Privacy Policy

Home » Privacy Policy

As a consultancy specialising in human-centred digital transformation, we not only focus on creating an optimal user experience but also on the responsible handling of your personal data. In the course of our collaboration and valuable exchanges, we come into contact with personal data. Your trust is very important to us, which is why we would like to inform you in this Privacy Policy about how and for what purposes we process your data.

For easier understanding, we also provide a summary in plain language

Through cookie-setting the cookie settings, you can control which personal data may be generated and processed when visiting this website. These settings can be modified at any time and apply across all subpages of the website.

Controller responsible for data processing in accordance with the GDPR:

UX Melange GmbH

Postgasse 8b
1010 Vienna, Austria
T: +43 677 63662993
M: office@uxmelange.com

Stand: September 2026

Scope of this Privacy Policy

UX Melange GmbH (hereinafter also referred to as “we”, “us”, or “our”) takes the protection of personal data seriously. We therefore comply with the European General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act (TKG 2021).
It is important to us to inform visitors (hereinafter also referred to as “you”, “your”) about the scope and purpose of the processing of personal data and the options available to them in this regard. This Privacy Policy applies exclusively to data that is collected and processed directly by us. It does not apply to external websites.
We reserve the right to amend this Privacy Policy at any time due to technical or legal developments.

What Data Is Processed?

According to the GDPR, personal data means any information relating to an identified or identifiable natural person, for example:
Name
Date of birth
Postal address
Email address
Telephone number
This also includes technical data, such as IP addresses and device information, which may be collected and processed when using our website.
We process personal data on this website only on the basis of your consent and our legitimate interests.
If the website is used solely for informational purposes (i.e. if you do not register or otherwise provide information), we only process the personal data transmitted by your browser or device. More details can be found under “Data Processing on this Website.”
In addition, we process personal data that is necessary for fulfilling contractual obligations, complying with legal requirements, or arising within the scope of a business relationship. This also includes documentation data, such as meeting notes and email correspondence.

For What Purpose and on What Legal Basis?

The legal basis for processing your personal data is Article 6(1) of the General Data Protection Regulation (GDPR). Data is processed for the following purposes:

Is Personal Data Shared with Third Parties?

Your data will only be disclosed to third parties if:
This is necessary for the performance of contractual, pre-contractual, or legal obligations;
Disclosure is justified by our legitimate interests; or
You have explicitly consented to the disclosure of your data.
In such cases, your data may be shared with the following recipients:
Service providers engaged as data processors (e.g. IT service providers, customer satisfaction survey providers)
Authorities and public bodies where disclosure is legally required

We always ensure that any disclosure is carried out on a lawful basis and that your data is protected both within and outside our organisation.

How Long Is Data Stored?

As a general rule, your data is retained only for as long as necessary for the duration of our business relationship or for the purposes described above.
Data may be stored for longer periods where:
A legal retention requirement exists;
Storage is necessary for the establishment, exercise, or defence of legal claims; or
Retention is permitted to safeguard our legitimate interests in accordance with Article 6(1)(f) GDPR.

What Are Your Rights?

In relation to the processing of your personal data, you have the following rights:
Right of access (Article 15 GDPR)
Right to rectification (Article 16 GDPR)
Right to object (Article 21(1) GDPR)
Right to erasure (“right to be forgotten”) (Article 17 GDPR)
Right to restriction of processing (Article 18 GDPR)
Right to data portability (Article 20 GDPR)

To exercise these rights or for any other privacy-related concerns, please contact us with the subject line “Data Privacy” per E-Mail unter: office@uxmelange.com or by post at Postgasse 8b, 1010 Vienna, Austria.
You may also withdraw your consent to the processing of your data at any time without providing reasons (Article 7(3) GDPR). From the moment of withdrawal, your data will no longer be processed on the basis of that consent.
Processing activities carried out on the website or in online communications are based on your prior consent. You provide such consent, for example, by allowing certain cookies when visiting the website or by ticking a checkbox in a form before submitting it. You may withdraw your consent by changing your privacy settings within the Consent Management Tool or by clicking the unsubscribe link included in electronic marketing communications.
We strive to address your concerns quickly and to your complete satisfaction. Should you nevertheless have reason to complain about data protection matters, we encourage you to contact us so that we can find a mutually satisfactory solution.
You also have the right to lodge a complaint with the competent data protection authority of the Republic of Austria: https://dsb.gv.at/

Data Processing on this Website

General Information

When you visit our website, we only collect personal data that is technically necessary to ensure the stable and secure operation of the website, including:
Date and time of the request
Time zone
IP address and location
Operating system used
Screen resolution
Browser type, language, and browser version
Content of the request (specific page accessed)
Access status / HTTP status code
Amount of data transferred
Website from which the request originated (referrer)
Number, duration, and timing of visits
Search engines and keywords used to access the website
In addition, technologies such as cookies, scripts, Local Storage, and Session Storage may be used to store or retrieve information on your device.

To ensure secure data transmission, we use SSL and TLS encryption technologies on our website (recognisable by the “https” protocol). These security measures help protect data from being intercepted by third parties during transmission.
However, despite our best efforts, no method of transmission over the Internet can guarantee complete protection against unauthorised access. Whenever you submit information via websites or send emails, there is always a risk that unauthorised third parties may gain access to your data. We nevertheless take all reasonable technical and organisational measures to protect your personal data to the greatest extent possible.

Hosting (Provider & Content Delivery Network – CDN)

Our website is hosted externally by the following hosting provider:
World4You Internet Services GmbH
Wolfgang-Pauli-Straße 2, BT3
4020 Linz
Austria
To ensure the secure and GDPR-compliant processing of personal data, we have concluded a Data Processing Agreement (DPA) with World4You.

How is data processed?

The hosting provider stores and processes all data generated through the operation of our website, whether automatically collected or actively provided by you. This may include personal data such as:
Metadata and communication data
Technical connection data
IP addresses
Date and time information
Accessed pages
Contact details
Contact enquiries
The data is processed only to the extent necessary for delivering the hosting services.

Purpose of processing and legal basis

Purpose: Provision and operation of the website.
Legal basis (Art. 6(1)(b) GDPR):
The website serves to establish contact with potential customers and maintain relationships with existing customers. Processing is therefore necessary for pre-contractual measures and contract performance.
Legal basis (Art. 6(1)(f) GDPR):
We have a legitimate interest in the secure and reliable operation of a professional online presence.

To protect your privacy and comply with GDPR requirements, we use the consent management tool CCM19, provided by:

Papoo Software & Media GmbH
Hersteller CCM19
Auguststr. 4
53229 Bonn, Germany

To ensure GDPR-compliant processing, we have concluded a Data Processing Agreement (DPA) with Papoo Software & Media GmbH.

How is data processed?

The CCM19 tool stores a technically necessary cookie that records your cookie consent preferences.
This cookie does not contain personal data. It only stores information about:
Whether consent was given
Which categories of cookies were accepted or rejected
Your consent preferences are stored on your device for a period of up to 12 months.

Purpose of processing and legal basis

Purpose: Obtaining, documenting, and managing your consent regarding cookies and similar tracking technologies.
Legal basis (Art. 6(1)(a) GDPR):
Consent-based processing.
We are legally required to obtain consent before certain cookies may be used.
The storage of consent information is additionally based on Section 165(3) Austrian Telecommunications Act (TKG 2021).

Cookies

This website uses so-called cookies. Cookies are small text files that are stored on your device (e.g. computer, smartphone, or tablet) to improve the user experience.
Cookies help us to:
Remember your preferences
Facilitate navigation
Provide certain website functionalities
Analyse website usage for optimisation purposes
Cookies do not cause damage to your device and cannot access or modify other data stored on your device.

How is data processed?

We distinguish between:
Session Cookies
Session cookies are stored only for the duration of your browser session and are automatically deleted when you close your browser.
These cookies are necessary for basic website functionality, such as:
Navigation
Authentication
Processing transactions (e.g. completing a purchase)
Persistent Cookies
Persistent cookies remain stored on your device for a longer period and enable us to recognise your device during subsequent visits.
You can delete persistent cookies at any time through your browser settings.
Non-Essential Cookies
Non-essential cookies, particularly:
Analytics cookies
Marketing cookies
are only used after you have provided your explicit consent.
Through our cookie settings, you can determine which cookies may be placed on your device. You also have the option to reject non-essential cookies entirely.
Please note that blocking or deleting cookies may negatively affect website functionality and limit user convenience.
Additional information on cookie management can be found in your browser’s help documentation.
Further details regarding the cookies used on this website can be found within the settings of our Consent Management Tool.

Purpose of processing and legal basis

Purpose: Ensuring the functionality, usability, and optimisation of our website.
Legal basis (Art. 6(1)(f) GDPR):
The storage of strictly necessary and functional cookies is based on our legitimate interest in providing a technically stable and fully functional website.
Legal basis (Art. 6(1)(a) GDPR):
All other cookies are set solely on the basis of your explicit consent and serve to improve your user experience. Consent may be withdrawn at any time.

Web Fonts

How is data processed?

Our website uses Google Fonts provided by Google.
The fonts are installed locally on our servers. Therefore, when you visit our website, no connection to Google’s servers should normally be established.
However, in the event of technical misconfiguration or unforeseen technical circumstances, it cannot be entirely ruled out that a connection to Google Fonts may be established:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Should such a connection occur, data will only be processed for the time necessary to retrieve and display the requested font resources.
To the extent that Google processes data independently beyond the provision of font files, Google acts as the sole controller. Further information is available in Google’s Privacy Policy and Google Fonts FAQ.

Purpose of processing and legal basis

Purpose: Display and visual presentation of the website.
Legal basis:
The processing is technically necessary to provide the website service explicitly requested by the user in accordance with Section 165(3) Austrian Telecommunications Act (TKG 2021).

Server Logs

When you visit our website, information is automatically recorded by our hosting provider, World4You, in so-called server log files.

How is data processed?

These data are collected exclusively for technical purposes, particularly:
Ensuring website functionality
Maintaining website security
Detecting technical issues
Analysing and resolving errors
Further information can be obtained directly from World4You:
World4You FAQ – What data is logged by the web servers?
World4You FAQ -How long are log files retained?

Purpose of processing and legal basis

Purpose: Operational security and error analysis.
Legal basis (Art. 6(1)(f) GDPR):
Server log files are stored based on our legitimate interest in maintaining a secure and reliable website and preventing security incidents.

Contact & Communication

Contacting Us by Email or Telephone

If you contact us by email or telephone, we process your personal data in order to handle your enquiry and provide you with the requested information or services.
Email communication and calendar management are carried out through Microsoft Exchange Online within Microsoft Outlook. Further information can be found in the section Use of Microsoft 365.

How is data processed?

We store your personal data only for as long as necessary to process your enquiry or fulfil the purposes described herein.
If a contractual relationship is established, the data will be retained in accordance with applicable contractual and statutory retention periods (for example, for tax or commercial law purposes).
Your personal data will be deleted once your enquiry has been fully processed, you request its deletion, or you withdraw your consent to storage.
Data will not be deleted where we are legally required to retain it.

Purpose of processing and legal basis

Purpose:
Responding to your enquiries and requests, providing requested services, and communicating within the scope of support and service activities.
Legal basis (Art. 6(1)(b) GDPR):
Processing is necessary to take steps prior to entering into a contract or to perform a contract with you.
Legal basis (Art. 6(1)(f) GDPR):
Processing is based on our legitimate interest in responding to your enquiries and providing the requested information or services. Without this data, we would not be able to respond to or process your requests.

Information About UX Melange Initiatives by Email

If you register via a sign-up form, for example in connection with an event, initiative, or topic (e.g. “Tired of Tech Sugarcoating”), we process the personal data you provide solely for the purpose of informing you by email about future events, new content, and updates relating exclusively to the topic or initiative specified in the registration form.
For the distribution of such information, we require your email address. Additional information such as your first name, last name, company or organisation, and country is used to personalise our communications.
To verify your registration, we use a double opt-in procedure. After submitting the registration form, you will receive a confirmation email containing a confirmation link. Your email address will only be activated for communications once you have completed this confirmation process.

How is data processed?

We process your personal data exclusively for sending information related to the specific topic or initiative for which consent was granted through the registration form.
Your data will not be used for:
General newsletters
Other products or services
Unrelated marketing activities
unless you have separately consented to such use.
Your personal data will generally be stored for as long as you wish to receive information regarding the selected topic.
You may withdraw your consent at any time with effect for the future by:
Using the unsubscribe link included in our emails; or
Contacting us at office@uxmelange.com

Once consent has been withdrawn, your data will no longer be used for these communications.
Where required by law, evidence of the consent provided may be retained for the duration of applicable limitation and evidentiary retention periods.
For the technical delivery of emails, we use:
Microsoft Outlook for smaller-scale distributions; or
Rapidmail for automated email campaigns.
In the event of technical issues, we reserve the right to use alternative service providers. When selecting providers, we give preference to companies that store and process data within the European Union in compliance with GDPR requirements.
Information regarding Outlook data processing can be found in the section “Use of Microsoft 365.”
Information regarding Rapidmail is available at:: https://www.rapidmail.de/datenschutz

Purpose of processing and legal basis

Purpose:
Distribution of information and notifications relating to UX Melange initiatives (e.g. Tired of Tech Sugarcoating) as specified in the registration form.
Legal basis (Art. 6(1)(a) GDPR):
Processing is based on your freely given consent provided through the registration form.
Electronic communications pursuant to Section 174 TKG 2021:
Information is sent by email only on the basis of your prior consent. You may withdraw this consent at any time with future effect.

Use of Microsoft 365

For business communication, collaboration, appointment management, and project work, we use a commercial Microsoft 365 Business licence provided by:
Microsoft Ireland Operations, Ltd
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
D18 P521
Ireland

All services provided under this licence include the Microsoft 365 Advanced Data Residency-Add-On (ADR), ensuring that data is stored and processed exclusively within the European Union (EU).
Microsoft’s parent company for data protection purposes is:
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052
United States
To ensure secure and GDPR-compliant processing of personal data, we have concluded a Data Processing Agreement (DPA) with Microsoft Ireland Operations Ltd.

Microsoft as a Data Processor

Microsoft acts as a data processor within the meaning of Article 28 GDPR when providing Microsoft 365 services.
The contractual basis is the Microsoft Products and Services Data Protection Addendum (DPA), as amended from time to time. This DPA serves as the Data Processing Agreement required under Article 28(3) GDPR and forms part of Microsoft’s Product Terms.
The agreement is concluded electronically when subscribing to Microsoft 365 services.
The current version of the Microsoft DPA is publicly available via Microsoft’s official documentation.
Additional information regarding privacy and data protection at Microsoft can be found at:
Microsoft Privacy Statement
Microsoft Privacy Principles
EU Data Boundary for the Microsoft Cloud
Microsoft Online Services Subprocessors List

Microsoft Subprocessors
Microsoft engages subprocessors where necessary to provide its services.
Organisations authorised to process personal data on Microsoft’s behalf are included in Microsoft’s Supplier Security and Privacy Assurance Program and published in Microsoft’s current list of Online Services Subprocessors.

Welche Dienste werden eingesetzt?

As part of our business operations, we primarily use the following Microsoft 365 services. This list may change as our business requirements or Microsoft 365 offerings evolve.
Outlook / Exchange Online
Used for:
Business email communication
Calendar management
Contact management
Teams
Used for:
Online meetings and video conferences
Chat communication
Telephony services
Collaboration with clients and business partners
Further details can be found under “Use of Microsoft Teams.”
Bookings
Used for:
Online appointment scheduling
OneDrive / SharePoint
Used for:
Storage of files
Document management
Controlled file sharing
Office Applications and Loop
Including:
Word
Excel
PowerPoint
OneNote
Loop
Used for creating, managing, and collaboratively editing documents, notes, and project content.
Planner and To Do
Used for:
Task management
Project planning
Forms
Used for:
Surveys
Feedback collection
Further details can be found under “Use of Microsoft Forms.”

Sharing Content with External Parties

As part of our collaboration with clients and business partners, selected content may be shared with external individuals outside UX Melange GmbH.
Examples include:
OneDrive files
SharePoint documents
Microsoft Loop pages
Shared documents within Microsoft Teams meetings
Sharing takes place exclusively through authenticated access granted to known email addresses.
In general:
Anonymous sharing is disabled.
Shared links are configured with expiration dates whenever possible.
External users receive only limited access rights.
Access is restricted to information necessary for the intended collaboration.
By accessing services made available to them, external users accept the applicable guest-user terms and conditions.

AI-Powered Features and Microsoft Copilot

Microsoft 365 may contain AI-powered features such as:
Suggested replies in Outlook
Meeting summaries in Teams
Other productivity-related AI capabilities
We limit the use of such features to what is operationally necessary and have implemented technical restrictions and protective measures wherever possible.
For example:
Anthropic-based models operating outside the EU data boundary have been disabled.
Only commercial Microsoft Copilot Business licences are used.
Processing takes place within the Microsoft EU Data Boundary.
Content data is not used by Microsoft to train foundation AI models.
Additional information can be found in Microsoft’s documentation regarding Enterprise Data Protection within Microsoft 365. Unternehmensdatenschutz in Microsoft 365

How Is Data Processed?

Depending on the service used, the following categories of personal data may be processed:
Communication Data
Emails
Chat messages
Meeting content
Telephone conversations
Contact Data
Name
Email address
Telephone number
Postal address
Contract-Related Data
Existing contractual relationships
Business interests
Contractual enquiries
Content Data
Files
Documents
Notes
Project-related content
Calendar and Booking Data
Meeting invitations
Appointments
Scheduling information
Metadata and Profile Data
IP addresses
Login information
Usernames
Meeting participation information
Service usage details
Technical Diagnostic Data
Log files
Service telemetry
Security-related records
We have restricted diagnostic data transmission to the minimum level required and have disabled optional diagnostic data wherever possible.
Processing may affect in particular:
Clients
Prospective clients
Business partners
Cooperation partners
Employees
Meeting participants
Individuals contacting us via email or booking services

Data Retention
The retention period for personal data depends on the specific purpose of processing and applicable statutory retention requirements.
Additionally, retention policies have been implemented within Microsoft 365 to support the automated deletion of data once applicable retention periods have expired.

Data Storage and Data Residency

All data is stored and processed on Microsoft servers located within the European Union.
Our Microsoft 365 tenant is configured for the Austria region.
Where transfers of personal data to the United States are necessary, Microsoft relies on:
The EU-US Data Privacy Framework
EU Standard Contractual Clauses (SCCs) pursuant to Article 46(2)(c) GDPR
A residual risk resulting from US legislation, particularly:
The CLOUD Act
FISA Section 702
cannot be completely excluded.
We have implemented technical and organisational measures designed to minimise such risks and enable GDPR-compliant use of Microsoft 365 services.
According to Microsoft, the storage and processing of European data have furthermore been progressively strengthened through the phased implementation of the EU Data Boundary initiative. Dokumentation EU-Datengrenze.

Technical and Organisational Measures (TOMs)

To protect personal data processed through Microsoft 365, we have implemented extensive technical and organisational measures in accordance with Article 32 GDPR.
These measures include, in particular:
Encryption of data during transmission and storage
Access control mechanisms
Authentication procedures
Data separation on devices
Restrictive sharing settings
Restrictive diagnostic data settings
Backup and recovery procedures
Comprehensive documentation of these technical and organisational measures is available upon request.

Purpose of Processing and Legal Basis

Purpose
Processing is carried out for the following purposes:
Business communication
Contract performance
Conducting meetings and video conferences
Appointment scheduling and management
Storage and collaborative editing of documents and project content
Contact management
Task and project planning
Surveys and feedback collection
Legal Basis (Art. 6(1)(b) GDPR)
Processing is necessary to carry out pre-contractual measures and to conclude and perform contracts.
Legal Basis (Art. 6(1)(f) GDPR)
Processing is based on our legitimate interest in efficient, secure, and professional communication, collaboration, and organisational processes.
Without these services, we would be unable to provide our services at the required quality level.
Legal Basis (Art. 6(1)(a) GDPR)
In exceptional circumstances, video conferences may be recorded after all participants have been informed in advance.
Any recording is carried out solely on the basis of explicit consent and may be withdrawn at any time.
Legal Basis (Art. 6(1)(c) GDPR)
Personal data is retained where necessary to fulfil statutory retention obligations, including obligations under Section 132 of the Austrian Federal Fiscal Code (BAO).

Use of Microsoft Teams

We primarily use Microsoft Teams for online communication and collaboration, including:
Individual meetings
Group meetings
Workshops
Training sessions
Seminars
Chat-based communication
Collaborative document editing
Whiteboards
Participation in meetings is possible both with and without a Microsoft account.
How Is Data Processed?
As a general rule, Microsoft Teams meetings are neither recorded nor transcribed.
Recordings are made only in exceptional cases where:
Requested by clients; or
Necessary for project-related purposes.
In such cases:
All participants are informed in advance.
Consent is obtained prior to recording.
Legal basis: Article 6(1)(a) GDPR.
Meeting recordings are deleted after project completion and, unless legal retention obligations apply, no later than twelve (12) months after creation.
Data Visible to Other Participants
The following information may be visible to other meeting participants:
Profile Data
Full name from Microsoft account or self-defined display name
Email address
Profile picture
Telephone number
Other account-related identification information
Meeting Data
Date and time
Meeting ID
Connection metadata
Participation information
Communication Data
Chat messages
Audio and video streams
Screen-sharing activities
Shared Content
Uploaded documents
Shared files
Whiteboards
Collaborative content and related activities
Technical Usage Data
Information necessary for conducting, administering, and troubleshooting meetings.
During online meetings, audio and video data from your device may be processed.
You remain in control of these functions at all times and may:
Disable your camera
Mute your microphone

Verwendung von Microsoft Forms

We use Microsoft Forms to conduct surveys and collect feedback.
Participation is always voluntary.
Legal basis: Article 6(1)(a) GDPR.
How Is Data Processed?
As a rule, surveys are configured to be anonymous.
Where anonymity is enabled, we do not store:
Participant names
Email addresses
IP addresses
Other information permitting direct identification
When using free-text fields, we kindly ask you not to disclose:
Sensitive personal information
Information that may allow identification of yourself or third parties
If a survey or feedback process requires personal identification for evaluation purposes, this will be clearly stated in the accompanying information.
Further information regarding data processing can be found in the section “Use of Microsoft 365.”
Purpose of Processing and Legal Basis
Purpose:
Collection of feedback, surveys, evaluations, and similar forms of participation.
Legal basis (Art. 6(1)(a) GDPR):
Processing is based on your voluntary consent.

Other Legal Notices

Disclaimer

The information provided on this website has been researched and prepared with the utmost care. However, we assume no liability for the accuracy, completeness, or timeliness of the content provided on this website.
Despite regular review and maintenance, errors or inaccuracies cannot be entirely excluded. Any errors or inconsistencies brought to our attention will be corrected without undue delay.
This website contains links to external websites. The respective operators of those websites are solely responsible for the processing of personal data on their platforms. We have no influence over the data processing activities conducted on those websites and assume no responsibility for their privacy practices.
Furthermore, we accept no liability for the content of external websites to which this website refers directly or indirectly through hyperlinks. As we have no control over the information provided on such third-party websites, we cannot assume responsibility for their content.
Despite implementing appropriate security measures and conducting regular reviews, we cannot guarantee that the content made available through this website is free from viruses, malware, or other harmful software. We accept no liability for any damage resulting from downloading data or using this website.
Users are responsible for implementing appropriate security measures, such as antivirus software and other protective technologies, to safeguard their own systems and devices.
We reserve the right to amend, supplement, or remove information provided on this website at any time and without prior notice. No legal claims or rights may be derived from the availability, completeness, or continued publication of such information.
Furthermore, we do not guarantee that the services provided through this website will be available at all times, uninterrupted, error-free, or free from technical disruptions.
All rights reserved.

Copyright

The content of this website, including but not limited to all text, images, graphics, logos, designs, trademarks, and other materials, is protected by copyright and other intellectual property laws.
In particular, the company logo of UX Melange GmbH and all associated branding elements are protected intellectual property.
The information provided on this website may only be used for private and non-commercial purposes.
Without the prior written consent of UX Melange GmbH, it is not permitted to:
Reproduce website content;
Store website content in electronic systems;
Modify or adapt website content;
Publish or distribute website content;
Use website content for commercial purposes;
Process website content through automated electronic systems.
This restriction applies regardless of whether the content is reproduced, stored, or distributed in electronic, digital, printed, or any other form.
Any unauthorised use of the content may constitute an infringement of copyright, trademark, or other applicable intellectual property rights and may result in legal action.
All rights reserved.


Last update: 17. September 2026