Privacy
Protecting your data matters to us. This privacy notice explains which personal data we process on kreditdirekt.at and within our platform, for which purposes and on which legal basis, who receives that data, how long we store it and which rights you have.
KreditDirekt is a platform for the brokerage of residential property financing in Austria. The brokerage is carried out by a non-tied credit intermediary. In doing so we provide no advisory services within the meaning of § 8 (6) HIKrG; we prepare your financing enquiry, review it and submit it to credit institutions.
1. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
- FA – FinanzAktiv e.U., owner Christian Kunz, MBA
- Address: Getreidegasse 3, 9020 Klagenfurt am Wörthersee, Austria
- E-Mail: office@kreditdirekt.at
- Commercial register number: FN 322235 a, commercial register court: Landesgericht Klagenfurt
- VAT ID: ATU66310066
- GISA number: 10720516 — the entry is available online in the Austrian trade information system (gisa.gv.at)
- Trade licence: Gewerbliche Vermögensberatung (commercial financial services under § 94 Z 75 GewO) with the authorisations to broker life and accident insurance as an insurance agent; brokerage of personal and mortgage loans as a non-tied credit intermediary
- Supervisory authority: Magistrat der Stadt Klagenfurt
FA – FinanzAktiv e.U. alone determines the purposes and means of the processing. The technical development and technical operation of the platform are outsourced; the technology provider acts solely on our instructions as a processor (see section 4).
Data protection officer
No data protection officer has been appointed. Given the nature and scope of our processing operations, there is no obligation to do so under Art. 37 (1) GDPR.
For any question concerning data protection you can reach us at office@kreditdirekt.at.
2. Principles and scope
This privacy notice applies to the website kreditdirekt.at, to the financing funnel, to the customer account including the document centre and to the AI assistant of the platform.
We follow these principles:
- Data minimisation: We collect only what is necessary for the step at hand. You can use the public loan calculator and obtain a first estimate without creating an account.
- Processing in the EU: The platform, the database and the document storage are operated exclusively within the European Union. Two processing operations may go beyond that — the AI service and, only with your consent, web analytics; both are described in sections 5 and 3.15.
- A human decides: Our AI prepares your case, structures it and shows the calculation transparently. It does not assess, does not recommend and makes no commitments. Every decision about your case is taken by a human being (see section 6).
- No real data in test environments: Development and test environments use synthetic data only.
3. The individual processing operations
The following description follows the processing activities in our record under Art. 30 GDPR. For each operation you will find the purpose, the legal basis, the categories of data, the recipients and the retention period.
3.1 Operation and security of the website
- Purpose: Provision and stability of the website, defence against misuse and attacks (among other things rate limiting and protection against request forgery).
- Data: IP address, browser and device identifier (user agent), timestamp, the address requested and technical metadata of the request.
- Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure and uninterrupted operation of the platform and in the defence against attacks and automated misuse.
- Recipients: Hetzner (hosting, EU).
- Retention: Server and security logs 30 to 90 days. Access logs are stripped of sensitive components (among other things access tokens).
3.2 Customer account and registration
- Purpose: Setting up and operating your access, allocating your data, signing in and restoring access.
- Data: Name, e-mail address, telephone number, sign-in data. Name and telephone number are additionally encrypted field by field in the database.
- Legal basis: Art. 6 (1) (b) GDPR (use of the platform and initiation of the brokerage).
- Recipients: Hetzner (hosting, EU); confirmation and system messages are sent via our e-mail service provider.
- Retention: An account without any financing case and without activity is deleted after 6 months. Where a case exists, the account remains for as long as the case does; after that the same period applies, counted from your last account activity (see section 7).
3.3 AI assistant, needs assessment and financing check
- Purpose: Recording your financing request in a dialogue, answering factual questions, guiding you through the process, preparing the personal preliminary conversation.
- Data: Your free-text entries in the chat, details of your financing project (property, purchase price, own funds, desired term), details of income and household, the course of the conversation.
- Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures at your request). We deliberately do not rely on consent here, because the dialogue is the very service you asked for. Where you use the assistant anonymously and no reference to a person arises, no processing of personal data takes place.
- Labelling: You are visibly communicating with an AI system. This notice is permanently displayed in the interface (transparency obligation under Art. 50 of Regulation (EU) 2024/1689 on artificial intelligence).
- Recipients: OpenAI Ireland Ltd. as a processor for language processing (no storage of your contents at the provider, no training on your data); Hetzner (storage of the history). Where the contents are processed, and which data a third country reference may affect, is set out in section 5.
- Retention: Anonymous conversations without an assigned case are deleted after 72 hours. Conversation histories of short-lived cases (non-binding enquiry, abandoned process, case ended early without a personal conversation) are deleted after 90 days. Histories of ongoing and brokered cases are kept for seven years from the completion of the brokerage — the same period as the conversation and brokerage record they form part of (see section 7).
- Please note: Do not enter health data or other special categories of personal data in the chat. We do not ask for such data, do not need it and do not transfer it into structured fields (see section 3.13).
3.4 Document upload and AI-assisted extraction
- Purpose: Collecting the documents required for the financing, automatically classifying the document type and reading out the values needed, so that you do not have to enter them manually. The extracted values are shown to you and to the reviewing person for correction.
- Data: Proof of income, bank statements, loan and leasing agreements, purchase contract or purchase offer, land register extract, property documents and — where the receiving credit institution requires it — identity documents.
- Legal basis: Art. 6 (1) (b) GDPR. The necessity is documented for each document type; documents the institution does not need are not requested.
- Identity data: Identity documents are not special categories of personal data within the meaning of Art. 9 GDPR: a photograph only becomes biometric data once it is processed for the purpose of uniquely identifying a person by technical means (Art. 4 (14), recital 51) — we carry out no biometric analysis. Nationality on its own is likewise not a statement about racial or ethnic origin. We nevertheless treat this data with particular care: identity data is additionally encrypted at application level.
- Security checks: Every upload passes through a chain of checks (size, actual file type, virus scan, sanitisation of the document). If any stage fails, the upload is rejected and not stored.
- Recipients: Hetzner (encrypted object storage in the EU); OpenAI Ireland Ltd. for reading the contents (handed over solely during the processing operation, no storage at the provider; see section 5); credit institutions upon submission (see section 3.6).
- Retention: 6 months where no brokerage comes about. After completion separate periods apply: copies of identity documents and the identity data read from them are deleted 30 days after the loan approval or the final completion of your case — the copy itself, the document number and the remaining pure identity-document details; all that remains is the note that, and how, the identity check took place. Your application data — name, date of birth, address and IBAN — is not affected: it is part of the case itself and of the record of the submission sent to the bank, and therefore follows the period of the core records. The remaining documents and the personal raw values read from them are deleted 2 years after completion; the values derived from them — in particular the household calculation with its calculation path — are kept for 7 years (see section 7). When a case is deleted, the associated files in storage are removed as well.
3.5 Household calculation and affordability pre-check
- Purpose: A transparent calculation of the instalment your household can carry, and preparation of the submission.
- Data: Income, expenses, existing liabilities, household size, assets.
- Legal basis: Art. 6 (1) (b) GDPR.
- How it works: The calculation is deterministic and rule-based — it follows fixed calculation rules, not an estimate made by the AI. The complete calculation path is stored, so that it can be traced at any time which of your entries led to which result. No score is created and no automatic rejection takes place: nobody is filtered out by the system or excluded from the further process without human review (see section 6).
- Recipients: none external — the calculation takes place exclusively on our systems at Hetzner; no AI service is used for it.
- Retention: 7 years from the completion of the brokerage — the stored calculation path is the evidence of how we calculated (see section 7).
- Impact assessment: For our processing operations likely to result in a high risk — this one among them — we have carried out a data protection impact assessment under Art. 35 GDPR and keep it up to date.
3.6 Selection of credit institutions and transmission of your documents
- Purpose: The core of the brokerage you commissioned — submitting your financing enquiry to suitable credit institutions.
- Data: the complete financing file (self-disclosure, household calculation, property data, the documents you provided).
- Legal basis: Art. 6 (1) (b) GDPR — without this transmission the brokerage cannot be carried out.
- Recipients — please note in particular: Your documents are transmitted to credit institutions in Austria (our submission circle currently comprises around 22 institutions with a focus on Carinthia). Your data goes only to those credit institutions we select for your specific case — never to all partner banks. We will provide an up-to-date list of these partner banks on request and shortly on this website as well. With individual credit institutions the submission is made through a brokerage partner who forwards your data solely on our behalf and on our instructions to the credit institution we have determined. For any further processing the institutions are controllers in their own right and apply their own data protection terms. Before submission you are informed which institutions will receive your documents, and the selection is agreed with you.
- Selection of the institutions: The pre-selection is rule-based and follows factual criteria (such as property type, federal province, loan-to-value, product types) — without a score and without any AI assessment. The final decision is taken by the responsible person.
- Transmission route: Submission is made by e-mail to the respective institution, supplemented by an access-protected, time-limited retrieval route for the documents.
- Retention: The record of which institutions received which documents and when is kept for 7 years from the completion of the brokerage — only that allows us to name the specific recipient banks on request. The documents themselves are subject to the periods set out in section 3.4 (see section 7).
3.7 Review and approval, brokerage documentation, ESIS
- Purpose: Substantive review of your case by the responsible person, review of the credit institution's European Standardised Information Sheet (ESIS) under the Austrian Mortgage and Real Estate Credit Act against the offer obtained and calculated for you, including documentation of any differences found, documentation of the procedure, settlement of the brokerage fee.
- Data: the entire case, the ESIS sheet and our review and difference documentation relating to it, the conversation and brokerage record, details of the remuneration.
- Legal basis: Art. 6 (1) (b) GDPR (performance of the brokerage) and Art. 6 (1) (c) GDPR (legal obligations under the Mortgage and Real Estate Credit Act and under the professional rules for credit brokerage, BGBl. II No. 86/2016).
- Note on preparation: As a rule you receive the ESIS sheet from the credit institution, together with the offer obtained for you; our platform is able to produce a sheet of its own but does not currently do so. Legally effective documents such as the ESIS are, where we produce them, generated from fixed templates with calculated values; they are not freely worded by an AI.
- Recipients: Hetzner (EU). Delivery to you via our e-mail service provider or via your document centre.
- Retention: 7 years from the completion of the brokerage for the conversation and brokerage record, the ESIS and the remuneration details. Documents and conversation histories have their own, shorter periods (see section 7).
3.8 Video conversation with recording (optional)
- Purpose: Holding the personal preliminary conversation by video and — only if you expressly agree — recording it and producing a transcript from which points of the conversation are pre-filled into the record.
- Data: Audio or video recording, transcript, the conversation points derived from it together with their references.
- Legal basis: Art. 6 (1) (a) GDPR — your consent. Without your consent no recording takes place; the conversation is possible without a recording. Your consent is documented with the text version and a timestamp and can be withdrawn at any time with effect for the future.
- Recipients: a provider for converting speech to text which carries out the processing within the EU and with whom a data processing agreement will be concluded before the function is enabled.
- Retention: the periods applicable to the respective type of data (see section 7).
- Note: This function is currently not active; it will only be taken into operation once it is enabled. We will then name the provider used at this point.
3.9 Newsletter and information about our services
This processing operation is not active yet; it will only start when the newsletter launches.
- Purpose: Sending information on financing topics and on our services.
- Data: E-mail address, form of address/name, stated interests, time of registration, proof of confirmation.
- Legal basis: Art. 6 (1) (a) GDPR — your consent, which we obtain in a double opt-in procedure. The consent can be withdrawn at any time, for example via the unsubscribe link in every message.
- Retention: until withdrawal. After a withdrawal we store a suppression list (an encrypted checksum of your e-mail address) so that you receive no further messages; the legal basis for this is Art. 6 (1) (c) or (f) GDPR (observing your objection).
3.10 Reach measurement and technical monitoring
- Purpose: Understanding where our process is abandoned and how long individual steps take, in order to improve the platform; detecting technical errors and performance problems.
- Data (our own funnel counter): For each process step your browser sends exactly two codes — the step code and an outcome code (entered, completed, exited). No cookie, no identifier, no access to information on your device, no reading of device information. On our server we derive a non-reversible checksum (SHA-256) from the IP address transmitted in any case, a secret key and a coarse time window (two hours), so that the steps of one session can roughly be held together; the IP address itself is not stored. From the language setting your browser sends in any case we additionally record in which language the step was displayed. No names, no e-mail addresses, no financial amounts. For error monitoring, personal components are technically stripped from the reports (request data, cookies, sign-in data, financial fields).
- Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in designing the platform to suit actual needs and in keeping it technically free of errors. Since the funnel counter neither stores information on your device nor reads it from there — your browser only sends the two codes — in our assessment no consent under § 165 (3) TKG 2021 is required (see section 8). Consent-based web analytics is governed by section 3.15.
- Recipients: none external — the funnel counter runs on our own systems at Hetzner (EU); error monitoring runs on our own server in the EU (a self-hosted installation, no external service provider). Analyses with a sensitive reference (for example to chat contents) remain exclusively on our own systems.
- Retention: Funnel event data up to 24 months, aggregate values as long as necessary.
- Objection: You can object to this processing under Art. 21 GDPR (see section 9).
- Note: The funnel counter and the technical error monitoring on our own server are running.
3.11 Logging and evidence
- Purpose: Meeting our accountability obligation under Art. 5 (2) GDPR, evidencing the human review steps, evidencing status changes, access to documents and conversation histories, and every deletion run.
- Data: User identifier, event codes, text version and timestamp of consents. The log is free of personal data in plain text (technically enforced: only short codes and identifiers, no free text), it is only appended to and never altered, and it is secured against subsequent manipulation by a cryptographic chain.
- For consents we additionally store the IP address as a means of evidence.
- Legal basis: Art. 6 (1) (c) GDPR (evidence obligations under the GDPR) and Art. 6 (1) (f) GDPR (securing evidence, security).
- Retention: The IP address belonging to a consent is removed after 365 days, the record of consent itself remains. The log itself has no separate retention period: it contains no personal data in clear text, only short codes and identifiers. When data is deleted the corresponding entries go with it; identifiers and counters without any substantive reference remain, and the cryptographic verification chain is re-anchored — which is precisely the evidence that deletion took place.
3.12 Withdrawal from contracts via the withdrawal button
- Purpose: Receiving and evidencing contract withdrawals via the statutory withdrawal button, immediate electronic confirmation of receipt to you, and processing the withdrawal.
- Data: Name, e-mail address, time of receipt, optionally the date the contract was concluded, a contract or case reference and a free-text message.
- Legal basis: Art. 6 (1) (c) GDPR (legal obligation under § 13a FAGG as amended by the VerbRÄG 2026 — receiving and confirming the withdrawal) in conjunction with Art. 6 (1) (b) GDPR (unwinding the withdrawn contract).
- Access is deliberately possible without signing in, so that you can declare the withdrawal at any time. The record is therefore not linked to your case.
- Recipients: internal (the responsible person, internal notification) and the e-mail address you provide (confirmation of receipt).
- Retention: 3 years from the completion of processing including the unwinding of the contract. In a dispute the record is the evidence that your withdrawal was in time; after that it is deleted. If a dispute about the withdrawal is pending, we exempt the record from deletion until that dispute is resolved (see section 7).
3.13 Special categories of personal data (Art. 9 GDPR)
We collect no special categories of personal data. Details of income, assets and liabilities are highly sensitive, but they do not fall under Art. 9 GDPR.
Health-related details could theoretically arise in two ways: through health questions relating to residual debt or term life insurance, and through free entries in the chat. We deliberately avoid both: we do not run an insurance application procedure on this platform; the AI assistant does not ask for health data; entries made inadvertently are not transferred into structured fields and are not processed further. On the classification of identity documents see section 3.4.
3.14 Contact and call-back service
- Purpose: Answering your enquiry, arranging a call-back.
- Data: Name, e-mail address, telephone number, the content of your enquiry, the preferred time window.
- Legal basis: Art. 6 (1) (b) GDPR where your enquiry concerns the initiation of the brokerage; otherwise Art. 6 (1) (f) GDPR (interest in answering enquiries).
- Retention: until your enquiry has been dealt with; if the enquiry leads to a case, the periods applicable to the respective type of data apply (see section 7).
3.15 Web analytics with Google Analytics 4 (only with your consent)
This processing takes place only if you have given your consent in the consent banner. Without your consent no Google service is loaded, no data is transmitted to Google and no identifiers are stored on or read from your device.
- Purpose: Analysing the use of our website (pages viewed, time spent, approximate region, device class) in order to improve content and campaigns.
- Data: an identifier assigned by Google, your IP address (used by Google only for coarse location and not stored as a data field), details of browser and device, the pages viewed and the events triggered. No names, no financial amounts, no contents of your documents.
- Legal basis: Art. 6 (1) (a) GDPR — your consent; for storing and reading information on your device additionally § 165 (3) TKG 2021.
- Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and its parent company Google LLC, United States.
- Third country transfer: Processing in the United States is possible. It is based on the adequacy decision of the European Commission on the EU-US Data Privacy Framework for as long as the recipient is certified under it; otherwise on the standard contractual clauses of the European Commission (Art. 46 (2) (c) GDPR). You can obtain a copy of these safeguards on request at office@kreditdirekt.at.
- Retention: Google retains the event data for at most 14 months. Your consent decision itself is stored in your browser with the text version and a timestamp and does not leave your device.
- Withdrawal: You can withdraw your consent at any time with effect for the future — via the “Cookie settings” link in the footer of our website, for example on the home page. The service is then no longer loaded.
- Note: As long as we have not enabled Google Analytics 4, this processing does not take place even where consent has been given.
4. Recipients of your data
Your data is passed on only to the following bodies:
- Hetzner Online GmbH — processor, EU (Nuremberg, Falkenstein): hosting of the application, database, document storage, encrypted backups.
- FPC GmbH, Bahnhofstraße 24/2, 9020 Klagenfurt am Wörthersee — processor, Austria: technical development, technical operation and maintenance of the platform, strictly on our instructions.
- OpenAI Ireland Ltd., Dublin, Ireland — processor: language processing for the AI assistant and for reading documents; no storage of the contents at the provider, no training on your data. On the place of processing and the third country reference see section 5.
- Credit institutions (the banks selected for your specific case — never all partner banks) — controllers in their own right, Austria/EU: reviewing your financing enquiry after submission.
- Brokerage partner for submitting financing enquiries — processor, Austria: with individual credit institutions the submission is made through a brokerage partner who forwards your data solely on our behalf and on our instructions to the credit institution we have determined.
- World4You Internet Services GmbH — processor, Austria: sending system, status and submission messages by e-mail.
- Google Ireland Limited (and its parent company Google LLC, United States) — only where consent has been given: web analytics with Google Analytics 4 (see section 3.15).
- Error monitoring — no external recipient, EU: detection of technical errors; the installation runs on our own server.
- Steuerberatung (tax accountancy), legal representation, public authorities — controllers in their own right, Austria: where required by law or necessary to pursue legal claims.
We conclude data processing agreements under Art. 28 GDPR with our processors.
5. Processing outside the EU
Your application data and your documents remain within the European Union. Hosting, database, document storage, e-mail dispatch, the funnel counter and monitoring all take place within the EU. Two processing operations may go beyond that: the AI service (below) and — only with your consent — web analytics (section 3.15).
AI processing: For the AI assistant and for reading documents we use OpenAI; our contractual partner and the recipient is OpenAI Ireland Ltd. A data processing agreement under Art. 28 GDPR is in place.
- The contents of your requests — your chat messages and the contents of your documents — are processed in the Europe region as soon as that processing has been set up for our account. We will only enable the AI functions once processing in Europe is set up; until then they remain switched off.
- Your contents are not stored at the provider and are not used to train models.
- Account, usage, billing and support data — the data arising from the operation of our access — are excluded from the regional commitment and may be processed by OpenAI in the United States. Your application data and your documents are not part of that.
Group context: Our contractual partners are companies established in the EU that belong to groups whose parent companies are in the United States. Access from a third country — for instance in the course of administration or support — cannot be entirely excluded by the choice of location alone.
Basis for transfers to the United States: Where such transfers occur, they are based on the adequacy decision of the European Commission on the EU-US Data Privacy Framework for as long as the respective recipient is certified under it, and otherwise on the standard contractual clauses of the European Commission (Art. 46 (2) (c) GDPR), which form part of the respective data processing agreement. You can obtain a copy of these safeguards on request at office@kreditdirekt.at.
6. Use of artificial intelligence — and why we do not decide automatically
Where AI is used: in the assistant (dialogue, factual information, recording your project), in classifying and reading uploaded documents, in summarising conversations and in producing text modules for internal summaries.
Where no AI is used: in the household calculation (fixed calculation rules with a stored calculation path), in the pre-selection of credit institutions (rule-based), and in legally effective documents such as the ESIS (templates with calculated values, where we produce them — as a rule the sheet comes from the credit institution).
Labelling: The AI assistant is labelled as such, as provided for by Art. 50 of Regulation (EU) 2024/1689 on artificial intelligence.
No automated decision in an individual case (Art. 22 GDPR): There is no decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. In concrete terms this means:
- No score is formed about you.
- No automatic filtering out takes place — nobody is rejected by the system or excluded from the further process.
- Every case is reviewed on the merits by a responsible person who may depart from the system's output and whose review steps are logged.
- The AI produces no assessment, no recommendation and no commitment.
- The decision on granting the loan is taken solely by the respective credit institution according to its own criteria.
Right to an explanation: You can ask us at any time to explain how your details fed into the pre-check. Because the calculation path is stored in full, we can show you in a comprehensible way which item of income and which expense led to which intermediate and final result.
7. How long we store your data
We delete personal data as soon as the purpose has ceased to apply and no statutory retention obligation stands in the way. Deletion is carried out automatically by regular deletion runs; every run is logged.
- Anonymous chat conversation without an assigned case: 72 hours
- Non-binding enquiry that was not pursued (status: draft): 90 days from your last activity
- Conversation history of short-lived cases: 90 days
- Abandoned financing process before submission: 6 months from your last activity
- Case ended early without a personal conversation: 6 months from your last activity
- Uploaded documents where no brokerage came about: 6 months
- Conversation history of an ongoing or brokered case: 7 years from the completion of the brokerage — the same period as the conversation and brokerage record; individual passages that the responsible person transfers to that record as relevant to the decision remain part of it
- Copies of identity documents and the identity data read from them (document number and the remaining pure identity-document details): 30 days after the loan approval or the final completion of the case — the note on the identity check remains, as does the application data (name, date of birth, address, IBAN) as part of the core records
- Remaining uploaded documents after completion (proof of income, bank statements, purchase contract, land register extract) together with the personal raw values read from them: 2 years
- Liability-relevant core records — conversation and brokerage record, ESIS, notices, records of consent, proof that the bank submission was sent, proof that co-applicants were informed, and the household calculation with its calculation path: 7 years from the completion of the brokerage — based on our documentation duties under the Mortgage and Real Estate Credit Act and the professional rules, and on our legitimate interest in defending legal claims
- Customer account: at the latest 6 months after your last account activity, once no case is attached to your account any more
- Expired sign-in and confirmation artefacts: 24 hours after expiry
- Records of consent: for as long as the core records of the associated case, at most until your customer account is deleted; the IP address belonging to a consent is removed after 365 days
- Event data of the reach measurement: up to 24 months
- Server and security logs: 30 to 90 days
- Withdrawal records (§ 13a FAGG): 3 years from the completion of processing including the unwinding of the contract
- Log of our accountability duties (section 3.11): no separate period — it contains no personal data in clear text, only short codes and identifiers; when data is deleted its verification chain is re-anchored
Tax-relevant records (commission statements, invoices, proof of payment) are not stored in this platform; they arise in the broker's own accounts and are subject there to § 132 BAO — seven years from the end of the calendar year to which the record relates.
What “your last activity” means: For the short retention periods only an action by you counts — a document upload, a message from you or a contribution from you in the chat. Merely signing in does not extend these case periods (for your customer account itself, signing in does count as activity). A message from us to you and an answer from the AI assistant do not extend the retention period. We deliberately set it up this way so that the storage period cannot be extended at will by our own actions (Art. 5 (1) (e) GDPR). For the seven-year period, by contrast, the anchor is the completion of the case; it is not extended by later access.
Deletion despite a retention obligation: If you request deletion before a brokerage has come about, we delete in full. If the brokerage has already taken place, we may not delete the liability-relevant core records — they are subject to our documentation duties under the Mortgage and Real Estate Credit Act and the professional rules and to our legitimate interest in defending legal claims; everything else we delete according to the periods set out above in this section. For those core records we restrict the data (restriction of processing, Art. 18 GDPR): it is kept for evidentiary purposes only, is no longer used operationally and is no longer processed by AI. Once the period has expired it is deleted automatically. We will tell you how long the restriction lasts.
Where an assignment is still running: If your case is waiting for a decision by the bank or for a missing document, we mark it internally as a running assignment — with a reason and a follow-up date. While that marker is set, the short periods for incomplete enquiries do not apply. It has to be expressly confirmed at the follow-up date, ends after 12 months at the latest and is logged.
Suspension of deletion in a dispute: Where data is necessary for the establishment, exercise or defence of legal claims (Art. 17 (3) (e) GDPR) — for instance in a dispute about whether a withdrawal was in time — we exempt exactly that data from deletion, with a stated reason. It is then used exclusively for that purpose, no longer operationally and no longer by AI. Setting and lifting the suspension are logged.
Backups: Deleted data may still be contained in encrypted backups for a short time; these are overwritten on a fixed cycle.
8. Cookies and reach measurement
Without your consent we use technically necessary cookies only. For anything beyond that — in particular for web analytics with Google Analytics 4 — we ask you beforehand via a consent banner. Declining there is just as easy as accepting; without your agreement no such service is loaded.
Technically necessary cookies and storage: We use only cookies and comparable storage that are necessary for operation — in particular to maintain your sign-in (session cookie), to protect against forged requests and to store your language choice. Under § 165 (3) TKG 2021 no consent is required for these, because they are strictly necessary to provide the service you expressly requested. The legal basis for the associated processing is Art. 6 (1) (b) or (f) GDPR.
Reach measurement without cookies: Our funnel counter works without cookies: for each process step your browser sends only two codes (step and outcome) as payload; in addition there are the details transmitted with every page request anyway (IP address, language), which we handle as described in section 3.10. No identifiers are stored on or read from your device and no device information is queried for analytics purposes. Several steps are only tied to one session on our server, as a salted, non-reversible checksum derived from the IP address and a time window; the IP address itself is not stored and no profile is created. Because this involves no access to your device within the meaning of § 165 (3) TKG 2021, in our assessment no consent is required; the processing is based on our legitimate interest (Art. 6 (1) (f) GDPR). You can object to this processing under Art. 21 GDPR.
Services requiring consent: Google Analytics 4 (section 3.15) is loaded only after you have given your consent. Your decision is stored in your browser with the text version and a timestamp; you can change or withdraw it at any time via the “Cookie settings” link in the footer of our website. We do not use advertising cookies for profiling.
9. Your rights
Under the General Data Protection Regulation you have the following rights:
- Access (Art. 15): You can request information on whether and which data we process about you, for which purposes, to which recipients it goes — including which credit institutions have received your documents — and how long we store it. You will receive a copy of your data. On request we will explain how your details fed into the pre-check (see section 6).
- Rectification (Art. 16): You can have inaccurate data corrected and incomplete data completed. Values read out of documents can be corrected by you in the platform itself.
- Erasure (Art. 17): You can request erasure, provided no statutory retention obligation stands in the way (see section 7).
- Restriction of processing (Art. 18): You can request that we only store your data and make no further use of it.
- Data portability (Art. 20): You can receive the data you provided in a structured, commonly used and machine-readable format, or have it transmitted directly to another body where this is technically feasible.
- Objection (Art. 21): You can object to processing that we base on a legitimate interest (sections 3.1, 3.10, 3.14) at any time on grounds relating to your particular situation. You can object to the use of your data for direct marketing at any time and without giving reasons; we will then no longer process your data for that purpose.
- Withdrawal of consent (Art. 7 (3)): If you have given us consent — for example to record a video conversation or for the newsletter — you can withdraw it at any time with effect for the future. The lawfulness of the processing carried out up to that point remains unaffected. Withdrawing is as easy as giving consent.
To exercise your rights please contact us at office@kreditdirekt.at or at the address given in section 1. We will respond without undue delay and at the latest within one month.
Right to lodge a complaint with a supervisory authority
Without prejudice to other remedies, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority in Austria is:
- Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
- Barichgasse 40–42, 1030 Vienna
- Telephone: +43 1 52 152-0
- E-Mail: dsb@dsb.gv.at
- Web: www.dsb.gv.at
10. Data security
We take technical and organisational measures under Art. 32 GDPR to protect your data. These include in particular:
- Encryption of transmission (TLS) and of stored data; documents are additionally encrypted at application level, identity data as well as name and telephone number field by field.
- Chain of checks for uploads: size check, verification of the actual file type, virus scan, sanitisation of the document — if a stage fails or the virus scanner is unavailable, the upload is rejected.
- Roles and permissions: You see only your own data; internal access is separated by role and protected by two-factor authentication.
- Append-only log with a cryptographic chain covering access, status changes, AI actions and deletion runs.
- Encrypted backups with regularly tested restores.
- Data minimisation towards the AI: only the details required for the respective step are sent to the AI service.
- Synthetic data in all test and development environments.
- Breach process for personal data breaches (notification to the data protection authority within 72 hours, Art. 33 GDPR).
11. Are you obliged to provide your data?
Providing your data is neither required by law nor by contract; you are not obliged to provide it.
Without certain details, however, we cannot deliver the service you asked for: without details of income, expenses and your project no household calculation is possible, and without the documents required by the credit institutions your financing enquiry cannot be submitted. We will tell you in the process which documents these are in each case.
The public loan calculator and a first estimate are available to you without an account and without providing personal data.
12. Where we obtain your data from (Art. 14 GDPR)
As a rule we receive your data directly from you. In the following cases data comes from other sources:
- From your documents: We read the values needed out of the documents you upload. Where those documents contain details of other persons — for example a co-applicant, dependants or the parties to a purchase contract — we process those details too, in so far as they are necessary for the financing.
- From a co-applicant: If you apply together with another person, we receive part of their details through you and vice versa.
- From credit institutions: Responses to your enquiry, offers, terms and requests for further documents.
If you transmit data of other persons, please inform them about this privacy notice. We inform co-applicants actively: As soon as the data of a second applicant is transmitted to us, that person receives an e-mail of their own — explaining who we are, that we received their data from the first applicant and for which purposes we process it — together with a link that leads directly, without signing in and without searching, to the information page for co-applicants containing the full information under Art. 14 GDPR.
13. Changes to this privacy notice
We adapt this privacy notice when our processing operations or the legal situation change. All versions are stored with a version number and the date on which they take effect; the version in force is available here. Which version you agreed to in the process is documented with the text version and a timestamp.
Version 7 · As at: 15 September 2026 · In force from publication on kreditdirekt.at
This English version is provided for convenience; the German version is authoritative.