Johanna Stangl

Privacy Policy

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy below.

Data Collection on This Website

Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the section "Information on the Responsible Party" below.

How do we collect your data?
Some data is collected when you provide it to us, for example, by entering it into a contact form.
Other data is collected automatically by our IT systems when you visit the website—primarily technical data such as the browser and operating system you are using or the time the page was accessed. This data is collected automatically as soon as you access our website.

What do we use your data for?
Some data is collected to ensure the proper functioning of the website. Other data may be used to analyze your user behavior.
If contracts can be concluded or initiated via this website, your submitted data will also be processed to manage requests, orders, or offers.

What rights do you have regarding your data?
You have the right to request information at any time—free of charge—about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of your data.
If you have given consent to data processing, you may withdraw this consent at any time with future effect.
Under certain conditions, you also have the right to request the restriction of the processing of your personal data.
Furthermore, you have the right to lodge a complaint with the relevant supervisory authority.
For any data protection inquiries, you can contact us at any time.

Analysis Tools and Tools from Third Parties

When visiting this website, your browsing behavior may be statistically evaluated. This is mainly done using so-called analytics tools.
Detailed information on these tools can be found in the privacy policy below.

2. Hosting

We host the content of our website with the following provider:

Strato

The provider is Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (hereinafter referred to as "Strato"). When you visit our website, Strato records various log files, including your IP address.

For more information, please refer to Strato’s privacy policy:
https://www.strato.de/datenschutz/

Legal basis:
The use of Strato is based on Art. 6(1)(f) GDPR. We have a legitimate interest in ensuring the reliable presentation of our website.
Where consent has been requested, processing is based solely on Art. 6(1)(a) GDPR and § 25(1) TDDDG, to the extent that the consent includes the storage of cookies or access to information on your end device (e.g., via device fingerprinting) as defined by the TDDDG. Consent can be revoked at any time.

Data Processing Agreement (DPA):
We have concluded a data processing agreement (DPA) with Strato. This contract ensures that personal data of our website visitors is processed strictly in accordance with our instructions and the applicable data protection laws (GDPR).

3. General Information and Mandatory Disclosures

Data Protection

We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection laws and this privacy policy.

When you use this website, various personal data may be collected. Personal data is any data that can personally identify you.
This privacy policy explains what data we collect, how we collect it, and the purpose behind the collection.

Please note that data transmission over the Internet (e.g., communication via email) can be subject to security vulnerabilities. Complete protection of data from access by third parties is not possible.

Responsible Party

The responsible party for data processing on this website is:

Johanna Stangl
Haydngasse 10, 46
8010 Graz
Styria, Austria
Phone: +43 650 4421146
Email: johannastangl04@gmail.com

The responsible party is the individual or legal entity that decides, alone or jointly with others, on the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Duration

Unless a specific retention period is stated in this privacy policy, we retain your personal data only as long as necessary to fulfill the purpose of the processing.
If you submit a legitimate request for deletion or revoke your consent, we will delete your data—unless we are legally obligated to retain it (e.g., retention periods under tax or commercial law). In the latter case, the data will be deleted once those obligations no longer apply.

Legal Basis for Data Processing

We process your personal data on the following legal bases:

  • Art. 6(1)(a) GDPR – based on your consent

  • Art. 9(2)(a) GDPR – for processing special categories of data

  • Art. 49(1)(a) GDPR – if personal data is transferred to third countries with your explicit consent

  • § 25(1) TDDDG – for accessing data on your device (e.g., via cookies or fingerprinting)

  • Art. 6(1)(b) GDPR – to fulfill a contract or pre-contractual measures

  • Art. 6(1)(c) GDPR – to comply with legal obligations

  • Art. 6(1)(f) GDPR – based on legitimate interest

You will find detailed explanations of the applicable legal basis in the relevant sections of this privacy policy.

Recipients of Personal Data

As part of our business operations, we may share your personal data with external service providers. This only occurs:

  • if necessary for contract performance,

  • when required by law (e.g., tax authorities),

  • if there is a legitimate interest according to Art. 6(1)(f) GDPR, or

  • if another legal basis allows the transfer.

If we engage processors, we share personal data only under a valid data processing agreement (DPA). In the case of joint data processing, we enter into a joint controller agreement.

Withdrawal of Your Consent

Many data processing operations are only possible with your explicit consent. You may revoke your consent at any time with future effect.
Data processing carried out before the revocation remains lawful.

Right to Object (Art. 21 GDPR)

Right to object to processing based on Art. 6(1)(e) or (f) GDPR:
You have the right to object, at any time and for reasons relating to your particular situation, to the processing of your personal data based on Art. 6(1)(e) or (f) GDPR. This also applies to any profiling based on these provisions.
If you object, we will no longer process your personal data—unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

Right to object to direct marketing:
Where your personal data is processed for direct marketing purposes, you have the right to object at any time to such processing—including profiling to the extent it is related to such marketing.
If you object, your personal data will no longer be used for direct marketing purposes.

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, place of work, or the place of the alleged infringement. This right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.

Right to data portability

You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract, in a common, machine-readable format, either for yourself or for transfer to a third party. If you request the direct transfer of the data to another controller, this will only be done if technically feasible.

Right to access, rectification, and erasure

Within the framework of applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients, and the purpose of the data processing. You also have the right to have this data rectified or erased, if applicable. You can contact us at any time with questions regarding personal data.

Right to restriction of processing

You have the right to request the restriction of processing of your personal data. You can contact us at any time regarding this. The right to restriction applies in the following cases:

  • If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of processing of your personal data.

  • If the processing of your personal data was/is unlawful, you may request restriction of processing instead of deletion.

  • If we no longer need your personal data but you require it to exercise, defend, or assert legal claims, you have the right to request the restriction of processing instead of deletion.

  • If you have objected pursuant to Art. 21 (1) GDPR, a balance must be struck between your interests and ours. As long as it is not yet determined whose interests prevail, you have the right to request the restriction of processing of your personal data.

If you have restricted the processing of your personal data, such data – aside from being stored – may only be processed with your consent or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.

SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the website operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address bar of the browser changes from "http://" to "https://" and by the lock icon in your browser bar. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

4. Data Collection on This Website

Cookies

Our websites use "cookies." Cookies are small data packets that do no harm to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted after your visit ends. Persistent cookies remain on your device until you delete them yourself or your browser automatically deletes them.

Cookies can be set by us (first-party cookies) or by third-party companies (third-party cookies). Third-party cookies enable the integration of specific services from third parties within websites (e.g., cookies for payment processing).

Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g., shopping cart function or displaying videos). Other cookies are used to analyze user behavior or for advertising purposes.

Cookies that are required to carry out electronic communication processes, to provide certain functions you desire (e.g., shopping cart), or to optimize the website (e.g., cookies for measuring web audience) are stored based on Art. 6 (1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services.

Where consent for the storage of cookies and similar recognition technologies has been requested, processing is based exclusively on this consent (Art. 6 (1)(a) GDPR and § 25 (1) TDDDG); consent can be revoked at any time.

You can configure your browser to notify you about cookie settings, to allow cookies only in individual cases, to exclude cookies for specific cases or in general, and to enable automatic deletion of cookies when the browser is closed. Disabling cookies may limit the functionality of this website.

You can find out which cookies and services are used on this website in this privacy policy.

Contact form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provide, will be stored by us for the purpose of processing your request and in case of follow-up questions. We do not share this data without your consent.

The processing of this data is based on Art. 6 (1)(b) GDPR, if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in effectively processing the requests addressed to us (Art. 6 (1)(f) GDPR) or on your consent (Art. 6 (1)(a) GDPR) if requested; the consent can be revoked at any time.

The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent for storage, or the purpose for data storage no longer applies (e.g., after your request has been fully processed). Mandatory legal provisions – especially retention periods – remain unaffected.

Inquiries by email, telephone, or fax

If you contact us by email, telephone, or fax, your request including all personal data (name, inquiry) resulting from it will be stored and processed by us for the purpose of handling your concern. We do not pass this data on without your consent.

The processing of this data is based on Art. 6 (1)(b) GDPR, if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in effectively processing the inquiries addressed to us (Art. 6 (1)(f) GDPR) or on your consent (Art. 6 (1)(a) GDPR) if requested; the consent can be revoked at any time.

The data you send us via contact inquiries will remain with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your concern has been fully addressed). Mandatory legal requirements – especially legal retention periods – remain unaffected.

5. Plugins and Tools

YouTube

When you visit one of our websites that includes YouTube, a connection to YouTube's servers is established. The YouTube server is informed about which of our pages you have visited.

If you are logged into your YouTube account, you allow YouTube to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.

We use YouTube in extended data protection mode. According to YouTube, videos played in extended data protection mode are not used to personalize browsing on YouTube. Ads shown in this mode are also not personalized. No cookies are set in extended data protection mode. However, so-called Local Storage elements are stored in the user's browser, which can contain personal data and be used for recognition similar to cookies.

Details about extended data protection mode can be found here:
https://support.google.com/youtube/answer/171780

After activating a YouTube video, additional data processing operations may be triggered, over which we have no control.

The use of YouTube is in the interest of an appealing presentation of our online offerings. This constitutes a legitimate interest pursuant to Art. 6 (1)(f) GDPR. If appropriate consent has been requested, processing is based solely on Art. 6 (1)(a) GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's device (e.g., device fingerprinting) as defined by the TDDDG. Consent can be revoked at any time.

For more information on data protection at YouTube, see their privacy policy at:
https://policies.google.com/privacy?hl=en

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards for data processing in the US. Every company certified under the DPF is committed to complying with these data protection standards. More information is available here:
https://www.dataprivacyframework.gov/participant/5780

Source: https://www.e-recht24.de