Legal information
Privacy Notice
How personal data is processed in connection with the Theralexis website, including enquiries made through the Contact form.
Last updated:
Approved for use for the first six months following public launch
This Privacy Notice is approved for use for the first six months after the Theralexis website is publicly launched and is scheduled for review on 20 February 2027. It describes the processing that applies from launch.
It is not approved indefinitely. Any material change to what is collected, retained or shared before that review is assessed separately rather than assumed to be covered.
Controller
Theralexis GmbH in GründungParkstrasse 32
2371 Hinterbrühl
Austria
Email: [email protected] · Contact Theralexis
Scope of this Privacy Notice
This notice explains how personal data may be processed when you visit the Theralexis website, submit the Contact form, arrange a meeting, contact us by email or use an external link. It reflects the functionality currently implemented on the Theralexis website.
It currently covers:
- visits to the Theralexis website
- technical delivery and protection of the website
- server and security logs
- the Contact form, in which you describe your strategic context
- appointment scheduling through Calendly, which is embedded after you submit that form
- communication by email
- use of external LinkedIn links
It does not yet cover a newsletter subscription service, because no subscription functionality is active.
Website delivery, hosting and security
The Theralexis website is delivered to you through Cloudflare, which provides content delivery, availability and security-related functions in front of the site. The website itself runs on a server operated for Theralexis, and Cloudflare passes your request to it.
Potential personal data may include, depending on the request and configuration:
- IP address
- date and time of the request
- requested URL and HTTP information
- browser and device information
- referring URL where transmitted
- technical and security-related request data
This data may be processed for the following purposes:
- delivering the website
- maintaining availability and performance
- detecting and responding to malicious or abusive traffic
- troubleshooting technical problems
- protecting the website and infrastructure
Legal basis
Article 6(1)(f) GDPR — our legitimate interests in securely, reliably and efficiently providing and protecting the website.
Cloudflare acts as a service provider that may process data on behalf of Theralexis, and may also process certain data for its own documented purposes where applicable. The precise controller and processor roles depend on the specific processing activity and the applicable Cloudflare terms. For the personal data described in this notice, the Cloudflare Data Processing Addendum provides that the customer is the controller and Cloudflare acts as processor, or sub-processor.
Technical and security logs
Automated rate limiting for the Contact form is not described here as active, because it has not been verified as active. The form does apply a basic automated check that discards submissions showing the signature of an automated script, without recording anything about them.
Technical and security logs may be enabled and retained for:
- security monitoring
- abuse prevention
- troubleshooting
- service integrity
- investigating incidents
- meeting applicable legal obligations
Technical and security logs are retained only for as long as reasonably necessary for the relevant security, troubleshooting, service-integrity or legal purpose. The applicable periods may vary depending on the type of log, the service configuration at Cloudflare and on the server delivering the site, and whether an incident requires further investigation.
Contact by email
The website provides a Contact form, described in the next section, and publishes an email address in this notice and in the Imprint. When you contact Theralexis by email, the personal data processed may include:
- name
- email address
- employer or organisation
- contact details
- message content
- attachments
- other information voluntarily supplied
This data may be processed for the following purposes:
- responding to enquiries
- arranging discussions
- managing business communications
- taking steps before entering into a contract
- maintaining relevant correspondence
- meeting legal obligations where applicable
Legal bases
Article 6(1)(b) GDPR where the communication concerns a contract or pre-contractual enquiry; Article 6(1)(f) GDPR for general professional and business communication; and Article 6(1)(c) GDPR where retention or processing is legally required.
Email correspondence is retained only for as long as necessary to handle and follow up the communication, unless contractual, statutory, regulatory or evidentiary requirements justify a longer period. Please note that ordinary email is not a completely secure or confidential means of communication.
Microsoft 365
Business email is received, stored and managed using Microsoft 365. Microsoft may process customer and service data under the applicable Microsoft contractual and data-protection terms. The specific data residency and processing arrangements depend on the Microsoft 365 tenant configuration and applicable terms.
The Contact form (your strategic context)
Before offering a scheduling step, the Contact page asks you about yourself and your situation. This is a form on the Theralexis website: what you enter is sent to an endpoint on the Theralexis server that serves this site, not to a third party.
Information you must provide in order to submit the form:
- your name
- your work email address
- your company
- your role or title
- the product, therapy or asset in focus
- at least one area you would like to understand — and, if you choose "Other", a short description of it
Information you may provide, and may equally leave blank:
- markets
- audiences
- timeframe
- any additional context you wish to add in your own words
The form does not ask for special categories of personal data, and the page asks you not to include confidential, patient or proprietary information.
Purpose. To understand your situation before a meeting, to prepare for that discussion, and to respond to your enquiry.
What happens to a submission. It is stored in a database file on the server that runs this website, which is operated for Theralexis and is not a third-party database service. An internal notification is then sent so that your enquiry is seen and answered.
This notice does not promise a storage territory for that server. Where the machine is located is a matter of how the hosting was chosen, not something the software enforces or can check — so stating a territory here would claim more than we are able to demonstrate. Until this notice says otherwise, please read it as making no residency guarantee. See "International data transfers" below.
The internal notification contains your enquiry. It repeats what you submitted — including your name, your email address, your company and role where you gave them, the product or therapy in focus, the areas you selected, your markets, your audiences, your timeframe and anything you wrote in your own words — together with the record number of the database entry. It is sent only to Theralexis addresses, and the system will refuse to send it at all to an address that has not been separately approved as a recipient. It is transmitted by Resend, a third-party email provider, and is received in a Microsoft 365 mailbox.
This means a second copy of your enquiry exists in an email mailbox, alongside the database entry. We tell you this because it affects how deletion works: a request to erase your information is applied to both, and the mailbox copy is removed manually rather than by the database's own retention schedule. See "Retention" and "Your rights" below.
Technical request data, such as your IP address, is processed by Cloudflare in delivering and protecting the page and the form endpoint, as described under "Website delivery, hosting and security". The form itself does not record your IP address, your browser information or any other request metadata, and none of it is written to the database alongside your enquiry.
Legal bases
Article 6(1)(b) GDPR, for steps taken at your request before entering into a contract, supplemented where appropriate by Article 6(1)(f) GDPR for professional and business communication.
Before you can submit the form you are asked to confirm that you have read this notice and agree to your information being handled for the purpose of answering your enquiry. The box is not ticked for you, and the form cannot be submitted without it.
That confirmation is an acknowledgement, not the legal basis. The processing rests on the bases above, not on your ticking the box; the box records that you were shown this notice first. Nothing about marketing or a newsletter is included in it, and there is no second box.
Appointment scheduling through Calendly
Scheduling is provided by Calendly. No Calendly script, frame or cookie is loaded when you simply visit a Theralexis page, and none is loaded for a visitor who does not complete the Contact form.
After you successfully submit the Contact form, and if JavaScript is available in your browser, a Calendly scheduling interface is embedded into the page. At that point your browser connects directly to Calendly, and your name and email address are passed to Calendly automatically, so that you do not have to type them again. This happens as the scheduling interface loads — that is, before you choose a time or confirm any booking.
If JavaScript is unavailable, or if the Calendly component cannot load, the page instead offers an ordinary external link to the Calendly scheduling page. On that path nothing is passed automatically, and no information reaches Calendly unless you choose to follow the link and use it.
To display the booking page and arrange the appointment, Calendly may process:
- name
- email address
- booking information
- time-zone information
- technical request data, including IP address and browser information
- information voluntarily entered
Calendly's own privacy information also applies to its platform. Theralexis may receive the booking details needed to arrange and manage the requested meeting.
Calendly Inc. is established in the United States. See "International data transfers" below.
Legal bases
Article 6(1)(b) GDPR for requested pre-contractual or business discussions; and Article 6(1)(f) GDPR for efficient scheduling and professional communication.
LinkedIn and other external websites
The website contains external links, including to LinkedIn. These services are not embedded in the current website: no LinkedIn feed, pixel or social plug-in is loaded merely by viewing a Theralexis page.
When you follow an external link, the external provider processes data under its own terms and privacy information. Theralexis does not control all processing performed on third-party websites.
Cookies, analytics and tracking
The current Theralexis website does not use web analytics, advertising trackers, behavioural profiling or non-essential cookies. It does not currently display a cookie-consent banner because no optional analytics or advertising technologies are active.
Theralexis does not intentionally set non-essential cookies or similar technologies in the current implementation.
This position must be reviewed before any analytics, embedded third-party service, advertising technology or other optional storage or access technology is introduced.
Functionality not currently active
The Theralexis website does not currently provide:
- newsletter registration
- CRM form submission
- account registration
- payment processing
- user profiles
A Contact form is active and its submissions are stored — see "The Contact form" above.
The Privacy Notice will be updated before any of the functionality listed above is activated.
Recipients and service providers
Personal data may be made available to the following categories of recipient:
- Cloudflare, for delivery of the website to you, availability and security-related functions in front of the site, and for passing requests — including Contact form submissions — to the server that serves it
- the provider of the server on which the website runs and on which Contact enquiries are stored. That provider is not named here yet, because the disclosure is being completed rather than guessed at; it will be named in this notice when it is
- Resend, for transmitting the internal notification email described above, which contains the enquiry
- Microsoft, for business email and related Microsoft 365 services, including receipt and storage of that notification
- Calendly, for appointment scheduling — including where the scheduling interface is embedded after a Contact form submission, as described above
- professional advisers or public authorities where disclosure is legally required
- other recipients only where necessary for the relevant purpose or permitted by law
Third-party providers may act in different roles depending on the processing activity.
International data transfers
Some service providers, or their subprocessors, process personal data outside the European Economic Area.
- Cloudflare states that it relies on the European Commission's Standard Contractual Clauses, including supplementary measures where necessary, for transfers from the EEA, Switzerland and the United Kingdom, and that it has certified its compliance with the EU-U.S. Data Privacy Framework. Cloudflare also offers optional data-localisation products.
- Calendly Inc. is established in the United States. Its data processing addendum states that processing occurs in the United States and in other jurisdictions outside the residence of the data subjects, that Calendly is self-certified under the Data Privacy Frameworks, and that the Standard Contractual Clauses apply should that framework cease to be available.
- Microsoft, for business email. The applicable data residency and transfer arrangements depend on the Microsoft 365 tenant configuration and the applicable Microsoft terms.
- Resend, which transmits the internal notification and therefore processes the enquiry it contains. The applicable transfer mechanisms, subprocessors and terms are assessed against Resend's then-current contractual terms, on the same basis as the providers above.
Contact enquiries themselves are stored on the server that runs this website, rather than in a database service belonging to any of the providers named above.
This notice makes no residency guarantee, and no statement here should be read as one. A previous version of this notice said that the database enforced an EU jurisdiction. That was accurate of the database service used until 28 August 2026 and is not accurate of the arrangement that replaced it, so the statement has been withdrawn rather than restated in weaker form. Residency and international-transfer safeguards remain two separate questions, and the safeguards described above are what govern the second.
The transfer mechanisms, subprocessor lists and any supplementary measures relevant to each provider are assessed against the then-current provider contracts and configuration, and are reassessed whenever a provider, its terms or our own configuration materially changes — and in any event at the review point stated at the end of this notice.
Retention
Personal data is retained only for as long as necessary for the purpose for which it was collected, including relevant follow-up, security, contractual, evidentiary and legal requirements. Data is deleted or anonymised when it is no longer required, unless continued retention is permitted or required by law.
For example, and without fixed periods:
- technical logs depend on security and incident-handling needs;
- email and booking correspondence depends on the enquiry and relationship;
- legal retention obligations may require longer storage.
Contact form submissions are kept for up to 36 months from the last meaningful contact-related interaction — that is, from your enquiry, or from a later booking, reply or meeting about it where one is recorded. Where nothing later is recorded, the period runs from the date of your enquiry.
The same period applies to the internal notification email described above. It is a second copy of the same enquiry, held in a Theralexis mailbox, and it is deleted on the same basis as the database entry rather than kept indefinitely.
Records are reviewed quarterly and those past the period are deleted. This review is carried out by a person, not automatically: nothing in the system deletes records on its own, and this notice does not claim otherwise.
If an enquiry becomes an ongoing business relationship managed in another system, that other system governs its own records — the original enquiry is not kept indefinitely simply because a relationship exists.
Legal bases
Depending on the processing activity, personal data may be processed on the basis of:
- Article 6(1)(b) GDPR — contracts and steps requested before entering into a contract
- Article 6(1)(c) GDPR — compliance with legal obligations
- Article 6(1)(f) GDPR — legitimate interests in website delivery, security, communication, business administration and scheduling
- Article 6(1)(a) GDPR — consent, only where consent-based processing is introduced or specifically requested
The current website does not yet use newsletter marketing consent, and consent is not used as the legal basis for ordinary, essential website delivery or for the Contact form.
The basis for the Contact form is set out in that section above. The legal bases in this notice are approved for the first six months following public launch, and are reviewed on 20 February 2027.
Legitimate interests
Where processing relies on Article 6(1)(f) GDPR, the relevant legitimate interests may include:
- securely and reliably operating the website
- preventing misuse
- responding to professional enquiries
- managing business relationships
- efficiently arranging requested meetings
- keeping appropriate records of business communications
These interests are balanced against your interests, rights and freedoms, and are not treated as automatically overriding them.
Your rights
Subject to the applicable conditions, you may have the right to:
- access
- rectification
- erasure
- restriction
- data portability
- object to processing based on legitimate interests
- withdraw consent for future processing where consent is used
- lodge a complaint with a supervisory authority
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
To exercise these rights, please contact [email protected]. Legal exceptions may apply, so not every request will necessarily result in deletion or another specific outcome.
Right to object
Where personal data is processed on the basis of legitimate interests under Article 6(1)(f) GDPR, you may object to that processing on grounds relating to your particular situation. Theralexis will then stop the processing unless compelling legitimate grounds or the establishment, exercise or defence of legal claims justify continuing it.
Complaints
You may lodge a complaint with a competent data-protection supervisory authority. In Austria, this is the Austrian Data Protection Authority.
You may also contact Theralexis first, although doing so is not a prerequisite for making a complaint.
Is providing personal data required?
- accessing the website requires normal technical request data;
- using the Contact form is voluntary, but the fields marked as required in "The Contact form" above must be completed, and the confirmation box ticked, in order to submit it;
- the remaining Contact form fields are optional and may be left blank;
- providing data by email or through Calendly is voluntary;
- without the necessary contact or booking details, Theralexis may be unable to answer the enquiry or arrange the meeting.
No automated legal or similarly significant decision is made through the current website. Routine, security-related filtering of malicious or abusive traffic is distinct from automated decision-making within the meaning of Article 22 GDPR.
Automated decision-making
Theralexis does not use personal data collected through the current website for automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR. Security providers such as Cloudflare may nonetheless carry out automated threat detection as part of protecting the website.
Changes to this Privacy Notice
This notice is reviewed on 20 February 2027, and is updated whenever the website's functionality, service providers or processing activities materially change.
Status: approved for use for the first six months following public launch; scheduled for review on 20 February 2027.