Skip to content
Horizon Scanner
Privacy

Legal · Version 1.2

Privacy Notice

Pursuant to Art. 13 and Art. 14 GDPR, the Austrian Data Protection Act (DSG), and taking into account the obligations of a deployer under Art. 26 EU AI Act. As of April 2026.

01

Controller

The controller within the meaning of the GDPR (EU) 2016/679 and the Austrian Data Protection Act (DSG, as amended) is:

Project Horizon — civil-law partnership (GesbR, Austrian law)
Schlachthammerstraße 83 C, 1220 Vienna, Austria
Email: privacy@horizon-scanner.com

Legal basis: Art. 13 GDPR (information obligation on direct collection); § 1 DSG (Austrian constitutional right to data protection).

02

Principles of processing

We process personal data exclusively in accordance with the GDPR and the DSG. The principle of data minimisation applies (Art. 5(1)(c) GDPR): we collect only the data strictly necessary to operate the service.

Horizon Scanner processes no personal data of the end-customers of the insurance undertakings we serve. The platform is aimed exclusively at B2B users (compliance, legal and regulatory teams).

03

Data processed

Account dataFirst name, last name, email address, password (hashed)Provision of the user account
Company dataCompany name, function / rolePersonal reference within the meaning of Art. 4(1) GDPR when combined with the name
Technical dataIP address, browser type, login timestampsIT security, abuse prevention
Usage dataFindings viewed, acknowledgements, status changes, reportsPart of the immutable audit trail (accountability under Art. 5(2) GDPR)
CommunicationsEmail address for alertingSending notifications per subscription
04

Purposes and legal bases

PurposeLegal basis
Provision and operation of the platform, user-account administrationArt. 6(1)(b) — performance of contract
Sending regulatory alerts by emailArt. 6(1)(b) — performance of contract
Audit trail (who acknowledged which finding, when)Art. 6(1)(b)+(c) — performance of contract + legal obligation (Art. 5(2), Art. 32 GDPR)
IP addresses, login logsArt. 6(1)(f) — legitimate interest (IT security)
Invoicing, bookkeepingArt. 6(1)(c) — legal obligation (§ 132 BAO, § 212 UGB, Austrian law)
05

Use of AI services

Horizon Scanner uses external AI models to process regulatory documents. Since we deploy but do not develop these models, we qualify as a deployer under the EU AI Act (Regulation (EU) 2024/1689).

ServiceProviderPurposePersonal data sent
Google GeminiGoogle LLC, USAPrimary scoring and summarisationNo
MiniMaxMiniMax AIIndependent second-pass verification at Impact ≥ 3No
GroqGroq Inc., USAFallback on provider unavailabilityNo

All AI models process exclusively publicly available regulatory texts — no personal data of users is transmitted to any AI API.

Risk classification under the EU AI Act

Self-assessment: not a high-risk system (Art. 6(4) EU AI Act). Annex III of the EU AI Act lists high-risk AI systems exhaustively. Every category listed there presupposes that the AI system evaluates natural persons or decides about them. Horizon Scanner evaluates only publicly available regulatory documents — no personal reference in the scoring process.

Deployer obligations (Art. 26 EU AI Act)

  • Use exclusively in accordance with the AI providers' terms of service
  • No transmission of personal data to AI APIs
  • Human-in-the-loop: AI scores are decision support, not binding determinations
  • AI-generated content is labelled as such in the dashboard (Art. 50(4) EU AI Act)
  • Users are informed during onboarding about how the AI works and its limits (Art. 4 EU AI Act)
06

Processors and third-party recipients

The following service providers are engaged as processors under Art. 28 GDPR. A data-processing agreement (DPA) is in place — or will be concluded before production use — with each.

ProviderPurposeRegionTransfer basis
Hosting (EU cloud)Cloud hosting, databaseEU / EEADPA
Vercel Inc.Landing-page hosting, cookieless analyticsUSA (HQ) · EU region FrankfurtEU-US Data Privacy Framework (Art. 45 GDPR) + DPA
Email serviceDelivery of alert emailsEUDPA
Google LLC (Gemini API)AI scoringUSASCCs under Art. 46(2)(c) GDPR
Groq Inc.AI fallbackUSASCCs
MiniMax AIAI verificationSCCs + TIA

We do not disclose data to third parties for marketing purposes, nor do we sell data.

07

Retention periods

Data categoryPeriodReasoning
Account and user dataSubscription term + 30 daysContract performance; grace period for data export
Audit trail5 yearsAccountability (Art. 5(2) GDPR); supervisory expectations of regulated customers
IP addresses / login logs90 daysIT security; no necessity beyond that
Invoices, accounting7 years§ 132 BAO, § 212 UGB (Austrian law)
Email correspondence3 yearsLegitimate interest; § 1489 ABGB
08

Cookies and analytics

Horizon Scanner uses exclusively functional cookies and a cookieless analytics solution. There are no tracking cookies, no third-party advertising, and no personal profiling.

NamePurposeDurationLegal basis
hs_langLanguage preference (DE / EN); set only when you actively use the language toggle1 year§ 165(3)(1) TKG · functional
Session cookieAuthentication in the signed-in areaEnd of session§ 165(3)(1) TKG · technically necessary
CSRF tokenProtection against cross-site request forgeryEnd of sessionArt. 32 GDPR · security

Analytics (Vercel Web Analytics): On the public landing page we use Vercel Web Analytics in its cookieless configuration. No cookies are set and no browser fingerprint is generated. Only aggregated, non-identifying data is processed: URL visited, referrer, device type and an imprecise location (country) derived from the IP address before the IP is discarded. Processing under Art. 28 GDPR; Vercel Inc. is certified under the EU-US Data Privacy Framework pursuant to Art. 45 GDPR.

Functionally necessary cookies and cookieless analytics without personal reference are permitted without consent under § 165(3)(1) TKG 2021 in conjunction with Art. 5(3) ePrivacy Directive — no cookie banner is displayed.

09

Rights of data subjects

RightArticleContent
AccessArt. 15Which data we process about you
RectificationArt. 16Correction of inaccurate data
ErasureArt. 17Unless a statutory retention obligation applies
RestrictionArt. 18Restriction of processing
PortabilityArt. 20Receipt of data in machine-readable format
ObjectionArt. 21In particular against processing on the basis of lit. (f)
WithdrawalArt. 7(3)Withdrawal of consent, at any time

Requests to privacy@horizon-scanner.com. Response window: 30 days (Art. 12(3) GDPR).

Right to lodge a complaint: Austrian Data Protection Authority (DSB), Barichgasse 40–42, 1030 Vienna · dsb.gv.at

10

Data security

We apply the following technical and organisational measures (TOMs):

  • Encrypted transport via TLS 1.2 / 1.3 (HTTPS) for all endpoints
  • Encrypted storage at rest (at-rest encryption)
  • Role-based access controls (RBAC)
  • Hosting exclusively on European cloud infrastructure
  • Regular backups with versioning
  • Strict tenant separation — no shared database access between customer accounts
11

Processing on behalf of our customers

To the extent that our customers (insurance undertakings) transmit user data to us for the operation of the platform, we act as a processor within the meaning of Art. 28 GDPR — the customer is the controller. The legal basis is the data-processing agreement (DPA) to be concluded with the customer.

12

Automated decision-making / profiling

No profiling and no automated decision-making under Art. 22 GDPR with legal or similarly significant effects on users takes place. The AI scoring function evaluates only public regulatory documents — not user behaviour or personal characteristics.

13

Changes to this Notice

We reserve the right to update this Privacy Notice. The current version is available at horizon-scanner.com/datenschutz. For material changes we inform registered users by email at least 14 days before the change takes effect.

© 2026 Project Horizon · Schlachthammerstraße 83 C, 1220 Vienna · As of April 2026 (Draft v1.2)← horizon-scanner.com