Privacy Policy
At Invisible-Light Labs GmbH, we value your privacy and are committed to protecting your personal data. We process your data responsibly and in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Austrian Telecommunications Act (TKG 2003), in all countries in which we operate.
This Privacy Policy outlines our general practices regarding the collection, use, and safeguarding of personal information. It applies to individuals interacting with us—whether as website visitors, clients, business partners, suppliers, or prospects—and complements any product-specific or service-related privacy information we may provide separately.
Identity of the Data Controller
Who is responsible for your data–
Invisible-Light Labs GmbH
Taubstummengasse 11, 1040 Wien, Austria
Company Registration No. FN 505017y
Email: info@invisible-light-labs.com
Website: www.invisible-light-labs.com
What Personal Data We Collect
Contact Information+
Website Usage Data+
Voluntarily Provided Data+
Transactional Information+
How and Why We Use Your Data
Contact Form / Enquiries+
Legal basis: Art. 6(1)(b) GDPR — performance of a contract or pre-contractual steps.
Order Processing & Fulfilment+
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
Legal & Financial Recordkeeping+
Legal basis: Art. 6(1)(c) GDPR — legal obligation.
Newsletter / Marketing Emails+
Legal basis: Art. 6(1)(a) GDPR — consent (withdrawable at any time). You may withdraw your consent at any time by using the unsubscribe link in any marketing email or by contacting us at info@invisible-light-labs.com.
Website Operation & Security+
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure and reliable website operation.
Business Partner Relationships+
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in maintaining business relationships.
Website Analytics (Cookies)+
Legal basis: Art. 6(1)(a) GDPR — consent (via cookie banner).
Legitimate Interests+
Data Retention Periods
How long we keep your data+
Contact form and general enquiry data: 2 years from the date of last contact.
Contractual data (orders, invoices, delivery records): 7 years in accordance with Austrian commercial and tax law (UGB / BAO).
Newsletter subscriber data: Until you withdraw your consent or unsubscribe.
Website usage data and analytics: Up to 13 months from collection, depending on the tool used.
Business partner contact data: For the duration of the business relationship and 3 years thereafter.
Recipients and Third-Party Processors
Who we share your data with+
Categories of recipients may include:
— Web hosting and IT infrastructure providers
— Email service and CRM providers
— Payment and invoicing platforms
— Analytics and website performance tools (e.g. Google Analytics, if applicable)
— Customer support software providers
Our CRM and customer relationship data is managed in Odoo, operated by Odoo S.A. (Chaussée de Namur 40, 1367 Grand-Rosière, Belgium). Odoo S.A. is established within the EEA, meaning no international data transfer is required for this processing. Customer data stored in Odoo includes contact details, order history, and business communication records, and is processed on the basis of Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in maintaining business relationships).
All processors are contractually bound to process your data only on our documented instructions, implement appropriate security measures, and not engage further sub-processors without our prior written consent.
International Data Transfers
Transfers outside the EEA+
The safeguards we rely on include:
— Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Decision 2021/914)
— Adequacy decisions issued by the European Commission for certain countries
For example, our website uses Google reCAPTCHA, which is operated by Google LLC (USA). Data submitted via the contact form may be processed in the United States. Google LLC participates in the EU-U.S. Data Privacy Framework and processes data under Standard Contractual Clauses.
Our CRM processor Odoo S.A. is based in Belgium (EEA) and does not involve an international transfer.
Your Rights Under GDPR
Right of Access (Art. 15)+
Right to Rectification (Art. 16)+
Right to Erasure (Art. 17)+
Right to Restriction of Processing (Art. 18)+
Right to Data Portability (Art. 20)+
Right to Object (Art. 21)+
Right to Withdraw Consent (Art. 7(3))+
How to exercise your rights+
Right to Lodge a Complaint
Supervisory Authority+
Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42, 1030 Vienna, Austria
Phone: +43 1 521 52-0
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
You may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence or place of work.
Data Security
How we protect your data+
— Encryption of data in transit (TLS/SSL)
— Access controls and role-based permissions
— Regular security assessments and software updates
— Staff confidentiality obligations and awareness training
We do not use your data for automated profiling or automated decision-making within the meaning of Art. 22 GDPR that produces legal or similarly significant effects for you.
Cookies and Tracking Technologies
Essential Cookies+
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure and reliable website operation.
Non-Essential Cookies (Analytics, Preferences)+
Legal basis: Art. 6(1)(a) GDPR — consent.
You can withdraw or adjust your cookie consent at any time by clicking [Cookie Settings] in the footer of our website, or by configuring your browser to block or delete cookies. Please note that disabling certain cookies may affect the functionality of the website.
Automated Decision-Making and Profiling
Our practices+
Updates to This Policy
Changes to Our Privacy Practices+
Last updated: April 2026
Questions about this policy? Contact us at info@invisible-light-labs.com