Privacy Policy
Introduction and Overview
We have prepared this Privacy Policy (version 05.01.2025-122926758) in order to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (hereinafter referred to as “data”) we, as the controller – and the processors commissioned by us (e.g. providers) – process, will process in the future, and what lawful options are available to you. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal terminology. This Privacy Policy, however, is intended to describe the most important matters to you as simply and transparently as possible. Where this contributes to transparency, technical terms are explained in a reader-friendly manner, links to further information are provided and graphics are used. We therefore inform you in clear and simple language that, as part of our business activities, we only process personal data where there is an appropriate legal basis for doing so. This would certainly not be possible if we provided explanations that were as brief, unclear and legally technical as is often standard on the Internet when it comes to data protection. We hope you find the following explanations interesting and informative and perhaps discover some information you were not previously aware of.
If you still have any questions, please contact the responsible entity named below or in the Legal Notice, follow the links provided and consult further information on third-party websites. Our contact details can, of course, also be found in the Legal Notice.
Scope
This Privacy Policy applies to all personal data processed by us within the company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information within the meaning of Article 4(1) GDPR, such as a person’s name, email address and postal address. The processing of personal data enables us to offer and invoice our services and products, whether online or offline.
The scope of this Privacy Policy includes:
-
all online presences (websites, online shops) operated by us
-
social media presences and email communication
-
mobile apps for smartphones and other devices
In short: This Privacy Policy applies to all areas in which personal data is processed systematically within the company via the channels mentioned above. Should we enter into legal relationships with you outside these channels, we will inform you separately where appropriate.
Legal Bases
In the following Privacy Policy, we provide transparent information about the legal principles and regulations, i.e. the legal bases under the General Data Protection Regulation, which allow us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read the EU General Data Protection Regulation online on EUR-Lex, the gateway to EU law, at:
https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679
We process your data only if at least one of the following conditions applies:
Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be storing the data you enter into a contact form.
Contract (Article 6(1)(b) GDPR): In order to fulfil a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase agreement with you, we require personal information beforehand.
Legal obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally required to retain invoices for accounting purposes. These generally contain personal data.
Legitimate interests (Article 6(1)(f) GDPR): Where we have legitimate interests that do not override your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and economically efficiently. This processing therefore constitutes a legitimate interest.
Other conditions, such as performing tasks in the public interest, exercising official authority or protecting vital interests, generally do not apply to us. If such a legal basis should nevertheless be relevant, it will be indicated at the appropriate point.
In addition to the EU Regulation, national laws also apply:
In Austria, this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), abbreviated as DSG.
In Germany, the Federal Data Protection Act (BDSG) applies.
If further regional or national laws apply, we will inform you about them in the following sections.
Storage Period
As a general principle, we store personal data only for as long as is absolutely necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases, we are legally obliged to retain certain data even after the original purpose has ceased to exist, for example for accounting purposes.
If you request the deletion of your data or withdraw your consent to data processing, the data will be deleted as quickly as possible, provided that there is no legal obligation to retain it.
Where further information is available, we will inform you below about the specific duration of the respective data processing.
Rights under the General Data Protection Regulation
In accordance with Articles 13 and 14 GDPR, we inform you about the following rights to which you are entitled in order to ensure fair and transparent data processing:
Under Article 15 GDPR, you have the right to obtain information as to whether we process data concerning you. If this is the case, you have the right to receive a copy of the data and to obtain the following information:
-
the purposes for which we carry out the processing;
-
the categories, i.e. types, of data being processed;
-
who receives this data and, if the data is transferred to third countries, how its security is guaranteed;
-
how long the data will be stored;
-
the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
-
that you may lodge a complaint with a supervisory authority (links to these authorities can be found below);
-
the source of the data if we did not collect it from you;
-
whether profiling is carried out, i.e. whether data is automatically evaluated in order to create a personal profile of you.
Under Article 16 GDPR, you have the right to rectification of data, which means that we must correct your data if you identify any errors.
Under Article 17 GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the deletion of your data.
Under Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but may no longer use it.
Under Article 20 GDPR, you have the right to data portability, which means that, upon request, we will provide your data to you in a commonly used format.
Under Article 21 GDPR, you have the right to object, which, if successfully exercised, will result in a change to the processing.
If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interests), you may object to the processing. We will then examine as quickly as possible whether we can legally comply with this objection.
If data is used for direct marketing purposes, you may object to this type of data processing at any time. We may then no longer use your data for direct marketing.
If data is used for profiling, you may object to this type of data processing at any time. We may then no longer use your data for profiling.
Under Article 22 GDPR, under certain circumstances, you have the right not to be subject to a decision based solely on automated processing (for example profiling).
Under Article 77 GDPR, you have the right to lodge a complaint. This means that you may lodge a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.
In short: You have rights – do not hesitate to contact the responsible entity listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been infringed, you may lodge a complaint with the supervisory authority. In Austria, this is the Austrian Data Protection Authority, whose website can be found at:
In Germany, each federal state has its own data protection authority. For further information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI).
The following local data protection authority is responsible for our company:
Austrian Data Protection Authority
Head: Dr. Matthias Schmidl
Address: Barichgasse 40-42, 1030 Vienna
Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/
Data Transfers to Third Countries
We transfer or process data in countries outside the scope of the GDPR (third countries) only if you consent to such processing or if another legal permission exists. This applies in particular where processing is required by law or is necessary for the performance of a contractual relationship, and in all cases only to the extent generally permitted.
In most cases, your consent is the primary reason why we have data processed in third countries. The processing of personal data in third countries such as the USA, where many software manufacturers provide services and operate servers, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that, according to the European Court of Justice, an adequate level of protection for data transfers to the USA currently exists only if a US company processing personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework.
More information can be found at:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Data processing by US services that are not active participants in the EU-US Data Privacy Framework may result in data not being processed and stored anonymously. Furthermore, US government authorities may, under certain circumstances, have access to individual data. It may also occur that collected data is linked to data from other services provided by the same provider if you have a corresponding user account.
Where possible, we try to use server locations within the EU if this option is offered.
Where applicable, we provide more detailed information about transfers of data to third countries in the relevant sections of this Privacy Policy.
Security of Data Processing
To protect personal data, we have implemented both technical and organisational measures. Wherever possible, we encrypt or pseudonymise personal data. In doing so, within the scope of our capabilities, we make it as difficult as possible for third parties to derive personal information from our data.
Article 25 GDPR refers to “data protection by design and by default” and means that both software (e.g. forms) and hardware (e.g. access to server rooms) should always be designed with security in mind and appropriate measures should be implemented. Where necessary, we will discuss specific measures below.
Cookies
Cookies Summary
👥 Data subjects: Website visitors
🤝 Purpose: Depends on the respective cookie. Further details can be found below or from the manufacturer of the software that sets the cookie.
📓 Data processed: Depends on the respective cookie. Further details can be found below or from the manufacturer of the software that sets the cookie.
📅 Storage period: Depends on the respective cookie and may range from hours to years.
⚖️ Legal bases: Article 6(1)(a) GDPR (consent), Article 6(1)(f) GDPR (legitimate interests)
What are cookies?
Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used so that you can better understand the following Privacy Policy.
Whenever you browse the Internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: cookies are genuinely useful little helpers. Almost all websites use cookies. More precisely, these are HTTP cookies, as there are also other types of cookies for different areas of application.
HTTP cookies are small files stored on your computer by our website. These cookie files are automatically placed in your browser’s cookie folder, effectively the “memory” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data, such as language or personal website settings. When you visit our website again, your browser sends the “user-related” information back to our website. Thanks to cookies, our website knows who you are and can provide you with the settings you are accustomed to.
In some browsers, each cookie has its own file, while in others, such as Firefox, all cookies are stored in a single file.
The following graphic illustrates a possible interaction between a web browser, such as Chrome, and a web server. The web browser requests a website and receives a cookie from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our website, while third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be assessed individually because each cookie stores different data. The expiry time of a cookie also varies from a few minutes to several years.
Cookies are not software programs and do not contain viruses, Trojans or other “malware”. Cookies also cannot access information on your computer.
Cookie data may, for example, look like this:
Name: _ga
Value: GA1.2.1326744211.152122926758-9
Purpose: Distinguishing website visitors
Expiry date: after 2 years
A browser should support at least the following minimum capacities:
-
At least 4096 bytes per cookie
-
At least 50 cookies per domain
-
At least 3000 cookies in total
What types of cookies are there?
The specific cookies we use depend on the services being used and are explained in the following sections of this Privacy Policy. At this point, we would like to briefly discuss the different types of HTTP cookies.
Four types of cookies can be distinguished:
Essential Cookies
These cookies are necessary to ensure basic website functionality. For example, these cookies are required when a user places a product in their shopping cart, continues browsing other pages and only later proceeds to checkout. These cookies prevent the shopping cart from being deleted even if the user closes the browser window.
Functional Cookies
These cookies collect information about user behaviour and whether the user receives any error messages. They are also used to measure loading times and website behaviour in different browsers.
Preference Cookies
These cookies improve user-friendliness. For example, entered locations, font sizes or form data may be stored.
Advertising Cookies
These cookies are also known as targeting cookies. They are used to provide users with individually tailored advertising. This can be very practical, but also very annoying.
Usually, when you visit a website for the first time, you are asked which of these types of cookies you wish to allow. Naturally, this decision is also stored in a cookie.
If you would like to learn more about cookies and do not mind reading technical documentation, we recommend:
https://datatracker.ietf.org/doc/html/rfc6265
the Internet Engineering Task Force (IETF) Request for Comments entitled “HTTP State Management Mechanism”.
Purpose of Processing via Cookies
The purpose ultimately depends on the respective cookie. Further details can be found below or from the manufacturer of the software that sets the cookie.
What data is processed?
Cookies are small helpers used for many different tasks. Unfortunately, it is not possible to generalise which data is stored in cookies, but we will inform you about the data processed or stored as part of the following Privacy Policy.
Storage Period of Cookies
The storage period depends on the respective cookie and is specified in more detail below. Some cookies are deleted after less than an hour, while others may remain stored on a computer for several years.
You also have control over the storage period. You can manually delete all cookies via your browser at any time (see also “Right to Object” below). Furthermore, cookies based on consent will be deleted at the latest when you withdraw your consent, without affecting the lawfulness of storage up to that point.
Right to Object – How Can I Delete Cookies?
You decide how and whether you want to use cookies. Regardless of which service or website the cookies originate from, you always have the option of deleting, disabling or only partially allowing cookies. For example, you can block third-party cookies while allowing all other cookies.
If you want to find out which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find this in your browser settings:
Chrome: Delete, enable and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Delete cookies to remove data that websites have stored on your computer
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete and manage cookies
If you generally do not want cookies, you can configure your browser so that it always informs you when a cookie is about to be set. This allows you to decide for each individual cookie whether or not to permit it.
The procedure differs depending on the browser. The best approach is to search Google for instructions using terms such as “delete cookies Chrome” or “disable cookies Chrome” if you use the Chrome browser.
Legal Basis
The so-called “Cookie Directives” have existed since 2009. They stipulate that storing cookies requires your consent (Article 6(1)(a) GDPR). However, there are still very different implementations of these directives among EU countries.
In Austria, this directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the Cookie Directives were not implemented as national law in this form. Instead, implementation was largely carried out through Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.
For strictly necessary cookies, even where consent has not been provided, legitimate interests exist (Article 6(1)(f) GDPR), which in most cases are of an economic nature. We want to provide visitors to our website with a pleasant user experience, and certain cookies are often absolutely necessary for this purpose.
Where non-essential cookies are used, this only takes place with your consent. The legal basis in this respect is Article 6(1)(a) GDPR.
The following sections provide more detailed information about the use of cookies where the software used employs cookies.
Website Builder Systems – Introduction
Website Builder Systems Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimisation of our services
📓 Data processed: Data such as technical usage information, including browser activity, clickstream activity, session heatmaps, as well as contact details, IP address or geographical location. Further details can be found below in this Privacy Policy and in the privacy policies of the respective providers.
📅 Storage period: Depends on the provider
⚖️ Legal bases: Article 6(1)(f) GDPR (legitimate interests), Article 6(1)(a) GDPR (consent)
What are website builder systems?
We use a website builder system for our website. Website builder systems are special forms of content management systems (CMS). A website builder enables website operators to create a website very easily and without programming knowledge.
In many cases, web hosting providers also offer website builder systems. By using a website builder system, personal data relating to you may also be collected, stored and processed.
In this Privacy Policy, we provide general information about data processing by website builder systems. More detailed information can be found in the privacy policy of the respective provider.
Why do we use website builder systems for our website?
The greatest advantage of a website builder system is its ease of use. We want to provide you with a clear, simple and well-organised website that we can easily operate and maintain ourselves without external support.
Website builder systems now offer many useful functions that we can use without programming knowledge. This enables us to design our online presence according to our requirements and provide you with an informative and pleasant experience on our website.
What data is stored by a website builder system?
Exactly which data is stored naturally depends on the website builder system being used. Each provider processes and collects different data relating to website visitors.
As a rule, however, technical usage information is collected, such as operating system, browser, screen resolution, language and keyboard settings, hosting provider and the date of your website visit.
Tracking data may also be processed, such as browser activity, clickstream activity, session heatmaps and similar information.
In addition, personal data may be collected and stored. This usually includes contact information such as email address, telephone number (if you have provided it), IP address and geographical location data.
The exact data stored can be found in the privacy policy of the respective provider.
How long and where is the data stored?
Where further information is available, we will provide details below about the duration of data processing in connection with the website builder system used.
Detailed information can be found in the provider’s privacy policy.
As a general rule, we process personal data only for as long as is absolutely necessary to provide our services and products. The provider may store data according to its own policies, over which we have no influence.
Right to Object
You always have the right to access, rectify and erase your personal data. If you have any questions, you can also contact the responsible persons at the provider of the website builder system used at any time. Contact details can be found either in our Privacy Policy or on the respective provider’s website.
Cookies used by providers for their functions can be deleted, disabled or managed in your browser. The exact procedure depends on the browser you use. Please note, however, that some functions may then no longer operate as usual.
Legal Basis
We have a legitimate interest in using a website builder system in order to optimise our online services and present them to you efficiently and in a user-friendly manner. The corresponding legal basis is Article 6(1)(f) GDPR (legitimate interests). Nevertheless, we only use the website builder insofar as you have given your consent where such consent is required.
Where data processing is not strictly necessary for the operation of the website, the data is processed only on the basis of your consent. This applies in particular to tracking activities. The legal basis in this respect is Article 6(1)(a) GDPR.
With this Privacy Policy, we have provided you with the most important general information regarding data processing. If you would like more detailed information, further information – where available – can be found in the following section or in the privacy policy of the respective provider.
Explanation of Terms Used
We always endeavour to make our Privacy Policy as clear and understandable as possible. However, this is not always easy, particularly when dealing with technical and legal topics.
It often makes sense to use legal terms (such as personal data) or certain technical terms (such as cookies or IP address). However, we do not want to use these without explanation.
Below you will find an alphabetical list of important terms used in this Privacy Policy that may not yet have been explained sufficiently. Where these terms are taken from the GDPR and constitute legal definitions, we will also reproduce the GDPR wording and, where appropriate, provide our own explanations.
Processor
Definition according to Article 4 GDPR
For the purposes of this Regulation:
“processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Explanation: As a company and website owner, we are responsible for all data that we process concerning you. In addition to controllers, there may also be so-called processors. This includes any company or person that processes personal data on our behalf.
Processors may therefore include service providers such as tax advisers, hosting or cloud providers, payment providers, newsletter providers or large companies such as Google or Microsoft.
Consent
Definition according to Article 4 GDPR
For the purposes of this Regulation:
“consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Explanation: On websites, such consent is generally provided via a cookie consent tool. You are probably familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree or consent to data processing.
In most cases, you can also make individual settings and decide for yourself which data processing activities you permit and which you do not.
If you do not consent, personal data may not be processed where consent is required as the legal basis. In principle, consent can of course also be provided in writing rather than through a tool.
Personal Data
Definition according to Article 4 GDPR
For the purposes of this Regulation:
“personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Explanation: Personal data therefore includes all data that can identify you as an individual. This generally includes data such as:
-
Name
-
Address
-
Email address
-
Postal address
-
Telephone number
-
Date of birth
-
Identification numbers such as social security number, tax identification number, identity card number or student registration number
-
Bank details such as account numbers, credit information, account balances and similar information
According to the European Court of Justice (ECJ), your IP address also constitutes personal data. IT experts can use your IP address to determine at least the approximate location of your device and, subsequently, identify you as the owner of the connection.
Therefore, storing an IP address also requires a legal basis within the meaning of the GDPR.
There are also so-called “special categories” of personal data that require particular protection. These include:
-
racial and ethnic origin
-
political opinions
-
religious or philosophical beliefs
-
trade union membership
-
genetic data, such as data obtained from blood or saliva samples
-
biometric data (information relating to physical, physiological or behavioural characteristics that can identify a person)
-
health data
-
data concerning sexual orientation or sex life
Profiling
Definition according to Article 4 GDPR
For the purposes of this Regulation:
“profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
Explanation: Profiling involves collecting various pieces of information about a person in order to learn more about that person.
In the online environment, profiling is frequently used for advertising purposes or credit assessments. Web and advertising analysis programs, for example, collect data about your behaviour and interests on a website.
This creates a specific user profile that can be used to target advertising at a particular audience.
Controller
Definition according to Article 4 GDPR
For the purposes of this Regulation:
“controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Explanation: In our case, we are responsible for processing your personal data and are therefore the “controller”.
If we pass collected data on to other service providers for processing, these service providers are “processors”. A “Data Processing Agreement (DPA)” must be concluded for this purpose where required.
Processing
Definition according to Article 4 GDPR
For the purposes of this Regulation:
“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Note: When we refer to processing in our Privacy Policy, we mean any type of data processing. As stated in the original GDPR definition above, this includes not only the collection of data but also its storage and processing.
All texts are protected by copyright.
Source: Privacy Policy created with the AdSimple Privacy Policy Generator for Austria.
The website was created with www.wix.com!