Privacy Policy.
This privacy policy describes what personal data is processed on the btlabs Core website, for what purpose and on what legal basis. It applies to the website and the associated communication channels (contact form, email, newsletter, WhatsApp). Processing is carried out in accordance with the GDPR (EU 2016/679) and the Italian Data Protection Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018).
1. Data controller
Data controller within the meaning of the GDPR:
Berger+Team d. Florian Berger
Reichrieglerweg 17/3
I-39100 Bozen (BZ)
Italy – South Tyrol
Email: info@berger.team
Phone: +393461033556
Contact person for data protection matters: Florian Berger
2. What data is processed
2.1 Server log files
When the website is visited, the hosting provider automatically processes the following data: IP address (truncated), date and time of access, page visited, browser and operating system information, referrer URL, HTTP status code.
Purpose: stable and secure operation, detection and defence against attacks, technical error analysis
Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
Retention period: Only for the period strictly necessary for technical error analysis
2.2 Contact requests
When contact is made via the contact form or by email, the following data is processed: first and last name, email address, phone number if provided, message content, time of the request. To prevent spam, a pseudonymised cryptographic hash of the IP address is generated; the IP address itself is not stored. Where provided, we store general attribution data on the origin of the request (campaign parameters).
Purpose: processing the request and communication; evaluation of the effectiveness of our own marketing measures
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure) or Art. 6(1)(f) GDPR (legitimate interest)
Retention period: Until the request is conclusively resolved, at most 6 months (automatic deletion), unless statutory retention obligations apply
AI-Ready Check (optional): If the free AI-Ready Check is requested via the contact form, we check what information publicly available AI models (e.g. ChatGPT) output about the business in question. For this purpose, the business data provided in the form (company name, website) is transmitted to the AI services listed in section 3. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure on request). No further personal data is transmitted.
2.3 Newsletter
When subscribing to the newsletter, the following data is processed: email address (required), first and last name (optional), time of subscription and confirmation (double opt-in), IP address at the time of subscription, click and open statistics.
Procedure: entry of the email address → confirmation email with opt-in link → subscription to the mailing list only takes effect after clicking.
Purpose: sending information, offers and news
Legal basis: Art. 6(1)(a) GDPR (consent)
Retention period: until consent is withdrawn; after unsubscribing, the email address may be stored on a block list to prevent further mailings
Unsubscribe: via the unsubscribe link in every email or by notifying info@berger.team
2.4 Communication via WhatsApp
When contact is made via WhatsApp (https://wa.me/393461033556), the following data is processed: phone number, WhatsApp profile name and profile picture if applicable, message content, timestamp, status information.
Provider: WhatsApp Ireland Limited (part of the Meta group), Ireland
Purpose: direct communication, answering enquiries, providing information
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure) or Art. 6(1)(a) GDPR (consent where contact is initiated by the user)
Third-country transfer: Meta may transfer metadata to the USA. Message content is end-to-end encrypted; metadata (phone numbers, timestamps, device information) is not.
Retention period: Until the request is conclusively resolved, at most 6 months.
Alternative contact channels: email at info@berger.team or phone at +393461033556. Transmission of sensitive data (health, payment information) via WhatsApp is not recommended.
WhatsApp Privacy Policy: whatsapp.com/legal/privacy-policy
2.5 Reach measurement
For the statistical evaluation of reach, we operate a privacy-friendly open-source analytics software on our own servers (self-hosting). The software operates cookieless without tracking cookies and without browser fingerprinting. No personal profiles are created, no cross-site tracking and no re-identification on return visits are carried out.
Data processed: page path visited, referrer, browser/device class, country code (no location), outbound clicks, defined custom events. The IP address is not stored; for session recognition within a day, the software generates a daily rotating hash.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Since no personal data is processed, no consent is required.
Retention period: unlimited (aggregated, non-personal statistics)
2.6 Cookies
This website uses only technically necessary cookies. Anonymous visitors do not receive any cookies. Exclusively upon login to the editorial area, a single technically necessary session cookie is set to ensure secure authentication for editors. This cookie is stored only for the duration of the respective session and is automatically deleted after logout or when the browser is closed.
Tracking, marketing or analytics cookies are not used. A cookie banner is therefore not required (Provvedimento Garante 10 June 2021).
This is made possible by cookieless first-party tracking: btlabs Core completely does away with cookie banners. Hosting is GDPR-compliant within the EU (see section 3).
2.7 Map display (OpenFreeMap)
To display maps we embed the OpenFreeMap service. When a map loads, the browser establishes a direct connection to the provider's servers, transmitting the IP address. According to the provider, IP addresses are not stored permanently, no cookies are set, and no tracking takes place.
Provider: Hyperknot Software Kft., Petőfi Sándor utca 48., 2724 Újlengyel, Hungary (EU)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an appealing display of our location)
Retention: no permanent storage of personal data by the provider
OpenFreeMap privacy policy: openfreemap.org/privacy
3. Data processors
The following external service providers process data exclusively on behalf of the data controller on the basis of agreements pursuant to Art. 28 GDPR:
Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland
Transactional emails (confirmations, newsletter): Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA (server location: Ireland)
File storage (images, documents): Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland
AI-assisted content editing (internal): OpenRouter (Lutra AI Inc., USA). No end-user data is processed here; only site content approved by the editorial team for editing is used. Depending on requirements, various established AI language models (e.g. from Anthropic or OpenAI) are used. Exception: the explicitly requested AI-Ready Check (see section 2.2) — in that case, the business data provided is transmitted to AI models.
4. Third-country transfers
Transfer to countries outside the EEA only takes place where a European Commission adequacy decision exists, EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR have been concluded, or another appropriate safeguard under Chapter V GDPR is in place.
This concerns the providers listed in section 3 with registered offices outside the EEA (in particular WhatsApp and AI sub-processors based in the USA; depending on the chosen mail provider and storage provider, potentially others). In the USA, there may not be a level of data protection comparable to that in the EEA; in particular, US authorities may access data.
5. Retention periods at a glance
Personal data is stored only for as long as necessary to fulfil the respective processing purpose. It is then deleted, unless statutory retention obligations apply:
Server log files: Only for the period strictly necessary for technical error analysis and to ensure system security.
Communication data (email, form, WhatsApp): Until the request is conclusively resolved, at most 6 months (automatic deletion).
Newsletter data: Until consent is withdrawn.
Contract and invoicing data: In accordance with statutory (in particular tax and commercial) retention periods.
6. Rights of data subjects
Data subjects have the following rights pursuant to Arts. 15–22 GDPR:
Access to the data processed (Art. 15)
Rectification of inaccurate or incomplete data (Art. 16)
Erasure of data, unless statutory retention obligations apply (Art. 17)
Restriction of processing (Art. 18)
Data portability in a structured, machine-readable format (Art. 20)
Objection to processing on grounds relating to a particular situation (Art. 21); in the case of direct marketing, at any time without giving reasons
Withdrawal of given consents with effect for the future (Art. 7(3))
Rights may be exercised informally at: info@berger.team
7. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. In Italy the competent authority is:
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma
garanteprivacy.it
8. Data security
Appropriate technical and organisational measures protect the data processed: encrypted data transmission (HTTPS/TLS), access restriction to authorised persons, regular security updates, backups, pseudonymisation and anonymisation procedures.
9. Obligation to provide data
The provision of personal data is neither legally nor contractually required. However, without the data specified in the respective sections, certain functions (e.g. answering enquiries, sending the newsletter) cannot be provided.
10. Automated decision-making
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
11. Minors
The services are not directed at persons under the age of 16. Data from minors is not knowingly collected without the consent of a parent or guardian. Notifications of any contrary transmission should be sent to info@berger.team; the data will in that case be deleted without delay.
12. Changes
This privacy policy is updated when the legal situation or the services provided change. The version currently published on this page is authoritative.
Last updated: July 11, 2026
© 2026 Berger+Team | All rights reserved