Personal data (hereinafter referred to as "data") are processed by us only as necessary and for the purpose of providing a functional and user-friendly website, including its contents and the services offered there.
Pursuant to Art. 4 no. 1. of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as "GDPR"), "processing" means any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organisation, filing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
With the following data protection declaration, we inform you in particular about the type, scope, purpose, duration and legal basis of the processing of personal data, insofar as we decide either alone or jointly with others on the purposes and means of the processing. In addition, we inform you below about the third-party components we use for optimisation purposes and to increase the quality of use, insofar as third parties process data under their own responsibility.
- Information about us as the responsible party
- Rights of users and data subjects
- Information on data processing
The responsible provider of this website in terms of data protection law is:
Phone: on request
Rights of users and data subjects
With regard to the data processing described in more detail below, users and data subjects have the right to
- to confirmation as to whether data concerning them are being processed, to information about the data being processed, to further information about the data processing and to copies of the data (cf. also Art. 15 DSGVO);
- to correct or complete incorrect or incomplete data (cf. also Art. 16 DSGVO);
- to the immediate erasure of the data relating to them (cf. also Art. 17 of the GDPR), or, alternatively, insofar as further processing is necessary pursuant to Art. 17(3) of the GDPR, to restriction of processing in accordance with Art. 18 of the GDPR;
- to receive the data concerning them and provided by them and to transfer this data to other providers/controllers (cf. also Art. 20 GDPR);
- to lodge a complaint with the supervisory authority if they are of the opinion that the data concerning them is being processed by the provider in breach of data protection provisions (cf. also Art. 77 of the GDPR).
In addition, the provider is obliged to inform all recipients to whom data has been disclosed by the provider about any correction or deletion of data or restriction of processing that takes place on the basis of Articles 16, 17 (1), 18 DSGVO. However, this obligation does not apply if such notification is impossible or involves a disproportionate effort. Notwithstanding the above, the user has a right to information about these recipients.
Likewise, users and data subjects have the right to object to the future processing of data concerning them in accordance with Art. 21 DSGVO, insofar as the data is processed by the provider in accordance with Art. 6 para. 1 lit. f) DSGVO. In particular, an objection to data processing for the purpose of direct advertising is permitted.
You also have the right to complain to the data protection supervisory authority responsible for us. In Vienna, where we are based, the competent supervisory authority is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna (telephone: +43 1 52 152-0, e-mail: firstname.lastname@example.org). Alternatively, you can contact the data protection authority in your place of residence, which will then forward your request to the competent authority.
Information on data processing
Your data processed when using our website will be deleted or blocked as soon as the purpose of the storage no longer applies, the deletion of the data does not conflict with any statutory retention obligations and no other information is provided below on individual processing procedures.
In order to provide our online offer securely and efficiently, we use the services of a web hosting provider from whose servers (or servers managed by them) the online offer can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space and database services as well as security services and technical maintenance services.
The data processed as part of the provision of the hosting offer may include all information relating to the users of our online offer that is generated as part of the use and communication. This regularly includes the IP address, which is necessary to be able to deliver the contents of online offers to browsers, and all entries made within our online offer or from websites.
E-mail dispatch and hosting: The web hosting services we use also include the dispatch, receipt and storage of e-mails. For these purposes, the addresses of the recipients and senders as well as further information regarding the e-mail dispatch (e.g. the providers involved) and the contents of the respective e-mails are processed. The aforementioned data may also be processed for the purpose of recognising SPAM. Please note that e-mails on the Internet are generally not sent in encrypted form. As a rule, e-mails are encrypted in transit, but (unless a so-called end-to-end encryption procedure is used) not on the servers from which they are sent and received. We can therefore not assume any responsibility for the transmission path of the e-mails between the sender and the reception on our server.
Collection of access data and log files: We ourselves (or our web hosting provider) collect data on every access to the server (so-called server log files). The server log files may include the address and name of the web pages and files accessed, the date and time of the access, the amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider.
The server log files can be used on the one hand for security purposes, e.g. to avoid overloading the servers (especially in the case of abusive attacks, so-called DDoS attacks) and on the other hand to ensure the utilisation of the servers and their stability.
- Types of data processed: Content data (e.g. text input, photographs, videos), usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f. DSGVO).
Services used and service providers:
SiteGround Hosting: web hosting and infrastructure services; SiteGround Hosting Ltd. 3rd Floor, 11-12 St. James's Square, London, SW1Y 4LB, United Kingdom;
WooCommerce and WooCommerce Germanized
This website uses the WordPress plugins Woocommerce and Woocommerce Germansized to ensure the sale of products is technically smooth. This is a local plugin. No personal data is transferred to Woocommerce. The Woocommerce plugin adds the functionality of an online shop to our content management system. WooCommerce Germanized extends WooCommerce and ensures the technical adaptation to the specific German legal conditions. In this way, we ensure compliance with data protection regulations when using WooCommerce.
Session Cookies / Session Cookies
We use so-called cookies with our website. Cookies are small text files or other storage technologies that are placed and stored on your end device by the internet browser you use. These cookies process certain information about you on an individual basis, such as your browser or location data or your IP address.
This processing makes our website more user-friendly, effective and secure, as the processing enables, for example, the reproduction of our website in different languages or the offer of a shopping cart function.
The legal basis for this processing is Art. 6 para. 1 lit b.) DSGVO, insofar as these cookies data are processed for contract initiation or contract processing.
If the processing does not serve to initiate or execute a contract, our legitimate interest lies in improving the functionality of our website. In this case, the legal basis is Art. 6 para. 1 lit. f) DSGVO.
When you close your internet browser, these session cookies are deleted.
This website uses Borlabs cookie, which sets a technically necessary cookie(borlabs-cookie) to store your cookie consents.
Borlabs Cookie does not process any personal data.
Where applicable, cookies from partner companies with which we cooperate for the purpose of advertising, analysis or the functionalities of our website are also used with our website.
Please refer to the following information for details on this, in particular the purposes and legal bases of the processing of such third-party cookies.
In order to improve our website, we use various technologies to analyse usage behaviour and evaluate the associated data. The data collected may include, in particular, the IP address of the end device, the date and time of access, the identification number of a cookie, the device identifier of mobile end devices and technical information about the browser and operating system.
This data is processed for marketing purposes, for example so that individualised advertising messages can be played. Before the use of these cookies and comparable technologies, you will be given the opportunity to make the settings via our cookie banner in order to consent to the use of the respective cookies. There you will also find details about the individual third-party providers. The legal basis for this data processing is your consent according to Art. 6 para. 1 p. 1 lit. a DSGVO.
The data provided by you for the purpose of using our range of goods and/or services is processed by us for the purpose of processing the contract and is necessary to this extent. Conclusion and processing of the contract are not possible without the provision of your data.
The legal basis for the processing is Art. 6 para. 1 lit. b) DSGVO.
We delete the data once the contract has been fully processed, but must observe the retention periods under tax and commercial law.
As part of the contract processing, we pass on your data to the transport company commissioned with the delivery of the goods or to the financial service provider, insofar as the transfer is necessary for the delivery of the goods or for payment purposes.
The legal basis for the transfer of the data is then Art. 6 para. 1 lit. b) DSGVO.
Transfer of personal data to shipping service providers:
If the goods are delivered by the transport service provider DPD (DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany), we will pass on your e-mail address and your telephone number to DPD prior to the delivery of the goods in accordance with Art. 6 Para. 1 lit. a DSGVO for the purpose of coordinating a delivery date or for delivery notification, provided that you have given your express consent to this in the ordering process. Otherwise, we will only pass on the name of the recipient and the delivery address to DPD for the purpose of delivery in accordance with Art. 6 Para. 1 lit. b DSGVO. This information will only be passed on if it is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with DPD or notification of delivery is not possible.
The consent can be revoked at any time with effect for the future vis-à-vis the responsible person named above or vis-à-vis the transport service provider DPD.
Use of payment service providers:
When paying via PayPal, credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "payment by instalments" via PayPal, we pass on your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. The transfer takes place in accordance with Art. 6 Para. 1 lit. b DSGVO and only insofar as this is necessary for the payment processing.
For the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "payment by instalments" via PayPal, PayPal reserves the right to carry out a credit check. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 Para. 1 lit. f DSGVO on the basis of PayPal's legitimate interest in determining your solvency. PayPal uses the result of the credit check in terms of the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The creditworthiness information may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they have their basis in a scientifically recognised mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data. For further information on data protection law, including information on the credit agencies used, please refer to PayPal's data protection declaration: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for the contractual processing of payments.
If you choose a payment method from the payment service provider Stripe, the payment will be processed via the payment service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we will pass on the information you provided during the ordering process together with information about your order (name, address, account number, bank sort code, any credit card number, invoice amount, currency and transaction number) in accordance with Art. 6 (1) lit. b DSGVO. Your data will only be passed on for the purpose of processing payments with the payment service provider Stripe Payments Europe Ltd. and only to the extent necessary for this purpose. You can find more information about Stripe's data protection at the URL https://stripe.com/de/privacy#translation.
Customer account / registration function
If you create a customer account with us via our website, we will collect and store the data you entered during registration (e.g. your name, address or e-mail address) exclusively for pre-contractual services, for the fulfilment of the contract or for the purpose of customer care (e.g. to provide you with an overview of your previous orders with us or to be able to offer you the so-called notepad function). At the same time, we will store your IP address and the date of your registration along with the time of day. Of course, this data will not be passed on to third parties.
Within the scope of the further registration process, your consent to this processing is obtained and reference is made to this data protection declaration. The data collected by us in this process will be used exclusively for the provision of the customer account.
Insofar as you consent to this processing, Art. 6 para. 1 lit. a) DSGVO is the legal basis for the processing.
If the opening of the customer account also serves pre-contractual measures or the fulfilment of the contract, the legal basis for this processing is also Art. 6 para. 1 lit. b) DSGVO.
In accordance with Art. 7 (3) DSGVO, you can revoke the consent you have given us to open and maintain the customer account at any time with effect for the future. To do so, you only need to inform us of your revocation.
The data collected in this respect will be deleted as soon as processing is no longer necessary. However, we must observe retention periods under tax and commercial law.
If you register for our free newsletter, the data you requested for this purpose, i.e. your email address and first name as well as - optionally - last name and other data, will be transmitted to us. At the same time, we store the IP address of the internet connection from which you access our website as well as the date and time of your registration. During the further registration process, we will ask for your consent to send you the newsletter, describe the content in detail and refer to this data protection declaration. We use the data collected in this process exclusively for sending the newsletter - it is therefore not passed on to third parties in particular.
The legal basis for this is Art. 6 para. 1 lit. a) DSGVO.
In accordance with Art. 7 (3) DSGVO, you can revoke your consent to receive the newsletter at any time with effect for the future. To do so, you only need to inform us of your revocation or click on the unsubscribe link contained in each newsletter.
The newsletter is sent using the dispatch service provider Flodesk, https://flodesk.com, an email marketing platform provider from the USA.
You can view the data protection provisions of the shipping service provider here: https://www.privacypolicies.com/privacy/view/bb9c8c7ecbee39b15f2f5be574def422
The email addresses of our newsletter recipients, as well as their other data described in the context of these notes, are stored on the servers of Flodesk in the USA. Flodesk uses this information to send and evaluate the newsletter on our behalf.
The shipping service provider is used on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f. DSGVO. The dispatch service provider may use the recipients' data in pseudonymous form, i.e. without assigning it to a user, to optimise or improve its own services, e.g. to technically optimise the dispatch and presentation of the newsletter or for statistical purposes. However, the dispatch service provider does not use the data of our newsletter recipients to write to them itself or to pass the data on to third parties.
Contact requests / contact possibility
If you contact us via the contact form or e-mail, the data you provide will be used to process your enquiry. The provision of the data is necessary for processing and answering your enquiry - without their provision we cannot answer your enquiry or at best only to a limited extent.
The legal basis for this processing is Art. 6 para. 1 lit. b) DSGVO.
Your data will be deleted as soon as your enquiry has been finally answered and there are no legal obligations to retain the data, e.g. in the case of subsequent contract processing.
User contributions, comments and ratings
We offer you the opportunity to publish questions, answers, opinions or evaluations, hereinafter referred to as "contributions", on our website. If you make use of this offer, we will process and publish your contribution, the date and time of submission and the pseudonym used by you, if applicable.
The legal basis for this is Art. 6 para. 1 lit. a) DSGVO. In accordance with Art. 7 (3) DSGVO, you can revoke your consent at any time with effect for the future. To do so, you only need to inform us of your revocation.
In addition, we also process your IP and email address. The IP address is processed because we have a legitimate interest in taking or supporting further action if your contribution infringes the rights of third parties and/or it is otherwise unlawful.
The legal basis in this case is Art. 6 para. 1 lit. f) DSGVO. Our legitimate interest lies in the legal defence that may be necessary.
We use Google Analytics on our website. This is a web analysis service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as "Google".
Through certification under the EU-US Privacy Shield ("EU-US Privacy Shield")
Google guarantees that the data protection requirements of the EU are also complied with when processing data in the USA.
The Google Analytics service is used to analyse the usage behaviour of our website. The legal basis is Art. 6 para. 1 lit. f) DSGVO. Our legitimate interest lies in the analysis, optimisation and economic operation of our website.
Usage and user-related information, such as IP address, location, time or frequency of visits to our website, is transmitted to a Google server in the USA and stored there. However, we use Google Analytics with the so-called anonymisation function. This function allows Google to truncate the IP address within the EU or EEA.
The data collected in this way is in turn used by Google to provide us with an evaluation of visits to our website and of the usage activities there. This data may also be used to provide other services related to the use of our website and the use of the internet.
Google states that it does not associate your IP address with any other data. In addition, Google keeps under
The website also provides you with further information on data protection law, for example on the options for preventing data use.
In addition, Google offers
Online presence in social media
We maintain online presences within social networks and platforms in order to be able to communicate with the customers, interested parties and users active there and to inform them about our services there.
We would like to point out that user data may be processed outside the European Union. This may result in risks for the users, because it could, for example, make it more difficult to enforce the rights of the users. With regard to US providers certified under the Privacy Shield, we point out that they thereby undertake to comply with the data protection standards of the EU.
Furthermore, user data is usually processed for market research and advertising purposes. For example, usage profiles can be created from the usage behaviour and resulting interests of the users. The usage profiles can in turn be used, for example, to place advertisements within and outside the platforms that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on the users' computers, in which the usage behaviour and the interests of the users are stored. Furthermore, data may also be stored in the usage profiles irrespective of the devices used by the users (especially if the users are members of the respective platforms and are logged in to them).
The processing of users' personal data is based on our legitimate interests in effectively informing users and communicating with users pursuant to Art. 6 para. 1 lit. f. DSGVO. If the users are asked by the respective providers of the platforms for consent to the aforementioned data processing, the legal basis of the processing is Art. 6 para. 1 lit. a., Art. 7 DSGVO.
For a detailed description of the respective processing and the options to object (opt-out), we refer to the information of the providers linked below.
In the case of requests for information and the assertion of user rights, we would also like to point out that these can be asserted most effectively with the providers. Only the providers have access to the users' data and can take appropriate measures and provide information directly. If you still need help, you can contact us.
Integration of third-party services and content
Within our online offer, we use content or service offers of third party providers on the basis of our legitimate interests (i.e. interest in the analysis, optimisation, multilingualism and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f. DSGVO) content or service offers from third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter uniformly referred to as "content").
This always requires that the third-party providers of this content are aware of the IP address of the user, as without the IP address they would not be able to send the content to their browser. The IP address is therefore necessary for the display of this content. We endeavour to only use content whose respective providers only use the IP address to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and other information about the use of our online offering, as well as being linked to such information from other sources.