Data Protection Policy

Thank you for visiting our website www.xarion.com.

At XARION, we take the protection of your data seriously. This page explains in plain terms which data we collect when you visit our website or get in touch with us, what we use it for, and what rights you have.

The main point first: you can visit our website without giving us any personal data. Data you choose to share with us is not sold and is not passed on to third parties for advertising purposes.

 

Who is responsible for your data?

XARION Laser Acoustics GmbH

Ghegastrasse 3

1030 Vienna, Austria

T: +43 1 907 60 76-0

E-Mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
Website: 
www.xarion.com

 

When you visit our website

Each time our website is accessed, our system automatically collects data from the computer system making the request:

  • Information on the browser type and the version used
  • Language and version of the browser software
  • The user’s operating system and its interface
  • The Internet service provider of the user
  • The IP-address of the user
  • Date and time of the access and time zone difference to coordinated universal time (UTC)
  • Transmitted data volume
  • Websites from which the user’s system accesses our website
  • Websites accessed from the user’s system via our website
  • Access status/HTTP status code

This data is also stored in our system log files.

Why we need it: Temporarily storing your IP address is necessary for us to deliver the website to your computer at all – the IP address has to remain stored for the duration of the session. We need the log files to keep the website working, to improve it, and to operate our systems securely. The data is not analysed for marketing purposes.

Legal basis: our legitimate interest in a secure, functioning website (Art. 6(1)(f) GDPR).

How long: Once your session ends, the data is anonymized and no longer allows any conclusions to be drawn about you. Data stored in log files is deleted after 31 days.

Recipient: our website provider ITronic Harald Leithner, Lichtäckerstraße 22, 2522 Oberwaltersdorf, Austria.

 

Cookies

Cookies are small text files stored in your browser. They are downloaded by your browser the first time you visit our website. If you return to the website later on the same device, the cookie and the information stored in it are sent back either to the website that created it (first-party cookie) or to another website it belongs to (third-party cookie). This makes it possible to recognise that the page has already been opened with this browser. Cookies “remember” things such as your language setting, or show us how our website is used.

We use them sparingly and only the following ones.

Cookies that are functionally necessary

For the purpose of carrying out the transfer of messages and making available the services you have asked for, we use the cookies set out below. The legal basis is our legitimate interest in providing a fully functioning website and the services you have asked for (Art. 6(1)(f) GDPR, Section 165(3) of the Austrian Telecommunications Act 2021). The technical details of these cookies are maintained and kept up to date by our website hosting provider.

Cookie 

Data type

Purpose

Storage duration

recipient

ac

approval

Hide the Cookie note dialogue

1 year

Provider

32 HEX Zeichen

Allocation of the session

Recognition of the session

End of the session

Provider

 

Further cookies – only with your consent

In addition, we use the following cookies on the basis of the consent you have provided (Art. 6(1)(a) GDPR, Section 165(3) of the Austrian Telecommunications Act 2021). As with the table above, the exact list of cookies is maintained and kept up to date by our website hosting provider. The two cookies with the prefix “_pk” belong to Matomo – more on that below.

Cookie 

Data types

Purpose

Storage duration

Recipient

32 HEX Zeichen

Language

Display of selected language

1 year

Provider

Matomo (see b)

_pk_id.<number>.<Symbol>

Browser identification

Browser allocation to past sessions

1 year

Provider

_pk_ses.<number>.<symbol>

allocation to sessions

Recognition of session

End of session

Provider

 

Web analytics with Matomo

This website uses Matomo, an open-source web analytics program. Matomo uses cookies – text files stored on your computer that allow an analysis of your use of the website. The information created in this way is stored on our website provider’s server. Your IP address is anonymised before it is stored. This information is not passed on to third parties.

You can prevent the storage of these cookies through the relevant setting in your browser software; in that case you may not be able to use all functions of this website in full. 

Your cookie settings

Alternatively, you can deselect all cookies that are not functionally necessary via the “Cookies” link in the footer of every page. You can also block cookies in your browser or delete cookies that have already been stored at any time; your browser help explains how. If you disable cookies for our website, individual parts of the website may not work as usual.

Recipient: our website provider ITronic Harald Leithner, Lichtäckerstraße 22, 2522 Oberwaltersdorf, Austria.

 

When you write to us via the contact form

Through our contact form we collect your first name, last name, company, email address and your message. We use these details solely to handle your enquiry and reply to you.

Legal basis: steps preliminary to a contract (Art. 6(1)(b) GDPR) where your enquiry concerns our products or a possible project – otherwise our legitimate interest in communicating with you (Art. 6(1)(f) GDPR).

The form itself transmits your details to us only. To follow up on your enquiry we then use HubSpot, our customer relationship management system (CRM). There we record what your enquiry is about and who will get back to you. HubSpot is based in the United States; how we safeguard this transfer is explained below under “Transfers to the United States”.

How long: We delete your enquiry once it has been dealt with and we no longer need it.

Recipients: our website provider ITronic Harald Leithner, Lichtäckerstraße 22, 2522 Oberwaltersdorf, Austria, and HubSpot Inc., USA.

 

Embedded YouTube videos

On our video page we embed videos from YouTube. The videos are only loaded once you click the play symbol – before that, no connection to YouTube is established and no YouTube cookies are set.

As soon as you start a video, your browser establishes a connection to YouTube’s servers (Google Ireland Limited or Google LLC). Your IP address and information about your device are transmitted to Google, and Google may set cookies. If you are signed in to Google at that moment, Google can associate the video with your account. How Google uses this data is described in Google’s privacy policy: https://policies.google.com/privacy

Legal basis: your consent, which you give by clicking the play symbol (Art. 6(1)(a) GDPR).

 

Social media links and sharing function

In the footer of our website you will find links to our profiles on LinkedIn and YouTube, and on our news items you can share a post via Facebook, X and LinkedIn.

In both cases these are plain links, not the platforms’ plugins: as long as you do not click a symbol, no data whatsoever is transmitted to Facebook, X, LinkedIn or YouTube. Only when you click does the relevant platform open in a new window – from that moment their privacy terms apply.

 

Who processes data on our behalf

We use external service providers for some of our processing of personal data.

  • Website hosting and maintenance: ITronic Harald Leithner, Lichtäckerstraße 22, 2522 Oberwaltersdorf, Austria.
  • Customer relationship management (CRM): HubSpot Inc., USA – we manage contacts and enquiries there. HubSpot is not integrated into our website and therefore receives no data about your visit to our website.
  • Videos: Google Ireland Limited / Google LLC (YouTube)

 

Transfers to the United States

HubSpot and Google are based, or have their group headquarters, in the United States. Both providers are certified under the EU-U.S. Data Privacy Framework – the European Commission has determined that certified US companies provide an adequate level of data protection. In addition, we base transfers on the European Commission’s Standard Contractual Clauses (Art. 46 GDPR).

The legal position on data transfers to the United States continues to develop. We keep an eye on it and will adjust our service providers if that becomes necessary.

 

Security of your data

Our website is available exclusively over HTTPS with TLS encryption. Beyond that, we take appropriate technical and organisational measures to protect your data against loss, alteration and unauthorised access, and we review these regularly.

 

Your rights

You can approach us at any time if you would like to know something about your data or have it changed. Specifically, you have these rights:

  • Access: you can find out what data we hold about you – including its origin, purpose, storage period and recipients.
  • Rectification: if details about you are inaccurate or incomplete, we will correct or complete them.
  • Erasure: you can request the deletion of your data.
  • Restriction: you can ask us to restrict the processing of your data while a question about it is being resolved.
  • Objection: you can object to the processing of your data on grounds relating to your particular situation (Art. 21 GDPR).
  • Data portability: you can receive the data you have given us in a commonly used, machine-readable format – or we will transfer it directly to another provider, where that is technically feasible.
  • Withdrawal of consent: where we process data on the basis of your consent, you can withdraw it at any time – for instance via the cookie settings. The withdrawal takes effect from the moment it reaches us.

Simply write to us at This email address is being protected from spambots. You need JavaScript enabled to view it. or by post to the address above – we will take care of it.

You also have the right to contact the data protection authority – in Austria, the Austrian Data Protection Authority (www.dsb.gv.at).

 

Changes to this data protection policy

If our website or the services we use change, we will update this policy. The version published here is the one that applies.

 

September 2026