TLMG

Privacy Policy

Last updated: September 20, 2026

Introduction

TLMG Advisory GmbH (“TLMG”, “we”, “us” or “our”) is committed to protecting the personal data of visitors to this website and of our clients and business partners. This Privacy Policy explains how we collect, use, store and share personal data in connection with our website and our advisory services. We process personal data in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and the Austrian Data Protection Act (Datenschutzgesetz, “DSG”), as applicable.

Controller and contact

The controller responsible for the processing of your personal data is TLMG Advisory GmbH, Björnsongasse 22, 1130 Vienna, Austria. If you have questions about this Privacy Policy or our data processing, you can reach us at office@legalmindsgroup.com or by phone on +43 664 540 6161.

Personal data we collect

Website access data. When you visit this website, the server automatically processes technical data, including your IP address, browser type and version, operating system, referring URL, pages visited and the date and time of access. This data is recorded in server log files by our hosting provider, which acts on our behalf.

Contact and communication data. When you contact us by e-mail, phone or through other channels, we process the information you provide, such as your name, e-mail address, phone number, company, job title and the content of your message.

Client and business partner data. In connection with our advisory services, we process professional and business-related data about our clients and business partners, including names, job titles, contact details, company information, contractual and billing data and project-related correspondence.

Purposes and legal bases

Performance of a contract (Article 6(1)(b) GDPR). We process personal data as necessary to perform a contract with you or to take steps at your request before entering into one. This includes providing our services, managing client relationships and processing invoices and payments.

Legitimate interests (Article 6(1)(f) GDPR). We process personal data where necessary for our legitimate interests, provided they are not overridden by your rights and freedoms. These include operating and securing our website, responding to enquiries, and communicating about our services with existing and prospective clients.

Consent (Article 6(1)(a) GDPR). Where we ask for your consent, we process personal data on that basis. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Legal obligation (Article 6(1)(c) GDPR). We process personal data where necessary to comply with legal obligations, including tax and accounting requirements under Austrian and EU law.

Cookies and third-party content

This website does not use cookies, analytics or tracking tools, and it does not load content from third-party servers. The fonts used on this website are hosted on our own server.

Data sharing and recipients

Service providers. We engage service providers for functions such as web hosting, IT support, cloud services, e-mail delivery and productivity tools. They process personal data only on our instructions and are bound by data processing agreements pursuant to Article 28 GDPR.

Professional advisors. We may share personal data with our legal, tax and accounting advisors where necessary for the management of our business.

Cooperation partners. Where an engagement involves AI engineering and technology solutions, we work together with Singularity.Inc. Personal data is shared with Singularity.Inc only to the extent necessary for such an engagement.

Authorities. We may disclose personal data to public authorities, courts or regulatory bodies where required by law or in response to valid legal process.

International data transfers

Our operations are based in Austria. Some of our service providers, such as cloud and productivity providers, may process personal data on servers outside the European Economic Area, for example in the United States. Where personal data is transferred to a country without an adequate level of data protection, we ensure that appropriate safeguards are in place, namely:

  • the EU–U.S. Data Privacy Framework, where the recipient is certified under it, on the basis of the European Commission’s adequacy decision of July 10, 2023 (Implementing Decision (EU) 2023/1795);
  • Standard Contractual Clauses approved by the European Commission (Article 46(2)(c) GDPR), supplemented where necessary by additional technical and organisational measures; or
  • other legally recognised transfer mechanisms under the GDPR.

You may request further information about these safeguards by contacting us.

Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or as required by law.

  • Website access data is kept in server log files for a limited period only and is then deleted.
  • Contact and communication data is retained for the duration of the business relationship and afterwards for as long as required by statutory retention obligations or to establish, exercise or defend legal claims.
  • Contractual and billing data is retained for the statutory retention periods under Austrian tax and commercial law, generally seven years.

After the applicable retention period, personal data is securely deleted or anonymised.

Your rights

Subject to applicable law, you have the following rights with respect to your personal data.

Access (Article 15 GDPR). You may obtain confirmation as to whether we process your personal data and request access to it together with certain supplementary information.

Rectification (Article 16 GDPR). You may request the correction of inaccurate personal data and the completion of incomplete data.

Erasure (Article 17 GDPR). You may request the deletion of your personal data where, among other grounds, it is no longer necessary for the purposes for which it was collected or you withdraw your consent.

Restriction of processing (Article 18 GDPR). You may request the restriction of processing in certain circumstances, for example where you contest the accuracy of the data.

Data portability (Article 20 GDPR). You may receive your personal data in a structured, commonly used and machine-readable format and transmit it to another controller where the processing is based on consent or a contract and carried out by automated means.

Objection (Article 21 GDPR). You may object to the processing of your personal data based on legitimate interests or for direct marketing purposes. If you object to direct marketing, we will stop such processing without undue delay.

Withdrawal of consent. Where processing is based on your consent, you may withdraw it at any time.

Complaint. You have the right to lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.

To exercise any of these rights, please contact us using the details above.

Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, such as access controls and encrypted transmission. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

Third-party links

This website contains links to third-party websites that we do not operate, for example LinkedIn, Singularity.Inc, INSEAD Knowledge, ResearchGate and Medium. This Privacy Policy does not apply to those websites, and we encourage you to review their privacy policies.

Children

This website and our services are not directed at individuals under the age of sixteen (16). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Changes are posted on this page with an updated date.

Governing law

This Privacy Policy is governed by the laws of Austria, in compliance with the GDPR and the Austrian DSG.

Contact

TLMG Advisory GmbH
Björnsongasse 22
1130 Vienna
Austria
T +43 664 540 6161
office@legalmindsgroup.com