Legal

Privacy Policy

Version: 2026-08-17

Released: August 17, 2026

Plug Ad Play privacy policy for processing, rights, and contact channels.

1. Controller and Data Protection Contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Plug Ad Play — Owner and controller: Thomas Geyer, MSc
Maria-Emhart-Weg 14/37
1220 Vienna, Austria

Data protection contact: office@plugadplay.at

A data protection officer has not been appointed, as the statutory requirements for a mandatory appointment do not apply according to our current assessment.

2. Purposes of Processing

We process personal data insofar as this is necessary for the operation and use of the Plug Ad Play platform. This includes in particular registration, login, account security, company workspaces, roles and invitation codes, screen and location management, campaigns, bookings, negotiation and chat, contact unlock, payment processing, billing, email delivery, support, legal records, abuse prevention, as well as the initial postal contact with operators of digital advertising screens.

3. Legal Bases

Depending on the purpose, processing is carried out on the basis of the following legal grounds:

ProcessingLegal basis
Account, login, workspaces, roles, bookings, contact unlock and platform functionsPerformance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR)
Billing, payment records, tax and commercial law obligationsLegal obligations (Art. 6(1)(c) GDPR)
Platform operation, security, abuse prevention, server logs, operator initial contact and supportLegitimate interests (Art. 6(1)(f) GDPR)
Optional product analyticsConsent (Art. 6(1)(a) GDPR)

Consent may be withdrawn at any time with effect for the future.

4. Legitimate Interests

Our legitimate interests include in particular the stable operation of the platform, fraud and abuse prevention, security, evidence of legal authorizations, improvement of support processes, protection of contractual partners, and approaching operators of digital advertising screens to build our brokerage offering. For postal operator outreach, we limit ourselves to publicly available business data, use no electronic cold acquisition without consent or active contact, enable simple objection, and document the associated balancing of interests internally.

5. Categories of Personal Data

Data processed may include in particular account and contact data, authentication data, company data, role and authorization data, screen and location data, campaign and booking data, chat and negotiation data, payment and billing data, technical log data, email and support data, as well as legal confirmation events.

6. Data from Publicly Accessible Sources (Information pursuant to Art. 14 GDPR)

To build our brokerage offering, we may collect data on operators of digital advertising screens from publicly accessible sources. These include in particular company websites, public company and industry directories, and publicly viewable location information.

The categories concerned are name or company, business address, publicly listed contact data, and information about advertising screens such as location, size and type. Insofar as this concerns exclusively data of legal entities with no reference to a natural person, such data is not subject to the GDPR.

The purpose is postal contact to provide information about our brokerage offering and about possible booking requests, as well as the provision of pre-filled advertising screen data to the respective operator after registration and verification.

The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). Data subjects are informed about the processing at the latest at the time of the first contact, and in any case within one month of collection.

Contact data collected from public sources is not published. Disclosure occurs only insofar as this is necessary for operation, verification, legal obligations, or the confirmed use of the platform. Access to pre-filled advertising screen data requires verification that the registering person is actually the operator of the respective screen, e.g. via an individual code from a postal mailing.

If no registration takes place, the data is deleted at the latest 12 months after the last contact. In the event of an objection, the data is deleted without undue delay; to ensure that no further contact takes place, minimal data is added to an internal suppression list.

7. Postal Contact

The initial contact with operators whose data we process from publicly accessible sources without an existing business relationship is made in accordance with the applicable telecommunications and competition-law requirements; under the law currently applicable in Austria, this means exclusively by postal mail. Before sending, the Robinson list of the Austrian Federal Economic Chamber is taken into account where available. Contact by email or telephone takes place only where a separate legal basis exists (e.g. express consent, active contact by the operator, or a legally permitted exception). Every postal mailing contains a notice of the right to object.

8. Platform Processes and Contact Unlock

Account and company data enable workspaces, roles and invitation codes. Screen, location, campaign and booking data enable offers, booking requests and bookings. Chat and negotiation data support communication between the parties, initially without disclosing certain contact data to the respective other side. Within the paid contact unlock, the designated contact data is displayed to the respective contractual partner after successful payment or authorization. Email and support data enable notifications, security communication and assistance.

9. Service Providers and Processing Activities Used

To provide individual functions, we use external services. The following sections describe the data processed and the legal bases in each case; a consolidated overview of all recipients is provided in Section 11.

9.1 Payment Processing with Stripe

For payments within the contact unlock, we use the payment service provider Stripe. The entry of payment data takes place directly at Stripe; we do not store complete card or payment data on our servers.

The data required for payment processing is transmitted to Stripe, in particular business contact data as well as technical payment and transaction references. For billing and record-keeping purposes, we process payment status and payment confirmations; invoicing and tax data may be processed internally for billing verification.

Depending on the processing activity, Stripe processes personal data either as a processor or as an independent controller, in particular for payment processing, fraud prevention and compliance with legal obligations. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).

9.2 Email Delivery with Resend

For sending transactional emails — such as verification codes, password resets, booking requests, claim and invitation links, and confirmations — we use the service provider Resend. In doing so, the recipient's email address, the content of the respective email, and technical delivery and dispatch data are processed.

Sending transactional emails is carried out, depending on the content, for the performance of a contract (Art. 6(1)(b) GDPR), for compliance with legal obligations (Art. 6(1)(c) GDPR), or on the basis of legitimate interests in secure and reliable communication (Art. 6(1)(f) GDPR).

9.3 Product Analytics with PostHog

We use PostHog (EU Cloud) for product analytics and improvement of the platform. In doing so, we distinguish between non-logged-in and logged-in users.

For non-logged-in visitors, usage measurement is carried out in anonymized form. No cookies are set and no information is permanently stored on or read from the end device; no permanent recognition takes place. The legal basis is our legitimate interest in privacy-friendly reach measurement (Art. 6(1)(f) GDPR).

For logged-in users, more extensive, user-related product analytics is carried out exclusively on the basis of separate, revocable consent (Art. 6(1)(a) GDPR). Only after this consent has been granted are cookies or comparable storage on the end device used for this purpose, and usage events are assigned to a pseudonymous user identifier. Without consent, no user-related product analytics takes place.

The data processed includes usage events such as page views, clicks and features used, as well as technical device and browser information. Consent may be withdrawn at any time in the account settings.

9.4 Map Display with MapTiler

For maps and the display of digital advertising screens, we use MapTiler. When maps are loaded, technical request data such as IP address, device and browser information, and the requested map section may be transmitted to MapTiler by the browser. The legal basis is, insofar as maps are necessary for platform functions, the performance of a contract (Art. 6(1)(b) GDPR), and otherwise our legitimate interest in a user-friendly display (Art. 6(1)(f) GDPR).

10. Technical Log Data, Security and Cookies

When our website and app are accessed, technical log data is processed, in particular the IP address or security values derived from it, the time of access, the resource accessed, and browser and system information. The purpose is the secure and stable operation of the platform as well as the defense against and tracing of attacks and abuse. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

Technical log data is stored only for as long as this is necessary for secure operation, error analysis and abuse prevention, and is generally deleted or anonymized after approximately 30 days. Longer retention only takes place insofar as this is necessary to investigate specific security incidents, to trace abuse, or to comply with legal obligations.

For the operation of the platform, we use technically necessary cookies and similar storage, in particular for authentication, session security, language and interface settings. During the registration process, a form draft may be temporarily stored in the browser. For non-logged-in visitors as well as for logged-in users without analytics consent, no consent-requiring analytics cookies or comparable persistent analytics storage are set. Consent-requiring storage for analytics purposes takes place exclusively for logged-in users and only after their consent (see Section 9.3).

11. Overview of Recipients and Service Providers

We use external service providers insofar as this is necessary for the operation, communication, product analytics, map display, payment processing, security and support of the platform. Insofar as service providers process personal data on our behalf, data processing agreements pursuant to Art. 28 GDPR are in place.

Service provider / recipientPurpose
IP-Projects GmbH & Co. KG, Am Vogelherd 14, 97295 Waldbrunn, Germany; hosting in German data centersHosting, operation of the app, database, security and technical infrastructure
StripePayment processing, payment status and confirmations, fraud prevention
ResendSending of transactional emails and technical dispatch logs
PostHog (EU Cloud)Optional product analytics and improvement of the platform
MapTilerDisplay of maps as well as location and screen views
Tax and legal advisors, authorities, banksBilling, legal obligations and enforcement of rights, where necessary

Personal data is only disclosed insofar as this is necessary for the stated purposes, a legal obligation exists, or consent has been given.

12. Third-Country Transfers

In the course of using individual service providers, personal data may be transferred to countries outside the European Economic Area. Such transfers only take place insofar as the statutory requirements are met, in particular on the basis of an adequacy decision, standard contractual clauses of the EU Commission, or other appropriate safeguards pursuant to Art. 44 et seq. GDPR. Further information on the safeguards used in each case can be requested via the data protection contact.

13. Retention Period

We store personal data only for as long as is necessary for the respective purposes, legal obligations, records, dispute resolution and security interests. In particular, the following applies:

  • Accounting, invoicing and payment data is generally retained for 7 years pursuant to § 132 BAO and § 212 UGB, beginning at the end of the respective financial year.
  • Contract, booking and record data is stored for the duration of the business relationship and beyond, until the expiry of relevant statutory limitation and record-keeping periods.
  • Data from publicly accessible sources without registration is deleted at the latest 12 months after the last contact, provided that no objection or registration takes place.
  • Technical log data is generally deleted or anonymized after approximately 30 days.
  • Other data (e.g. chat, support and delivery data) is stored for as long as this is necessary for communication, support, security or record purposes.

14. Rights of Data Subjects

Data subjects have, in accordance with the GDPR, the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Consent may be withdrawn at any time with effect for the future.

15. Right to Object

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you that is carried out on the basis of legitimate interests (Art. 6(1)(f) GDPR). Where processing is carried out for the purpose of direct marketing, including postal contact, you have the right to object at any time and without giving reasons; the data will then no longer be processed for these purposes.

The objection can be submitted informally to the data protection contact.

16. Right to Lodge a Complaint

Data subjects may lodge a complaint with the competent data protection supervisory authority. For Austria, this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at.

17. Required Data and Consequences of Non-Provision

Certain data is necessary for account creation, performance of a contract, bookings, payments, security and legal records. Without the required information, individual functions or the conclusion of a contract cannot be provided.

18. Automated Decisions and Profiling

There is no exclusively automated decision-making with legal effect or similarly significant impact. Should such procedures be introduced later, this policy will be updated beforehand.

19. Account Deletion and Anonymization

Upon account deletion, personal account data is deleted, anonymized or unlinked in accordance with legal obligations and technical dependencies. Legal events as well as booking, payment, billing and record data may be retained insofar as this is necessary to comply with statutory retention obligations, for dispute resolution, for security, or to safeguard legitimate record-keeping interests.

20. Data Protection Requests

Requests regarding data subject rights can be submitted via the data protection contact or the support contact. We respond to requests within the statutory period of one month.

21. Governing Language Version

This privacy policy is provided in German and English. In case of doubt or discrepancies in interpretation, the German version prevails.