Privacy Policy
Last updated: June 9, 2026
General information
This Privacy Policy explains how GreenOnion FlexCo processes personal data when you visit or use ecoreguard.eu, including the EcoReguard compliance check and the AI advisor.
EcoReguard is a free information service concerning EmpCo-related compliance topics. The information, assessments and AI-generated responses provided through EcoReguard are general and non-binding. They do not replace individual legal advice or a professional assessment of a specific case.
For general information about data processing by GreenOnion FlexCo outside EcoReguard, please also refer to the GreenOnion Privacy Policy. This Privacy Policy takes precedence for processing activities specifically related to EcoReguard.
Controller
The controller within the meaning of Art. 4(7) GDPR is:
GreenOnion FlexCo
Salurnerg. 4
2340 Mödling
Austria
Managing Director: Martin Watzka
Company Register Number: FN 480558d
VAT Number: ATU72745746
Email: office@greenonion.at
Legal bases
We process personal data only where a legal basis applies. Depending on the processing activity, we rely in particular on:
- Art. 6(1)(a) GDPR: consent
- Art. 6(1)(b) GDPR: pre-contractual steps or performance of a contract
- Art. 6(1)(c) GDPR: compliance with a legal obligation
- Art. 6(1)(f) GDPR: legitimate interests
Where we rely on legitimate interests, these include secure website operation, protection against misuse and cyberattacks, responding to enquiries and providing the requested information service.
Hosting and server logs
This website and its server-side functions are hosted by Netlify, Inc. (512 Second Street, Suite 200, San Francisco, CA 94107, USA).
When the website or one of its server-side functions is accessed, Netlify may process technically necessary connection and log data, including:
- IP address
- Date and time of access
- Requested page, file or function
- Browser type and version
- Operating system
- Device and connection information
- Referrer URL, where transmitted
- Status codes, error and security information
The processing is necessary to deliver the website and its functions, maintain availability, identify technical errors and protect the systems against misuse, attacks and unauthorised access.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure, stable and efficient website operation.
As Netlify is based in the United States and may use service providers outside the European Economic Area, personal data may be transferred to third countries. Such transfers are based on applicable safeguards under Art. 44 et seq. GDPR, including adequacy decisions, certifications under the EU-US Data Privacy Framework or Standard Contractual Clauses.
Further information: Netlify Privacy Statement.
External resources and CDNs
EcoReguard may load technical design resources such as fonts, icons or stylesheets from external content delivery networks.
The website currently uses or may use Google Fonts, Google Material Symbols, Tailwind CSS resources or comparable technical content delivery services.
When such an external resource is requested, the relevant provider may receive technical connection data, in particular IP address, date and time of the request, requested resource, browser and device information and referrer information where transmitted.
Where these external resources are necessary for the technical presentation of the website, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in providing a functional and consistent website presentation.
We aim to host fonts, icons and styles locally wherever reasonably possible in order to reduce unnecessary transfers of personal data to third parties.
Consent decisions and local storage
EcoReguard may store consent decisions in the browser using Local Storage or comparable technologies.
This may include whether the user has accepted or rejected the loading of Typeform, the date and time of the decision, the version of the consent information and technically necessary settings for displaying the relevant consent notice.
The purpose is to remember the user’s privacy choice, avoid repeatedly displaying the same request and ensure that external services are not loaded without the required consent.
Legal basis: Art. 6(1)(c) GDPR where storage is necessary for legal accountability requirements, and Art. 6(1)(f) GDPR for reliable implementation and documentation of privacy choices.
Consent can be withdrawn or reset using the relevant privacy control provided on the website.
Compliance Check — Typeform
The EcoReguard compliance check is provided using Typeform (TYPEFORM S.L., Carrer de Bac de Roda 163, 08018 Barcelona, Spain).
The Typeform form is only loaded after the user has actively agreed to load it. Before consent, EcoReguard should not establish a connection to Typeform, load a Typeform iframe or permit Typeform to store cookies or comparable information on the user’s device.
When the form is loaded or used, the following data may be processed:
- Answers submitted in the compliance check
- Industry or business sector
- Information concerning environmental or sustainability claims
- Geographic markets
- Company-related information
- Name and contact details, where voluntarily provided
- IP address, browser and device information
- Date and time of access
- Typeform session identifiers
- Cookies and Local Storage information used by Typeform
- Technical interaction and form-completion data
The data is processed to provide the compliance check, generate a non-binding initial assessment, display relevant information concerning possible EmpCo risks, evaluate and improve the questionnaire, respond to an enquiry where contact details are voluntarily provided and document submitted information where required for follow-up communication.
The loading of Typeform and the associated access to the user’s device are based on consent pursuant to Art. 6(1)(a) GDPR. Where the user requests contact, an offer or further information, the processing is additionally based on Art. 6(1)(b) GDPR.
The user may access the rest of EcoReguard without loading or using Typeform.
Data submitted through the compliance check will not be used for a newsletter or unrelated electronic marketing unless the user has separately and expressly consented to such communication.
Typeform may use subprocessors, including providers located outside the European Economic Area. Where data is transferred to third countries, the transfer is subject to applicable safeguards under Art. 44 et seq. GDPR.
Typeform responses are stored for as long as they are required to provide the compliance check, process a requested follow-up, document the result or protect legitimate legal interests. Responses that are no longer required will be deleted or anonymised unless statutory retention obligations or legal claims require longer storage.
Consent to load Typeform may be withdrawn at any time using the “Revoke Typeform consent” or corresponding privacy control in the website footer.
Further information: Typeform Privacy Policy.
AI Advisor — OpenAI API
EcoReguard provides an AI-based information assistant. The AI advisor is operated through a server-side backend hosted on Netlify. Messages are sent from the user’s browser to the EcoReguard backend and from there to the OpenAI API.
The OpenAI service is provided by OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. Depending on the contractual and technical setup, other OpenAI group companies and subprocessors may be involved in providing the service.
When the AI advisor is used, the following data may be processed:
- Messages entered by the user
- Questions concerning EmpCo, sustainability claims or compliance
- Information voluntarily included in the message
- AI-generated responses
- Conversation history
- Date and time of the conversation
- Session identifiers
- IP address and technical connection data
- Browser and device information
- Technical error and security information
The AI advisor does not actively ask for the user’s name, email address or other contact details. Users should nevertheless avoid entering names, contact details, special categories of personal data, confidential customer information, trade secrets, passwords or information that is not necessary for the question.
The data is processed to provide the AI advisor, answer questions concerning EmpCo-related topics, maintain the context of the conversation, store and display conversation history, identify and correct technical errors, protect the service against misuse and improve the EcoReguard information service.
The processing begins when the user actively submits a message to the AI advisor.
Legal basis: Art. 6(1)(a) GDPR where the user voluntarily chooses to use the AI advisor and consents to the processing required for that function. To the extent that a user asks a specific pre-contractual or business-related question, Art. 6(1)(b) GDPR may additionally apply. Technical security, abuse prevention and error logging are based on Art. 6(1)(f) GDPR.
The user’s message and the conversation context required to generate an answer are transmitted to the OpenAI API. According to OpenAI’s information for business and API customers, data submitted through the API is not used to train OpenAI’s general models by default unless the customer explicitly opts in to such use. GreenOnion does not intentionally opt in to the use of EcoReguard chat content for the training of general OpenAI models.
EcoReguard stores chat conversations. Stored information may include messages submitted by the user, responses generated by the AI advisor, timestamps, technical session identifiers and information necessary to maintain the conversation and operate the service.
Chat histories are retained only for as long as required to provide conversation history, review technical issues, prevent misuse and improve the service. They will be deleted or anonymised when no longer needed, unless statutory obligations or legal claims require longer retention.
Users may request the deletion of a stored conversation by contacting office@greenonion.at. GreenOnion may require sufficient information to identify the relevant conversation without disclosing data to an unauthorised person.
Responses are generated automatically and may be inaccurate, incomplete or outdated. The AI advisor does not provide legal advice, does not replace an individual professional assessment and does not make legally binding decisions.
Further information: OpenAI Privacy Policy.
Contact requests through Typeform
Where a user voluntarily provides contact information through Typeform, GreenOnion may process name, email address, company, position or function, information submitted in the compliance check, content of the requested follow-up and subsequent communication.
The processing is carried out to respond to the request, provide requested information, discuss possible services or prepare an offer.
Where the request concerns a possible contract, the legal basis is Art. 6(1)(b) GDPR. For other business-related enquiries, the legal basis is Art. 6(1)(f) GDPR.
Data relevant to offers, contracts, accounting or legal claims may be stored for the applicable statutory retention periods.
Recipients and international transfers
Personal data may be disclosed to or processed by hosting and infrastructure providers, Typeform as form provider, OpenAI as provider of the AI model and API, IT security and maintenance providers, legal, tax and other professional advisers, and public authorities or courts where disclosure is legally required.
Where a service provider processes personal data on our behalf, we enter into a data processing agreement pursuant to Art. 28 GDPR where required.
Some service providers or their subprocessors may be located outside the European Economic Area or may access data from third countries. Personal data is transferred to a third country only where the requirements of Art. 44 et seq. GDPR are met.
Depending on the recipient, safeguards may include an adequacy decision by the European Commission, certification under the EU-US Data Privacy Framework, Standard Contractual Clauses approved by the European Commission or supplementary technical and organisational safeguards.
Storage periods
We store personal data only for as long as required for the relevant purpose.
- Server and security logs are retained for the period required for operation, error analysis and security.
- Consent decisions are stored for the period required to implement and document the user’s choice.
- Typeform responses are retained while required to provide the check, process requested follow-up or protect legal interests.
- Contact data is retained while an enquiry or business relationship is active and for applicable statutory retention periods.
- AI chat histories are retained while required to provide conversation history, review technical issues, prevent misuse and improve the service.
Data may be retained for longer where statutory retention obligations apply, where the data is required for legal claims, where a security incident is being investigated or where the data subject has consented to longer storage.
Data security
We use appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration, disclosure or destruction.
These measures may include encrypted transmission using HTTPS and TLS, server-side handling of API credentials, restricted access rights, secure authentication, technical logging and monitoring, separation of frontend and backend functions, contractual confidentiality obligations and selection of suitable service providers.
OpenAI API credentials must not be stored in or delivered to the public browser code. Requests to OpenAI are processed through the Netlify backend.
Automated decision-making
The compliance check and AI advisor may generate automated initial assessments, classifications or responses. These outputs are informational and non-binding.
GreenOnion does not use EcoReguard to make decisions based solely on automated processing that produce legal effects concerning users or similarly significantly affect them within the meaning of Art. 22 GDPR.
The results do not establish legal compliance and do not replace an individual legal assessment.
Your rights
Under the applicable statutory requirements, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal (Art. 7(3) GDPR)
Where processing is based on Art. 6(1)(f) GDPR, you may object at any time for reasons arising from your particular situation. You may object to processing for direct marketing purposes at any time without providing reasons.
To exercise your rights or for any privacy-related questions, please contact: office@greenonion.at
Right to lodge a complaint
You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.
The supervisory authority responsible for GreenOnion FlexCo is:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria
www.dsb.gv.at
External links
EcoReguard may contain links to websites or resources operated by third parties. When a user follows an external link, the relevant third party is generally responsible for the processing carried out on its website.
Changes to this Privacy Policy
We may update this Privacy Policy where the website, its functions, the service providers, our processing activities or the applicable legal requirements change.
The version published on EcoReguard at the time of use applies.