This notice explains how personal data is processed when you visit this website, under the General Data Protection Regulation (GDPR).
120 Ventures GmbH
Baumgasse 129, 1030 Vienna, Austria
Email: info@120.ventures
This website tells fertility clinics and other healthcare organisations about the Kelia service. It creates no user accounts and collects no health data. The Kelia application itself is provided through partner clinics and is governed separately — see section 12.
We process personal data under Article 6(1) GDPR — in particular point (a) consent, point (b) steps taken at your request prior to entering into a contract, and point (f) our legitimate interest in a secure and functioning website.
In line with Article 32 GDPR we apply appropriate technical and organisational measures, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing. These include in particular:
When you open the website, your browser transmits technically necessary data that our hosting provider may store in server log files: IP address, date and time of access, the page requested, the volume of data transferred, the referrer URL and browser and operating system details. Legal basis: Article 6(1)(f) GDPR. The data is deleted after a short period unless it is needed to investigate misuse.
All fonts are self-hosted on our own server. Loading a page opens no connection to third-party servers and transmits no data to third parties.
If you contact us by email, we process what you send us in order to deal with your enquiry. Legal basis: Article 6(1)(b) and (f) GDPR. We keep this data for as long as handling the matter requires, or as long as statutory retention obligations apply.
On the start page you can request a non-binding call. We process: your name, your clinic or organisation, your email address and, optionally, your message. For security reasons we also store a truncated IP prefix (the last octet of your IP address is replaced with a zero) and your browser identification. The full IP address is not stored.
Legal basis: your consent under Article 6(1)(a) GDPR, given when you submit the form, together with Article 6(1)(b) GDPR (pre-contractual steps). You can withdraw your consent at any time by writing to info@120.ventures; this does not affect the lawfulness of processing carried out before the withdrawal.
Retention: we delete enquiry data once it is no longer needed for the purpose, and at the latest 24 months after the last contact, unless statutory retention obligations require otherwise.
Processor: the form and database run on Supabase. Data is stored exclusively in the eu-west-1 (Ireland) region. No transfer to a third country takes place.
No health data: please do not send health data or any patient data through this form. It is intended solely for business contact by organisations.
Where we stand: we use Google Tag Manager to manage embedded services centrally. It loads when the page opens, sets no cookies of its own and collects no personal data (details below). Through it, the analytics service PostHog is delivered in the “Statistics” category — and only after your explicit consent. The “Marketing” category contains no service at all: no data goes to advertising networks, there is no retargeting and there are no advertising pixels.
Consent management: on your first visit you are shown a dialogue in which you decide about the “Statistics” and “Marketing” categories. Both are off by default and are only activated after your explicit agreement (opt-in).
Legal basis for storing and reading information on your device: Article 5(3) of the ePrivacy Directive 2002/58/EC as implemented in your country, together with Article 6(1)(a) GDPR. This applies not only to cookies in the narrow sense but to any storing or reading of information on your device — including the use of localStorage and sessionStorage, as happens here.
| Category | Purpose | Currently used | Legal basis |
|---|---|---|---|
| Essential | Storing your cookie choice | no third parties | Article 6(1)(f) GDPR; strictly necessary under Article 5(3) ePrivacy Directive |
| Statistics | Analytics (page views, click paths) | our own analysis on Supabase (EU, Ireland); PostHog (PostHog Inc., EU cloud) | Article 6(1)(a) GDPR; Article 5(3) ePrivacy Directive |
| Marketing | Advertising and measuring its performance | none at present | Article 6(1)(a) GDPR |
| Tag management (not a consent category) | Central management and delivery of the services above | Google Tag Manager (Google Ireland Limited) — sets no cookies itself | Article 6(1)(f) GDPR (legitimate interest in efficient tag management) |
If you enable “Statistics”: only then is a random session identifier placed in your browser's sessionStorage and are page views and button clicks recorded. We store browser, operating system, device type, screen resolution, language, time zone, referring page and a truncated IP prefix. This analysis runs on our own infrastructure in Ireland. Without your consent none of this processing takes place — the session identifier is not even created.
Google Tag Manager: provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Tag Manager is a tool for managing website tags through one interface. It sets no cookies itself and collects no personal data; it only triggers the tags embedded through it — in our case solely the analytics service named below. Tag Manager itself loads when the page opens; the services it controls run only after your consent. We use Google Consent Mode v2 for this. When Tag Manager loads, your IP address is transmitted to Google; onward transfer to Google LLC in the United States cannot be ruled out (see section 11). Legal basis: Article 6(1)(f) GDPR (legitimate interest in efficient tag management). You may object under Article 21 GDPR. More: policies.google.com/privacy.
PostHog: provided by PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. We use the EU cloud edition only; data is processed on European servers. A transfer to the United States cannot be fully ruled out; in that case processing relies on the European Commission's standard contractual clauses under Article 46 GDPR (see section 11). PostHog records page views and individual interactions for us (a button click, a selection in the journey chart, submitting the contact form) and stores a pseudonymous identifier in your browser. Data processed: IP address (pseudonymised), browser type, operating system, device type, pages visited, click behaviour, referring page. We have deliberately limited what is collected: no automatic capture of every click, no session recording, no person profiles. No data is passed to advertising networks. Here too: without your consent, PostHog is not loaded. Retention: governed by the provider's defaults and ending at the latest when you withdraw your consent; you can also delete the identifier at any time through your browser settings. More: posthog.com/privacy.
What is stored: your cookie choice is kept locally in your browser (localStorage, key kelia-consent), together with a timestamp and a version number. This information does not leave your device.
Withdrawal: you can change or withdraw your consent at any time with effect for the future, through the “Cookie settings” link in the footer of every page. You can also delete the locally stored data through your browser settings.
Switzerland belongs neither to the European Union nor to the European Economic Area. For people in Switzerland the revised Federal Act on Data Protection (revFADP) applies in addition. We apply the principles described here uniformly; for visitors in Switzerland the GDPR articles cited should be read as the corresponding provisions of the revFADP. No representative under Article 14 revFADP has been appointed: that obligation presupposes extensive, regular processing carrying a high risk, and this website collects no health data, creates no user accounts and processes essentially business contact details.
Where we process data in a third country — that is, outside the European Union or the European Economic Area — or where this happens through third-party services, it takes place only in accordance with the law.
Where the European Commission has adopted an adequacy decision (Article 45 GDPR), transfers rely on that basis. For the United States we rely on the EU-US Data Privacy Framework (DPF) where the recipient holds a valid DPF certification. Google is certified under the DPF.
Otherwise transfers rely on the European Commission's standard contractual clauses (Article 46(2)(c) GDPR) or on your explicit consent (Article 49(1)(a) GDPR).
In concrete terms this concerns two services: Google Ireland Limited (Google Tag Manager, with Google LLC in the United States as parent company) and PostHog Inc. (USA), of which we use the EU cloud edition. Both load only after your consent. If you do not consent, no such transfer takes place.
The Kelia application for patients is provided through partner clinics and is covered by separate data protection arrangements agreed with each clinic. This notice covers this website only.
Under the GDPR you have the right to:
For people in Switzerland, the corresponding rights follow from Article 25 et seq. revFADP.
An informal message to info@120.ventures is enough to exercise any of these rights.
You have the right to lodge a complaint with a supervisory authority. The authority at our establishment is competent, but under Article 77 GDPR you may also approach the authority where you live or work.
Austria (our establishment):
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
www.dsb.gv.at (opens in a new tab)
Elsewhere in the EEA: the European Data Protection Board maintains a list of national authorities: edpb.europa.eu (opens in a new tab)
Switzerland:
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern
www.edoeb.admin.ch (opens in a new tab)
Last updated: September 2026