Privacy Policy

Information on data processing pursuant to the GDPR and the Austrian Data Protection Act (DSG)

General information

Protecting your personal data is a key concern for us. We process your data exclusively on the basis of statutory provisions (GDPR, Austrian DSG, TKG 2021). This privacy policy informs you about the most important aspects of data processing in connection with our website beynance.com and our property management software.

Personal data is any information relating to an identified or identifiable natural person. This privacy policy explains which data we collect, what we use it for, on what legal basis the processing takes place, and which rights you are entitled to.

Controller within the meaning of the GDPR

Taps.im Secure Tech GmbH

Stolberggasse 44/17
1050 Vienna
Austria

Phone: +43 676 404 1337
E-Mail: info [at] beynance.com

Represented by the Managing Director: Philipp Beyrl

Your rights as a data subject

With regard to the personal data we process, you have the following rights:

  • Right of access to your processed data (Art. 15 GDPR)
  • Right to rectification of inaccurate or completion of incomplete data (Art. 16 GDPR)
  • Right to erasure ("right to be forgotten", Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent with effect for the future (Art. 7(3) GDPR)
  • Right to lodge a complaint with the competent supervisory authority (Art. 77 GDPR)

To exercise your rights, an informal message via e-mail or post to the contact details stated above is sufficient.

Homepage

Log files

Whenever you access our website, technically necessary data is temporarily stored in log files on our own servers:

  • IP address of the requesting computer (anonymized / shortened where technically possible)
  • Date and time of access
  • Requested URL and HTTP status code
  • Referring website (referrer)
  • Browser and operating system used
  • Volume of data transferred

These data are processed exclusively to ensure the operation of the website, to defend against attacks and for error analysis. The data is not merged with other data sources, nor used for any individual analysis. Log data is anonymized or deleted after 14 days at the latest, unless security incidents require longer retention.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and stable operation of the website).

Google Tag Manager and Google Analytics 4

Subject to your consent, we use Google Tag Manager and Google Analytics 4 (GA4) provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) on the homepage to analyze the use of our website on a statistical basis and to improve our offering.

GA4 uses cookies and transmits pseudonymized usage data (IP address with IP anonymization activated, pages visited, time on site, device and browser information, approximate geographic location) to Google. We use IP anonymization and โ€“ where available โ€“ server-side collection via the GA4 Measurement Protocol API to reduce data volumes and third-party load.

On our side, no link is created between this data and identifying personal attributes or other Google services. You can object to the collection at any time via the cookie banner.

Note on third-country transfers: When GA4 is active, Google may transfer personal data to the United States. The transfer takes place on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR) and the self-certification of Google LLC under the EU-US Data Privacy Framework. Outside of this analysis โ€“ which requires your consent โ€“ no transfer of your data to third countries takes place.

Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with ยง 165(3) TKG 2021.

Cookies and consent management

Our website uses cookies and comparable technologies (e.g. local storage) to provide functionality, store language preferences and โ€“ with your consent โ€“ to measure reach.

We distinguish between technically necessary cookies (e.g. NEXT_LOCALE for language selection, SELECTED_COUNTRY for country routing, the cookie consent status) which are set without consent, and optional cookies (analytics, marketing) which are activated only after active opt-in via our cookie banner.

You can withdraw your consent at any time by deleting the cookies in your browser settings or by re-opening the banner. A detailed list of the cookies in use is available via the cookie banner.

Legal basis: Technically necessary cookies: Art. 6(1)(f) GDPR. Optional cookies: Art. 6(1)(a) GDPR in conjunction with ยง 165(3) TKG 2021 (consent).

Contact form and e-mail contact

When you use our contact form or send us an e-mail, we process the following data:

  • Name
  • E-mail address
  • Phone number (optional)
  • Company (optional)
  • Subject and message content
  • IP address for abuse prevention (rate limiting)
  • Time of submission

We use this data exclusively to process your inquiry and to communicate with you. Data will not be passed on to third parties unless this is necessary to initiate or perform a contract.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures / contract performance) or Art. 6(1)(f) GDPR (legitimate interest in answering inquiries).

Storage period: Storage period: We store your inquiry for as long as it is necessary to process the matter โ€“ usually up to 24 months after the correspondence has ended, and at most until the expiry of statutory retention periods (e.g. ยง 132 BAO, ยง 212 UGB).

Sign-in / authentication (live demo, protected areas)

If you sign in for the live demo, a trial account or a protected area, we process the data required for this purpose (e-mail address, authentication tokens, session data). This data is used exclusively to provide the function and to ensure authenticity.

Legal basis: Art. 6(1)(b) GDPR (contract performance) or Art. 6(1)(f) GDPR (secure operation of the login function).

Hosting (own infrastructure)

Our website and software platform are operated exclusively on hardware owned by Taps.im Secure Tech GmbH within the EU (Austria, Germany, Finland). We do not use any external cloud or hosting providers and deliberately avoid third-party virtualization. There is therefore no processing-on-behalf relationship in the area of hosting.

All data transfers between your device and our servers take place exclusively via encrypted connections (TLS 1.2/1.3, HSTS).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

Property Management Software (Beynance)

The Beynance property management software is operated exclusively on hardware owned by Taps.im Secure Tech GmbH within the EU (Austria, Germany, Finland). We deliberately avoid external cloud providers and third-party virtualization. All data stored within the platform is encrypted; sensitive content is additionally encrypted at the application level before it is written to the database.

Important note: The use of Google Tag Manager and Google Analytics 4 described earlier applies exclusively to our homepage. Within the Beynance property management software, zero external services are used โ€” no analytics, no tag manager, no cloud providers, no third-party trackers or APIs. The entire platform is operated and hosted entirely by ourselves.

Sensitive content of our software platform is encrypted separately before storage, including in particular:

  • API keys and service tokens
  • Telephony credentials (e.g. SIP passwords, auth tokens)
  • Personal data of tenants, owners and business partners
  • Financial data (e.g. bank details, accounting records, rent payments)

We implement comprehensive technical and organizational measures (TOM) pursuant to Art. 32 GDPR to protect your data against unauthorized access, loss or manipulation. These include TLS 1.2/1.3 encryption in transit, AES-256 encryption of sensitive data at rest in the database, multi-level access controls, logging of security-relevant events, regular security audits and penetration tests.

The Beynance platform uses industry-leading encryption standards and is designed to meet the requirements of regulated sectors (real estate, public sector, banking). Backups are likewise encrypted and stored exclusively at our own facilities in Austria, Germany and Finland.

Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. The competent authority in Austria is:

Austrian Data Protection Authority (Datenschutzbehรถrde)

Barichgasse 40-42, 1030 Vienna

Phone: +43 1 52 152-0

E-Mail: [email protected]

www.dsb.gv.at

Updates to this privacy policy

We reserve the right to update this privacy policy in order to keep it in line with current legal requirements and our processing practices at all times. The version that is current at the time of your visit applies. We will announce material changes on the website where appropriate.

As of: 09/05/2026