Privacy policy
Introduction and Overview
We have written this privacy policy (version 05.07.2026-113225560) in order to explain to you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (in short: data) we as the controller – and the processors commissioned by us (e.g. providers) – process, will process in the future, and what lawful options you have. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, on the other hand, is intended to describe the most important things to you as simply and transparently as possible. Where it aids transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics are used. We are thus informing you in clear and simple language that we only process personal data in the course of our business activities if there is a corresponding legal basis for doing so. That is certainly not possible with brief, unclear and legalistic-technical statements, as are often standard on the internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is some information you were not yet familiar with.
If you still have questions, we kindly ask you to contact the responsible party named below or in the legal notice (Impressum), to follow the links provided, and to look at further information on third-party sites. You can of course also find our contact details in the legal notice.
Scope
This privacy policy applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data enables us to offer and invoice our services and products, whether online or offline. The scope of this privacy policy includes:
- all online presences (websites, online shops) that we operate
- social media presences and email communication
- mobile apps for smartphones and other devices
In short: This privacy policy applies to all areas in which personal data is processed in a structured manner within the company via the channels mentioned. Should we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.
Legal Bases
In the following privacy policy, we provide you with transparent information on the legal principles and regulations, i.e. the legal bases of the General Data Protection Regulation, that enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course read this EU General Data Protection Regulation online at EUR-Lex, the gateway to EU law, at https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
- Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
- Contract (Article 6(1)(b) GDPR): We process your data in order to fulfil a contract or pre-contractual obligations with you. For example, if we conclude a purchase contract with you, we need personal information in advance.
- Legal obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally required to keep invoices for accounting purposes. These usually contain personal data.
- Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we have to process certain data in order to operate our website securely and economically efficiently. This processing is therefore a legitimate interest.
Other conditions, such as processing for reasons of public interest and the exercise of official authority, as well as the protection of vital interests, do not generally apply to us. Should such a legal basis nevertheless be relevant, it will be indicated in the appropriate place.
In addition to the EU regulation, national laws also apply:
- In Austria, this is the Federal Act concerning the Protection of Personal Data (Datenschutzgesetz), in short DSG.
- In Germany, the Bundesdatenschutzgesetz (Federal Data Protection Act), in short BDSG, applies.
If further regional or national laws apply, we will inform you about them in the following sections.
Contact Details of the Controller
If you have any questions about data protection or the processing of personal data, you will find the contact details of the responsible person or controller pursuant to Article 4(7) of the EU General Data Protection Regulation (GDPR) below:
Immanuel Schranz
Josef Bierenz-Gasse 10b/4/50, 2700 Wiener Neustadt, Austria
Email: hello@byvercano.com
Storage Period
It is a general criterion for us that we store personal data only for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for the data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.
If you wish your data to be deleted or revoke your consent to data processing, the data will be deleted as quickly as possible, provided there is no obligation to store it.
We will inform you below about the specific duration of the respective data processing, provided we have further information on this.
Rights under the General Data Protection Regulation
In accordance with Articles 13 and 14 GDPR, we inform you of the following rights to which you are entitled so that data is processed fairly and transparently:
- Under Article 15 GDPR, you have a right of access to information about whether we are processing data about you. If that is the case, you have the right to receive a copy of the data and to be informed of the following:
- the purpose for which we carry out the processing;
- the categories, i.e. the types of data, that are processed;
- who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
- how long the data is stored;
- the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
- that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
- the origin of the data, if we did not collect it from you;
- whether profiling is carried out, i.e. whether data is automatically evaluated in order to arrive at a personal profile of you.
- Under Article 16 GDPR, you have a right to rectification of the data, which means that we must correct data if you find errors.
- Under Article 17 GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the deletion of your data.
- Under Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it further.
- Under Article 20 GDPR, you have the right to data portability, which means that we will provide you with your data in a common format upon request.
- Under Article 21 GDPR, you have a right to object, which, once enforced, entails a change in the processing.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then examine as quickly as possible whether we can legally comply with this objection.
- If data is used for direct marketing, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
- If data is used for profiling, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
- Under Article 22 GDPR, you may have the right not to be subject to a decision based solely on automated processing (for example, profiling).
- Under Article 77 GDPR, you have the right to lodge a complaint. This means that you can complain to the data protection authority at any time if you believe that the processing of personal data violates the GDPR.
In short: You have rights – do not hesitate to contact the responsible party listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you can complain to the supervisory authority. For Austria, this is the data protection authority (Datenschutzbehörde), whose website you can find at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Head: Dr. Matthias Schmidl
Address: Barichgasse 40-42, 1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/
Data Transfer to Third Countries
We only transfer or process data in countries outside the scope of the GDPR (third countries) if you consent to this processing or if there is another legal permission. This applies in particular if the processing is legally required or necessary for the fulfilment of a contractual relationship, and in any case only to the extent that this is generally permitted. Your consent is in most cases the most important reason for us having data processed in third countries. The processing of personal data in third countries such as the USA, where many software manufacturers offer services and have their server locations, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that, according to the European Court of Justice, an adequate level of protection for data transfer to the USA currently only exists if a US company that processes personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework. You can find more information on this at: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Data processing by US services that are not active participants in the EU-US Data Privacy Framework may result in data not being processed and stored anonymously. Furthermore, US government authorities may be able to access individual data. In addition, collected data may be linked to data from other services of the same provider, provided you have a corresponding user account. Where possible, we try to use server locations within the EU, if this is offered.
We will inform you in more detail about data transfer to third countries at the appropriate places in this privacy policy, where applicable.
Security of Data Processing
In order to protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. In doing so, we make it as difficult as possible, within the scope of our capabilities, for third parties to infer personal information from our data.
Art. 25 GDPR speaks here of “data protection by design and by default”, meaning that both software (e.g. forms) and hardware (e.g. access to the server room) should always be designed with security in mind and that appropriate measures should be taken. Below, we will go into specific measures where necessary.
TLS Encryption with https
TLS, encryption and https sound very technical, and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transfer data securely on the internet.
This means that the complete transmission of all data from your browser to our web server is secured – nobody can “listen in”.
We have thus introduced an additional layer of security and fulfil data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transfer on the internet, we can ensure the protection of confidential data.
You can recognise the use of this data transmission security by the small lock symbol at the top left of the browser, to the left of the internet address (e.g. examplepage.com), and by the use of the https scheme (instead of http) as part of our internet address.
If you want to know more about encryption, we recommend a Google search for “Hypertext Transfer Protocol Secure wiki” to get good links to further information.
Communication
Communication summary
- 👥 Data subjects: Everyone who communicates with us by phone, email or online form
- 📓 Data processed: e.g. phone number, name, email address, form data entered. You can find more details under the respective type of contact used
- 🤝 Purpose: Handling communication with customers, business partners, etc.
- 🗓 Storage period: duration of the business case and legal requirements
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)
If you contact us and communicate by phone, email or online form, personal data may be processed.
The data is processed for the handling and completion of your enquiry and the related business transaction. The data is stored for as long as the law requires.
Data Subjects
The above processes affect all those who seek contact with us via the communication channels we provide.
Phone
When you call us, the call data is stored in pseudonymised form on the respective end device and by the telecommunications provider used. In addition, data such as name and telephone number may subsequently be sent by email and stored for answering the enquiry. The data is deleted as soon as the business case has ended and legal requirements allow.
If you communicate with us by email, data may be stored on the respective end device (computer, laptop, smartphone, …) and data is stored on the email server. The data is deleted as soon as the business case has ended and legal requirements allow.
Online Forms
If you communicate with us using an online form, data is stored on our web server and, if applicable, forwarded to one of our email addresses. The data is deleted as soon as the business case has ended and legal requirements allow.
Legal Bases
The processing of the data is based on the following legal bases:
- Art. 6(1)(a) GDPR (consent): You give us your consent to store your data and to use it further for purposes related to the business case;
- Art. 6(1)(b) GDPR (contract): There is a need to fulfil a contract with you or a processor such as the telephone provider, or we need to process the data for pre-contractual activities, such as preparing an offer;
- Art. 6(1)(f) GDPR (legitimate interests): We want to conduct customer enquiries and business communication in a professional manner. Certain technical facilities such as email programs, exchange servers and mobile network operators are necessary to be able to conduct communication efficiently.
Cookies
Cookies summary
- 👥 Data subjects: visitors to the website
- 🤝 Purpose: depends on the respective cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
- 📓 Data processed: depends on the respective cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
- 🗓 Storage period: depends on the respective cookie, can vary from hours to years
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What are cookies?
Our website uses HTTP cookies to store user-specific data. In the following, we explain what cookies are and why they are used, so that you can better understand this privacy policy.
Whenever you surf the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: cookies are really useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are also other cookies for other areas of application. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically placed in the cookie folder, effectively the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser transmits the “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are used to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site; third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiry time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, trojans or other “malware”. Cookies also cannot access information on your PC.
For example, cookie data may look like this:
Name: _ga
Value: GA1.2.1326744211.152113225560-9
Purpose: distinguishing website visitors
Expiry date: after 2 years
A browser should be able to support these minimum sizes:
- at least 4096 bytes per cookie
- at least 50 cookies per domain
- at least 3000 cookies in total
What types of cookies are there?
The question of which cookies we use in particular depends on the services used and is clarified in the following sections of this privacy policy. At this point, we would like to briefly discuss the different types of HTTP cookies.
Four types of cookies can be distinguished:
Strictly necessary cookies
These cookies are necessary to ensure basic functions of the website. For example, these cookies are needed when a user places a product in the shopping cart, then continues browsing on other pages and only later goes to checkout. These cookies ensure that the shopping cart is not deleted, even if the user closes their browser window.
Functional cookies
These cookies collect information about user behaviour and whether the user receives any error messages. These cookies are also used to measure the loading time and behaviour of the website in different browsers.
Targeted cookies
These cookies ensure better user-friendliness. For example, entered locations, font sizes or form data are stored.
Advertising cookies
These cookies are also called targeting cookies. They serve to deliver individually tailored advertising to the user. This can be very practical, but also very annoying.
Usually, when you visit a website for the first time, you are asked which of these cookie types you want to allow. And of course, this decision is also stored in a cookie.
If you want to know more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism”.
Purpose of processing via cookies
The purpose ultimately depends on the respective cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
What data is processed?
Cookies are little helpers for many different tasks. Unfortunately, it is not possible to generalise which data is stored in cookies, but we will inform you about the processed or stored data in the following privacy policy.
Storage period of cookies
The storage period depends on the respective cookie and is specified further below. Some cookies are deleted after less than an hour, others can remain stored on a computer for several years.
You also have influence on the storage period yourself. You can manually delete all cookies at any time via your browser (see also “Right to object” below). Furthermore, cookies based on consent will be deleted at the latest after you revoke your consent, whereby the lawfulness of the storage remains unaffected until then.
Right to object – how can I delete cookies?
You decide for yourself how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option of deleting, deactivating or only partially allowing cookies. For example, you can block third-party cookies but allow all other cookies.
If you want to find out which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find this in your browser settings:
Chrome: Clear, enable and manage cookies in Chrome
Safari: Manage cookies and website data in Safari
Firefox: Clear cookies and site data in Firefox
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete cookies in Microsoft Edge
If you generally do not want cookies, you can set up your browser so that it always informs you when a cookie is about to be set. This way, you can decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. It is best to search for the instructions in Google using the search term “delete cookies Chrome” or “deactivate cookies Chrome” in the case of a Chrome browser.
Legal basis
The so-called “cookie directives” have existed since 2009. They state that the storage of cookies requires your consent (Article 6(1)(a) GDPR). Within the EU countries, however, there are still very different reactions to these directives. In Austria, this directive was implemented in § 165(3) of the Telecommunications Act (2021). In Germany, the cookie directives were not implemented as national law. Instead, this directive was largely implemented in § 15(3) of the Telemedia Act (TMG), which has been replaced by the Digital Services Act (DDG) since May 2024.
For strictly necessary cookies, even where no consent has been given, legitimate interests (Article 6(1)(f) GDPR) exist, which in most cases are of an economic nature. We want to provide visitors to our website with a pleasant user experience, and certain cookies are often strictly necessary for this.
Where cookies that are not strictly necessary are used, this only happens with your consent. The legal basis in this respect is Art. 6(1)(a) GDPR.
In the following sections, you will be informed in more detail about the use of cookies, insofar as the software used uses cookies.
Shopify (Shop System & Web Hosting)
Shopify summary
- 👥 Data subjects: visitors and customers of our online shop
- 🤝 Purpose: provision and operation of our online shop, processing of orders and payments, fraud prevention
- 📓 Data processed: incl. name, contact details, delivery and billing address, order and payment data, IP address, device and usage data
- 🗓 Storage period: as long as required for the operation of the shop or due to legal obligations (e.g. accounting)
- ⚖️ Legal bases: Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(a) GDPR (consent)
Our online shop is based on the Shopify shop system. The provider is Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. Shopify hosts our shop and processes on our behalf all data generated when you visit the website and place orders (e.g. name, address, email address, order and payment data, IP address).
In doing so, data may also be transferred to the parent company Shopify Inc. in Canada as well as to other Shopify locations (including in the USA). An adequacy decision of the European Commission exists for Canada; transfers to the USA are safeguarded via the EU-US Data Privacy Framework or standard contractual clauses.
Shopify also carries out certain processing operations under its own data protection responsibility, for example in the context of enhanced features for fraud prevention and for improving Shopify's services. In these cases, Shopify itself is the controller and also responds to requests to exercise your data subject rights. You can find more details in the Shopify Consumer Privacy Policy at https://www.shopify.com/legal/privacy/customers. You can exercise your rights vis-à-vis Shopify via the Shopify Privacy Portal: https://privacy.shopify.com.
Payment Providers
Payment providers summary
- 👥 Data subjects: customers who pay in our online shop
- 🤝 Purpose: processing of payments
- 📓 Data processed: incl. name, billing address, payment data (e.g. credit card data, account data), order total
- 🗓 Storage period: in accordance with statutory retention obligations
- ⚖️ Legal basis: Art. 6(1)(b) GDPR (contract)
We use payment service providers to process payments. When you select a payment method, the data required for the payment (e.g. name, billing address, card or account data, amount) is transmitted directly to the respective provider and processed by it under its own responsibility. We ourselves do not store complete credit or debit card data. Providers currently used:
- Shopify Payments (Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, Ireland)
- PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg)
- Klarna (Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden)
Details on data processing can be found in the privacy policy of the respective provider.
Order Processing and Shipping (Fulfilment)
Fulfilment summary
- 👥 Data subjects: customers who order in our online shop
- 🤝 Purpose: processing, packaging and delivery of your order
- 📓 Data processed: name, delivery address, email address or phone number (for shipping notifications), ordered items
- 🗓 Storage period: duration of order processing plus statutory retention obligations
- ⚖️ Legal basis: Art. 6(1)(b) GDPR (contract)
To fulfil your order, we work with the fulfilment service provider HyperSKU and with the logistics companies commissioned with delivery. We pass on the data required for shipping (name, delivery address, where applicable email address/phone number for shipping notifications, ordered items) to these partners. Processing may also take place outside the EU (e.g. in Hong Kong/China) where this is necessary for order fulfilment; in this case, the transfer takes place on the basis of standard contractual clauses or Art. 49(1)(b) GDPR (performance of a contract).
Google Ads (Conversion Tracking)
Google Ads summary
- 👥 Data subjects: website visitors who reach us via Google ads
- 🤝 Purpose: measuring the success of our advertisements (conversion tracking)
- 📓 Data processed: incl. IP address, cookie data, information about clicked ads and purchases made
- 🗓 Storage period: conversion cookies usually expire after 30–90 days
- ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent)
We use Google Ads to advertise our online shop via Google search results and Google Shopping. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. If you reach our website via a Google ad and have consented to the setting of marketing cookies, a conversion cookie is set which enables Google and us to track whether, for example, a purchase has taken place. We only receive aggregated statistics, no information with which we can identify you personally.
Data may also be transferred to Google LLC in the USA; Google LLC is an active participant in the EU-US Data Privacy Framework. You can deactivate personalised advertising in your Google account at https://adssettings.google.com. Without your consent in the cookie banner, no conversion tracking takes place.
Google Fonts (Local Hosting)
Google Fonts summary
- 👥 Data subjects: website visitors
- 🤝 Purpose: uniform display of fonts on the website
- 📓 Data processed: no data is transmitted to Google
- ⚖️ Legal basis: Art. 6(1)(f) GDPR (legitimate interests)
We use the font “Outfit” from Google Fonts on our website. The font files are hosted locally, on our own web server. This means that no connection to Google servers is established when you visit our website and no data (such as your IP address) is transmitted to Google. The font files are delivered exclusively via the infrastructure of our shop hosting provider (Shopify).
Judge.me (Product Reviews)
Judge.me summary
- 👥 Data subjects: customers who submit a product review and visitors who read reviews
- 🤝 Purpose: collection and display of product reviews
- 📓 Data processed: name, email address, review content, order reference
- 🗓 Storage period: as long as the review is published or until deletion at your request
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
For product reviews in our shop, we use the Judge.me service provided by Judge.me Limited, 20-22 Wenlock Road, London, N1 7GU, United Kingdom. When you submit a review, your name, email address and the review content are processed and the review is published in our shop. An adequacy decision of the European Commission exists for the United Kingdom. You can find more details in the Judge.me privacy policy: https://judge.me/privacy.
Email Marketing Introduction
Email marketing summary
- 👥 Data subjects: newsletter subscribers
- 🤝 Purpose: direct marketing by email, notification of system-relevant events
- 📓 Data processed: data entered during registration, but at least the email address. You can find more details under the respective email marketing tool used.
- 🗓 Storage period: duration of the subscription
- ⚖️ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is email marketing?
To keep you up to date at all times, we also use the option of email marketing. In this process, provided you have agreed to receive our emails or newsletters, your data is also processed and stored. Email marketing is a sub-area of online marketing. News or general information about a company, products or services is sent by email to a specific group of people who are interested in it.
If you want to participate in our email marketing (usually via newsletter), you normally just have to register with your email address. To do this, you fill out an online form and submit it. However, it may also happen that we ask you for your title and name, for example, so that we can also address you personally.
Basically, registering for newsletters works with the help of the so-called “double opt-in procedure”. After you have registered for our newsletter on our website, you will receive an email through which you confirm the newsletter registration. This ensures that the email address belongs to you and that nobody has registered with someone else's email address. We, or a notification tool we use, log every single registration. This is necessary so that we can also prove the legally correct registration process. As a rule, the time of registration, the time of the registration confirmation and your IP address are stored. In addition, it is also logged when you make changes to your stored data.
Why do we use email marketing?
We naturally want to stay in touch with you and always present you with the most important news about our company. For this, we use, among other things, email marketing – often just referred to as “newsletters” – as an essential part of our online marketing. If you agree to this or if it is legally permitted, we will send you newsletters, system emails or other notifications by email. When we use the term “newsletter” in the following text, we mainly mean regularly sent emails. Of course, we do not want to bother you in any way with our newsletter. That is why we always strive to offer only relevant and interesting content. For example, you can find out more about our company, our services or products. Since we are always improving our offers, our newsletter will also always let you know when there is news or when we are currently offering special, attractive promotions. If we commission a service provider that offers a professional mailing tool for our email marketing, we do so in order to be able to offer you fast and secure newsletters. The purpose of our email marketing is basically to inform you about new offers and also to get closer to our business goals.
What data is processed?
If you become a subscriber to our newsletter via our website, you confirm membership of an email list by email. In addition to your IP address and email address, your title, name, address and telephone number may also be stored. However, only if you consent to this data storage. The data marked as such is necessary for you to be able to participate in the offered service. Providing this information is voluntary, but failure to provide it will mean that you cannot use the service. In addition, information about your device or your preferred content on our website may also be stored. You can find more about the storage of data when you visit a website in the section “Automatic data storage”. We record your declaration of consent so that we can always prove that it complies with our laws.
Duration of data processing
If you unsubscribe your email address from our email/newsletter distribution list, we may store your address for up to three years on the basis of our legitimate interests so that we can still prove your consent at that time. We may only process this data if we have to defend ourselves against any claims. However, if you confirm that you have given us your consent to subscribe to the newsletter, you can submit an individual deletion request at any time. If you permanently object to the consent, we reserve the right to store your email address in a blocklist. As long as you have voluntarily subscribed to our newsletter, we will of course also keep your email address.
Right to object
You have the option to cancel your newsletter subscription at any time. All you have to do is revoke your consent to the newsletter registration. This normally only takes a few seconds or one or two clicks. Usually, you will find a link to cancel the newsletter subscription directly at the end of each email. If the link really cannot be found in the newsletter, please contact us by email and we will cancel your newsletter subscription immediately.
Legal basis
Our newsletter is sent on the basis of your consent (Article 6(1)(a) GDPR). This means that we may only send you a newsletter if you have actively registered for it beforehand. Where applicable, we may also send you advertising messages if you have become our customer and have not objected to the use of your email address for direct marketing.
Information on special email marketing services and how they process personal data can be found – where available – in the following sections.
Klaviyo (Newsletter Delivery)
Klaviyo summary
- 👥 Data subjects: newsletter subscribers
- 🤝 Purpose: sending our newsletter, evaluating newsletter usage
- 📓 Data processed: email address, name where applicable, time of registration, IP address, opening and click behaviour
- 🗓 Storage period: duration of the subscription; after unsubscribing, up to three years for evidence purposes (see Email Marketing section)
- ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent)
We use Klaviyo to send our newsletter. The provider is Klaviyo Inc., 125 Summer Street, Boston, MA 02110, USA. Registration takes place using the double opt-in procedure (see above). Your data is processed on Klaviyo servers in the USA; Klaviyo is an active participant in the EU-US Data Privacy Framework. Klaviyo also evaluates whether and when newsletters are opened and which links are clicked, so that we can improve our content. You can unsubscribe at any time via the unsubscribe link at the end of each newsletter. You can find more details in Klaviyo's privacy policy: https://www.klaviyo.com/legal/privacy/privacy-notice.
Explanation of Terms Used
We always strive to write our privacy policy as clearly and understandably as possible. However, this is not always easy, especially with technical and legal topics. It often makes sense to use legal terms (such as personal data) or certain technical expressions (such as cookies, IP address). However, we do not want to use these without explanation. Below you will find an alphabetical list of important terms used, which we may not have sufficiently addressed in the privacy policy so far. If these terms were taken from the GDPR and are definitions, we will also cite the GDPR texts here and add our own explanations where appropriate.
Supervisory Authority
Definition according to Article 4 of the GDPR
For the purposes of this Regulation:
‘supervisory authority’ means an independent public authority which is established by a Member State pursuant to Article 51;
Explanation: “Supervisory authorities” are always state, independent institutions that are also authorised to issue instructions in certain cases. They serve to carry out so-called state supervision and are located in ministries, special departments or other authorities. For data protection in Austria, there is an Austrian data protection authority; for Germany, there is a separate data protection authority for each federal state.
Processor
Definition according to Article 4 of the GDPR
For the purposes of this Regulation:
‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data that we process from you. In addition to the controllers, there can also be so-called processors. This includes every company or person that processes personal data on our behalf. In addition to service providers such as tax advisors, processors can therefore also be hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
Third Party
Definition according to Article 4 of the GDPR
For the purposes of this Regulation:
‘third party’ means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
Explanation: The GDPR basically only explains here what a “third party” is not. In practice, a “third party” is anyone who also has an interest in the personal data but does not belong to the persons, authorities or institutions mentioned above. For example, a parent company can act as a “third party”. In this case, the subsidiary is the controller and the parent company is the “third party”. However, this does not mean that the parent company may automatically view, collect or store the personal data of the subsidiary.
Consent
Definition according to Article 4 of the GDPR
For the purposes of this Regulation:
‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
Explanation: As a rule, such consent is given on websites via a cookie consent tool. You are certainly familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree or consent to the data processing. Usually, you can also make individual settings and thus decide for yourself which data processing you allow and which you do not. If you do not consent, no personal data about you may be processed. In principle, consent can of course also be given in writing, i.e. not via a tool.
Personal Data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation:
‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Explanation: Personal data is therefore all data that can identify you as a person. This is usually data such as:
- name
- address
- email address
- postal address
- phone number
- date of birth
- identification numbers such as social security number, tax identification number, ID card number or matriculation number
- bank details such as account number, credit information, account balances and much more
According to the European Court of Justice (ECJ), your IP address is also considered personal data. IT experts can use your IP address to determine at least the approximate location of your device and subsequently you as the connection owner. Therefore, storing an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called “special categories” of personal data, which are also particularly worthy of protection. These include:
- racial and ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership
- genetic data, such as data taken from blood or saliva samples
- biometric data (this is information on psychological, physical or behavioural characteristics that can identify a person)
- health data
- data on sexual orientation or sex life
Profiling
Definition according to Article 4 of the GDPR
For the purposes of this Regulation:
‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
Explanation: Profiling involves compiling various pieces of information about a person in order to learn more about that person. In the web sector, profiling is frequently used for advertising purposes or for credit checks. Web or advertising analysis programs, for example, collect data about your behaviour and interests on a website. This results in a special user profile that can be used to target advertising to a specific target group.
Controller
Definition according to Article 4 of the GDPR
For the purposes of this Regulation:
‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Explanation: In our case, we are responsible for the processing of your personal data and are consequently the “controller”. If we pass on collected data to other service providers for processing, they are “processors”. For this, a “data processing agreement (DPA)” must be signed.
Processing
Definition according to Article 4 of the GDPR
For the purposes of this Regulation:
‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
Note: When we speak of processing in our privacy policy, we mean any kind of data processing. This includes, as mentioned above in the original GDPR declaration, not only the collection but also the storage and processing of data.
All texts are protected by copyright.