Elio

Privacy

Last updated: 4 October 2026

Who is responsible

Elio Technologies FlexCo, Schönbrunner Straße 81/2/6, 1050 Vienna, Austria ("Elio", "we") is the controller for the processing described here. You can reach us at hello@elio.earth.

Visiting this website

The site is hosted on AWS Amplify Hosting, provided by Amazon Web Services, Inc. (USA). Pages are delivered through Amazon CloudFront, and the forms on this site are received by an AWS Lambda function; both run in the AWS region US East (N. Virginia), USA. When you visit the site, the servers process technical data your browser sends, such as your IP address, the time of the request, the page requested and your browser type, so the page can be delivered and the service kept secure. AWS keeps these request logs as part of the hosting service; we retrieve them only to investigate security issues. The legal basis is our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).

AWS processes this data on our behalf under its data processing addendum (Art. 28 GDPR). Transfers to the USA are covered by the EU–US Data Privacy Framework, under which Amazon is certified, and by the EU standard contractual clauses included in that addendum (Art. 45 and 46 GDPR). Our server logs, including any form request saved there because our database couldn't be reached (see below), are deleted after one year.

Our fonts are served by Adobe Fonts. To display them, your browser connects to Adobe's servers, which receive your IP address. Adobe Fonts sets no cookies. The legal basis is our legitimate interest in a consistent presentation of the site (Art. 6(1)(f) GDPR). For details, see Adobe's privacy policy for Adobe Fonts.

We use no marketing or advertising cookies. With your consent, we use analytics to improve the site (see Analytics below). Without your consent, nothing is stored in your browser except your privacy choice itself: we save whether you accepted or rejected analytics, the date, and the version of this notice in your browser's local storage under the name elio-consent, so we don't ask again on every page. This is strictly necessary to respect your choice (§ 165(3) TKG 2021). It is not sent to us, and it is kept for 12 months, after which we ask again.

Error monitoring

To keep the site secure and working, we record technical errors that occur in your browser while you use it: the error message and where in the site's code it occurred, the page, your browser, operating system and device type, and a random ID that is not stored and changes with every page you open. Your IP address is processed in transit to deliver this data and is not stored. Error reports contain no form contents, and nothing is stored on your device for this purpose: no cookies and no local storage. The legal basis is our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR).

Error data is processed on our behalf by PostHog on its EU Cloud (see Analytics below for details on PostHog) and kept for up to seven years, after which it is deleted.

Analytics (PostHog)

Purpose. With your consent, we collect usage statistics and session replays to understand how visitors use this site, for example which pages are read and where navigation is unclear, so we can improve its content and design. We do not use this data for marketing or advertising, do not combine it with data from other websites, and do not use it to make decisions about you.

Legal basis. Your consent (Art. 6(1)(a) GDPR and § 165(3) TKG 2021). Analytics start only after you accept them, in the banner or in Privacy settings. If you reject them or make no choice, no usage statistics or session replays are collected.

Usage statistics. Pages visited, the referring page, clicks on links and buttons, the time and length of the visit, device type, browser, operating system, screen size and approximate location (country and city) derived from your IP address. Your IP address itself is discarded and not stored. Each browser is given a random ID so that visits can be counted. It is not linked to your name or email address.

Session replays. A replay shows how a page was used: the page layout, scrolling, mouse movements and clicks. Anything typed into form fields is hidden, and the contents of our forms, including compound lists, are excluded entirely. Replays contain no console output and no network request contents.

Cookies and storage in your browser. With your consent, PostHog stores the random ID and session information in a first-party cookie and in your browser's local storage, both named ph_<project key>_posthog, and information about the current tab in session storage, which is cleared when you close the tab. These are removed when you withdraw consent, and at the latest after 12 months, when your consent expires.

Processor. The data is processed on our behalf by PostHog Inc. (USA) on its EU Cloud, hosted in Frankfurt, Germany, under a data processing agreement (Art. 28 GDPR). PostHog is a US company, so access from the USA is possible in exceptional cases, for example for support. Such transfers are covered by the EU standard contractual clauses (Art. 46 GDPR).

Retention. Usage statistics are kept for up to seven years and session replays for up to 90 days; after that they are deleted. IP addresses are not stored.

Withdrawing consent. You can withdraw your consent at any time, as easily as you gave it, with Privacy settings in the footer of every page or the button below. Withdrawal stops analytics immediately and removes PostHog's data from your browser. It does not affect processing that took place before.

Booking a call

When you book a call, our booking form collects your name, work email, what you would like to talk about (PCF data, the ecodesign app, or something else) and anything you add about your use case, and the booking calendar collects the time you choose. We use this to prepare and hold the call and to follow up on your request (Art. 6(1)(b) GDPR, steps prior to a contract). Your compound list stays strictly confidential.

The booking calendar is provided by Cal.com, Inc. (USA). It is loaded on our pages only after you click “Pick a time”, and it is prefilled with the name and email you entered. Transfers to the USA are covered by the EU–US Data Privacy Framework, under which Cal.com is certified, and by standard contractual clauses (Art. 45 and 46 GDPR). Cal.com keeps booking details while our account with it is active. The time of your call is also added to your request in our records (see below).

Chemical check and whitepaper requests

When you send us your compound list through the “Check your chemicals” form, or request our whitepaper, we process the details you enter (name, work email, anything you add about your use case, and for the chemical check your compound list) to answer your request and, for the whitepaper, to send it to you (Art. 6(1)(b) GDPR). Your compound list stays strictly confidential. A compound list you enter on the homepage is kept only in your browser's session storage until it is added to the form, and is never sent in a web address.

Submissions are received by our own server on AWS (see Visiting this website) and stored in Notion, provided by Notion Labs, Inc. (USA), under its data processing addendum (Art. 28 GDPR). Transfers to the USA are covered by the EU–US Data Privacy Framework, under which Notion is certified, and by the EU standard contractual clauses included in that addendum (Art. 45 and 46 GDPR). The anti-spam check (ALTCHA) runs on our own server, with no third party and no cookies. Anything you send later, such as chemicals added after your first request or the time of a booked call, is added to the same record. If our database can't be reached when you submit, your request is kept in our server log on AWS instead, so it isn't lost, and entered into the database by hand.

We keep your request for as long as we need it to answer you and for any business relationship that follows, and delete it when it's no longer needed or when you ask us to.

Contacting us by email

If you email us, we process your message and contact details to answer you (Art. 6(1)(b) or (f) GDPR). We keep this correspondence only as long as needed for your request and any legal retention obligations.

LinkedIn

We link to our LinkedIn page. This is a plain link: nothing is loaded from LinkedIn until you follow it. If you visit LinkedIn, its own privacy policy applies.

How long we keep data

We keep personal data only as long as it is needed for the purposes above, or as long as the law requires us to keep it (for example, tax retention periods for business correspondence).

Your rights

You have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to data portability (Art. 15–21 GDPR). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). To exercise these rights, email us at hello@elio.earth.

You also have the right to lodge a complaint with a supervisory authority. In Austria, this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna (dsb.gv.at).