Privacy policy
Information pursuant to Articles 13 and 14 GDPR.
This is a courtesy translation. The German version is the legally binding one.
The short version first. Anyone scanning a QR code needs no account, receives no cookie and is not counted. There are no analytics tools, no advertising networks, and no fonts or scripts loaded from third-party servers. The scan log stores no IP address — not even as a hash.
Controller
- Company
- NEED immersive reality GmbH
- Address
- Joanneumring 7/7, 8010 Graz, Österreich
- office@xr-need.com
No data protection officer has been appointed; the statutory conditions for doing so are not met.
1. Visiting the website
When a page is requested, the hosting provider processes technically necessary data in its server logs: IP address, time, requested address, amount of data transferred, status code, referring page and browser identification. These logs serve secure operation and fault finding.
- Legal basis: Article 6(1)(f) GDPR (legitimate interest in trouble-free and secure operation).
- Retention: as set out in the hosting contract; the logs are not analysed and not combined with other data.
Cookies
The public pages — home page, example, imprint, this page and every answer page after a scan — set no cookie. A session cookie is created only after signing in to the administration area; it is technically necessary for the sign-in to work (§ 165(3) of the Austrian Telecommunications Act 2021) and expires when the session ends. No consent is required for it, and there is therefore no consent banner.
2. Scanning a QR code
When a code belonging to a revision is opened, an entry is created in the scan log. What is stored:
- the time of the request,
- which revision was opened,
- the result (current, superseded, withdrawn),
- a coarse device class such as “iPhone”, “Android” or “Windows”.
Not stored are the IP address, the full browser identification string, location data, or any other identifier leading back to a person. A single entry cannot be attributed to any particular person.
- Purpose: evidence that and when a revision was checked, and detection of misuse and technical faults.
- Legal basis: Article 6(1)(f) GDPR.
- Retention: 12 months, then automatic deletion.
Protection against guessing codes
If an unknown code is opened or a sign-in is attempted, a counter is kept. This counter contains the IP address solely as a hash value and is deleted automatically after 24 hours at the latest. Its purpose is narrowly limited: to prevent anyone from guessing codes or passwords.
- Legal basis: Article 6(1)(f) GDPR (security of the service).
3. Data about drawings
For each revision the project name, drawing number, title, scale, sheet size, issue date, status and the change description are stored. The drawings themselves are never uploaded.
These entries are made by the office issuing the drawing. If they contain personal data — the name of an author or checker, for instance — that office is the controller within the meaning of the GDPR; the operator processes such data on its behalf (Article 28 GDPR). The operator does not analyse these entries and does not use them for any purpose of its own.
4. Access to the administration area
For administration accounts the email address, name and a password hash are stored. The password itself is not stored and is not readable by the operator either.
- Legal basis: Article 6(1)(b) GDPR (performance of the user relationship).
- Retention: for the duration of the account, then deletion, unless a statutory retention obligation applies.
5. Test environment
Anyone who clicks “Try it” receives their own test environment. Neither an account nor an email address is required. A technically necessary session cookie is set; in addition, an address containing a random component is created, through which the same environment can be reopened later. Anyone who knows that address has access — treat it like a key.
Whatever is entered in the test environment is stored like data about drawings (see section 3). Please do not enter real drawing data or personal data there.
- Legal basis: Article 6(1)(f) GDPR (legitimate interest in trying the service without signing up).
- Retention: seven days after creation the content of the test environment is deleted. The codes generated in it remain permanently and answer a scan with a note that this is a test code. The reason is safety: a printed code that no longer answers would be more dangerous than an honest reply. After deletion these codes carry no content.
6. Email address for the test environment
Starting a test environment requires an email address. The access link, which reopens the same environment later, is sent to it. Without an address the test environment cannot be started; the remaining parts of the website — home page, example result and scanning a code — are unaffected and remain usable without providing anything.
- Legal basis: Article 6(1)(b) GDPR (steps taken at the request of the data subject prior to entering into a contract).
- Retention: at most 24 months from entry, then automatic deletion. On request it is deleted immediately.
- Disclosure: none. The address is not passed on to third parties and is not analysed.
7. News by email (only with consent)
Next to the address field there is a separate, unticked checkbox. Only by ticking it do you agree to receive occasional messages about Planstatus. If you leave it empty, you receive the access link and nothing else.
Consent is obtained by double opt-in: after ticking, a separate message with a confirmation link is sent. Only clicking it adds the address to the list. If the click does not happen, nothing occurs and no further message follows. The time of confirmation and the version of the agreed wording are stored for this purpose.
Every message contains an unsubscribe link. It takes effect immediately, without further questions and without signing in. Withdrawal does not affect the lawfulness of processing carried out beforehand.
- Legal basis: Article 6(1)(a) GDPR (consent), section 174 Austrian Telecommunications Act 2021.
- Retention: until withdrawal, at most 24 months without contact. Proof of consent is kept for as long as it is needed to defend against claims.
8. Contacting us
If you write by email, your details are processed in order to deal with your enquiry (Article 6(1)(b) or (f) GDPR) and deleted as soon as they are no longer needed and no retention obligation applies.
9. Recipients
The website and the database are operated at a hosting provider inside the European Union acting as a processor pursuant to Article 28 GDPR. No transfer to third countries takes place. No disclosure for advertising or analytics purposes takes place.
10. No automated decision-making
There is no automated decision-making within the meaning of Article 22 GDPR and no profiling. The display “current” or “superseded” concerns a drawing, not a person.
11. Your rights
You have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and the right to object to processing based on legitimate interests (Article 21). To exercise them, contact office@xr-need.com.
Independently of this, you have the right to lodge a complaint with the supervisory authority:
- Authority
- Austrian Data Protection Authority
- Address
- Barichgasse 40–42, 1030 Vienna, Austria
- dsb@dsb.gv.at
Version: 09.09.2026. Changes to this policy are published here.