GoAware
Data protection

Privacy information.

What technical data GoAware may process when you visit the website or contact the operator.

Privacy information

1. Controller

Controller within the meaning of Article 4(7) GDPR:
Oliver Ramoner
Innsbruck, Tyrol, Austria
Email: [email protected]

Further operator information is available in the Imprint.

2. Scope of this notice

This privacy information explains the processing of personal data in connection with the public GoAware website, its server-side traffic statistics and email contact. It is intended to provide the information required by Articles 12 and 13 GDPR and, where applicable, Austrian data-protection and telecommunications law.

3. Website access, hosting and server logs

GoAware is operated on a self-managed rented server. When the website is accessed, the web server necessarily processes technical connection data. Depending on the request and server configuration, this may include the IP address, date and time, requested URL or file, HTTP status, amount of data transferred, referrer where supplied by the browser, browser/user-agent information and technical security or error information.

Purpose: delivery of the website, maintenance of availability, troubleshooting, prevention and investigation of attacks or misuse and protection of the server infrastructure.

Legal basis: Article 6(1)(f) GDPR. The legitimate interests are the secure, stable and technically reliable operation of GoAware and the prevention and investigation of misuse.

Recipients: the hosting/infrastructure provider may receive technically necessary connection data in the course of providing the server and network infrastructure. Service providers are used only to the extent required for the relevant technical service and, where they act as processors, are to be bound in accordance with Article 28 GDPR.

Retention: raw web-server logs are subject to server-side log rotation. They are retained only for as long as required for operation, troubleshooting and security. Where a security incident must be investigated or legal claims must be established, exercised or defended, relevant records may be retained for the duration necessary for that purpose.

4. Private traffic statistics and IP addresses

GoAware maintains a private, non-public traffic-statistics database on the server. It may contain the full public IP address, timestamps, requested paths, request counts and technical classifications such as likely browser, bot or security-scanner traffic. These statistics are not displayed publicly and are accessible only through the operator's authenticated server environment.

Purpose: basic internal audience measurement, technical diagnostics, abuse detection and security monitoring.

Legal basis: Article 6(1)(f) GDPR. The legitimate interests are understanding the technical use of the service, detecting abuse and maintaining the security and reliability of the website.

Retention: full-IP event data and associated cached IP-location data are currently retained for a maximum of 370 days and are then deleted. Aggregated statistics that no longer permit identification of an individual visitor may be retained for longer.

GoAware does not use these statistics for advertising, behavioural profiling, personalised travel recommendations or decisions producing legal or similarly significant effects for visitors.

5. Approximate IP geolocation via ipwho.is

For private server statistics, a public IP address may be queried by the GoAware server against the ipwho.is / IPWhois geolocation API. The purpose is to obtain an approximate country, region/city and network/ASN assignment. This is IP-based estimation only; GoAware does not obtain GPS coordinates or browser/device geolocation from the visitor.

The queried IP address is necessarily disclosed to the API provider when the lookup is performed. According to the provider's published privacy information, usage data may include IP addresses and data may be stored on infrastructure located in different countries. Further information is available in the IPWhois privacy policy.

Legal basis on the GoAware side: Article 6(1)(f) GDPR, based on the legitimate interests in abuse detection, security monitoring and coarse internal audience statistics.

6. Interactive map and Plotly.js

The interactive world map is rendered in the visitor's browser using Plotly.js. The current website loads the Plotly JavaScript library from cdn.plot.ly. When the browser loads this file, it establishes a direct connection to the delivery infrastructure used for that CDN request. Technical connection data, in particular the visitor's IP address, request time and browser/network information, are therefore disclosed to that infrastructure.

GoAware does not send the selected destination, a GoAware Safety Score or the visitor's precise location to Plotly. The map uses geographic geometry in the browser and does not use Google Maps, map tiles or browser geolocation.

Purpose: providing the interactive world map.

Legal basis: Article 6(1)(f) GDPR, based on the legitimate interest in providing the interactive comparison. Further information is available in the Plotly Privacy Policy.

7. Transfers outside the EEA

Requests to external technical services may result in processing outside the European Economic Area. In particular, the public information of IPWhois states that data may be stored on servers in different countries. Plotly Technologies Inc. is a Canadian company, and the European Commission recognises Canada as providing an adequate level of protection for covered commercial organisations; however, service providers and technical routing may involve additional infrastructure.

Where a transfer to a third country takes place and no applicable adequacy decision covers the recipient and processing, such a transfer requires another valid safeguard under Chapter V GDPR. GoAware does not rely on a privacy notice alone as a substitute for such a transfer mechanism.

8. Fonts

GoAware does not load Google Fonts or another remote font service. Font-family names in the CSS refer to fonts that may already be installed locally on the visitor's device; otherwise the browser uses local system fallback fonts. GoAware therefore does not initiate a connection to Google Fonts for page rendering.

9. Cookies, local storage and similar technologies

GoAware does not intentionally use advertising cookies, marketing cookies, Google Analytics, tracking pixels, browser fingerprinting or embedded social-media widgets. The website does not require a user account. Ordinary links to government websites or social-media profiles do not transmit data to those providers merely because the link is displayed; the external provider is contacted only when the visitor chooses to open the link.

If GoAware introduces non-essential cookies, local-storage identifiers or comparable access to information on a visitor's terminal equipment in the future, they will not be used before any consent required by Austrian telecommunications law has been obtained.

10. Government advisory data

The travel-advisory datasets shown by GoAware are refreshed by the GoAware server and delivered to visitors as local snapshot files. For the normal display of these datasets, the visitor's browser does not need to contact the government or ArcGIS advisory APIs directly. Opening an original government-source link constitutes a separate visit to that external provider and is subject to that provider's own privacy information.

11. Email contact

If you contact GoAware at [email protected], the sender address, message content, technical metadata and any additional information you provide are processed in order to answer and, where necessary, document the request.

Legal basis: Article 6(1)(b) GDPR where the communication is necessary for steps requested by you in connection with a contractual or pre-contractual matter; otherwise Article 6(1)(f) GDPR, based on the legitimate interest in responding to and documenting legitimate enquiries.

Recipients: technical email or hosting providers may process message and connection data to the extent necessary to provide the email service.

Retention: correspondence is deleted when it is no longer required for the purpose for which it was received, unless statutory retention duties apply or longer retention is necessary for the establishment, exercise or defence of legal claims.

12. Whether you must provide personal data

Technical connection data such as an IP address are automatically transmitted by the browser and network when the website is requested. Without this technically necessary data, the website cannot be delivered. Providing additional information by email is voluntary; if information required to answer a request is not provided, GoAware may be unable to respond fully.

13. Your rights

Subject to the applicable statutory requirements, you may have the right to obtain access to your personal data (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and, where the legal requirements are met, data portability (Article 20). Where processing is based on Article 6(1)(f) GDPR, you may object to the processing on grounds relating to your particular situation under Article 21 GDPR.

Requests may be sent to [email protected]. GoAware may request information reasonably necessary to verify the identity of the person making a request where this is required to protect personal data from unauthorised disclosure.

You also have the right to lodge a complaint with a supervisory authority. In Austria, the competent authority is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Austria, email: [email protected].

14. Automated decision-making and profiling

GoAware does not make decisions about website visitors based solely on automated processing that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR. The GoAware Safety Score concerns travel destinations, not individual visitors. Technical classifications used in server statistics, such as likely bot or scanner detection, are used only for operational and security purposes.

15. Security and data minimisation

GoAware applies technical and organisational measures appropriate to the nature and risk of the processing, including access restriction to server-side statistics and administrative interfaces. Personal data are intended to be limited to what is necessary for the purposes stated above and are not sold to advertisers.

16. Changes to this privacy information

This privacy information may be updated when the website, service providers, retention periods or legal requirements change. The version date below identifies the currently published version.

Privacy information version: 23 September 2026. This page describes the current GoAware website and server-side statistics configuration known at the time of publication. External links are governed by the privacy rules of the respective third party.