Privacy Policy
EFFECTIVE DATE: JANUARY 1, 2026 •
LAST REVISED: FEBRUARY 2026 •
DOCUMENT REFERENCE: BLM-GDPR-V4
1. Introduction and Data Controller Information
Browselabmatrxx Alpine Logistics Ltd. ("Browselabmatrxx", "we", "our", or "us") operates the website browselabmatrxx.com and associated digital road trip routing services. We take your personal privacy seriously and are dedicated to processing personal data in full compliance with the European Union General Data Protection Regulation (EU Regulation 2016/679 - "GDPR"), the UK Data Protection Act 2018, and the California Consumer Privacy Act ("CCPA").
The designated Data Controller responsible for personal data collected across this website is Browselabmatrxx Alpine Logistics Ltd., Alpenstrasse 142, 5020 Salzburg, Austria. For inquiries regarding our privacy practices or to exercise statutory data subject rights, please contact our appointed Data Protection Officer (DPO) at [email protected].
2. Categories of Personal Data Collected
Depending on your interactions with our website, we may collect and process the following categories of information:
- Directly Provided Information: When you complete our contact forms, submit route inquiries, or request technical dossiers, we collect your full name, email address, inquiry subject, and the contents of your message.
- Telemetry and Device Data: When navigating route guides, our servers automatically collect IP addresses (anonymized prior to persistent logging), browser user-agent strings, operating system identifiers, screen resolution, referral URLs, time stamps, and page load telemetry.
- Location Data: Non-precise, regional geolocation derived from anonymized IP addresses to dynamically present relevant country-specific vignette laws and pass warnings.
- Interaction Data: Search queries entered into our route filtering system, bookmarks saved locally in your browser storage, and interactions with interactive elevation charts.
3. Legal Bases for Data Processing under GDPR
We process personal data solely in instances where a lawful basis under Article 6 of the GDPR applies:
- Article 6(1)(a) Consent: For voluntary communications, analytical cookie deployment, and subscription services where you have granted explicit consent.
- Article 6(1)(b) Contractual Performance: Processing necessary to fulfill route dossiers, logistics support, or contractual obligations initiated by you.
- Article 6(1)(c) Legal Compliance: Retention of accounting, business records, and tax filings in accordance with Austrian federal commercial law (UGB).
- Article 6(1)(f) Legitimate Interests: Protecting website security, preventing automated bot scraping of proprietary telemetry, and optimizing site performance.
4. Third-Party Sub-Processors and Data Transfers
We do not sell, rent, or lease your personal information to third parties. We engage trusted enterprise infrastructure sub-processors who adhere to stringent confidentiality and data security standards:
- Hosting & Content Delivery: Cloudflare Inc. (Security, CDN caching, DDoS mitigation - EU-US Data Privacy Framework certified).
- Server Infrastructure: Hetzner Online GmbH (Dedicated high-security servers located within ISO/IEC 27001 certified facilities in Nuremberg, Germany).
- Transactional Email Services: Postmark / ActiveCampaign (Standard Contractual Clauses implemented for cross-border transit).
5. Data Retention Schedules
Personal data collected through interactive forms is retained only as long as necessary to resolve your inquiry, typically not exceeding 24 months from the last documented interaction, unless a statutory legal retention period (e.g., Austrian commercial code 7-year retention for business correspondence) applies. Server telemetry logs are purged or pseudonymized on a rolling 30-day cycle.
6. Your Statutory Rights under GDPR and CCPA
As a data subject, you hold comprehensive rights under applicable data protection frameworks:
- Right to Access (GDPR Art. 15): Request a copy of all personal records held about you in a structured format.
- Right to Rectification (GDPR Art. 16): Require immediate correction of inaccurate or incomplete personal records.
- Right to Erasure / "Right to be Forgotten" (GDPR Art. 17): Request deletion of your personal records where no overriding legal basis for retention exists.
- Right to Restrict Processing (GDPR Art. 18): Restrict processing during ongoing disputes regarding accuracy or lawfulness.
- Right to Data Portability (GDPR Art. 20): Receive your data in a commonly used, machine-readable format.
- Right to Object (GDPR Art. 21): Object at any time to data processing carried out under legitimate interest grounds.
- California Specific Rights (CCPA): California residents have the right to request disclosure of categories of information collected, the right to opt out of the sale or sharing of personal data (which we do not engage in), and protection from discriminatory treatment for exercising privacy rights.
To exercise any of these rights, submit your written request to [email protected]. You also maintain the right to lodge a formal complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, [email protected]) or your local supervisory authority.
7. Security Safeguards
Browselabmatrxx utilizes state-of-the-art technical and organizational measures (TOMs), including 256-bit Transport Layer Security (TLS 1.3) encryption in transit, strict access controls, principle of least privilege, automated vulnerability assessments, and DDoS edge protection to ensure the confidentiality, integrity, and resilience of all processing systems.