Legal notice & privacy

This page contains the legal notice and privacy information for GroupMixer, operated as an Austrian sole trader business.

Business and legal notice

Business disclosures under § 5 ECG and media disclosures under § 25 MedienG. GroupMixer is operated as a sole trader business.

Business owner / media owner
Guido Witt-Dörring
Business address
Mühlgasse 3/1, 2322 Zwölfaxing, Austria
Registered trade
Dienstleistungen in der automatischen Datenverarbeitung und Informationstechnik
GISA registration
39856968
Trade authority
Bezirkshauptmannschaft Bruck an der Leitha
Chamber membership
Wirtschaftskammer Niederösterreich, Fachgruppe Unternehmensberatung, Buchhaltung und Informationstechnologie
VAT identification number
ATU83599009
Trade regulations
Gewerbeordnung 1994 (GewO)
Purpose of the website
Website for browser-based creation and optimisation of groups, teams and session plans with optional paid Pro access.
Editorial direction
Provision of a web tool together with accompanying information about the use and capabilities of GroupMixer.
Contact
support [at] groupmixer.app
Telephone
+43 677 64032554

Privacy information

1. Controller

The controller for this website is Guido Witt-Dörring, Mühlgasse 3/1, 2322 Zwölfaxing, Austria. For privacy-related questions or to exercise your rights, you can contact us at support [at] groupmixer.app.

2. Hosting and technical server data

This website is provided through Vercel; the separate public solver API is additionally delivered through Cloudflare and hosted on Render. When the website or API is accessed, technically required connection data such as IP address, access time, requested URL, referrer information, browser/device data and similar log data may be processed to deliver the service, ensure security and detect misuse.

Where personal data is processed in this context, the legal basis is our legitimate interest in the secure and stable operation of the website (Art. 6(1)(f) GDPR).

3. Scenario data and feedback form

The browser-based GroupMixer tool does not automatically transmit entered participant names or result data. When a signed-in person expressly enables remote synchronization for a specific scenario, its scenario and result documents are encrypted in transit and stored by Cloudflare so they can be recovered on another device using the same account. The separate public solver API does process scenario JSON that API users intentionally submit; callers should use non-identifying technical IDs where possible. API telemetry does not retain scenario payloads. Product telemetry sends coarse usage events; when solver failures occur it may also send an anonymized scenario structure in which people, groups, attribute names and attribute values are replaced with technical placeholders. The solution-rating form can transmit an expressly selected 1–5-star rating, an optional comment, and coarse scenario or solver size categories. Rating count and average may be displayed publicly in aggregate; comments remain private unless separate explicit publication consent is provided. The full feedback form can also transmit the message you enter, optional contact details and optional browser diagnostics. Non-anonymized browser-tool scenarios are not sent automatically outside expressly enabled remote synchronization.

4. Public community, accounts, and private contact

Community threads and replies publish immediately after submission and can be indexed by search engines. Your displayed name, post text, authored language, status, and timestamps may remain discoverable on the public internet. Your email address, Google identity, sign-in provider, and internal account identifier are not displayed publicly. A GroupMixer account is optional, provides a product-wide sign-in identity, and can be used for community features; the grouping workspace remains available without an account. For password sign-in, Convex stores only a cryptographic password verifier, not the plaintext password.

You can edit guest posts using access information stored in the browser where you submitted them. Clearing site data or changing devices removes that access; signing in later does not transfer guest posts to your account. GroupMixer share links may encode scenario data. Publish them or other material only when you have authority to do so and they contain no confidential or identifying data. Private contact submissions are stored separately and are never converted into public threads. Signed-in people may voluntarily enable per-discussion emails about public replies, status changes, accepted answers, and related GroupMixer updates. This processing relies on consent (Art. 6(1)(a) GDPR); consent can be withdrawn at any time in the discussion or account area or through every message’s unsubscribe link, with effect for the future. Other requested community, account, and contact functions rely on Art. 6(1)(b) GDPR; abuse prevention, moderation, security, and legal defence rely on legitimate interests under Art. 6(1)(f) GDPR.

Community rules and content license

You retain your rights in submitted content and grant GroupMixer a non-exclusive, worldwide, royalty-free license to store, reproduce, display, index, back up, and moderate it for operating the community. Do not submit unlawful, abusive, harassing, deceptive, rights-infringing content or unnecessary sensitive personal data. Content may be reported, hidden, locked, or removed for legal, privacy, safety, or policy reasons. Removing a public post deletes its text and displayed author details; necessary records for moderation, security, or legal claims may be retained separately.

5. Web analytics

This website currently uses Vercel Web Analytics, Cloudflare Web Analytics, and PostHog Cloud EU to measure visits and broad interactions and to compare these services. This baseline measurement continues when you decline richer product analytics. It records visited pages, visit duration, content-free click signals, times, referring websites, browser, operating system, device type, and location information. Click signals contain no text, inputs, link destinations, or selected or copied content. PostHog also receives the app version, recognised campaign labels, and your analytics choice with the consent-notice version. Random, short-lived session identifiers let us connect PostHog and Convex events from the same visit. URL parameters, share-link contents, and unknown campaign values are removed. PostHog temporarily processes the IP address, hostname, and browser identifier to create a daily identifier, then removes those inputs before storing events. It uses no cookies, person profiles, or persistent cross-browser identifiers. Cloudflare provides country information and technical performance statistics. Vercel may derive country, region, and city and uses a technical identifier that is deleted after 24 hours.

Regardless of your analytics choice, Convex records use of features such as group generation, solving, examples, export, and help, together with broad scenario-size, runtime, error, app-version, and session information. This includes whether local saving, recovery, sign-in, and expressly enabled cloud sync succeed or fail. These events contain no participant names, inputs, group assignments, scenario contents, credentials, or free-text errors. Separate solver-failure reports may include a scenario structure with people, groups, attribute names, and attribute values replaced by technical placeholders. Convex telemetry is currently stored without a fixed deletion period. After you consent, PostHog additionally records navigation, clicks, form changes, ineffective or repeated clicks, language, app version, and broad scenario size. A random session identifier is stored in your browser for this purpose; session recording is disabled. PostHog events and daily aggregated Vercel and Cloudflare statistics are retained in a private Cloudflare archive in Western Europe for up to three years. You can withdraw or grant consent for richer PostHog product analytics using the setting below this section. Baseline measurement and Convex telemetry continue regardless. We rely on legitimate interests in understanding usage and improving the service for baseline measurement and Convex telemetry (Art. 6(1)(f) GDPR), and on your consent for richer PostHog product analytics (Art. 6(1)(a) GDPR).

Convex also records interactions with Pro notices, upgrade and payment steps, payment status, broad error categories, and confirmed first purchases. Random identifiers connect these events within a session that ends after 30 minutes of inactivity or at most 12 hours. To associate a later payment confirmation, these identifiers are linked to the protected purchase record for up to 30 days. The link is then deleted even if the purchase record must be kept longer. The events themselves contain no email, account, contract, or payment-provider identifiers; the temporary link makes them pseudonymous, not irreversibly anonymous. They are currently stored in Convex without a fixed deletion period. They are not additionally sent to PostHog, but can be connected to its events through the session linking described above.

6. Browser-local storage and offline functions

GroupMixer stores drafts, scenarios, results, UI state and similar functional data locally in the browser (for example via browser databases, local and session storage, and offline caches) so that the app works as intended. This data generally remains on the user’s device and is not used for server-side collection of tool content.

This browser-local storage supports scenario editing, draft recovery and offline use. For ratings, the browser stores a random rating identifier so a later rating from the same browser profile replaces the previous response instead of increasing the public count. Convex stores only a protected fingerprint of that identifier, which is not used for other analytics. Your browser also stores the information needed to access your private rating conversation. Rating comments, replies, and in-app notification read state are stored in Convex. Only authorized submitters and active moderators or administrators can access them. Feedback submitted while signed in is associated with that account; later sign-in alone does not claim a guest conversation. No name or email is required, and replies do not trigger email. Clearing site data removes guest access, but does not delete the stored conversation. Private-contact retention rules apply.

7. Retention of community and account data

Public posts are retained until deleted by an authorized owner or removed through moderation. Remotely synchronized scenario and result documents remain until confirmed cloud deletion, account removal, or a necessary operational removal. Deleted cloud documents remain in active encrypted backup history for 30 days. Separate weekly backups of the Convex database and its file storage are encrypted and retained for 90 days from creation. A separate older scenario backup is retained until at least 4 October 2026 and is deleted only once we have checked and confirmed that it is no longer needed for recovery. Personal OneDrive may then retain the removed encrypted files in its provider recycle bin for ordinarily up to 30 further days; operational outages, account restrictions, or legal retention duties can delay final removal. Account deletion ends active Stripe subscriptions and removes operational Stripe customer references before deletion is declared complete; legally required invoice, tax, payment, refund, and dispute records held by Stripe or GroupMixer may nevertheless remain for the applicable statutory period. Confirmed Pro contract evidence, including consents, the full contract version, email address and payment references, is retained for three years after acceptance or one year after the contract ends, whichever is later, including after account deletion. For an ongoing contract, the latter period starts when it ends. Unused purchase reviews are deleted after 30 days; verified expired checkouts after a further 30 days. A purchase with unresolved payment status is retained pending reconciliation and checked again regularly. Account deletion also invalidates sessions, removes stored password verifiers, and labels remaining public contributions as “Deleted user.” Notification consent is stored until withdrawal; after withdrawal, pending deliveries are cancelled and necessary consent, withdrawal, and delivery evidence is retained only as long as needed for accountability, reconciliation, abuse prevention, or legal obligations. Private contact submissions, other delivery state, and moderation, security, and removal audit records are likewise kept only as long as needed; their continued necessity is reviewed regularly. Short-lived sign-in, verification, and password-reset codes expire within minutes; providers may keep their own necessary delivery and security logs. Guest access remains available in the original browser until its site data is cleared.

8. Service providers and data recipients

We use Vercel for website hosting, Convex for accounts, password verification, community, usage statistics, purchase records, and cloud-sync administration, Stripe Managed Payments for Checkout, payment, automatic renewal, invoicing, tax, payment methods, refunds, and disputes, Google when you expressly choose Google sign-in, Mailjet for email sign-in, account-verification, and password-reset codes and expressly enabled community notifications, as well as contract withdrawal/cancellation receipts, Cloudflare for abuse protection, web analytics, the public API, expressly synchronized scenario/result documents, the analytics archive, and encrypted database backups, Microsoft OneDrive for scenario and database backups encrypted before upload, GitHub Actions for creating database backups, with temporary access to unencrypted database and file contents, Render for the public API, PostHog for analytics, and potentially GitHub for internal delivery of private contact submissions. Scenario backups are created on our own equipment in Austria. Microsoft receives encrypted backup contents; the decryption keys are kept separately and are not provided to Microsoft. We can recover the data using those keys. Microsoft can still process storage-account and connection information, file sizes, and timestamps. Stripe receives the contact, billing, tax, and payment details entered in Checkout plus a technical GroupMixer account reference. GroupMixer does not store full card details or invoice contents; it stores necessary customer, subscription, event, paid-term, and reconciliation references, plus contract records containing your verified email address, consent choices, full contract text, confirmed payment total, relevant dates, and confirmation delivery status. Mailjet receives that address and the complete confirmed contract. This processing is necessary to enter into and perform the purchase contract (Art. 6(1)(b) GDPR); legally required financial records rely on Art. 6(1)(c) GDPR. Google sign-in shares the provider-confirmed identity and profile data with us. For sign-in, verification, and reset codes, Mailjet receives the destination address and code but never the password; for community notifications, Mailjet receives the destination address, the relevant discussion title, the discussion or related-update title and URL, a public reply/status/accepted-answer or related-update notice, and a non-public delivery/unsubscribe identifier. For contract declarations, Convex stores the submitted name, contract details, confirmation address, declaration and receipt time privately; Mailjet receives the confirmation address and full receipt, including the declaration and timestamp. This processing handles your request and preserves required evidence (Art. 6(1)(b) and (c) GDPR). Where we control retention, the periods above apply; otherwise each provider’s necessary retention and deletion rules apply.

9. Data protection rights

Where personal data is processed in connection with community, accounts, payments, contact submissions, hosting, logs, or reach measurement, statutory data protection rights apply, including access, rectification, erasure, restriction, portability, and objection. Signed-in people can manage subscriptions, payment methods, and invoices through the billing area and can export account data and delete their account. For refunds, withdrawal or other statutory consumer rights, guest content, or further privacy requests, use the contact above; technical self-service functions do not limit statutory rights. You also have the right to lodge a complaint with the Austrian Data Protection Authority.