Technologies on our website
Cloudflare
- Provider
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA
- Representative in the EU
- Cloudflare Portugal Unipessoal Lda, Praça Marquês de Pombal 14 7th floor, 1250-162 Lisboa, Portugal, DSA-legal-representative@cloudflare.com
- Purpose
- Measurement and analysis of website performance from the user's perspective
- Category
- Statistics
- Recipients
- USA
- Data processed
- Page load times, response times, Web Vitals metrics, URL, browser, operating system, country
- Data subjects
- Website visitors
- Technology
- JavaScript beacon, cookies (details in the cookie list)
- Legal basis
- Consent (purpose)
- Certifications
- EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework
- Further information
-
cloudflare.com/de-de/privacypolicy
cloudflare.com/de-de/website-terms
On our website, we use the Cloudflare Web Analytics service to measure and analyse website performance from the perspective of our users. This tool enables us to record and understand important performance indicators such as loading times, responsiveness and the visual stability of our website.
Cloudflare Web Analytics works by inserting a JavaScript snippet into HTML pages. This beacon collects data about the user experience, including metrics such as page load time, time to first byte and other Web Vitals. The tool also records information about the browser used, the operating system and the user's country.
The collected data is updated in real time and is available shortly after a user request. This enables us to continuously monitor and improve the performance of our website. According to the provider, Cloudflare Web Analytics does not use cookies for analysis purposes, but does use them to recognise users (identification cookie).
The data is stored for the duration of the statutory retention obligations and deleted without delay after they expire. Additional details can be found in the linked further information. We recommend checking these links regularly for changes, so that you are always informed about the current practices of Cloudflare Web Analytics.
Additional information on the rights of data subjects as well as the relevant contact details can be found in the general section of this Privacy Policy.
Cookies and local storage
On our website, we use cookies to make our online presence more user-friendly and functional. Some cookies remain stored on your device.
Cookies are small data packets that are exchanged between your browser and the/our web server when you visit our website. They cause no harm whatsoever and serve solely to recognise website visitors. Cookies can only store information provided by your browser, i.e. information that you have entered into the browser yourself or that is present on the website. Cookies cannot execute any code and cannot be used to access your device.
The next time you access our website with the same device, the information stored in cookies can subsequently be sent back either to us ("first-party cookie") or to a third-party web application to which the cookie belongs ("third-party cookie"). Through the stored and returned information, the respective web application recognises that you have already accessed and visited the website with your device's browser.
Cookies contain the following information:
- cookie name
- name of the server from which the cookie originally originates
- cookie ID number
- a date on which the cookie is automatically deleted
Depending on the purpose and function, we divide cookies into the following categories:
- Technically necessary cookies, to ensure the technical operation and basic functions of our website. This type of cookie is used, for example, to retain your settings while you navigate the website; or they can ensure that important information is retained throughout the session (e.g. login, shopping basket).
- Statistics cookies, to understand how visitors interact with our website by collecting and analysing information solely on an anonymous basis. This gives us valuable insights to optimise both the website and our products and services.
- Marketing cookies, to carry out targeted advertising activities for users on our website.
- Unclassified cookies are cookies that we are currently attempting to classify together with the providers of individual cookies.
Depending on the storage period, we also divide cookies into session and permanent cookies. Session cookies store information used during your current browser session. These cookies are automatically deleted when you close the browser. No information whatsoever remains on your device. Permanent cookies store information between two visits to the website. Based on this information, you are recognised as a returning visitor on your next visit and the website responds accordingly. The lifespan of a permanent cookie is determined by the provider of the cookie.
The legal basis for using technically necessary cookies is our legitimate interest in the technically flawless operation and the smooth functionality of our website. Our website cannot function properly without these cookies. The use of statistics and marketing cookies requires your consent. You can withdraw your consent to the use of cookies at any time for the future. Consent is voluntary. If it is not given, no disadvantages arise. Further information about the cookies we actually use (in particular about their purpose and their storage period) can be found in this Privacy Policy and in the information about the cookies we use in our cookie banner.
You can also set your internet browser so that the storage of cookies on your device is generally prevented, or so that you are asked each time whether you agree to cookies being set. You can delete cookies once set at any time. How all of this works in detail can be found in your browser's help function.
Please note that a general deactivation of cookies may lead to functional restrictions on our website.
On our website, we also use so-called local storage functions (also called "local storage"). Here, data is stored locally in your browser's cache and, unless you delete the cache or it is session storage, continues to exist and can be read out even after the browser is closed.
Third parties cannot access the data stored in local storage. Where special plugins or tools use the local storage functions, this is described in the respective plugin or tool.
If you do not wish plugins or tools to use local storage functions, you can control this in the settings of your respective browser. We point out that functional restrictions may then occur.
Consent management (consent banner): On your first visit to our website, external content (e.g. Google Maps maps) is not loaded automatically; at first you see a placeholder. Only when you select "Accept all" via our consent banner or actively click on an individual placeholder are these external media loaded and the associated connections to the respective providers established. We store your decision solely in a technically necessary entry in your browser's local storage ("hl-consent-v1"); no personal data is transferred to us or third parties in the process. You can withdraw or change your consent at any time with effect for the future, via the "Cookie settings" link in the footer of every page.
External hosting
- Category
- General processing activity
- Purpose
- technical provision, operation and delivery of the website
- Data types
- technical data and usage data
- Data subjects
- Visitors to the online offering
- Recipients
- hosting service providers and technical infrastructure partners
- Technologies
- server and network infrastructure
- Legal basis
- legitimate interest (provision & operation)
Our website is operated by an external hosting provider. When the website is accessed, various technical data is processed that is required for the operation, security and delivery of the content. This generally includes information that the browser transmits automatically. The data processed may include:
- IP address
- date and time of access
- pages or files accessed
- amount of data transferred
- notifications about successful or failed requests
- browser type and browser version
- operating system used
- Referrer URL
- hostname of the accessing device
The hosting provider processes this data to ensure the technical operation of the website, detect attacks or misuse, rectify faults and provide a stable connection. The processing is carried out exclusively on our behalf. The legal basis for the processing is our legitimate interest in the secure, reliable and efficient operation of our website.
Google Analytics
- Provider
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Email: support-de@google.com
- Parent company
- Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Purpose
- web analytics, measurement of success, conversion tracking, collection of statistical data
- Category
- Statistics
- Recipients
- EU, USA
- Data processed
- IP address, information about the website visit, user data
- Data subjects
- Website visitors
- Technology
- JavaScript call, cookies (details in the cookie list), fingerprinting, local storage
- Legal basis
- Consent (purpose)
- Certifications
- EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework
- Further information
-
policies.google.com/privacy
safety.google/intl/de/principles
business.safety.google/privacy
business.safety.google/adsprocessorterms
google.com/about/datacenters/locations
myaccount.google.com/data-and-privacy
Web and app activities recorded within the scope of Google Analytics can be viewed and deleted by logged-in Google users under "My Activity" (myaccount.google.com/data-and-privacy).
On our website, we use the functions of the Google Analytics web analytics service to analyse user behaviour and to optimise our online presence. The reports provided by Google serve to analyse the performance of our website and to measure the success of possible campaigns via our website.
Google Analytics uses cookies that enable an analysis of the use of our website. All details (name, purpose, storage period) about the cookies can be found in our specific list of the cookies used.
Google Analytics can use local storage. This is an alternative to using cookies for storing the client ID. It makes it possible to track user behaviour without setting cookies.
Information about the use of the website, such as browser type/version, operating system used, the previously visited page, hostname of the accessing computer (IP address) and time of the server request, is generally transmitted to a Google server and stored there. We have concluded a contract with Google for this purpose.
On our behalf, Google will use this information to evaluate the use of our website, to compile reports on the activities within our website and to provide us with further services associated with the use of our website and internet usage.
We use Google Analytics only with IP anonymisation activated by default. This truncates a user's IP address by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. According to Google, the IP address transmitted by a user's browser within the scope of Google Analytics is not merged with other Google data.
During the website visit, user behaviour is recorded in the form of so-called events. These may represent the following:
- page views, a user's click path
- first visit to our website
- websites visited
- start of a session
- interaction with our website
- user behaviour (for example clicks, scrolls, time on page, bounce rates)
- file downloads
- advertisements seen / clicked
- interaction with videos
- internal search queries
the following is also recorded:
- approximate location (region)
- date and time of the visit
- IP address (in truncated form)
- technical information about the browser or the devices used (e.g. language setting, screen resolution)
- internet provider
- Referrer URL (which website/advertising medium a user came to our website through)
The processing of this data is essentially carried out by Google for its own purposes, such as profiling (without any possibility of influence on our part).
The data about the use of our website is deleted without delay after the end of the retention period set by us in each case. Google Analytics specifies a default retention period of 2 months for user and event data, with the maximum retention period being 14 months. This retention period also applies to conversion data. For all other event data, the following options are available: 2 months, 14 months, 26 months (Google Analytics 360 only), 38 months (Google Analytics 360 only), 50 months (Google Analytics 360 only). We choose the shortest storage period that corresponds to our intended use. You can enquire with us at any time about the retention period we currently have set.
The deletion of data whose retention period has been reached takes place automatically once a month.
Additional details can be found in the linked further information. We recommend checking these links regularly for changes, as Google Analytics may update its functions and privacy policies. Further information on rights and the contact details can be found in the general part of this Privacy Policy.
Google Fonts (locally hosted)
- Provider
- Lifestyle Group GmbH (delivered from our own server)
- Purpose
- Consistent display of fonts
- Category
- Technically necessary
- Recipients
- No transfer to third parties
- Data processed
- No personal data (the font files are delivered directly from our server)
- Data subjects
- Website visitors
- Technology
- Locally embedded web fonts (WOFF2)
- Legal basis
- Legitimate interest (Art. 6(1)(f) GDPR) in the technically flawless and consistent operation of the website
For the consistent display of fonts, our website uses the font families "Roboto" and "Roboto Slab". These web fonts are hosted locally on our own server and loaded directly from there when the page is accessed.
In the process, no connection to Google servers is established. No data, in particular not your IP address, is transmitted to Google or other third parties. The fonts used are subject to the Apache License 2.0 and may be embedded locally.
Google Maps
- Provider
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC (USA)
- Purpose
- Integration of map services
- Category
- Statistics
- Recipients
- EU, USA
- Data processed
- IP address, information about the website visit, user data
- Data subjects
- Users
- Technology
- JavaScript call, cookies
- Legal basis
- Consent, Data Privacy Framework, Data Privacy Framework
- Website
- www.google.com
- Further information
-
policies.google.com/privacy
safety.google/intl/de/principles
business.safety.google/adsprocessorterms
google.com/about/datacenters/locations
On our website, the Google Maps service is integrated in order to better display geographical information about locations for users.
Google Maps is an online map service with which geographical information is made more legible via a device. Among other things, it displays travel options or embeds map sections of a location into a website.
When Google Maps is accessed, the browser establishes a connection to Google's servers. As a result, Google becomes aware that our website was accessed via the user's IP address. The use of Google Maps enables Google to collect and process data about the use of the service.
To provide this service, Google Maps processes, among other things, entered search terms as well as latitude and longitude coordinates on the basis of the IP address. If the route planner function of Google Maps is used, the entered starting address is also stored. This data processing is carried out exclusively by Google and is outside our sphere of influence.
We point out that when this service is executed, Google sets a cookie called "NID". Google Maps does not currently offer us the option of operating this service in a mode without this cookie. The NID cookie contains information about your user behaviour, which Google uses to optimise its own services and to provide individual, personalised advertising for you.
Google anonymises data in server logs by deleting part of the IP address and cookie information after 9 or 18 months respectively.
Location and activity data is stored for either 3 or 18 months and then deleted. Via a Google account, users can also manually delete the history at any time. To completely prevent location tracking, a user must switch off the "Web & App Activity" section in their Google account.
Google Marketing Platform / Google Ad Manager
- Provider
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC (USA)
- Purpose
- Personalised advertising, conversion tracking, remarketing, measurement of campaign success
- Category
- Marketing
- Recipients
- EU, USA
- Data processed
- IP address, information about the website visit, user data
- Data subjects
- Users
- Technology
- JavaScript call, cookies
- Legal basis
- Consent, Data Privacy Framework, Data Privacy Framework
- Website
- www.google.com
- Further information
-
policies.google.com/privacy
safety.google/intl/de/principles
business.safety.google/privacy
business.safety.google/adsprocessorterms
google.com/about/datacenters/inside/locations
On this website, the Google Ads service is used for the purpose of advertising our products and services. Google Ads is Google's own in-house online advertising system.
For us, it is important to know whether an interested visitor ultimately also becomes our customer. In order to measure this, there is so-called conversion tracking. We also want to be able to address visitors to our website again in a targeted manner. We achieve this through so-called remarketing (retargeting).
Google Ads serves both conversion tracking and remarketing, i.e. we can recognise what happened after you clicked on one of our advertisements. For this service to work, cookies are used and visitors are partly added to remarketing lists so that they are shown only certain advertising campaigns.
This is done by means of a pseudonymous identification number (pID) that a user's browser receives and to which it is assigned. Through this pID, the service can recognise which advertisements have already been shown to a user and which have been accessed. The data serves to display advertisements across websites, as the user enables Google to identify the pages visited.
Our aim is that, through the use of Google Ads, the offering of our website reaches, in a targeted manner, those visitors who are genuinely interested in our offering. Through the data from conversion tracking, we can measure the benefit of individual advertising measures and optimise our web presence for our visitors. The conversion can be measured through the use of cookies.
The information generated is transmitted by Google to a server in the USA for evaluation and stored there. A transfer of the data by Google to third parties takes place only on the basis of legal provisions or within the scope of commissioned data processing. Under no circumstances will Google merge a user's data with other data collected by Google.
Google reCAPTCHA
- Provider
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company Google LLC (USA)
- Parent company
- Google LLC, USA
- Purpose
- Protection against misuse, prevention of spam
- Category
- Technically required
- Recipients
- EU, USA
- Data processed
- IP address, information about the website visit, address of the page the user comes from, information about the operating system, cookies, mouse and keyboard behaviour, date and language settings, JavaScript objects, screen resolution
- Data subjects
- Users
- Technology
- JavaScript call, cookies, local storage
- Legal basis
- Legitimate interest (protection against misuse, prevention of spam)
- Legal basis for data transfer
- Adequacy decision (EU-U.S. Data Privacy Framework)
- Website
- www.google.com
- Further information
-
developers.google.com/recaptcha
safety.google/intl/de/principles
business.safety.google/adsprocessorterms
google.com/about/datacenters/locations
On our website, we use the Google reCAPTCHA service to protect against misuse and to prevent spam. The service serves to verify whether entries on our website are made by a human or by automated programs. The technical operation takes place through the integration of a JavaScript call, whereby a connection to Google's servers is established when the website is loaded or during interactions. In the process, IP address, information about the website visit, the address of the page the user comes from, information about the operating system, cookies, mouse and keyboard behaviour, date and language settings, JavaScript objects as well as the screen resolution are processed.
JavaScript call, cookies and local storage are used. The cookies specifically used with this service, together with detailed information, can be found in our cookie list.
The specific processing depends on the technical implementation on our website. In principle, the data is stored only for as long as is necessary to fulfil the respective purpose and corresponds to statutory retention obligations; once the purpose no longer applies and the retention periods have expired, the data is deleted.
Additional details can be found in the linked further information. We recommend checking these links regularly for changes, in particular with regard to Google reCAPTCHA. Further information on rights and the contact details can be found in the general part of this Privacy Policy.
Google Tag Manager
- Provider
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC (USA)
- Purpose
- Management of tools and plugins
- Category
- Technically required
- Recipients
- EU, USA
- Data processed
- IP address
- Data subjects
- Users
- Technology
- JavaScript call
- Legal basis
- Berechtigtes Interesse, Data Privacy Framework, Data Privacy Framework
- Website
- www.google.com
- Further information
-
policies.google.com/privacy
safety.google/intl/de/principles
business.safety.google/adsprocessorterms
google.com/about/datacenters/locations
On our website, the Google Tag Manager service is used.
The Tag Manager is a service with which we can manage website tags via an interface. This allows us to incorporate code snippets such as tracking codes or conversion pixels into websites without intervening in the source code. In the process, the data is only forwarded by the Tag Manager, but neither collected nor stored. The Tag Manager itself is a cookie-free domain and does not process any personal data, as it serves purely to manage other services in our online offering.
When the Google Tag Manager starts, the browser establishes a connection to Google's servers. These are mainly located in the USA. As a result, Google becomes aware that our website was accessed via a user's IP address.
The Tag Manager ensures the triggering of other tags, which for their part may under certain circumstances collect data. However, the Tag Manager does not access this data. If a deactivation has been carried out at domain or cookie level, this remains in place for all tracking tags implemented with the Tag Manager.
Instagram
- Provider
- Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, Parent company: Meta Platforms, Inc. (USA)
- Purpose
- Integration of Instagram posts (Reels)
- Category
- Marketing / External media
- Recipients
- EU, USA
- Data processed
- IP address, information about the website visit, device and browser data, cookies where applicable
- Data subjects
- Website visitors
- Technology
- JavaScript call (Instagram embed.js), cookies
- Legal basis
- Consent (Art. 6(1)(a) GDPR)
- Website
- www.instagram.com
- Further information
- privacycenter.instagram.com/policy
In individual news articles, we link to Reels from our Instagram profile; where available, we display videos as a player directly from our own server (self-hosted). Instagram content is not embedded or loaded automatically. As long as you do not actively click on an Instagram link, there is no connection to Instagram or Meta.
Only when you open an Instagram link do you leave our website and go to Instagram/Meta, where their privacy provisions apply. In the process, your IP address and further data may be transmitted to Meta, including to the USA. We have no influence on this data processing.
Contacting us
On our website, various options for making contact are offered, for example via contact forms or provided email addresses. Within the scope of making contact, the personal data provided is processed exclusively for the handling and answering of the respective enquiry. The processing is carried out insofar as this is necessary for carrying out pre-contractual measures or for the fulfilment of a contract, or on the basis of legitimate interests, for example to maintain customer relationships or to document processes.
The provision of certain data may be necessary in order to be able to process an enquiry in full. Without this information, the processing of the enquiry may not be possible, or only possible to a limited extent.
Personal data from contact enquiries may also be stored in a customer or prospect database on the basis of legitimate interests in order to optimise communication and support. Use for marketing purposes only takes place if separate consent exists for this or if a legitimate interest exists and no overriding interests of the data subject worthy of protection conflict with it.
Personal data from contact enquiries is stored only for as long as this is necessary for the handling and processing of the enquiry or as long as statutory retention obligations exist. After the final processing of the enquiry and the expiry of any statutory periods, the data is deleted or anonymised. As a rule, deletion takes place at the latest after three years without further contact, unless longer statutory or contractual retention obligations exist.
Further information on the handling of personal data can be found in the website's Privacy Policy.
Meta Pixel
- Provider
- Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Email: privacy@facebook.com
- Parent company
- Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA
- Purpose
- Web analytics, tracking (conversion)
- Category
- Marketing
- Recipients
- EU, USA
- Data processed
- Visitor data (e.g. IP address, location data), behavioural data (e.g. clicks, time on page, conversion data), device data (e.g. browser type, operating system), e-commerce data (e.g. order ID, product information)
- Data subjects
- Website visitors
- Technology
- JavaScript, cookies (details in the cookie list), tracking pixel
- Legal basis
- Consent (purpose)
- Certifications
- EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework
- Website
- facebook.com/business/tools/meta-pixel
- Further information
-
facebook.com/privacy/policy
facebook.com/legal/terms
On our website, the Meta Pixel service of the social network Facebook is used for the analysis, optimisation and economic operation of our online offering.
With the help of Meta Pixel, Meta is able, on the one hand, to determine the visitors to our website as a target group for the display of personalised advertisements. Accordingly, we use Meta Pixel to display the advertising we place only to those users who have also shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products, determined on the basis of the websites visited) that we transmit to Meta (so-called "Custom Audiences"). With the help of Meta Pixel, we also want to ensure that our Meta ads correspond to the potential interest of users and are not annoying. With the help of Meta Pixel, we can, on the other hand, track the effectiveness of the Meta advertisements for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Meta advertisement (so-called "conversion").
The actions of users are stored in one or more cookies. These cookies enable Meta to match user data (such as IP address, user ID) with the data of a Facebook account. The data collected is anonymous and not viewable for us and can only be used within the scope of advertisements. Users can prevent the linking with the Facebook account by logging out before they carry out an action.
To set which types of advertisements are displayed within Facebook, users can access the page set up by Meta and follow the instructions there on the settings for usage-based advertising: facebook.com/settings?tab=ads
The settings are made independently of the platform, i.e. they are applied to all devices, such as desktop computers or mobile devices.
Additional details can be found in the linked further information. We recommend checking these links regularly for changes, as Meta may update its functions and privacy policies. Further information on rights and the contact details can be found in the general part of this Privacy Policy.
Server log files
- Category
- General processing activity
- Purpose
- technical security, stability and error analysis
- Data types
- technical connection data and access data
- Data subjects
- Visitors to the online offering
- Recipients
- hosting provider or technical service providers
- Technologies
- server logs
- Legal basis
- legitimate interest (technical operation & security)
When our website is accessed, so-called server log files are automatically created. These log files contain the following data, which the browser transmits automatically:
- IP address
- date and time of access
- file or page accessed
- amount of data transferred
- notification about successful request
- browser type and version used
- operating system used
- Referrer URL (previously visited page)
- hostname of the accessing device
This data is processed to ensure the functionality, security and stability of our web presence, in particular to ward off or trace attacks (e.g. DDoS attacks), for error analysis and for the technical provision of the website. The legal basis for this is legitimate interest in the secure and error-free provision of the website.
The log file data is automatically deleted after a technically customary period, at the latest after 12 weeks, as soon as it is no longer required for the stated purposes. Longer storage may take place in individual cases if data is required for evidentiary purposes (e.g. to clarify security-relevant incidents). This data is not merged with other data sources.
SSL encryption
For your visit to our website, we use the widely used SSL procedure (Secure Socket Layer) in conjunction with the highest encryption level supported by your browser in each case. Whether an individual page of our website is transmitted in encrypted form can be recognised by the closed depiction of the key or padlock symbol in your browser's status bar. The use of this procedure is based on our legitimate interest in employing suitable encryption techniques.
We also use suitable technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorised access by third parties. Our security measures are continuously improved in line with technological developments and kept at the state of the art.
Webcare
- Provider
- DataReporter GmbH, Zeileisstraße 6, 4600 Wels, Austria
- Purpose
- Consent Management
- Category
- technically required
- Recipients
- EU, AT
- Data processed
- IP address, consent data
- Data subjects
- Users
- Technology
- JavaScript call, cookies, Swarmcrawler
- Legal basis
- Legitimate interest, consent (Swarmcrawler for evaluating search results)
- Website
- datareporter.eu
- Further information
- datareporter.eu/company/info
On our website, we use the Webcare tool for consent management. Webcare records and stores the decision of the respective users of our website. Through our consent banner, it is ensured that statistical and marketing technologies such as cookies or external tools are only set or started once the user has declared explicit consent to their use.
For this purpose, we store information about the extent to which the user has confirmed the use of cookies. The user's decision can be withdrawn at any time by accessing the cookie settings and managing the consent declaration. Existing cookies are deleted after consent is withdrawn. To store the information about the status of the user's consent, a cookie is also set, which is referred to in the cookie details. Furthermore, to call up this service, the IP address of the respective user is transmitted to DataReporter's servers. The IP address is neither stored nor associated with any other data of the user; it is used solely for the correct execution of the service.
With the help of Webcare, our website is regularly examined for technologies relevant under data protection law. This examination is only carried out for those users who have expressly declared consent (for statistics or marketing purposes). The users' search results are evaluated by Webcare in anonymised form and relating only to technologies, and used to fulfil our information obligations. To start the Swarmcrawler technology, a request is sent to our servers and, for the purpose of data transmission, the user's IP address is transmitted. Servers are selected that are located in geographical proximity to the respective location of the user. It can be assumed that for users within the EU, a server located within the EU is also selected. The user's IP address is not retained and is removed again immediately after the end of the communication.
General information on data protection
The following provisions apply in principle not only to the data collection on our website, but also generally to the other processing of personal data.
Personal data
Personal data is information that can be individually attributed to you. Examples of this include, among other things, your address, your name as well as your postal address, email address or telephone number. Details such as, for example, the number of users who visit a website are not personal data, because they do not allow attribution to an individual person.
Legal bases for the processing of personal data
Insofar as no more specific information is provided in this Privacy Policy (e.g. for the technologies used), we may process your personal data on the basis of the following legal bases:
- Consent in accordance with Art. 6(1)(a) GDPR: the data subject has given their consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual measures in accordance with Art. 6(1)(b) GDPR: the processing is necessary for the performance of a contract to which the data subject is party, or in order to carry out pre-contractual measures.
- Legal obligation in accordance with Art. 6(1)(c) GDPR: the processing is necessary for compliance with a legal obligation.
- Protection of vital interests in accordance with Art. 6(1)(d) GDPR: the processing is necessary in order to protect the vital interests of the data subject or of another natural person.
- Legitimate interests in accordance with Art. 6(1)(f) GDPR: the processing is necessary to safeguard the legitimate interests of the controller or of a third party, unless the interests or fundamental rights and freedoms of the data subject override those interests.
Please note that in addition to the provisions of the GDPR, the national data protection provisions in your or our home country may apply.
Transfer of personal data
A transfer of your personal data to third parties for purposes other than those listed in this Privacy Policy does not take place.
We only pass on your personal data to third parties if:
- you have given your express consent to this in accordance with Art. 6(1)(a) GDPR,
- the disclosure in accordance with Art. 6(1)(f) GDPR is necessary to safeguard legitimate interests as well as to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding interest worthy of protection in your data not being disclosed,
- there is a legal obligation for the disclosure in accordance with Art. 6(1)(c) GDPR, and this is legally permissible and / or
- it is necessary in accordance with Art. 6(1)(b) GDPR for the handling of contractual relationships with you.
Cooperation with processors
We carefully select our service providers who process personal data on our behalf. Insofar as we commission third parties with the processing of personal data on the basis of a data processing agreement, this is done in accordance with Art. 28 GDPR.
Transfer to third countries
Insofar as we process data in a third country or this happens within the scope of using third-party services or the disclosure or transfer of data to other persons or companies, this only takes place on the basis of the legal bases set out above for the disclosure of data.
Subject to express consent or contractual necessity, we process or have the data processed, in accordance with Art. 44 to 49 GDPR, only in third countries with a level of data protection recognised as adequate or on the basis of special guarantees, such as, for example, a contractual obligation through so-called standard contractual clauses of the EU Commission, the existence of certifications or binding internal data protection rules.
Transfer of data to the USA
We would like to expressly point out that, as of 10 July 2023, the EU Commission adopted an adequacy decision on the EU-US data protection framework (Data Privacy Framework) in accordance with Art. 45(1) GDPR. Accordingly, organisations or companies (as data importers) in the USA that are registered in a public list within the scope of the self-certification of the Data Privacy Framework offer an adequate level of protection for the data transfer. Whether the specific provider of a service is already certified can be found here: dataprivacyframework.gov/s/participant-search
The Data Privacy Framework represents a valid legal basis for the transfer of personal data to the USA. This creates binding guarantees in order to take account of all the requirements of the ECJ; for example, it is provided that access by US intelligence services to EU data is limited to a necessary and proportionate extent and that a court for reviewing data protection is established, to which individuals in the EU also have access.
Insofar as a data transfer by us to the USA takes place at all or a service provider based in the USA is used by us, we refer to this explicitly in this Privacy Policy (see in particular the description of the technologies on our website).
It should be noted that, apart from significant improvements, the Data Privacy Framework applies only partially and only to data transfers to those data importers in the USA that appear in the public list of certified organisations / companies.
What can the transfer of personal data to the USA mean for you as a user and what risks exist in this connection?
Risks for you as a user, insofar as data importers in the USA are affected that do not fall under the Data Privacy Framework, are in any case the powers of the US intelligence services and the legal situation in the USA, which, in the opinion of the ECJ, no longer ensure an adequate level of data protection at present. Among other things, this concerns the following points:
- Section 702 of the Foreign Intelligence Surveillance Act (FISA) provides for no restrictions on the surveillance measures of the intelligence services and no guarantees for non-US citizens.
- Presidential Policy Directive 28 (PPD-28) gives data subjects no effective legal remedies against measures by the US authorities and provides for no limits to ensure proportionate measures.
- the ombudsperson provided for in the Privacy Shield does not have sufficient independence from the executive; it cannot issue binding orders to the intelligence services.
Legally compliant transfer of data to the USA on the basis of the standard contractual clauses for data importers that do not fall under the Data Privacy Framework?
In June 2021, the European Commission adopted new standard contractual clauses (Standard Contractual Clauses SCC) with Decision 2021/914/EU. These create a new legal basis for the data transfer in cases where the same level of data protection as in the EU does not prevail.
Legally compliant transfer of data to the USA on the basis of consent?
Insofar as a data transfer takes place to a service provider based in the USA that does not fall under the Data Privacy Framework and this data transfer is based on express consent, we inform you about this explicitly in this Privacy Policy, in particular in the description of the technologies used on our website.
What measures do we take to make a data transfer to the USA legally compliant?
Insofar as US providers offer the option, we choose the processing of data on EU servers. This should technically ensure that the data lies within the European Union and that access by US authorities is not possible.
Storage period in general
Insofar as no express storage period is specified when data is collected (e.g. within the scope of a consent declaration), we are obliged, in accordance with Art. 5(1)(e) GDPR, to delete personal data as soon as the purpose of its processing no longer exists. In this connection, we would like to point out that statutory retention obligations to which we are subject constitute a legitimate purpose for the further processing of the personal data covered by them.
In principle, we store and retain data in personal form until the end of a business relationship or until the expiry of applicable warranty, guarantee or limitation periods, and beyond that until the end of any legal disputes in which the data is required as evidence, or in any case until the end of the third year after the last contact with a business partner.
Storage period in specific cases
Within the scope of the description of individual technologies on our website, specific information on the storage period of data can be found. In our cookie table, you are informed about the storage period of individual cookies. In addition, you always have the option of enquiring directly with us about the specific storage period of data. To do this, please contact us using the contact details listed in this Privacy Policy.
Rights of data subjects
Data subjects have the right:
- (i)in accordance with Art. 15 GDPR, to request access to your personal data processed by us. In particular, you can request access to the processing purposes, the category of personal data, the categories of recipients to whom your data has been or is being disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, as well as the existence of automated decision-making including profiling and, where applicable, meaningful information about the details thereof;
- (ii)in accordance with Art. 16 GDPR, to request without delay the rectification of inaccurate or the completion of your personal data stored by us;
- (iii)in accordance with Art. 17 GDPR, under certain circumstances to request the erasure of your personal data stored by us, insofar as the processing is not necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the assertion, exercise or defence of legal claims;
- (iv)in accordance with Art. 18 GDPR, to request the (temporary) restriction of the processing of your personal data, insofar as the accuracy of the data is contested by you, the processing is unlawful but you refuse its erasure, we no longer need the data but you require it for the assertion, exercise or defence of legal claims, or you have lodged an objection to the processing in accordance with Art. 21 GDPR;
- (v)in accordance with Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format, or to request its direct transmission to another controller; however, this covers only those of your personal data that we process by automated means on the basis of your consent or on the basis of a contract;
- (vi)in accordance with Art. 21 GDPR, insofar as your personal data is processed on the basis of our legitimate interest, to lodge an objection to the processing of your personal data, insofar as there are grounds for this arising from your particular situation or the objection is directed against direct marketing. In the latter case, you have a general right to object, which is implemented by us without stating a particular situation;
- (vii)in accordance with Art. 7(3) GDPR, to withdraw your once-given consent towards us at any time. This has the consequence that we may no longer continue, in the future, the data processing that was based on this consent. Among other things, you have the option of withdrawing your once-given consent to the use of cookies on our website with effect for the future by accessing our cookie settings;
- (viii)in accordance with Art. 77 GDPR, to lodge a complaint with a supervisory authority regarding the unlawful processing of your data by us. As a rule, you can contact the supervisory authority of your habitual residence or place of work or of our company headquarters for this purpose.
The competent supervisory authority for Lifestyle Group GmbH is:
Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna, Austria
Tel.: +43 1 52 152-0, dsb@dsb.gv.at
Exercising data subject rights
You yourself decide on the use of your personal data. If you therefore wish to exercise one of your rights mentioned above towards us, you are welcome to contact us by email at info@hairlodge.at or by post, as well as by telephone.
Please support us in specifying your request by answering questions from our responsible member of staff regarding the specific processing of your personal data. In the event of justified doubts about your identity, a copy of your identification may be requested by us.
For questions on the subject of data protection, you can reach us at info@hairlodge.at or via the other contact details listed in this Privacy Policy.
Ebbs, 13 May 2026