privacy policy.

The protection of your personal data is of particular importance to us. We therefore process your data exclusively on the basis of the Datenschutz-Grundverordnung (DSGVO) and the Austrian data protection laws (DSG, TKG 2021). In this privacy policy we inform you about which data we collect, for what purpose it is processed and what rights you have with regard to your data.

Declaration on information obligation

This privacy policy explains which personal data we collect when you use our website, how we use it and what rights you have as a data subject.

Personal data is all information that refer to an identified or identifiable natural personThis includes, for example, your name, your address, your email address or technical data such as your IP address.

We only collect and process your data in accordance with the legal provisions of the GDPR and the applicable data protection laws in Austria.

Automatic data collection when visiting the website

As soon as you access our website, for technical reasons, your The IP address recorded and stored in server log files. This serves the technical provision of the website, system stability and security from attacks and abuse.

In addition to the IP address, the following technical data is also automatically recorded:

  • Date and time of access
  • Duration of the session (start and end)
  • Visited pages and content
  • Referrer URL (the previously visited page, if applicable)
  • browser type, operating system and device type
  • Amount of data transferred and loading times

The processing of this data is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR on a stable and secure provision of our website.

This technical log data is stored for a limited period of time and then automatically deleted, unless security-related incidents require longer storage. It is not merged with other data sources and no profiling takes place.

Processing of personal data

Depending on the nature of your interaction with our website, we process personal data for various purposes, such as:

  • Contacting us by email or via forms
  • order and payment processing in the online shop
  • newsletter registration and marketing communication
  • Technical analysis and website optimization (e.g. Google Analytics)

We only process your data if a legal basis according to Art. 6 GDPR exists, in particular if:

  • Your consent (Art. 6 para. 1 lit. a GDPR) is available – e.g. for marketing and tracking technologies.
  • The processing is necessary for the performance of the contract (Art. 6 para. 1 lit. b GDPR) – e.g. for orders and payment processing.
  • A legal obligation (Art. 6 para. 1 lit. c GDPR) exists – e.g. for storing invoice data.
  • A legitimate interest (Art. 6 para. 1 lit. f GDPR) exists – e.g. for the security and functionality of the website.

Processing of personal data in the webshop

If you are in our place an order in the webshop, we process personal data that is necessary for contract execution and fulfillment of our services.

1. Order and contract processing

As part of an order, we collect and process:

  • First Name, Last Name
  • Billing and shipping address
  • E-mail address (for order confirmation and customer communication)
  • Telephone number (if required for delivery)
  • Order details (purchased items, invoice amount, order number)

This processing is carried out in accordance with Article 6 paragraph 1 letter b GDPR to fulfill the contract between you and us.

2. Payment processing

To process the payment, we pass on your payment information (e.g. transaction ID, payment amount) to the respective payment service (e.g. PayPal, Stripe, Klarna).

  • We do not store complete bank details or credit card numbers, these are processed directly by the payment providers.
  • The processing is based on Article 6 paragraph 1 letter b GDPR for contract execution and on the basis of Art. 6 para. 1 lit. f GDPR to prevent fraud.
  • Further information on data processing by payment service providers can be found in the respective data protection declarations.

3. Customer account (if applicable)

If you are a Account create, we save your master data and order historyto help you more easily manage and reuse your data.

  • The storage is based on Article 6 paragraph 1 letter b GDPR, provided that a customer account is used for recurring orders.
  • You can delete your customer account at any time by contacting us.

4. Shipping and Logistics

To deliver your order we provide name, address and, if applicable, telephone number to our logistics service provider (e.g. DHL, DPD, UPS). This processing is carried out on the basis of Article 6 paragraph 1 letter b GDPR to fulfill the contract.

5. Legal retention obligations

We are legally obliged certain data from orders and invoices for tax and accounting purposes for up to seven years according to § 132 BAO (Austrian Federal Tax Code) The processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR.

Data transfer to third parties

We pass on your data not to third parties without your consent, unless this is necessary for the performance of a contract, required by law or serves the technical provision of the website (e.g. hosting providers, payment service providers).

We will not pass on your data to third parties without your consent, unless this is necessary for the performance of a contract, required by law or for the technical provision of the website (e.g. hosting providers, payment service providers). If data in third countries outside the EU/EEA We ensure that appropriate Data protection measures be taken, in particular by EU standard contractual clauses (SCCs) as well as additional technical protection measures such as EncryptionPlease note that despite these measures, when transferring data to countries such as the USA there is a residual risk that authorities could access your data, which we cannot completely rule out.

storage and deletion of personal data

Your data will only be stored for as long as it is necessary for the respective processing purpose or as long as statutory retention periods exist.

  • Invoice-relevant data: up to 7 years (tax retention obligation according to § 132 BAO)
  • Communication data (email inquiries): up to 6 months after final processing
  • Website tracking data (e.g. Google Analytics): 2 to 14 months (depending on the setting)
  • Server logs: 30 - 90 days, then automatic deletion

After the deadlines have expired, your data will either deleted or anonymizedso that personal identification is no longer possible.

Your rights according to DSGVO

You have according to Art. 15–21 GDPR the following rights with regard to your stored personal data:

  • Right to information (Art. 15 GDPR): You can request confirmation as to whether and which data is stored about you.
  • Right to rectification (Article 16 GDPR): If your data is incorrect or incomplete, you have the right to have it corrected.
  • Right to erasure (Article 17 GDPR): You can request the deletion of your personal data, provided that there are no statutory retention periods to the contrary.
  • Right to restriction of processing (Article 18 GDPR): You can request restricted use of your data.
  • Right to data portability (Art. 20 GDPR): You can request your data in a machine-readable format.
  • Right to object (Article 21 GDPR): You can object to the processing of your data, especially for direct advertising or tracking technologies.

Exercising these rights is free of charge for you, unless your requests are manifestly unfounded or excessively frequent. If you wish to exercise any of these rights, please contact us using the contact details provided in the legal notice.

Complaint to the Privacy Commission

If you believe that the processing of your data violates the GDPR or your data protection rights have been violated, you have the right to complain to a Supervisory authority to complain.

In Austria, the responsible data protection authority is:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna, Austria
Website: https://www.dsb.gv.at/

However, we recommend that you contact us directly first to clarify any open questions or concerns together.

Our contact details

Website operator: Amaros GmbH

Shipping service

In order to deliver your orders quickly and reliably, we work with external shipping service providers Depending on the chosen shipping method and the logistics partner, processing of personal data passed on to the respective shipping service provider.

The transfer of this data takes place in accordance with Article 6 paragraph 1 letter b GDPR to Fulfillment of the contract (delivery of the ordered goods). In certain cases, processing may be based on a legitimate interest pursuant to Art. 6 (1) lit. f GDPR in particular for shipment tracking or to optimize shipping processes.

hosting and server infrastructure

Our website is hosted on the servers of a hosting provider which provides the necessary technical infrastructure. This includes the storage and processing of website data, emails and databases as well as ensuring the availability and security of the website.

As part of the hosting, technical data are automatically recorded Server log files which may contain the following information:

  • visitor's IP address
  • Date and time of access
  • Pages and files accessed
  • Referrer URL (the previously visited page, if applicable)
  • browser type, version and operating system
  • Amount of data transferred and loading times

This data is used exclusively for technical monitoring, error analysis and security of the server infrastructure (e.g. to defend against attacks or to optimize server performance).

The processing of this data is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR at a stable, secure and efficient operation of our websiteThe server log files are stored for a limited period of time and then automatically deleted, unless security-relevant events require longer storage.

hetzner

Our website partially uses the hosting services of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

Hetzner stores and processes technical Server log files in accordance with the data protection regulations mentioned above. The data processing is carried out for Ensuring the technical functionality, availability and security of the website.

Further information on data processing by Hetzner can be found in the privacy policy:
https://www.hetzner.com/legal/privacy-policy/

Shop platform and technical provision

Our website uses a e-commerce systemto enable the sale of products and services. Depending on the platform, different functions are provided, such as product management, order processing, customer accounts and payment integration.

WooCommerce

Our website uses WooCommerce, an e-commerce extension for WordPress developed by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA, is developed. WooCommerce enables the provision and administration of our online shop, including product catalog, order processing and payment integration.

WooCommerce does not store its own customer data, but processes it directly within our system. Depending on the selected payment method or shipping option, necessary order data is sent to Third-party providers such as payment service providers or shipping companies transmitted.

For more information about data processing by WooCommerce, see Automattic’s privacy policy:
https://automattic.com/privacy/

Security & Attack Detection

To protect our website and user data, we use security solutions that help unauthorized access, hacking attempts and malicious activities These systems analyze the traffic on our website, block suspicious activities and report security-related incidents.

The processing of this data is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR, to the integrity, availability and security of our website .

As part of these security measures, the following data may be processed:

  • IP address and location information (to identify potential attackers)
  • access attempts & login attempts (to detect brute force attacks)
  • browser and system information (to analyze bot traffic and potential security threats)
  • Failed login attempts & suspicious activities

This data is stored limited in time and is used exclusively for detection and defense against attacks utilized.

Imunify Security

We use Imunify Security, a security solution from CloudLinux Inc., 2318 Louis Rd, Palo Alto, CA 94303, USA, the protection monitoring of our servers and websites.

What data does Imunify process?

  • IP address & access logs
  • Firewall and malware scans on the website
  • Automatic blocking of suspicious traffic
  • log data about possible security breaches

The data collected are stored encrypted and only for analysis of attacks and threats .

Further information on data protection at Imunify can be found here:
https://www.cloudlinux.com/privacy-policy

Wordfence

We use Wordfence, a security solution from Defiant Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USAto protect our website from hacker attacks, malware and brute force attacks to protect.

What data does Wordfence process?

  • IP address & geolocation (to block suspicious activities)
  • Real-time monitoring of login attempts
  • Firewall logs & suspicious requests to the server
  • data from known threats (Threat Intelligence Feed)

The processing is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR at a safe and secure website.

Further information on data protection at Wordfence can be found here:
https://www.wordfence.com/privacy-policy/

messenger services and live chats

To communicate with our customers and interested parties, we offer various messenger and live chat services These enable a quick and direct contact via our website or external platforms.

The use of these messenger services is based on:

  • Article 6 paragraph 1 letter b GDPR – if the communication to contract fulfillment or customer service necessary is.
  • Art. 6 para. 1 lit. f GDPR – based on our legitimate interest on fast and efficient customer communication.
  • Art. 6 para. 1 lit. a GDPR – if certain functions require a consent required (e.g. chatbots or message storage).

When using these services, personal data may be collected and processed, including:

  • Name or username (depending on the platform)
  • Phone number or email address (if provided)
  • message content and transmitted files
  • time of communication
  • IP address and technical data (for web chats)

This data is not used for advertising purposes, but serve exclusively the processing of inquiries and support services.

WhatsApp Business

We use WhatsApp Business, a service of Meta Platforms Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, for direct customer communication.

Which data are processed?

  • Phone number & profile picture (if publicly visible)
  • message content & sent files
  • Metadata such as time and duration of communication

WhatsApp stores and processes this data on servers outside the EU. If a WhatsApp business solution via third-party providers (e.g. Twilio), their privacy policies apply.

Important note:

WhatsApp uses end-to-end encryption, but can process metadata (e.g. time of communication) and use it for your own purposesIf you do not want this, we recommend a alternative contact via email or telephone.

Opt-Out: You can ask us to delete your WhatsApp communication history at any time.

Further information on data protection at WhatsApp:
https://www.whatsapp.com/legal/privacy-policy

reservation and booking systems

To simplify table reservations, appointment bookings or event registrations we use different online reservation systems, which can be integrated directly into our website or linked as external booking platforms. These systems enable our guests and customers to View availability in real time and make bookings conveniently online.

The use of these reservation systems is based on:

  • Article 6 paragraph 1 letter b GDPR – if the reservation is Fulfillment of the contract or provision of a requested service.
  • Art. 6 para. 1 lit. f GDPR – based on our legitimate interestto provide efficient reservation options.
  • Art. 6 para. 1 lit. a GDPR – provided that a consent is necessary, especially when using external systems with additional analysis or marketing functions.

What data is processed when making reservations?

Depending on the system used, the following personal data may be collected and processed:

  • Name and contact details (email address, telephone number)
  • Date, time and number of reserved persons
  • Special requests or comments regarding the reservation
  • IP address and technical data (for online reservations via embedded widgets or platforms)
  • Payment details (if a reservation requires a deposit or prepayment)

This data is used exclusively for processing the reservation and will not be passed on to third parties unless this is necessary for technical provision of the booking function or for contract processing.

reservation via third-party platforms

If you make a reservation via a integrated third-party platform on our website or via an external link, the data processing will be carried out in accordance with the data protection guidelines of the respective providerDepending on the system used, data is processed on servers outside the EU.

Further information on data processing by the respective providers can be found in their privacy policies.

Opt-Out & Deletion

  • If you would like to cancel a reservation or restrict the processing of your reservation data, you can contact us directly.
  • Reservation data will only be stored for as long as is necessary to fulfill the booking purpose or to comply with legal retention requirements.

Calendly

We use Calendly, an appointment booking service of Calendly LLC, 88 N Avondale Rd #603, Avondale Estates, GA 30002, USAto make scheduling and managing appointments easier.

Which data are processed?

  • Name, email address and, if applicable, telephone number
  • Selected date & any additional information
  • IP address & technical data (to detect duplicate bookings)

data transfer and storage

  • Calendly stores the data on servers in the USA and uses EU standard contractual clauses (SCCs) as a legal basis for data protection.
  • If you have one Google or Outlook calendar integration , appointments will be saved in your calendar.

Opt-Out & Deletion

If you do not want your data to be processed via Calendly, please book no appointment via the tool and contact us instead via Email or phone.

More information about privacy at Calendly:
https://calendly.com/privacy

Cookie policy

Our website uses Cookies and similar technologiesto improve the user experience, perform statistical analysis and provide personalized content or advertising. In this privacy policy we explain what types of cookies we use, what data is processed and how you can manage your cookie settings.

What are cookies?

Cookies are small text files that are stored on your device (computer, smartphone, tablet) when you visit a website. They contain information that allows the website to recognize your device on future visits. In addition to cookies, there are also similar technologies such as Local storage, pixel tags or web beacons, which can also be used for data storage or processing.

Types of cookies we use

Our website uses different types of cookies:

  1. Necessary cookies (Essential Cookies)
    • These cookies are necessary for the basic functionality of the website and cannot be deactivated.
    • They store, for example, login data, shopping cart contents or language settings.
    • Legal basis: Legitimate interest pursuant to Art. 6 (1) lit. f GDPR.
  2. Functional cookies
    • These cookies enable additional functionality such as storing user preferences.
    • Without these cookies, certain features may not work properly.
    • Legal basis: Consent pursuant to Art. 6 para. 1 lit. a GDPR.
  3. analysis and statistics cookies
    • These cookies help us understand how visitors use our website by collecting anonymous usage statistics.
    • Examples: Google Analytics, Matomo, Hotjar.
    • Legal basis: Consent pursuant to Art. 6 para. 1 lit. a GDPR.
  4. marketing and tracking cookies
    • These cookies are used to targeted advertising or create user profiles for personalized content.
    • They can be set by third parties (e.g. Google Ads, Facebook Pixel, Microsoft Ads).
    • Legal basis: Consent pursuant to Art. 6 para. 1 lit. a GDPR.

storage period and third-party cookies

Cookies are either Session cookies (are deleted after closing the browser) or persistent cookies (remain on the device for a predefined period of time). Third-party cookies come from external services that are integrated into our website.

The exact storage period depends on the respective cookie. A list of all cookies set, their function and storage period can be found in our cookie banner or browser settings . view

Consent and management of cookies

When you first visit our website, you will be presented with a Cookie banner asked to choose your preferences. Before your consent we set only necessary cookiesthat are necessary for the basic functionality of the website. Non-necessary cookies (e.g. for analysis or marketing) are only activated after your explicit consent. You can choose between:

  • Accept all cookies
  • Allow only necessary cookies
  • Make individual cookie settings

You can change your cookie settings at any time via our cookie management tool Alternatively, you can change or revoke your consent in your Delete or block browser cookiesHowever, disabling certain cookies may limit the functionality of the website.

Objection to cookies and tracking technologies

If you do not have one analysis and marketing cookies If you want to allow this, you have the following options:

Further information

For detailed information on the processing of cookies by third parties and the applicable privacy policies, you can consult their privacy policies:

Real cookie banners

We use the "Real Cookie Banner" consent tool to manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and to provide consent in this regard. Details on how "Real Cookie Banner" works can be found at https://devowl.io/de/rcb/datenverarbeitung/.

The legal basis for the processing of personal data in this context is Art. 6 (1) (c) GDPR and Art. 6 (1) (f) GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the relevant consents.

The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we cannot manage your consents.

Cookies Settings

Content Delivery Network (CDN) and hosted libraries

In order to optimize the loading times of our website and to ensure stable performance, we use so-called Content Delivery Networks (CDNs)A CDN is a network of servers that serves static content such as scripts, stylesheets or fonts from a geographically nearby server. This enables faster loading speed and better website availability.

When you visit our website, certain external libraries can be loaded from CDN servers. Your IP address is transmitted to the respective provider in order to make the file available. Depending on the service provider, additional technical information such as browser type, operating system or the page accessed may be processed.

If you do not want data to be transferred to third parties via CDNs, you can disable the use of external scripts in your browser or use browser extensions that block CDNs.

Font Awesome

To display icons we use Font Awesome, which is served either locally or via a CDN. If Font Awesome is served via a CDN such as cdnjs or the official Font Awesome CDN is loaded, your IP address may be transferred to the respective provider.

For more information on data protection when using Font Awesome, please visit:

bootstrap

Our website uses Bootstrap, a framework for the responsive design of websites. This can be loaded via a CDN, for example the official Bootstrap CDN or Cloudflare.

When you access Bootstrap from an external CDN, your IP address may be transmitted to the network provider. The privacy policies of the common Bootstrap CDNs can be found here:

jQuery

Our website uses jQuery, a JavaScript library often used to simplify scripting functions. In some cases, jQuery is loaded from an external CDN, for example from Google Hosted Libraries or cdnjs.

If jQuery is loaded from an external server, your IP address can be transmitted to the CDN provider. Further information on usage and data protection regulations can be found at the respective providers:

Google Analytics 4 (GA4)

Our website uses Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables us to analyze the behavior of users on our website and thereby optimize our content and services.

Which data are processed?

Google Analytics 4 uses cookies and similar tracking technologies to collect information about the use of our website. The following data is processed, among others:

  • Pages visited and interactions on the website
  • time spent on individual pages
  • Origin of the website visit (referrer, search engine, advertisement)
  • device type, browser and operating system
  • Anonymized IP address (shortened by IP anonymization)
  • Location data (approximate geographic origin)
  • language settings and technical information

In GA4, data collection takes place event-based and no longer session-based, allowing for more detailed analysis.

Purpose of data processing

We use Google Analytics to statistically record and evaluate the use of our website. This enables us to improve the user experience, optimize content and measure the success of advertising measures.

The data processing is based on our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR to analyze user behavior. If consent is required (e.g. through a cookie banner), the processing is based on Art. 6 Para. 1 lit. a GDPR.

data transfer and storage

The data collected by Google Analytics is transferred to and stored on Google servers. Google may transfer this information to third parties if required to do so by law or if third parties process the data on Google's behalf.

Some of these servers are located in the USA or other third countries. Since the USA is considered an unsafe third country within the meaning of the GDPR, access to personal data by US authorities cannot be ruled out. To ensure security, we use standard contractual clauses (SCCs) of the EU Commission which requires Google to comply with European data protection standards.

Storage duration of the data

The data collected is stored in Google Analytics for a period of 2 to a maximum of 14 months stored, depending on the settings of our account. After this period, the data is automatically deleted.

right of objection and opt-out options

You can object to the use of Google Analytics at any time:

  1. Settings in the cookie banner: If you refuse the use of analysis cookies, Google Analytics will not be activated.
  2. Browser add-on for deactivation: You can use Google Analytics with a browser plug-in from Google deactivate:
    https://tools.google.com/dlpage/gaoptout?hl=de
  3. Do-Not-Track setting: You can activate the “Do Not Track” setting in your browser to limit the analysis of your activities.

Your rights

According to the GDPR, you have the following rights with regard to your data:

  • Right to information (Article 15 GDPR): You can request confirmation as to whether and which of your personal data is being processed.
  • Right to rectification (Article 16 GDPR): If your data is incomplete or incorrect, you can request that it be corrected.
  • Right to erasure (Article 17 GDPR): You can request the erasure of your personal data under certain conditions.
  • Right to restriction of processing (Article 18 GDPR): You have the right to request restriction of the processing of your data.
  • Right to object (Article 21 GDPR): You can object to the processing of your data if it is based on a legitimate interest.

To exercise these rights or for further information, please contact us using the contact details provided in the imprint.

Further information

You can find Google’s privacy policy here:
https://policies.google.com/privacy?hl=de

Google Fonts

Our website uses fonts from Google Fonts, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, IrelandGoogle Fonts allows us to load fonts directly from Google servers and display them on our website.

Which data are processed?

When you load Google Fonts, a connection is established to Google's servers. Google can collect the following data:

  • your The IP address,
  • the website you are visiting,
  • the browser and operating system used,
  • as well as technical information on the display of fonts.

This data may be used by Google for analysis purposes. However, according to Google, no cookies are set or personal user profiles created.

Legal basis and purpose of use

Google Fonts are used to uniform and appealing presentation of our website This is a legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR. If a consent via a cookie banner is required, the processing is carried out in accordance with Art. 6 para. 1 lit. a GDPR.

Data transfer to third countries

Since Google is a US company, the data collected may be stored on servers in the USA or other third countries Google uses EU standard contractual clauses (SCCs)to ensure an adequate level of data protection.

Further information about Google Fonts and Google’s privacy policy can be found here:
https://policies.google.com/privacy
https://developers.google.com/fonts/faq

Locally hosted Google Fonts

To improve data protection and avoid data transmission to Google, we host the Google Fonts locally on our own server. This results in no connection to Google's servers, and there will be no data is transmitted to Google.

The processing is carried out exclusively on the basis of our legitimate interest pursuant to Art. 6 (1) lit. f GDPR at a uniform and data protection-friendly presentation of the website.

use of map services

Our website uses various map servicesto provide interactive maps and enable the display of geographic locations. These services are operated by third parties and may process personal data when loading the map.

Depending on the provider, the following information may be collected:

  • your The IP address,
  • the page called with the embedded map,
  • Location data (if location sharing has been activated),
  • technical information about your browser and device.

The use of these map services is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPRto provide you with a comfortable map display. If a consent required (e.g. when using cookies or active location sharing), the processing is carried out in accordance with Art. 6 para. 1 lit. a GDPR.

Google Maps

Our website uses Google Maps, a map service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When you load the Google Maps map, a connection is established to Google's servers. The IP address, location data (if enabled) and browser and device information. The data may be stored on servers in third countries, in particular the USA,. Google uses EU standard contractual clauses (SCCs)to ensure data protection.

For more information, see Google’s privacy policy:
https://policies.google.com/privacy

If you want to prevent data transfer to Google, you can Disable JavaScript in your browser, which, however, affects the map display.

 Google reCAPTCHA

Our website uses  Google reCAPTCHA , a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irelandto ensure that certain form entries are not misused by automated programs (bots).

reCAPTCHA analyzes the behavior of website visitors and helps us prevent spam and abuseVarious data is collected and transmitted to Google.

The use of reCAPTCHA is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR on the security of our website. If Google reCAPTCHA uses cookie or tracking technology, processing can only take place with your Consent pursuant to Art. 6 para. 1 lit. a GDPR respectively.

Google reCAPTCHA v3

Our website uses Google reCAPTCHA v3, an advanced version of reCAPTCHA, which invisible works in the background without the need for manual user verification.

Unlike reCAPTCHA v2, reCAPTCHA v3 automatically detects whether an interaction comes from a human or a bot by risk assessment (score) forgives.

Which data are processed?

Google may collect and analyze the following information:

  • The IP address of the user
  • Mouse movements, scrolling behavior and interactions on the page
  • time spent on the website
  • browser and device information
  • Cookies and Google IDs (if available)
  • Previous website activity

This data helps Google to evaluate suspected cases of bot activity and a score between 0.0 (highly suspicious) and 1.0 (human user) Based on this evaluation, our website decides whether an interaction is considered safe or if further verification measures are required.

With reCAPTCHA v3, data can also be third countries, in particular the USA,. Google uses EU standard contractual clauses (SCCs).

For more information about how Google reCAPTCHA works and its privacy policy, please see here:
https://policies.google.com/privacy
https://developers.google.com/recaptcha

If you do not want Google to process your data, you can Disable JavaScript or Block advertising and tracking cookiesHowever, this may result in some website functionality being limited.

Google Tag Manager

Our website uses the Google Tag Manager, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The Google Tag Manager enables us to management and implementation of tracking tags (e.g. for Google Analytics, Google Ads, Facebook Pixel or other tracking and analysis tools) without having to directly change the source code of the website.

Which data are processed?

The Google Tag Manager itself stores no personal data and sets no own cookiesIt only serves as a management tool for other tracking services that are integrated through it.

However, the tracking services loaded by Google Tag Manager may collect personal data, including:

  • The IP address
  • browser and device information
  • Pages visited and interactions
  • location data (if enabled)
  • cookie IDs and user behavior

Whether and which data is collected depends on the services integrated via the Google Tag Manager (e.g. Google Analytics, Facebook Pixel, Google Ads). Details about these services can be found in the respective sections of this privacy policy.

Purpose and legal basis of data processing

The Google Tag Manager is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR on simple and efficient management of tracking and analysis tools.

If tracking tags are integrated, the require consent (e.g. Google Analytics, Facebook Pixel), the processing is only carried out on the basis of your Consent pursuant to Art. 6 para. 1 lit. a GDPRwhich you can give or refuse via our cookie banner.

Data transfer and transmission to third countries

Google can store data in Third countries, in particular the USA, transferTo ensure an appropriate level of data protection, Google uses EU standard contractual clauses (SCCs).

Further information on data processing by Google can be found in the Google Privacy Policy:
https://policies.google.com/privacy

How can you control tracking through Google Tag Manager?

If you do not want tracking tags to be executed via Google Tag Manager, you have the following options:

  • Adjust cookie settings: You can manage your consent to certain tracking services through our cookie management tool.
  • Enable Do-Not-Track: Many browsers offer an option to reject tracking requests by default.
  • Use browser add-ons: Google offers a opt-out plugin for Google Analytics, which you can find here:
    https://tools.google.com/dlpage/gaoptout

The Google Tag Manager itself cannot be deactivated directly, as it does not store or process any data. If you want to block tracking tools completely, we recommend browser add-on or an ad blocker.

translation services

Our website uses translation servicesto provide content in different languages. These services are operated by third parties and may process personal data, in particular when automatic translation is invoked.

The following data can be recorded:

  • The IP address
  • website accessed
  • browser and device settings
  • language settings
  • input data in forms (if applicable)

The processing is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR on a barrier-free, multilingual presentation of the website. If data is transferred to third parties, your Consent pursuant to Art. 6 para. 1 lit. a GDPR to be required.

GTranslate

Our website can also be used for multilingual presentation GTranslate use a service of GTranslate Inc., 5960 South Land Park Dr #546, Sacramento, CA 95822, USA.

GTranslate offers a automatic machine translation, depending on the configuration of Google Translate or other providers (DeepL, Microsoft Translator) is supported.

The following data may be processed:

  • The IP address
  • Pages visited with translation enabled
  • Language settings and selected language
  • Technical information about your browser and device

If GTranslate connects to external translation services, a Data transfer to the USA or other third countriesGTranslate itself does not store any personal data, but forwards the requests to the respective translation service.

Further information on data processing by GTranslate can be found here:
https://gtranslate.io/privacy-policy

If you do not want GTranslate or associated translation services to collect data, you can disable the translation function or local language switcher without external services use.

Newsletter and email marketing

We offer you the opportunity to subscribe to our newsletter in order to be regularly informed about news, offers and relevant information. Our newsletter will only be sent with your express consent in accordance with Art. 6 Paragraph 1 Letter a of GDPR. You can revoke your consent at any time by using the unsubscribe link in the respective email or by contacting us directly.

To send our newsletter, we work with external service providers who process your data on our behalf. Depending on the provider you choose, your personal data will be stored and processed in the systems described below.

Revocation and unsubscription from the newsletter

You can revoke your consent to receive our newsletter at any time. To do so, you can either "Unsubscribe" link at the end of each email or contact us directly. After unsubscribing, your data will be deleted unless there are statutory retention periods.

Newsletter delivery via Mailchimp

We use the service Mailchimp, a provider of Intuit Inc., 2700 Coast Avenue, Mountain View, CA 94043, USA, for sending our newsletter. The data you provide when registering for the newsletter (name, email address) will be stored and processed on Mailchimp's servers.

Mailchimp offers extensive analysis options on how newsletters are opened and used. For this purpose, technical information is recorded, such as time of opening, IP address, browser type and click behavior within the email. This data is used exclusively to optimize our newsletter content and adapt it to the interests of our subscribers.

Since Mailchimp is headquartered in the USA, data may be transferred to a third country. This transfer is based on EU standard contractual clauses (SCCs)to ensure an appropriate level of data protection. For more information, see Mailchimp's privacy policy:
https://www.intuit.com/privacy/statement/

social media and integrated services

Our website may include content and features from social networks to enable you to better interact with our content. This may result in the transfer of personal data to the respective platforms. This happens in particular when you click on a social media button, view embedded content or visit our website with a logged-in social media account.

Depending on the platform, data such as your IP address, device information, pages accessed, date and time of visit and your user behavior processed. If you are logged into your social media account at the same time, the respective platform can assign the collected information to your user profile.

Data processing by social media services is generally carried out on the basis of our legitimate interest (Art. 6 Para. 1 lit. f GDPR) in the presentation of appealing content and on the basis of your consent (Art. 6 Para. 1 lit. a GDPR), provided that you actively consent to the use of certain services.

If you do not want social media providers to collect data about you, you can log out of your social media account before visiting our website or Use your browser's tracking protection features.

Facebook

We use various Facebook services to interact with our community and provide relevant content. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Facebook widgets (like button, comments, embeds)

Our website can integrate Facebook widgets such as the "Like" or "Share" button. When loading these elements, your browser establishes a connection to Facebook's servers, which receives meta data about your visit - regardless of whether you click on a widget or not.

If you are logged in to Facebook, Facebook can link your visit to your user account. If you do not want this, you should log out first. You can find more information about data processing by Facebook in Meta's privacy policy:
https://www.facebook.com/privacy/explanation

Social media coordinator

Our website may contain functions of Social media coordinator, a service of Meta Platforms Ireland Ltd., be integrated. This includes Instagram widgets (e.g. embedded posts or story previews) that are loaded from Instagram servers.

When you visit a page with Instagram content, your IP address is transmitted to Instagram. If you are logged into your Instagram account during this time, Instagram can assign your usage behavior to your profile.

This data is processed on the basis of our legitimate interest in accordance with Art. 6 (1) (f) GDPR or your consent in accordance with Art. 6 (1) (a) GDPR.

For more information about data processing by Instagram, please see Meta’s privacy policy:
https://privacycenter.instagram.com/policy

If you wish to avoid linking your Instagram account, please log out before visiting our website.

Rank Math Plugin

Our website uses the Rank Math plugin for search engine optimization. This plugin collects and processes technical data (e.g. page information, meta data) to improve the SEO performance of our website. The data processing is based on our legitimate interest in accordance with Art. 6 Para. 1 lit. f GDPR. Further information on how your data is handled can be found in the Rank Math Privacy Policy.

server hosting and security

Our website is hosted on a server of hosting provider which provides the technical infrastructure for the operation and accessibility of the website. Depending on the hosting provider, personal data may be processed, in particular Ensuring server stability, error analysis and defense against attacks.

The processing of this data is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR on the safe and reliable operation of our website.

SSL / TLS encryption

Our website uses a SSL/TLS encryption (Secure Sockets Layer / Transport Layer Security). secure transmission of data between your browser and our server.

You can recognize active SSL/TLS encryption by:

  • "https://" in the address bar of your browser
  • A lock symbol in the browser bar

This encryption ensures that Third parties cannot read or manipulate datathat you enter on our website. This particularly applies to:

  • login data and user accounts
  • order and payment information
  • Entered form data (e.g. contact forms)

SSL/TLS encryption is used for fulfillment of legal data protection requirements according to Art. 32 DSGVO and is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR on secure communication.

If an encrypted connection is not established automatically, we recommend entering the URL manually on https:// or check your browser settings.

server logs

When you visit our website, Server log files These log files contain Technical informationthat are necessary for monitoring, troubleshooting and ensuring the security of our website.

Which data are processed?

The following information is recorded in the server log files:

  • visitor's IP address
  • Date and time of access
  • Pages and files accessed
  • Referrer URL (the previously visited page, if applicable)
  • browser type, version and operating system
  • Status codes and server responses (e.g. error 404, successful requests)
  • Amount of data transferred

This data is used exclusively for technical monitoring of server operations, optimisation of performance and defence against attacks (e.g. DDoS attacks or hacking attempts).

storage and deletion

The server log files are stored for a limited period of time and then automatically deleted, unless security-related incidents require longer storage. There is no linking with other data sources or profiling.

The processing of this data is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR on a stable and secure provision of our website. This technical log data is stored for a maximum period of 90 days and then automatically deleted, unless security-related incidents (e.g. attacks or misuse) require longer storage. There is no merging with other data sources and no profiling takes place.

Payment Methods

We take the protection of your personal data very seriously. As part of the payment processing in our online shop, we process your payment information in compliance with the statutory data protection regulations, in particular the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

What is a payment provider?

A payment provider (also known as a payment service provider, or PSP for short) is a service provider that handles the technical and secure processing of online payments. It provides interfaces between our online shop, your bank or your payment service provider (e.g. credit card company, PayPal, Sofortüberweisung) and ensures that payments are processed quickly, securely and reliably.

Why do we need a payment provider?

We work with specialized payment service providers so that you can pay for your purchases in our online shop easily and securely. These providers ensure:

  • Secure payment processing: Your payment data is transmitted encrypted and processed according to the highest security standards.
  • Diverse Payment Options: We can offer you various payment methods such as credit card, instant bank transfer or digital wallets.
  • Fraud prevention: Providers conduct security checks to prevent misuse and fraudulent transactions.
  • Legal and technical security: By working with regulated payment providers, we ensure that all transactions comply with applicable legal requirements.

credit check and fraud prevention (fraud control)

To minimize the risk of payment defaults and fraudulent activities, our payment providers and/or we ourselves may carry out a credit check or fraud prevention. The following measures may be applied:

  • Credit check: If you choose a payment method with later payment (e.g. purchase on account), our payment provider or a commissioned credit agency can carry out a credit check. Data from external credit agencies (e.g. CRIF, KSV 1870) is used to assess your ability to pay.
  • Fraud Control: To prevent fraud, our payment providers use automated systems to detect suspicious transactions. These systems analyze various factors, including IP addresses, unusual order patterns or device information.

These checks are carried out on the basis of our legitimate interest in accordance with Art. 6 (1) (f) GDPR in order to prevent payment defaults and fraud. If a credit check is negative, we reserve the right not to offer you certain payment methods.

Further details on the processing of your data by the respective payment providers can be found in the following sections.

Storage and deletion of payment data

We do not store complete payment data such as credit card numbers or bank details. This sensitive information is only processed and securely stored by our payment providers. Our system only stores the data that is required to process the payment and to comply with legal requirements.

This includes in particular billing data such as name, billing address, order information and payment status. Depending on the payment method, it may be necessary to store a transaction reference or a token provided by the payment provider to enable the payment to be assigned. In some cases, partial information, such as the last four digits of a credit card, may also be stored if this is necessary to identify a payment.

Invoice-related data is subject to statutory retention periods and is stored for up to seven years in accordance with tax law. We only store technical payment data, such as transaction IDs, for as long as is necessary for accounting purposes or to prevent fraud.

After the statutory deadlines have expired, the stored data is either deleted or anonymized so that it can no longer be assigned to a person.

WooPayments (Powered by Stripe)

WooPayments is provided by Automattic and uses Stripe as a technical payment processor. When selecting WooPayments, the information required for payment is transmitted to Stripe. This includes:

  • Name
  • Billing Address
  • Email address
  • payment information (e.g. credit card number, bank details)
  • The IP address

For more information about how Stripe processes your data, please see the Stripe's privacy policy:
https://stripe.com/at/privacy

The privacy policy of Automattic (WooCommerce) can be found here:
https://automattic.com/privacy/

    0
    Your Shopping Cart
    Your cart is emptyContinue Shopping
      Shipping costs
      Apply coupon code

        Newsletter

        Register now and receive exclusive news and promotions.

        Cookie Consent with Real Cookie Banner