Post Logo positioned on a street

Privacy policy Post Online Services

Privacy policy Post Online Services

Information about data use pursuant to the General Data Protection Regulation (GDPR):

Mandatory information according to Art 13 and 14 GDPR of a purely informative nature.
Updated: August 2026

1. What information is available on this page?

Österreichische Post AG (hereinafter referred to as "Austrian Post", "we", "us") processes your personal data in full compliance with the provisions of data protection law, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act and all other applicable laws.

In this document, you will find information about data processing performed in relation to our customer management. This document includes the following sections:

  • To whom is this information addressed? (item 2)
  • Who is responsible for the processing of your data? (item 3)
  • Information on possible data processing operations (item 4), in particular on
    • Post Online Accounts: Post.at, Action Finder, Philatelists (4.1 - 4.4)
    • The e-letter service (4.5)
    • The "Meine Marke" service (4.6)
    • Digital Stamps (Cryptostamps) (4.7)
    • The Post Kartenstudio (4.8)
  • With whom are we allowed to share your data? (item 5)
  • Automated decision making and profiling (item 6)
  • What rights do you have? (item 7)
  • How can you get in touch with us? (item 8)
  • Use of technical interfaces (so-called Software Develepment Kits hereinafter "SDK") in the Post App (item 9)

Information about the use of cookies on our websites is available at Data protection.

If you are looking for information on specific Post products or services such as mail and parcel delivery, advertising and marketing or business customer relations, you will find it in the selection field on the right-hand side. If you need printed copies of the information provided on this page or on additional pages, please contact the staff at our service locations.

2. To whom is this information addressed?

This privacy policy is intended for all of our customers who use the Austrian Post online services.

3. Who is responsible for the processing of your data?

The responsible party for data processing described on this page is

Österreichische Post AG,
Rochusplatz 1,
1030 Vienna,
Austria

4. Information about possible data processing

4.1. Austrian Post online accounts (private customers)
If you create an Austrian Post online Account, we may process your data as part of the registration and account creation process.

Which of your data can we process for this purpose?
For this purpose, we process the following data:
address data, contact details, personal master data

What is the legal basis for this processing?
The legal basis for this processing is your acceptance of the Terms of Use for the respective product or service (Article 6(1)(b) GDPR).

How long can your data be stored?
Your data will be deleted no later than three years after your account becomes inactive.

With whom are we allowed to share your data?
Your data may be disclosed to the following categories of recipients for the purpose of registering for an Austrian Post online account:

Processors

Other information about this processing:
If you do not provide the above data, it will not be possible to conclude a contract for an online account with Austrian Post.

4.2. Identification of online accounts (private customers)
We may process your data to verify the identity associated with your online account for access to additional Austrian Post products and services. Below you will find information about how your data is processed as part of this identification process. Further information about the identification process is available here: 
Photo identification – Austrian Post (login to your Austrian Post account required).

Which of your data can we process for this purpose?
For this purpose, we process the following data:
Personal master data (name, date of birth) and login and account data (user ID) from your Austrian Post online account; your identification status and identity document data obtained during the identity verification process (issuing authority, type of identity document, document number, date of issue);  identity document data, where provided; biometric data (facial recognition) for identification purposes, where provided by you.

What is the legal basis for this processing?
The legal basis for this processing is

  • the performance of a contract based on the Terms of Use for the respective product or service (Article 6(1)(b) GDPR);
  • our legitimate interests in retaining the identity document data obtained (to document reliable identification and to defend against warranty and/or compensation claims by senders – Article 6(1)(f) GDPR);
  • where you provide image data for biometric identification, we process this data solely on the basis of your explicit consent pursuant to Article 9(2)(a) GDPR.

You may withdraw your consent at any time, without giving reasons, with effect for the future. Please note that the biometric comparison is carried out immediately and in real time once the photos have been uploaded. Biometric data is not stored. It is therefore no longer possible to withdraw your consent once all photos have been uploaded.
Further information on how to exercise your data subject rights can be found in item 8 of our general data protection policy:
post.at/datenschutz. Once you have been successfully identified, for security reasons you will no longer be able to change your personal master data (name, date of birth, title) yourself in your Austrian Post account.   If any changes are required, our Austrian Post Customer Service team can assist you.

How long will your data be stored?
Your uploaded photos will only be stored for a maximum of 72 hours for the purposes of manual review and troubleshooting.   The identity document data obtained during the identity verification process will be deleted no later than three years after the associated Austrian Post account becomes inactive or when you delete the account yourself (for information on how to delete your Austrian Post online account, please refer to the “General Questions” section here).

With whom are we allowed to share your data?
Your data may be disclosed to the following categories of recipients for the purpose of identifying your Austrian Post online account: 

Processors

Your identity document data is matched against your Austrian Post online account exclusively by us.

Other information about this processing:
If you do not provide the above data, it will not be possible to verify the identity associated with your Austrian Post online account. 
If any errors occur during the identification process or you do not wish to use this verification method, you can verify your identity in person with our staff at an Austrian Post branch or use your mobile phone signature (Handy-Signatur). The provision of your data is neither contractually nor legally required. If you do not provide your data for biometric identity verification, you can use the other methods mentioned above or purchase the desired (additional) services directly at one of our branches without an identified Austrian Post account.

4.3. Online accounts (philatelists)
We process your data when you use the online shop and when you order goods from the philately online shop.

Which of your data can we process for this purpose?
For this purpose, we may process the following data:
personal master data, contact data, address data

What is the legal basis for this processing?
The legal basis  this processing is

  • the contract concluded when purchasing a product from the philately online shop (Article 6(1)(b) GDPR); and
  • our legitimate interests in ensuring that purchases are processed properly (Article 6(1)(b) GDPR).

How long can your data be stored?
Your data will be deleted for the purposes of using the online shop and ordering goods, depending on the relevant data category, no later than three years after your account becomes inactive or 72 hours after termination.

For card printing purposes, your data may be transmitted to the following categories of recipients: 

Processors

Other information about this processing:
You are under no contractual or legal obligation to provide your data for the creation and management of online accounts for philatelists. The above data is required to create an account. If you do not provide us with the above data, an online account for philatelists cannot be created.

4.4. Aktionsfinder discount finder (online service)
We process your data in connection with the Aktionsfinder service (online service) in order to provide you with the full range of features offered by this service in accordance with the Aktionsfinder General Terms of Use.

Which of your data can we process for this purpose?
For this purpose, we may process the following data:
Personal master data, contact details, login and account data, internet and online usage data

What is the legal basis for this processing?
The legal basis for this processing is the performance of a contract and taking steps prior to entering into a contract (Article 6(1)(b) GDPR) in order to provide the Aktionsfinder service (online service).

How long can your data be stored?
Your data will be deleted no later than one week after termination of the contract or, at the latest, three years after inactivity.

With whom are we allowed to share your data?
Your data will be disclosed to processors for storage purposes.

Other information about this processing:
You are under no contractual or legal obligation to provide your data for the Aktionsfinder discount finder (online service). The contract for the Aktionsfinder service (online service) can only be concluded and performed if you provide your data in advance. If you do not provide the necessary data, no contract can be concluded or the service cannot be provided.

4.5. E-letter recipients
We may process your data in connection with the E-Letter product in order to enable you to receive electronic items and to upload and categorise your important documents.

Which of your data can we process for this purpose?
For this purpose, we may process the following data:
Address data, personal master data, login and account data, other documents

What is the legal basis for this processing?
The legal basis for this processing is the performance of a contract and taking steps prior to entering into a contract pursuant to Article 6(1)(b) GDPR, in order to provide the E-Letter service.

How long can your data be stored?
Your data will be deleted no later than 30 days after termination or three years after inactivity.

With whom are we allowed to share your data?
Your data may be disclosed to the following categories of recipients for the purpose of processing E-Letter:

Processors

Other information about this processing:
You are under no contractual or legal obligation to provide your data for the  e-letter service. The contract for the E-Letter service can only be concluded and performed if you provide your data in advance. If you do not provide the necessary data, no contract can be concluded or the E-Letter service cannot be provided.

4.6. Meine Marke personalised stamps
We process your data in connection with the purchase and delivery of your customised stamp.

Which of your data may we process for this purpose? 
For this purpose, we process the following data: 
Personal master data, address data, contact details, order and invoice data, image, audio and video data, login and account data, delivery notes

What is the legal basis for this processing?
The legal basis for this processing is

  • the contract concluded when purchasing a “Meine Marke” product (Article 6(1)(b) GDPR);
  • our legitimate interests in ensuring that the purchase is processed properly (Article 6(1)(b) GDPR).

How long can your data be stored?
Your data will be deleted for the purpose of purchasing and delivering your personalised stamp no later than two years after receipt by the Austrian State Printing House. In the Collectors’ Exchange, the data will be deleted no later than three working days after receipt of the withdrawal.

With whom are we allowed to share your data?
Your data may be disclosed to the following recipients/categories of recipients for the purpose of purchasing and delivering your personalised stamp:

              Processors

Other information about this processing:
You are under no contractual or legal obligation to provide your data for the creation of your personalised stamp. The aforementioned data are required for the conclusion of a contract. If you do not provide the aforementioned data, we will not be able to provide the "Meine Marke personalised stamps" service.

4.7. Digital stamps
We may process your data in connection with the purchase of your Crypto Stamp and, subsequently, when you order the associated physical stamp.

Which of your data can we process for this purpose?
For this purpose, we process the following data:
Personal master data, address data, payment data, contact details, order and invoice data, item data

What is the legal basis for this processing?
The legal basis  this processing is

  • the contract for the “Digital Stamp” product that we have entered into with you (Article 6(1)(b) GDPR);
  • and our legitimate interests in ensuring that the product is purchased properly (Article 6(1)(b) GDPR).

How long can your data be stored?

  • If you request your physical Crypto Stamp via the Onchain Store,
  • your data will be deleted for the purpose of delivering your Crypto Stamp no later than three business days after placing your order.
  • If you purchase your physical Crypto Stamp from the Austrian Post online shop, your data will be retained for the purpose of delivering your Crypto Stamp in accordance with the statutory retention periods set out in Section 132 of the Austrian Federal Tax Code and Section 212 of the Austrian Commercial Code. Where there are additional legal grounds for retention or pending legal proceedings, the relevant data may be retained for a longer period where necessary.

With whom are we allowed to share your data?
Your data may be disclosed to the following categories of recipients for the purpose of delivering your physical Crypto Stamp:

Processors

Other information about this processing:
You are under no contractual or legal obligation to provide your data for the delivery of the physical stamp. The aforementioned data are required for the conclusion of a contract. If you do not provide the aforementioned data, we will not be able to provide the "digital stamp" service.

5. With whom are we allowed to share your data?

You can find out which categories of recipients your data may be transferred to in the section "Information on possible data processing". You will find a detailed description of the recipients or categories of recipients of Austrian post in section 5 under Data protection.

6. Automated decision making and profiling

In general, no automated decision-making or profiling pursuant to Art 22 (1) and (4) GDPR takes place in connection with the processing of data by Austrian post.

7. What rights do you have?

You have the right of access to your personal data that we process as a controller. For more information, please refer to Article 15 of the GDPR.

Under certain conditions, you may request the restriction of processing as well as the rectification and deletion of your personal data. For more information, please refer to Articles 16 to 19 of the GDPR.

In addition, under certain conditions, you also have the right to data portability, meaning that we would give you all personal data you have disclosed to us in a structured, standard, and machine processable format. For more information, please refer to Article 20 of the GDPR.

As a data subject, you have the right to object to the use of your data if the processing serves the purpose of direct marketing. In addition, you have the right to object at any time to the processing of your data carried out in the legitimate interests of Austrian Post or third parties if reasons arise from your specific circumstances. For more information, please refer to Article 21 of the GDPR. The processing of your personal data may be based on your consent pursuant to Art. 6 (1) (a) of the GDPR. You can revoke this consent at any time without the need to state reasons with future effect. Until then, we will lawfully process your data.

For information about the legal basis of our data processing, please see item 4 ("Information about possible data processing").

In addition, you have the option of filing a complaint with the Austrian Data Protection Authority:

Austrian Data Protection Authority,
Barichgasse 40-42,
1030 Vienna
Austria

Telephone: +43 1 52 152-0
E-mail: dsb@dsb.gv.at

8. How can you get in touch with us?

Would you like to exercise your rights or do you have further questions, suggestions, or feedback?
To contact Austrian Post's data protection officer or to exercise your rights, please use one of the contact options listed under item 8 of our general data protection policy: post.at/Datenschutz.

9. Use of technical interfaces (so-called Software Develepment Kits hereinafter "SDK") in the Post App:

For the Österreichische Post app, we rely on different technologies (so-called software development kits, hereinafter referred to as "SDK") to make the app more user friendly. A software development kit (SDK) is a collection of software development tools in one installable package. They facilitate the creation of applications by having compiler, debugger and perhaps a software framework. They are normally specific to a hardware platform and operating system combination. The following SDKs are used for the Österreichische Post app:
Firebase Analytics and tag manager: We use the Firebase Analytics service by Google to create analysis reports and user analyses. When this service is used, data (IP address) are processed and shared with the provider (Google).
Firebase Crashlytics: We use the Firebase Crashlytics service by Google to receive crash reports and use them to correct any mistakes that may have been identified. When this service is used, data (IP address) are processed and shared with the provider (Google).
Firebase Messaging: We use the Firebase messaging service by Google to send push notifications to our users. When this service is used, data (IP address) are processed and shared with the provider (Google).
Firebase Performance: We use the Firebase performance service by Google to measure our app's performance and improve it on an ongoing basis When this service is used, data (IP address) are processed and shared with the provider (Google).
Firebase Remote Config: We use the Firebase remote config service by Google to make changes to the app via remote access. Among others, we use it to activate maintenance pages or deactivate specific app versions. When this service is used, data (IP address) are processed and shared with the provider (Google).
(Android only) Google Play Core: We use the Google Play Core services by Google to display update notifications in the app. When this service is used, data (IP address) are processed and shared with the provider (Google).
Install Referrer: We use the Install Referrer service by Google to identify the origin of a verification. When this service is used, data (IP address) are processed and shared with the provider (Google).
Google Maps / Apple Maps: We use Google Maps (Android) and Apple Aps (iOS) to offer certain app functions such as our branch locator and parcel forwarding. When this service is used, data (IP address, device's location data after approval) are processed and shared with the provider (Google/Apple).
FaceID / TouchID / Fingerprint: We use FaceID and TouchID by Apple (iOS) and fingerprint services by Google (Android) to protect e-postboxes if needed. When you choose one of these security options, data (IP address, encrypted biometric data) are processed and shared with the provider (Google/Apple).

(iOS only) MessageUI: We use the MessageUI service by Apple to send e-mails from the app in the case of support requests. When this service is used, data (IP address) are processed and shared with the provider (Google).