information beyond the EEA is therefore likely.

GDPR rules apply to all such processing in full. Where a third-country transfer within the meaning of the Regulation occurs, we rely on appropriate safeguards under GDPR Art. 46, such as the standard contractual clauses published by the European Commission, reinforced by technical controls like encrypted links, individual accounts and two-step sign-in. In individual cases a transfer may also rest on GDPR Art. 49(1)(b) where it is necessary for a contract with you or for pre-contractual steps taken at your request. We cannot entirely exclude that authorities in the third country might demand access under their national law. On request to office@apply.at we will supply a copy of the safeguards in place.

Protection and erasure

When no listed purpose justifies keeping something and no statutory period is pending, we erase it or strip it of anything that could point to an individual.

  • Access follows need-to-know: nobody sees data unrelated to their tasks.
  • Accounts are personal, with a second authentication factor wherever supported.
  • Traffic travels encrypted; backups are stored away from live systems.
  • A breach involving personal data that poses a risk to the people concerned would be notified to the competent data protection authority within 72 hours of our becoming aware of it, and to affected individuals as well where the risk to them is high.

Rights you can exercise

The GDPR, together with the DSG, grants you these entitlements, usable whenever you wish and, as a rule, without charge:

  • Access: learn what we hold and receive a copy (GDPR Art. 15).
  • Rectification of wrong or out-of-date entries (GDPR Art. 16).
  • Erasure (GDPR Art. 17).
  • Restriction, e.g. while the accuracy of your data or your objection is being checked (GDPR Art. 18).
  • Portability in a structured, commonly used, machine-readable format (GDPR Art. 20).
  • Objecting where we rely on legitimate interests (GDPR Art. 21).
  • Freedom from decisions made purely by automated means (GDPR Art. 22).

Email office@apply.at, naming the right concerned. Where there is reasonable doubt about who is asking, we may request extra proof of identity. Answers come as soon as we can manage and never later than one month; complicated cases can justify two further months, which we would announce within the first.

Unhappy with how we responded, or convinced your data is being handled unlawfully? Lodge a complaint with Austria's data protection authority, the Datenschutzbehörde, at dsb.gv.at. Alternatively, approach the supervisory body in whichever EU member state you live or work in.

Statutory retention trumps an erasure request for invoices and bookkeeping records. Until the period expires they remain blocked and serve legal compliance only; afterwards they are destroyed.

Reaching us about privacy

Questions on this notice, or requests for access, correction or deletion, belong in office@apply.at. That mailbox is attended Monday to Friday, 8:00-17:00 Austrian time (CET/CEST). All other channels are listed on the Contact page.

How ready is your own company for a GDPR check?

We support you with the record of processing activities, processor agreements and the technical safeguards worth showing should the Datenschutzbehörde ever come knocking.

GDPR compliance

Questions about your data?

Ask us what we store about you, or tell us what should be corrected or removed. A reply reaches you within one month at most.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.