Pursuant to the GDPR (EU) 2016/679 · Last updated: July 2026
This page has every section a privacy policy is supposed to have. We just refuse to pad any of them with the vague language that usually fills them, because we spend our working hours pointing out exactly that vague language in other people's apps. So: full sections, plain claims, and where a claim is checkable, we tell you how to check it.
RFI-IRFOS (Research Focus Institute — Interdisciplinary Research Facility for Open Sciences)
Elisabethinergasse 25/10, 8020 Graz, Austria
E-Mail: rfi.irfos@gmail.com
Server logs: IP address, access timestamp, URL, HTTP status code — collected by GitHub Pages (GitHub, Inc., USA) and Fly.io (Superfly, Inc., USA) as an unavoidable side effect of any request reaching a web server anywhere.
Contact form: name, email, subject, message — submitted via Web3Forms (web3forms.com/privacy), only if you fill it in and press send.
Payment data: for purchases made through the website, payment data (card details, email, name) is processed by Stripe, Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA). RFI-IRFOS never receives or stores your card data. Stripe's privacy policy: stripe.com/privacy.
Visit statistics: one self-hosted tracking pixel (Lighthouse, Graz) that logs a page view and a referrer, on every page including this one. On this legal/security page family specifically, we also log, in aggregate only, whether a visit scrolled all the way to the footer at the bottom of the page, the same in-memory, no-cookie mechanism as the section counters described in "Cookies" below, applied here to answer one question: are these pages actually being read to the end. On the homepage specifically, we also log, once per visit and in aggregate only, whether your browser's developer tools appear to be open (a passive window-size check, no timing tricks) — this exists purely because we left a message in the console for anyone who looks, and we're curious how often anyone actually does. No cookie, no device fingerprint, no cross-site identifier. See "Cookies" below for the unglamorous truth about what that pixel actually is.
What we do not collect, for the avoidance of doubt: no location data, no device fingerprinting, no advertising ID, no biometric data, no cross-site profile, nothing sold or shared with a data broker, nothing handed to an ad network, because there is no ad network on the other end of anything on this site.
Performance of a contract (Art. 6(1)(b) GDPR): payment processing, contact inquiries.
Legitimate interest (Art. 6(1)(f) GDPR): server logs for security and error analysis, and the single anonymized page-view pixel described above.
Stripe, Inc. — payment processing. Data Processing Agreement (DPA) concluded pursuant to Art. 28 GDPR. Data transferred to the USA on the basis of Standard Contractual Clauses (Art. 46(2)(c) GDPR).
GitHub, Inc. — frontend hosting (GitHub Pages). Data transferred to the USA on the basis of Standard Contractual Clauses.
Superfly, Inc. (Fly.io) — backend API hosting, including the Lighthouse tracking pixel endpoint. Data transferred to the USA on the basis of Standard Contractual Clauses.
Web3Forms — contact form delivery only, invoked only when you submit the form.
Where a processor above is US-based, the transfer runs on Standard Contractual Clauses (Art. 46(2)(c) GDPR) rather than an adequacy decision. We list this plainly rather than burying it in a "may transfer data internationally" clause, because that phrase is doing a lot of quiet work on most privacy pages.
We don't use cookies. Here is the part every privacy policy is expected to have, done as an actual answer instead of a checkbox. The standard four categories, quoted the way they usually get phrased, and our real answer underneath each one:
"Strictly necessary cookies, required for the website to function and cannot be switched off."
We have none. Open your browser's dev tools, Application tab, Cookies, on this exact page, right now. It will be empty. Nothing is being "switched off" because nothing was ever switched on.
"Functional cookies, used to remember your preferences."
We do let you pick a light, dark, or high-contrast theme and a language, and we do remember that choice, in localStorage, not a cookie. It never leaves your device, carries no identifier, and is not readable by us.
"Performance / analytics cookies, used to understand how visitors use our site."
This is usually where the actual tracking lives, and this is usually the one place a privacy policy goes vague. We won't. This site loads a single 1×1 pixel image, self-hosted, no cookie, no consent needed for it because a cookie-consent requirement (ePrivacy Art. 5(3)) attaches to storing or reading something on your device, and this pixel never does either. Each page load sends exactly this, the literal tag that is live on this page right now, copy it and inspect it yourself:
<img src="https://lighthouse-rfi-irfos.fly.dev/lighthouse/api/track/pixel.gif?site=rfi-irfos&p={page-path}&r={referrer}&utm_source={utm}" width="1" height="1" alt="" style="display:none">What lands in our database from that request: the page path, the referring domain normalized into a channel bucket ("organic search", "direct", "referral", "linkedin", and so on, so we can tell a board member where visitors come from), and the site tag. That's it, in full: path, source, referrer, utm_source, utm_medium, utm_campaign, site. No IP address column exists in that table. No visitor-ID field is ever populated by this site's copy of the pixel, so two visits from the same person land as two independent, unlinked rows, not one growing profile. Full source, backend included: github.com/rfi-irfos/rfi-irfos-web. We are not asking you to trust a sentence, we are pointing at the code that either does or doesn't match it.
One more signal lands the same way: which section of this single-scrolling-page site came into view during your visit (the disclosure ledger, pricing, the tip-submission form, and so on), stored as one more anonymous section column on the same table. This is a hit-counter, not a viewer log — "the ledger section was seen 214 times today," never "visitor X looked at the ledger." The page keeps a plain JavaScript variable in memory so scrolling up and down past a section doesn't count it twice; that variable is never written to a cookie, localStorage, or sessionStorage, and is gone the instant the page reloads. Same reasoning as the pixel above: nothing is stored on your device, so the ePrivacy consent trigger never applies, and nothing here identifies you, so it isn't personal data to begin with.
"Targeting / advertising cookies, used to build a profile of your interests."
We run no ads, have no ad account, and have nothing to target you with even if we wanted to. There is no third party on the other side of this site who would pay for that profile.
We could have shipped a cookie banner with a satisfying "Accept All" button anyway, because everyone expects one. We didn't, because a consent banner implies a decision is being made on your behalf, and there isn't one here to make. If that ever changes, this section changes with it, publicly, in the same commit history as everything else on this site.
None. We do not use profiling or automated decision-making that produces legal or similarly significant effects on you.
Contact inquiries are deleted once communication concludes, at the latest after 7 years per Austrian statutory retention rules. Payment receipts are retained for 7 years pursuant to § 132 BAO (Federal Fiscal Code). Server logs and pixel data are retained only as long as needed for security and traffic analysis, then rotated out.
This is a B2B research and disclosure site. It is not directed at children, and we do not knowingly collect data from anyone below the age required for consent under Art. 8 GDPR.
Access, rectification, erasure, restriction, data portability, and objection, all of it, at: rfi.irfos@gmail.com. Given what little we actually hold on any one person, most of these requests take us minutes, not weeks, to resolve.
Austrian Data Protection Authority (Datenschutzbehörde): dsb.gv.at
Any change to what we actually collect gets reflected here first, with the "last updated" date above moved forward. We track changes to this page the same way we would expect anyone else to.
We spend our research auditing other companies for exactly this kind of policy. This one describes what actually happens on this site, in the same evidence-first spirit — nothing here is aspirational, and the parts that are checkable are checkable by you, not just by us.